Early warning from peers
When one peer sees an attack attempt or a new IoC, the whole mesh knows within seconds. Build detection on data from the entire sector — not just your own logs.
Shared security toolkit for the Norwegian energy sector
A shared early-warning network for the Norwegian energy sector.
Three conditions, each manageable on its own — together they paint a clear picture:
Volt Typhoon. Sandworm. Industroyer. State-aligned actors prioritise power supply as a target — and when one Norwegian actor is hit, the others are likely next.
The NIS2 directive, Norway's security act and power-sector preparedness regulations require sector actors to notify and share relevant threat information. Which channel? What auditability? Still unanswered.
IoCs are shared by email, Signal groups, and shared spreadsheets. No signing, no auditability, no automation. When one peer sees something, hours or days pass before the others know.
Nordlys is built for the energy sector's real problems:
When one peer sees an attack attempt or a new IoC, the whole mesh knows within seconds. Build detection on data from the entire sector — not just your own logs.
NIS2, Norway's security act, and power-sector preparedness regulations expect information sharing. Nordlys provides a signed, auditable medium — no manual emails or shared spreadsheets.
No central database. No foreign cloud service. Every organisation owns its own node. KraftCERT signs identities but never sees the payload.
Value grows with every peer that joins. Individuals from several major energy actors are already engaged — join in and put your organisation on the map.
Nordlys is open source. There is no licence fee — but participants are expected to contribute according to capacity.
No cash licence. Contributions are expected proportional to size: large actors like Statnett contribute substantially through development, infrastructure, and coordination. Smaller energy companies can participate without contributing financially — the value to the community lies in their presence in the mesh.
Plugin architecture based on open interfaces. Custom detections, integrations against internal SIEM/SOAR, and sector-specific modules can ship as open plugins and be shared across peers — without waiting for a central release cycle.
All code is published on GitHub. No black box, no hidden components. Security audits and independent code review are explicitly welcome.
Security events from SIEM systems are signed locally and propagated to other peers via mesh.
Local scanning and receipt of shared vulnerabilities with CVSS scoring and status tracking.
Visual mesh graph with live RTT, health scoring and event route trails.
Indicators (IP, domain, hash) with TLP marking, signed by source.
Nordlys is not a corporate project — it is an open initiative driven forward by individuals working at several Norwegian energy companies:
Three steps from zero to mesh — about as long as it takes to make coffee.
Docker compose up. The node runs on your own machine or VPS. ~2 GB RAM, sub-minute cold start.
The setup wizard generates a signed access request. Send it to KraftCERT via a secure channel.
Once KraftCERT approves, you receive an invitation token. Paste it — the node is live in the mesh.
Nordlys is in active development for a demo at TechDay 2026. We welcome feedback, code review, and pilot participants now.