Book an Appointment

Systems for Attack Detection (SzA)

How to implement the obligation to deploy attack detection systems under § 31 BSIG in a structured way – from the BSI guidance through log sources and detection engineering to the required evidence.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

3areas in the BSI guidance: logging, detection and response
0–5implementation-level model – as a rule, at least level 3 must be achieved for the evidence
3years between evidence submissions under § 39 BSIG (previously every two years)
222techniques in the ATT&CK Enterprise matrix v19 – alongside 15 tactics and 475 sub-techniques

Operators of critical facilities in Germany are legally required to deploy attack detection systems (Systeme zur Angriffserkennung, SzA) – governed, since the transposition of NIS2, by § 31(2) BSIG. What counts as appropriate is specified by the BSI in its guidance document (Orientierungshilfe) with MUST, SHOULD and MAY requirements and an implementation-level model from 0 to 5. Whether attack detection actually works, however, is decided not on paper but by the coverage of log sources, the quality of detection rules and well-rehearsed response processes. This article puts the legal situation, the BSI requirements and the technical building blocks into context – from Sigma rules and ATT&CK mapping to the use-case lifecycle.

From obligation to evidence

Five milestones from the first edition of the BSI guidance to ATT&CK v19 – tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

The interplay of technology building blocks

SIEM, EDR and NDR compared – no single tool fulfils the requirements on its own; what matters is documented coverage of the entire scope.

Central analysis
  • Centrally collects and correlates log data from heterogeneous sources.
  • Delivers the required continuous, automated analysis with alerting when thresholds are exceeded.
log dataheterogeneous sourcesalerting

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Bundesrepublik Deutschland / gesetze-im-internet.de · 2025

Gesetz über das Bundesamt für Sicherheit in der Informationstechnik und über die Sicherheit in der Informationstechnik von Einrichtungen (BSIG)

New version enacted through the NIS2 Implementation Act, in force since 06.12.2025; the key provisions are § 2 (legal definition of SzA), § 31(2) (deployment obligation for operators of critical facilities) and § 39 (evidence every three years).

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2024

Orientierungshilfe zum Einsatz von Systemen zur Angriffserkennung, Version 1.1

Specifies the MUST, SHOULD and MAY requirements for logging, detection and response and defines the implementation-level model 0–5 for providing evidence.

The MITRE Corporation · 2026

MITRE ATT&CK v19 (Updates – April 2026)

Current version of the knowledge base; Enterprise matrix with 15 tactics, 222 techniques and 475 sub-techniques as the reference taxonomy for detection coverage mapping.

SigmaHQ · 2026

About Sigma – Sigma Detection Format

Documentation of the open, YAML-based signature format for log events, including conversion into SIEM query languages via sigma-cli and pySigma.

SigmaHQ (GitHub) · 2026

SigmaHQ/sigma – Main Sigma Rule Repository

Community-maintained rule repository whose detection rules can be translated into product-specific SIEM queries.

Ready to make your attack detection audit-proof?

We support you with the gap analysis against the BSI guidance, with detection engineering and with providing evidence under § 39 BSIG. Contact us for a no-obligation initial consultation.