How do you build a strong data foundation to estimate the grid expansion and investment needs accurately?
Helen Electricity Network, a Finnish grid operator, shares their approach. Learn it firsthand 👉
With our software, the Intelligent Grid Platform, we support distribution system operators (DSOs) in supplying electricity to households and businesses. Our Intelligent Grid Platform, or IGP for short, digitizes, automates, and unifies planning and operations processes for future-proof and efficient grid management. As a software-based support system, the IGP turns power grids into digital, flexible, and interactive smart grids.
In our daily work, we handle confidential information, including personal data and grid data. In most countries, the energy supply constitutes critical infrastructure, which makes information from this sector particularly sensitive and in need of protection. At the same time, we support our customers in meeting statutory requirements, including Section 14a of the German Energy Industry Act (EnWG) and Section 9 of the German Renewable Energy Sources Act (EEG), and in addressing their implications for the technical implementation in the IGP.
As a software provider in the energy sector, particularly in the context of critical infrastructure, we carry a particular responsibility for data and information security, including the reliability of our software and secure supporting processes. We are therefore also subject to legislation such as the EU GDPR, the EU AI Act, and the German NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), as well as relevant standards.
Our information security management system is certified to ISO 27001. In addition, we align with further relevant requirements from ISO 27019, ISO 27002, the OWASP Top 10 Web Application Security Risks for web applications, and the Secure Software Development Lifecycle as defined by the German Federal Office for Information Security (BSI).
ISO 27001 defines requirements for an information security management system (ISMS), which contributes indirectly to information security.
Our digital ISMS is based on a risk-based approach, as required by ISO 27001. With the help of the standard, risks are identified that relate to the following three objectives of information security.
These risks are assessed according to their potential impact and prioritized accordingly. We then define controls to reduce the potential impact of these risks. Annex A of ISO/IEC 27001 contains a reference set of 93 information security controls. We define additional controls as needed.
ISO 27001 provides a systematic framework for defining organizational rules and processes to establish, implement, operate, maintain, monitor, review, and continually improve information security.
All risks are assessed individually and in detail, and the acceptability of each risk is determined. Appropriate controls are defined on this basis. The framework for these rules and processes is defined by ISO 27001.
Following the German Bundestag's adoption of the NIS2 implementing legislation in November 2025 and its entry into force on December 6, 2025, envelio was classified as an "important entity." Following an internal assessment and the implementation of additional measures, we confirmed compliance with the applicable NIS2 requirements.
We recognize the importance to our customers of the BDEW Whitepaper, an established energy-sector standard in the German-speaking DACH region (currently version 3.0). The whitepaper describes security requirements for components and systems as well as for maintenance processes, project processes, and development processes. These requirements are primarily addressed to energy suppliers and their three core areas: "operations management / control systems and system operations," "transmission technology / voice communications," and "secondary, automation and telecontrol technologies." Against this background, not all requirements are directly transferable to envelio or the Intelligent Grid Platform (IGP).
We already fulfill the majority of the requirements. For some of the remaining requirements, measures have been defined or are currently being implemented. Some requirements are not directly applicable to our role and to the context in which the IGP is used, and are therefore classified as permanently not applicable.
Our ISMS was first certified according to ISO 27001 in December 2019 and has maintained its certification through regular recertification. The certificate is available for download. On request, we are happy to provide the public version of our Statement of Applicability. To provide greater transparency and build trust, we provide some insights into our information security process. If you require further information, please contact our security department at security@envelio.de.
Our information security process begins when you contact us, for example by e-mail. We always treat your data confidentially.
Our employees are provided with S/MIME certificates to enable encrypted communication with their contacts. For larger data transfers, we provide an upload server that ensures the encrypted transmission of information.
As a general principle, we follow the need-to-know principle for all types of information and data, and the least-privilege principle for access to directories and systems and for physical access to secure areas.
Your data from the IGP systems and from the business relationship is stored and transmitted securely and in encrypted form. Access is limited to selected employees who need the information to perform their duties.
For the storage of information and data in the cloud, we only use the services of ISO 27001-certified data centers.
In these data centers, we build our own secure infrastructure, eliminating the need to operate systems locally on our premises.
We monitor our endpoints and systems around the clock. In the event of anomalous behavior, a monitoring tool alerts us so that we can act quickly.
In the event of an information security incident, our information security team specializes in emergency management. A business continuity plan (BCP) plan is in place, and regular emergency exercises are conducted.
Through our internally established communication channels, we provide information on currently relevant topics and developments in the field of information security. Regular training and awareness sessions also ensure that our workforce is always up to date. This covers not only information security and data protection, but also other compliance training, for example on anti-money laundering and antitrust law.