Category
ISMS & Compliance
Topic
Cybersecurity in Smart Cities in accordance with BSI TR-03187
Audience
Local authorities, municipal utilities & IT managers
Reading time
approx. 6 minutes

The digitalisation of urban areas is advancing at a rapid pace. Intelligent transport systems, connected energy supply, smart buildings and digital citizen services are no longer merely visions of the future – they are a reality. However, the more interconnected cities become, the greater their vulnerability to cyberattacks. Cybersecurity is not just a technical necessity, but the foundation for trust and resilience in the smart city. 

Smart Cities: Digitalisation with Risks

Smart cities operate on the basis of data. Sensors, IoT devices, platforms and mobile apps collect and process information in real time to make processes more efficient, from refuse collection to traffic light control. Yet it is precisely this connectivity that creates a multitude of new points of vulnerability.

  • Insecure IoT devices: IoT devices in public spaces are often inadequately secured and can be compromised.

  • Vulnerable interfaces: Interfaces between systems offer potential attack vectors if they are not implemented securely.

  • Centralised data platforms: These process sensitive information, the loss or manipulation of which can have massive consequences.

  • Unclear responsibilities: These make it difficult to establish consistent security strategies between IT departments, municipal utilities and service providers.

The consequences of a cyberattack on a city can be severe, ranging from infrastructure outages and data breaches to a loss of trust among citizens. 

BSI TR-03187: Standardising security, building trust

To provide cities and their partners with a uniform security framework, the BSI has developed Technical Policy TR-03187, which was published in early 2025. It sets out specific security requirements for Urban Data Platforms (UDPs), which play a central role in smart city infrastructures.

🏗️

Secure architecture

Network segmentation, separation of front-end and back-end, use of trusted protocols.

🔑

Access control

Strong authentication mechanisms and clear concepts for rights and roles.

🔒

Data integrity

Protection against tampering through encryption, digital signatures and validation mechanisms.

📡

Monitoring & Response

Logging of security-related events, SIEM systems, Incident Response processes.

The policy also distinguishes between the roles and responsibilities of operators, solution providers and developers, and sets out specific requirements. These can be divided into three levels (1 to 3), with 1 being the lowest level. It is important to note that the protection levels set out in the technical policy do not correspond exactly to those of the BSI’s Basic Protection framework, which should be applied in addition, as it covers further areas that are not directly attributable to a UDP. 

Security strategies for the smart city

Cybersecurity in smart cities must be approached holistically, across all technologies and throughout the organisation.

1

Security by Design

Security requirements must form part of the planning and architecture of new systems from the outset, rather than being added as an afterthought.

2

Zero Trust Principles

No device, user or service is trusted unconditionally; identities are verified and access is continuously monitored.

3

Incident management

Contingency and recovery plans must be tailored to smart city threats, including backup strategies and clear escalation procedures.

4

Regular audits and penetration tests

Vulnerabilities should be proactively identified and rectified, not only after an incident has occurred.

5

Training & Awareness

Local authorities, operators and service providers must be made aware of digital risks and receive ongoing training.

The role of the cybersecurity sector

Cybersecurity companies play a key role in the digital transformation of urban areas. They support cities in the development, implementation and auditing of secure IT infrastructures, both in an advisory and operational capacity.

  • Security concepts: Development in accordance with BSI guidelines such as TR-03187.

  • Technical implementation: Setting up monitoring and defence systems.

  • Risk assessments: Conducting audits and penetration tests.

  • Incident Response: Management and forensic analysis in the event of an incident.

  • Training: For local authority IT and project managers.

“Smart only with security: without a well-thought-out security architecture, the connected city becomes an attack surface rather than a benefit for its citizens.” Mint Secure GmbH 

How Mint Secure supports you

We help local authorities and municipal utilities to operate digital infrastructures in compliance with the law whilst minimising risk.

📐

BSI TR-03187 consultancy

We guide you through the implementation of the requirements for Urban Data Platforms in accordance with BSI guidelines.

🎯

Penetration tests for IoT & UDP

We test sensors, interfaces and central data platforms for exploitable vulnerabilities.

📡

Incident Response & Monitoring

We help you set up SIEM systems and establish clear escalation procedures for emergencies.

Ready to get started? We offer a free initial consultation. Get in touch now.

Conclusion

The smart city brings efficiency, innovation and quality of life, but without security it is vulnerable, susceptible to manipulation and potentially dangerous. The BSI policy TR-03187 provides a technical framework for this, but implementation requires expertise, resources and clear lines of responsibility.

Cybersecurity is the foundation of digital sovereignty; local authorities, technology partners and security providers must take joint responsibility for this.

Mint Secure supports you in making your own smart city infrastructure secure and BSI-compliant. Get in touch with us.