You are here:

IT and OT security in
control systems

Consulting IT/OT Security
Security Operations Center (SOC)
Penetration Testing
Safety audits

Consulting IT/OT Security

Supporting relevant stakeholders (e.g. CISO) in the
event of acute threats to IT/OT security
Drawing up and reviewing requirements for the
information security of the network control technology
Promoting security awareness and security competence
Conducting threat and risk analyses to identify security
risks in the system architecture of railway infrastructures
Defining and implementing security measures to
protect critical systems
Implementing relevant security standards such as IEC
62443, ISO 27001, NIS2 and KRITIS in accordance with
the BSI Act

Security Operations Center (SOC)

Advising relevant stakeholders (OT security officers) in
the event of acute OT security incidents
Setting up, optimising and maintaining a Security
Information and Event Management (SIEM) system
Integration of threat intelligence for the proactive
detection and defence against threats in real time
Threat intelligence as the basis for reporting to
management and relevant stakeholders
Implementation of incident response playbooks for
a rapid response to security incidents
Conducting regular SOC maturity assessments
(further development of security processes)

Penetration Testing

Penetration tests for IT and OT systems in railway and
industrial environments
Testing of railway installations, control systems and
OT/IT infrastructures
Penetration tests for IT infrastructure
Penetration tests for mobile and desktop applications to
identify vulnerabilities
Security assessments of industrial systems to
identify vulnerabilities in OT infrastructure
Development of measures to rectify identified
vulnerabilities in IoT and OT products

Safety audits

Threat analyses for IT infrastructures, network control
technology and control and monitoring systems
Risk minimisation measures for IT infrastructures,
network control technology and control technology
Audits and security checks of network control technology
Compliance with international security standards such as
IEC 62443, TS 50701, NIS2, ISO 27001 and KRITIS in
accordance with the BSI Act
Security audits of OT and IT infrastructures to assess the
effectiveness of security measures
Audit reports for continuous improvement