Security system for technical infrastructures, comprising a
cell unit (300) that generates an individual security environment for each actor, a pattern unit (310) with cryptographically signed
authorization patterns, an entry gate (320) as the single access point, and a family root unit (330) with cryptographic rights inheritance, wherein the
system further comprises: a) an integrity unit (500) that persists each state change of a security environment in a cryptographically linked protocol chain (501), wherein each entry contains the cryptographic hash value of the preceding entry, and subsequent manipulation of an entry destroys the cryptographic integrity of all subsequent entries;b) a voting unit (510) that requests at least two other independent security environments for validation in the case of safety-critical escalation decisions, wherein an escalation decision only becomes effective upon reaching a configurable quorum; c) a governance unit (520) that subjects safety-critical configuration changes to a configurable
delay period, wherein cancellation by authorized bodies is possible during the
delay period; wherein no
data traffic can reach the technical infrastructure (400) without being bound to a security environment, and every state change within a security environment is cryptographically chained and logged.