
The digitalisation of urban areas is advancing at a rapid pace. Intelligent transport systems, connected energy supply, smart buildings and digital citizen services are no longer merely visions of the future – they are a reality. However, the more interconnected cities become, the greater their vulnerability to cyberattacks. Cybersecurity is not just a technical necessity, but the foundation for trust and resilience in the smart city.
Smart Cities: Digitalisation with Risks
Smart cities operate on the basis of data. Sensors, IoT devices, platforms and mobile apps collect and process information in real time to make processes more efficient, from refuse collection to traffic light control. Yet it is precisely this connectivity that creates a multitude of new points of vulnerability.
-
Insecure IoT devices: IoT devices in public spaces are often inadequately secured and can be compromised.
-
Vulnerable interfaces: Interfaces between systems offer potential attack vectors if they are not implemented securely.
-
Centralised data platforms: These process sensitive information, the loss or manipulation of which can have massive consequences.
-
Unclear responsibilities: These make it difficult to establish consistent security strategies between IT departments, municipal utilities and service providers.
The consequences of a cyberattack on a city can be severe, ranging from infrastructure outages and data breaches to a loss of trust among citizens.
BSI TR-03187: Standardising security, building trust
To provide cities and their partners with a uniform security framework, the BSI has developed Technical Policy TR-03187, which was published in early 2025. It sets out specific security requirements for Urban Data Platforms (UDPs), which play a central role in smart city infrastructures.
Secure architecture
Network segmentation, separation of front-end and back-end, use of trusted protocols.
Access control
Strong authentication mechanisms and clear concepts for rights and roles.
Data integrity
Protection against tampering through encryption, digital signatures and validation mechanisms.
Monitoring & Response
Logging of security-related events, SIEM systems, Incident Response processes.
The policy also distinguishes between the roles and responsibilities of operators, solution providers and developers, and sets out specific requirements. These can be divided into three levels (1 to 3), with 1 being the lowest level. It is important to note that the protection levels set out in the technical policy do not correspond exactly to those of the BSI’s Basic Protection framework, which should be applied in addition, as it covers further areas that are not directly attributable to a UDP.
Security strategies for the smart city
Cybersecurity in smart cities must be approached holistically, across all technologies and throughout the organisation.
Security by Design
Security requirements must form part of the planning and architecture of new systems from the outset, rather than being added as an afterthought.
Zero Trust Principles
No device, user or service is trusted unconditionally; identities are verified and access is continuously monitored.
Incident management
Contingency and recovery plans must be tailored to smart city threats, including backup strategies and clear escalation procedures.
Regular audits and penetration tests
Vulnerabilities should be proactively identified and rectified, not only after an incident has occurred.
Training & Awareness
Local authorities, operators and service providers must be made aware of digital risks and receive ongoing training.
The role of the cybersecurity sector
Cybersecurity companies play a key role in the digital transformation of urban areas. They support cities in the development, implementation and auditing of secure IT infrastructures, both in an advisory and operational capacity.
-
Security concepts: Development in accordance with BSI guidelines such as TR-03187.
-
Technical implementation: Setting up monitoring and defence systems.
-
Risk assessments: Conducting audits and penetration tests.
-
Incident Response: Management and forensic analysis in the event of an incident.
-
Training: For local authority IT and project managers.
How Mint Secure supports you
We help local authorities and municipal utilities to operate digital infrastructures in compliance with the law whilst minimising risk.
BSI TR-03187 consultancy
We guide you through the implementation of the requirements for Urban Data Platforms in accordance with BSI guidelines.
Penetration tests for IoT & UDP
We test sensors, interfaces and central data platforms for exploitable vulnerabilities.
Incident Response & Monitoring
We help you set up SIEM systems and establish clear escalation procedures for emergencies.
Ready to get started? We offer a free initial consultation. Get in touch now.
Conclusion
The smart city brings efficiency, innovation and quality of life, but without security it is vulnerable, susceptible to manipulation and potentially dangerous. The BSI policy TR-03187 provides a technical framework for this, but implementation requires expertise, resources and clear lines of responsibility.
Cybersecurity is the foundation of digital sovereignty; local authorities, technology partners and security providers must take joint responsibility for this.
Mint Secure supports you in making your own smart city infrastructure secure and BSI-compliant. Get in touch with us.

