Blog
Blog

Cybersecurity is mandatory: what gas suppliers need to know now

Regulierung 22 January 2025 By fortControl Editorial Team

Since 1 July 2025 the ICT minimum standard for gas supply in Switzerland has been binding. Operators of gas pipelines have to meet the G1008 requirements applicable to their protection level and demonstrate this to the competent supervisory authority.

For the gas sector, cybersecurity is therefore no longer just good practice, but part of the regulatory requirements.

The key question for companies today is therefore: are the required measures not only defined, but also implemented, documented and permanently manageable?

Why cybersecurity is decisive for gas supply

Swiss gas supply is increasingly dependent on digital systems. Control systems, network monitoring, remote access, communication systems, ERP applications and interfaces to external service providers enable efficient operations – but at the same time create new dependencies and attack surfaces.

A cyber incident can therefore go far beyond a classic IT outage. If systems relevant to operations are impaired, this can affect processes, plants and ultimately security of supply.

That is precisely why binding cybersecurity requirements have applied to gas pipeline operators since 1 July 2025. The Federal Office for Cybersecurity (BACS) today explicitly designates the ICT minimum standard for gas supply as a mandatory industry standard.

What is G1008?

G1008, the “minimum standard for the security of information and communication technology in gas supply”, is the sector-specific ICT minimum standard for Swiss gas supply.

The 2024 edition was developed together with industry representatives and the competent federal agencies. The aim is to provide companies with a practical instrument for assessing and improving their cybersecurity.

The cybersecurity programme comprises 108 measures and is oriented, among other things, towards established international standards and frameworks such as the NIST Cybersecurity Framework and ISO/IEC 27001.

The point is not to prescribe the same technical solutions for all companies. Instead, G1008 defines requirements for different areas of cybersecurity and specifies, depending on the criticality of the company, which protection level has to be achieved.

Binding since 1 July 2025

The legal basis is found in the Pipeline Safety Ordinance (RLSV). Art. 39a para. 4 states that the requirements of the ICT minimum standard for gas supply, edition May 2024, are binding for operators of gas pipelines.

Even more important for practical implementation: operators have to demonstrate to the supervisory authority that they meet the requirements of the protection level applicable to them.

It is therefore not enough to have merely planned or broadly introduced cybersecurity measures. Companies have to be able to show traceably:

  • which requirements apply to them
  • what the current implementation status looks like
  • which measures have been implemented
  • where action is still required
  • who is responsible for open measures
  • how implementation is documented and verified

This is exactly where cybersecurity becomes a permanent management task.

Three protection levels for different operators

G1008 follows a risk-based and proportionate approach. Not every operator has to meet the same requirements. Companies are assigned to protection level A, B or C.

For gas pipeline operators, the average volume of energy transported over the last five calendar years is generally considered. This includes both gas distributed to end customers and gas transported onwards to other gas network operators.

  1. A More than 2,600 GWh per year Highest requirements. Also assigned automatically: gas pipeline installations with an operating pressure above 5 bar and a pipeline length of more than 15 kilometres.
  2. B More than 400 up to 2,600 GWh per year A graduated set of binding measures between protection level A and C.
  3. C Up to 400 GWh per year Reduced scope. According to the SVGW guide G15004, protection level C focuses on 39 binding measures.

The decisive figure is the average volume of energy transported over the last five calendar years — distributed gas and gas transported onwards to other network operators combined.

Assignment of protection levels according to G1008, edition May 2024.

The requirements are graduated accordingly. Protection level A sets the highest requirements, while a reduced scope of binding measures is provided for smaller operators in protection level C. Further measures can nevertheless make sense depending on the individual risk situation.

What does the obligation mean in practice?

The challenge is not to fill in a questionnaire once.

G1008 requires a structured security level across different areas. This includes, for example, knowledge of your own systems and dependencies, dealing with risks, protecting critical systems, detecting security events and the ability to respond to incidents and restore operations.

In practice this means:

Create an inventory Which IT and OT systems, applications, interfaces and dependencies are relevant for operations?

Assess risks Which cyber risks exist and what effects could they have on operations and security of supply?

Determine maturity or implementation status Where does the company already meet the requirements – and where are there gaps?

Define measures Concrete improvement measures have to be derived from identified deviations.

Assign responsibilities Every measure needs a responsible person and a binding due date.

Document evidence Implementation has to be presentable to the supervisory authority in a traceable way.

Review regularly Cybersecurity changes. Assessments, measures and documentation therefore have to be kept continuously up to date.

A self-assessment is the beginning – not the end

For implementation, the industry provides a self-assessment tool, among other things. Companies can use it to systematically assess their current status and identify which requirements call for action. In addition, SVGW has published the G15004 guide, which supports smaller companies in particular in understanding and implementing the requirements of protection level C.

An assessment alone, however, does not yet create cybersecurity. The decisive step begins afterwards: what happens with the identified gaps?

Who takes on the measure? What priority does it have? By when does it have to be implemented? What evidence is available? And has it been verified that the measure is actually effective?

This is exactly where it becomes clear whether a one-off inventory turns into functioning security management.

Does that require an ISMS?

G1008 does not simply prescribe across the board that companies introduce an ISMS certified to ISO/IEC 27001. A structured information security management system can nevertheless make implementation considerably easier.

Because many of the central tasks are the same:

  • identify and assess risks
  • define security measures
  • assign responsibilities
  • monitor implementation status
  • document evidence
  • trace changes
  • manage improvements continuously

Especially when this information has so far been spread across Excel spreadsheets, Word documents, emails and various storage locations, the effort for updating and providing evidence can quickly become large. An ISMS creates a common framework for this.

From 108 measures to a manageable process

The real challenge of G1008 therefore lies less in the number of measures. What matters is making them permanently manageable.

A company has to be able to see: where do we stand today? Which requirements apply to us? Which gaps exist? Which measures are under way? Who is responsible? And can we demonstrate implementation traceably?

Anyone who can bring this information together at any time is not only better prepared for a review. They also improve their own cyber resilience.

How fortControl supports implementation

fortControl helps companies bring requirements, assessments, risks and measures together in a structured process. The ICT minimum standard can be mapped as a framework and the current implementation status recorded systematically.

Identified deviations do not remain isolated entries in an assessment. They can be linked directly to risks and concrete measures.

fortControl makes visible:

  • which requirements are already met
  • where action is still required
  • which measures have been derived from this
  • who is responsible for their implementation
  • which due dates apply
  • which evidence is available
  • how the implementation status is developing

Dashboards and analyses create a consolidated view for those responsible and for management. This turns an extensive catalogue of requirements into a manageable and traceable security process.

How fort IT can support you

Not every company has the internal resources or experience to implement the G1008 requirements entirely on its own.

fort IT supports gas suppliers in determining their own implementation status, identifying security gaps and deriving suitable measures. Depending on the starting point, this includes:

Security assessments Structured evaluation of the existing security level and identification of the need for action.

ISMS consulting Support in setting up and further developing structured information security management.

Measure planning and implementation support Prioritisation and guidance for improvement measures.

fortControl Digital management of assessments, risks, measures, responsibilities and evidence.

This makes it possible to combine expert consulting with digital management.

Meet the obligation – strengthen cyber resilience

Since 1 July 2025 the situation has been clear: the ICT minimum standard for gas supply is binding.

For operators, the question is therefore no longer whether they should engage with G1008. What matters is how well the requirements are already implemented and how traceably that implementation status can be demonstrated. BACS explicitly confirms the mandatory character of the industry standard.

G1008 should not be regarded solely as a regulatory obligation. It offers companies a structured framework for making cyber risks visible, addressing weaknesses in a targeted way and increasing the resilience of their critical systems.

Understand requirements. Identify risks. Implement measures. Demonstrate progress.

With a structured ISMS and central management via fortControl, the regulatory requirement becomes a continuous process – and cybersecurity becomes an integral part of security of supply.

Loslegen

Risiken im Blick. Sicherheit im Griff.

Lernen Sie fortControl in einer persönlichen Demo kennen.

fortControl – Risikomanagement und Informationssicherheit einfach steuern.