For CISOs, SOCs, and security leadership in the energy sector

Nord lys.

Shared security toolkit for the Norwegian energy sector

A shared early-warning network for the Norwegian energy sector.

§ 01

The problem

Three conditions, each manageable on its own — together they paint a clear picture:

  1. 01 Threat

    The energy sector is a targeted domain

    Volt Typhoon. Sandworm. Industroyer. State-aligned actors prioritise power supply as a target — and when one Norwegian actor is hit, the others are likely next.

  2. 02 Regulation

    Information-sharing requirements are tightening

    The NIS2 directive, Norway's security act and power-sector preparedness regulations require sector actors to notify and share relevant threat information. Which channel? What auditability? Still unanswered.

  3. 03 Practice

    Today's sharing is manual and slow

    IoCs are shared by email, Signal groups, and shared spreadsheets. No signing, no auditability, no automation. When one peer sees something, hours or days pass before the others know.

§ 02

The solution

  1. 01 Each organisation runs its own Nordlys node locally. The node collects events from its own SIEM, scans for vulnerabilities, and shares signed findings with other peers in real time.
  2. 02 KraftCERT is the trust anchor that signs peer identities — and is itself a peer in the mesh. KraftCERT sees the same as every other participant. No central storage, no hidden channel.
  3. 03 Every share is signed by its source. The receiver can verify who said what, when. Auditability without giving up ownership.
§ 03

Why join?

Nordlys is built for the energy sector's real problems:

A

Early warning from peers

When one peer sees an attack attempt or a new IoC, the whole mesh knows within seconds. Build detection on data from the entire sector — not just your own logs.

B

Compliance without extra bureaucracy

NIS2, Norway's security act, and power-sector preparedness regulations expect information sharing. Nordlys provides a signed, auditable medium — no manual emails or shared spreadsheets.

C

Sovereignty over your own data

No central database. No foreign cloud service. Every organisation owns its own node. KraftCERT signs identities but never sees the payload.

D

Network effect from day one

Value grows with every peer that joins. Individuals from several major energy actors are already engaged — join in and put your organisation on the map.

§ 04

Model

Nordlys is open source. There is no licence fee — but participants are expected to contribute according to capacity.

Licence · NOK 0

Cost: solidarity-based contribution

No cash licence. Contributions are expected proportional to size: large actors like Statnett contribute substantially through development, infrastructure, and coordination. Smaller energy companies can participate without contributing financially — the value to the community lies in their presence in the mesh.

Plugins · MIT-licensed

Extensible via plugins

Plugin architecture based on open interfaces. Custom detections, integrations against internal SIEM/SOAR, and sector-specific modules can ship as open plugins and be shared across peers — without waiting for a central release cycle.

Repo · public

The whole stack is open

All code is published on GitHub. No black box, no hidden components. Security audits and independent code review are explicitly welcome.

§ 05

Core capabilities

I

Event sharing

Security events from SIEM systems are signed locally and propagated to other peers via mesh.

II

Vulnerability management

Local scanning and receipt of shared vulnerabilities with CVSS scoring and status tracking.

III

Peer topology

Visual mesh graph with live RTT, health scoring and event route trails.

IV

Threats and IoCs

Indicators (IP, domain, hash) with TLP marking, signed by source.

§ 06

Initiative

Nordlys is not a corporate project — it is an open initiative driven forward by individuals working at several Norwegian energy companies:

§ 07

How to get started

Three steps from zero to mesh — about as long as it takes to make coffee.

  1. 01 · ~5 min

    Spin up the node

    Docker compose up. The node runs on your own machine or VPS. ~2 GB RAM, sub-minute cold start.

  2. 02 · ~2 min

    Generate access request

    The setup wizard generates a signed access request. Send it to KraftCERT via a secure channel.

  3. 03 · ~30 sec

    Paste invitation

    Once KraftCERT approves, you receive an invitation token. Paste it — the node is live in the mesh.

§ 08

Status

Nordlys is in active development for a demo at TechDay 2026. We welcome feedback, code review, and pilot participants now.