Is your organisation NIS2 compliant?
Take the free check — results in 2 minutes →
OT Security for Municipalities plays a crucial life in daily life.

OT Security for Municipalities: Protecting the Systems That Keep a City Running

15 minutes reading time

OT security for municipalities means knowing, monitoring and protecting the technology that runs physical public services: pumping stations, wastewater installations, movable bridges, locks, traffic control systems and the building management in town halls, sports centres and swimming pools. These systems are increasingly connected, often managed by external vendors, and in many municipalities still outside the view of the security team. Under NIS2 that is becoming hard to defend, because the duty of care covers the whole service, not only the office IT.

Key takeaways

  • Municipal OT (pumping stations, bridges, traffic systems, building management) is often a blind spot: Dutch municipal CISOs gave their own OT security an average score of 5.0 out of 10 in 2024.
  • Public administration was the most targeted sector in the EU between July 2024 and June 2025 (ENISA), and ransomware was particularly prevalent against municipalities.
  • NIS2 lets each member state decide whether local government is in scope. The Netherlands did: since 15 August 2026 municipalities are essential entities under the Cyberbeveiligingswet.
  • You cannot secure what you cannot see. A complete, current OT asset inventory and continuous monitoring are the starting point.
  • Passive monitoring fits municipal OT, because it gives visibility without touching fragile, unpatchable systems.

In this article we explain which OT a municipality typically runs, why it stays out of sight, what NIS2 asks of local government, and how to get a grip on it without disrupting the services residents rely on every day.

What is OT in a municipality?

Operational technology (OT) is the hardware and software that monitors and controls physical processes. In a factory that is the production line. In a municipality it is the infrastructure of public space, often called “IT in the street”. A Dutch survey among municipal CISOs found that a municipality is responsible for around five types of OT objects on average. Typical examples:

  • Water and wastewater: sewage pumping stations, stormwater pumps and wastewater installations, controlled by PLCs and a central telemetry or SCADA system.
  • Mobility: movable bridges, locks, traffic control installations, tunnels, matrix signs and parking garages.
  • Buildings: heating, ventilation, access control and energy management in town halls, schools, sports centres and swimming pools. We wrote more about this in our article on BMS cybersecurity.
  • Public space: cameras, IoT sensors, street lighting controllers, underground waste containers, EV chargers and solar installations.

What these systems have in common: they run for 15 to 25 years, they speak industrial protocols such as Modbus, BACnet or Siemens S7 instead of normal IT traffic, and they were built for availability, not for security. Many are connected through a VLAN, a 4G router with its own SIM card, or a remote access connection for the supplier.

Why is municipal OT a security blind spot?

The problem is rarely a lack of technology. It is a lack of overview and ownership. The OT belongs to the department for public space or water management, the maintenance is done by suppliers, and the security team sits in the IT department. Nobody sees the full picture.

The Dutch information security service for municipalities (IBD) said exactly this in May 2025. In a position paper it stated that municipalities still pay too little attention to OT. The main challenges it named:

  • Ageing systems that run for years without updates and were not designed with modern security in mind.
  • Knowledge gaps, because municipal IT teams traditionally focus on information systems, not on OT.
  • Outsourcing, especially in smaller municipalities, where OT including management and maintenance is often done by suppliers. That makes supplier management a core part of OT security.
  • No standard approach, so every municipality has to find its own solution for similar systems.

The last survey with hard numbers dates from early 2024. Researchers of The Hague University of Applied Sciences asked 65 municipal CISOs and security advisers, on behalf of the Association of Netherlands Municipalities (VNG) and the IBD, about their OT. The results:

Finding (Dutch municipalities, early 2024)Result
Average score for own OT security5.0 out of 10
Gave their own municipality a failing score57%
Average score for configuration management4.5 out of 10
Have OT security policy or procedures in placeless than a quarter
Do not know how OT management is organised20%
Little or no involvement of the board75%

One CISO summed it up: “OT and IoT are still largely a blind spot. We are working on it.” The municipalities that scored better on configuration management mentioned a CMDB and network discovery with monitoring. In other words: the ones that can see their assets, manage them better.

How big is the threat for local government?

Local government is not a side target. The ENISA Threat Landscape 2025, covering July 2024 to June 2025, shows that public administration was the most targeted sector in the EU, with 38.2% of incidents where the sector was known. Most of these were hacktivist DDoS attacks on websites, but not all of them:

  • Ransomware against EU public administration was, in ENISA’s words, “particularly prevalent against municipalities”.
  • State-linked groups targeted government entities across several member states, including municipal administrations, for espionage.
  • At least one pro-Russian hacktivist group claimed an intent to target operational technology, next to public administration and transport.

On the OT side, the Dragos 2026 OT Cybersecurity Year in Review estimates that fewer than 10% of OT networks worldwide have network visibility and monitoring. Dragos also describes how attacks on exposed PLCs and poorly secured HMIs led to water-system outages and unauthorised parameter changes at US water facilities. Those are exactly the kind of devices that sit in a municipal pumping station.

What a successful attack means for a municipality is easy to picture. Pumps that can be run by hand for a few hours, but not for days, with flooding or surface water pollution as a result. Bridges or traffic lights that stop working and block emergency services. Or a building management system that gives an attacker a route into the office network. The impact is not only data, it is public safety and trust.

Does NIS2 apply to municipalities?

It depends on the country, and often on what the municipality does. The NIS2 Directive (EU) 2022/2555 covers public administration at central and regional level. For local government, Article 2(5)(a) leaves the choice to each member state: they may decide to bring “public administration entities at local level” into scope. Separately, a municipality or municipal company can fall under NIS2 through other sectors in Annex I, for example when it collects or treats urban wastewater as a core activity.

So the first step for any municipality is simple: check how your national law has implemented NIS2, and which of your services are in scope.

The Netherlands as an example: the Cyberbeveiligingswet

The Netherlands chose to include municipalities. Since 15 August 2026 the Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, applies without a transition period, and municipalities are classed as essential entities. According to the VNG, this means:

  • a cyber risk analysis and appropriate measures, based on the BIO2 (Baseline Informatiebeveiliging Overheid), the mandatory security baseline for all Dutch government, built on ISO 27001 and ISO 27002;
  • registration in the national entity register;
  • reporting significant incidents within 24 hours via the NCSC;
  • mandatory cyber training for the mayor and aldermen, who are responsible as the management body;
  • supervision by the Dutch Authority for Digital Infrastructure (RDI), which can request information, inspect and enforce.

The VNG made clear in its member letter of August 2026 that this also covers OT, such as the control of bridges, locks and traffic lights. For OT, two controls quickly become concrete: a complete and current asset inventory, and monitoring of what happens on the network. We explain why an IT CMDB alone is not enough in Cbw and NIS2: why your CMDB is not complete once OT is in scope.

Other member states made different choices, so always check your national transposition. But the direction is the same everywhere: supervisors want to see that measures work in practice, not only that a policy exists.

What does good OT security for municipalities look like?

There is no need to start with a big programme. The municipalities that make progress start with visibility and build from there. In practice that means six steps.

1. Build a complete and current OT asset inventory

Know which devices are on the network, what type and vendor they are, which firmware they run and where they are. Not a spreadsheet from the last tender, but an inventory that updates itself when something changes. Our article OT asset visibility: what good looks like goes deeper into this.

2. Map how systems communicate

Which devices talk to each other, to the office network, to the internet and to suppliers? This is where you find the 4G router nobody remembers, or the pumping station that is reachable from the internet. It is also the only way to check if your network segmentation works in practice and not only on a drawing. A firewall alone does not give you this picture, as we explain in IT vs OT security.

3. Get a grip on supplier access

Much municipal OT is maintained remotely by suppliers. Know which connections exist, who uses them and when. Make supplier management part of your OT security, as the IBD also advises.

4. Monitor continuously and alert on anomalies

A one-time scan shows the situation of one day. OT changes over time: a laptop of a technician, a new sensor, a changed setpoint. Continuous monitoring with alerting tells you when something deviates, 24/7, so you can act before it becomes an incident.

5. Link vulnerabilities to risk

Most OT cannot be patched quickly. So you need to know which vulnerabilities (CVEs) apply to which devices, and which of those really matter. Expressing risk in euros helps the board make decisions.

6. Connect OT to the processes you already have

OT security should not become a separate island. Feed the OT inventory into the CMDB, and send alerts to the existing service desk or SOC. That way IT and the department for public space work from the same information.

Why does passive monitoring fit municipal OT?

Active scanning tools send requests to every device to find out what it is. On an office network that is fine. On a 15-year-old PLC in a pumping station it is a risk: older OT devices can react badly to unexpected traffic, and nobody wants to explain why a bridge stopped during a scan.

Passive monitoring works differently. A sensor connects to a SPAN port or network TAP on the wired (ethernet) network and only listens to a copy of the traffic. It never sends anything into the OT network. From that traffic it recognises devices, protocols, firmware and communication patterns. For municipal OT this has clear benefits:

  • No impact on operations. A pumping station or bridge in use notices nothing.
  • No agents. PLCs, HMIs and controllers cannot run security software, and with passive monitoring they do not need to.
  • Works with legacy. Old and unpatched devices are visible too, without touching them.
  • Fast to deploy. A sensor on the right switch gives a first inventory within hours.

What about remote locations?

Municipal assets are spread over a wide area. A pumping station on the edge of town or a bridge with its own 4G connection is not on the town hall switch. In many cases that is not a problem: the traffic of these sites comes together at a central point, such as the telemetry or SCADA control centre or the VPN gateway. A sensor at that point covers all sites that report into it.

For networks that do not come together anywhere, Nautilus has an integration with P-X Systems. P-X places passive nodes at the remote site and sends the data over its own radio network, separate from the municipal network and the internet. That information arrives in the Nautilus platform and is monitored there together with the rest of the network.

From policy on paper to evidence that it works

Under NIS2 the question is no longer only “do you have a policy?” but “can you show it works?”. For the OT part, continuous monitoring gives you the evidence:

  • a current asset inventory with history, exportable for your auditor;
  • proof of 24/7 monitoring, including the alerts it produced;
  • a recorded trail of issues: what was found, who picked it up and when it was resolved.

This evidence supports your ISMS, your BIO2 or national baseline reporting, and questions from the supervisor. Every statement can be traced back to an observation on the network, which makes an audit much more concrete.

One principle matters here: a monitoring platform delivers evidence, not the score. The judgement on maturity and compliance stays with the municipality, its auditor and the supervisor. Tools that promise to make you “NIS2 compliant” skip that step, and supervisors know it.

How Nautilus helps municipalities

Nautilus is a European platform for passive OT, IoT and IT monitoring, hosted in a Dutch data centre. For municipalities it brings the OT in public space and the IT in the office into one view:

  • Passive asset discovery of all OT, IoT and IT devices, with category, type and vendor, updated continuously.
  • Protocol insight into the traffic of OT and building management, including Modbus, BACnet, Siemens S7, PROFINET and OPC-UA.
  • Network visibility of who talks to whom, between OT, IT, the internet and suppliers.
  • Vulnerability mapping of observed firmware and versions to known CVEs, prioritised by risk.
  • 24/7 detection and alerting on unusual behaviour, unknown connections and unexpected commands, enriched with threat intelligence.
  • Risk in euros and executive reporting the mayor and aldermen can understand.
  • Integrations with TOPdesk, ServiceNow, CMDBs, Microsoft Sentinel and other SIEMs. All connections are outbound from Nautilus.
  • European hosting, including the AI language model, with no dependency on US cloud providers. Each municipality gets its own separated environment.

Read more on our page for municipalities and governments.

How to start

  1. Traffic analysis. Record network traffic at a central point, ideally for at least 72 hours. Nautilus processes it once into a report with devices, protocols, vulnerabilities and anomalies. A snapshot, and a strong starting point.
  2. Sensor in place. A physical or free virtual sensor on a SPAN port. The first inventory is visible within hours, a full rollout per site usually takes one to two weeks.
  3. Continuous monitoring. A monthly subscription based on the number of active devices, which grows and shrinks with your environment.

We work with consulting and integration partners, so municipalities get advice, implementation and follow-up from one team. In the Netherlands, for example, we work together with Legian.

Frequently asked questions about OT security for municipalities

What is OT security for municipalities?

OT security for municipalities is the protection of the operational technology that runs public services, such as pumping stations, wastewater installations, movable bridges, locks, traffic control systems and building management. It starts with a complete inventory of these systems and continuous monitoring of their network traffic, so problems are detected before they affect residents.

Do municipalities fall under NIS2?

NIS2 lets each EU member state decide whether local government is in scope (Article 2(5)(a)). Some countries included municipalities, others did not. A municipality can also fall under NIS2 through another sector, for example wastewater. In the Netherlands municipalities are essential entities under the Cyberbeveiligingswet since 15 August 2026.

Does NIS2 also cover OT, or only IT?

The duty of care covers the network and information systems that support a service, and that includes OT. The Dutch association of municipalities (VNG) explicitly mentions the control of bridges, locks and traffic lights as falling under the Cyberbeveiligingswet requirements.

What is the BIO2?

The BIO2 (Baseline Informatiebeveiliging Overheid) is the mandatory information security baseline for all Dutch government organisations, based on ISO 27001 and ISO 27002. Under the Cyberbeveiligingswet it is the way Dutch municipalities fulfil their duty of care.

Is passive OT monitoring safe for old systems like PLCs?

Yes. A passive sensor only listens to a copy of the network traffic via a SPAN port or TAP and never sends packets into the OT network. That makes it suitable for legacy PLCs and controllers that cannot be patched or scanned.

How can a municipality monitor remote sites like pumping stations?

In most cases the traffic of remote sites comes together at a central point, such as the telemetry or SCADA control centre or the VPN gateway, where one sensor can monitor all connected sites. For sites without such a connection, Nautilus has an integration with P-X Systems, which brings data from remote networks into the Nautilus platform over a separate radio network.

Where should a municipality start?

Start with visibility: a traffic analysis or a sensor at a central point gives a first inventory of OT devices, their communication and their vulnerabilities. From there you can prioritise, set up continuous monitoring and build the evidence your supervisor will ask for.

Want to know what OT is running in your municipality?

Organisations that start monitoring their OT are often surprised by what they find in the first days: devices nobody had on a list, supplier connections that were forgotten, or a route from the office network straight to a pumping station. That is not a failure. It is the starting point.

Book a demo or contact me directly at jeroen@nautilus-ot.com. Want a quick first impression? Take the free NIS2 compliance check, results in 2 minutes.

Jeroen van Es Chief Commercial Officer | Nautilus OT

Foto van Jeroen van Es

Jeroen van Es

Chief Commercial Officer | Nautilus OT

Share:

OT Security for Municipalities plays a crucial life in daily life.

Related articles

Cbw and NIS2: why your CMDB is not complete once OT is in scope

Read more

OT MDR: The Visibility Foundation Every Industrial Organisation Needs

Read more

IT vs OT Security: Why Your Standard Firewall Is Not Enough

Read more