Cybersecurity for critical infrastructure.
Penetration testing, security monitoring and OT protection for operators of critical infrastructure. A family business from Dortmund, trading as Yekta IT GmbH since 2015.
IT and OT security.
We advise on corporate IT and on the plant technology behind it. For many clients the same people work across both worlds for years.
IT security
- Penetration testing and assessments Web, network, cloud, API, red teaming, OSINT.
- SOC, SIEM and monitoring Design, SIEM engineering, detection.
- Cyber exercises and crisis management Red, blue and purple team, tabletop, business continuity.
- Compliance and consulting NIS2, DORA, ISO 27001, DevSecOps.
- Training Awareness, phishing simulation, live hacking.
OT security
- OT penetration testing and assessments OT and ICS, SCADA, IEC 62443 risk assessment.
- OT SOC, SIEM and monitoring OT monitoring, anomaly detection, SIEM integration.
- OT cyber exercises and crisis management Red, blue and purple team, tabletop, crisis simulation.
- OT compliance and consulting KRITIS, IEC 62443, NIS2, network segmentation.
- OT training OT awareness, live hacking on ICS.
Sectors we have advised in for years.
Every sector has its own rule books, plant types and escalation paths. We know the conventions, and we know where the gaps open up in practice.
Energy and utilities
Protection equipment, smart meter gateways, substations and control rooms of the energy networks.
Read moreRail and transport
Signalling and control technology, ETCS, interlocking environments, for operators and suppliers alike.
Read moreFinance and insurance
DORA implementation, SIEM build, third-party risk and regulatory reporting duties.
Read moreAutomotive and mobility
E/E architectures, gateways, V2X and backend services to UN R155 and ISO 21434.
Read moreIndustry and manufacturing
PLC and plant penetration tests, hardening to IEC 62443, brownfield migrations without downtime.
Read morePublic administration
IT-Grundschutz, municipal KRITIS structures and the German Online Access Act in federal states and municipalities.
Read moreOur own testbeds for critical infrastructure.
We rebuild plant as demonstrators and play attacks through on them without risk. What we learn there goes straight back into our clients' projects.
Two completed projects in detail.
Extracts from our work for operators of critical infrastructure. Reference details are named once released, and in person.
Certifications and memberships.
Talk to us about your project.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.