---
titel: "Industries: Energy, Manufacturing, MedTech, Aviation · SACOSI"
url: https://sacosi.ch/en/industries
seite: /en/industries
stand: 2026-09-24
beschreibung: "IT advisory for industries with high criticality in Switzerland and Germany: energy, manufacturing, MedTech and aviation, with the rules that apply to each."
---

> Knowledge version of the page https://sacosi.ch/en/industries. It contains the full text, including what is shortened or collapsible on the page itself. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner, Zürich.

# Where an IT outage hits the business immediately.

**Short answer:** I work primarily for industries where IT is critical: energy, manufacturing, MedTech and aviation. There, in addition to data protection and standards, separate rules apply, from the ICT minimum standard for electricity supply through TISAX and the medical devices ordinances to Part-IS in aviation. My largest engagements and the term Situational Awareness both come from aviation.

## [IT in energy supply](https://sacosi.ch/en/industries/energy)

Security of supply depends on control systems and networks that must not fail.

Typically relevant: ICT minimum standard under the Electricity Supply Ordinance (StromVV), reporting obligation for cyberattacks (Information Security Act, ISG), the NIS2 Directive, ISO/IEC 27001, the Swiss Federal Act on Data Protection (FADP).

[More on energy](https://sacosi.ch/en/industries/energy)

## [IT in manufacturing](https://sacosi.ch/en/industries/manufacturing)

A halt in production immediately costs revenue and the ability to deliver.

Typically relevant: TISAX, the Cyber Resilience Act (CRA), the NIS2 Directive, ISO 9001, ISO/IEC 27001, the EU General Data Protection Regulation (GDPR).

[More on manufacturing](https://sacosi.ch/en/industries/manufacturing)

## [IT in MedTech](https://sacosi.ch/en/industries/medtech)

Approval and market access depend on complete documentation.

Typically relevant: the EU Medical Device Regulation (MDR), ISO 9001, ISO/IEC 27001, the Cyber Resilience Act (CRA), the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), the EU AI Act.

[More on MedTech](https://sacosi.ch/en/industries/medtech)

## [IT in aviation](https://sacosi.ch/en/industries/aviation)

Flight operations do not forgive outages in the Operations Control Center.

Typically relevant: Part-IS (aviation information security), ISO/IEC 27001, the NIS2 Directive, reporting obligation for cyberattacks (Information Security Act, ISG), the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR).

[More on aviation](https://sacosi.ch/en/industries/aviation)

## And other industries?

The method is the same. What matters is how critical IT is for the business, not the industry.

The overview of all rules is under [Regulation](https://sacosi.ch/en/regulation).

## How critical is IT in your industry?

Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile.

CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English
