Completed projects in detail.
Extracts from our work for operators of critical infrastructure. Reference details are named once released, and in person.
Security in critical and regulated environments
A security test in a power plant differs fundamentally from one at a financial company or in a production environment. Architecture, regulation and risk profile determine the approach.
Energy and grid operators
Energy infrastructure is distributed, regulated and grown over years. Control rooms, substations and telecontrol stations have to run stably, even as IT and OT become more closely interlocked. In that environment we do not only test the technical attack surface but assess segmentation, remote access and monitoring capability as they really are. We also support energy companies in building OT monitoring that works, and qualify their teams for safety-critical operating situations.
Rail operations and infrastructure
Railway operating networks and control systems are safety-critical and organisationally complex. The difficulty usually lies in the combination of legacy systems, service provider access and operations-adjacent IT. We analyse the actual network separation, develop monitoring concepts suited to operational systems, and support operators in handling security-relevant incidents in a structured way.
Automotive and industrial production
Production environments are highly automated but often only logically separated from the office network. At the same time, digitalisation and remote access create new dependencies. We assess the real communication paths between IT and production networks, identify structural weaknesses, and support the build of security and monitoring structures that fit how the plant actually runs.
Insurers and financial services
Insurers and financial service providers work in highly regulated IT environments with complex identity and permission structures. Beyond classic security requirements, resilience, the ability to produce evidence, and third-party risk are gaining weight, not least in the context of DORA. We test real access paths, assess the scope for internal movement, and support the build of monitoring and response that works.
Other regulated sectors
Beyond our core sectors we work with other regulated companies for whom security requirements and the ability to produce evidence are central. The focus is always the technical reality, not the policy or the documentation.
Case studies
What was done in these projects is set out in detail. Where a client is named, their release is on file.
Where we work
Every sector brings its own protocols, its own supervision and its own limits on what may be tested during operation. The sector pages set out how we work in each.
Rail and transport
Signalling and control technology, ETCS, interlocking environments, for operators and suppliers alike.
Read moreEnergy and utilities
Protection equipment, smart meter gateways, substations and control rooms of the energy networks.
Read moreAutomotive and mobility
E/E architectures, gateways, V2X and backend services to UN R155 and ISO 21434.
Read moreIndustry and manufacturing
PLC and plant penetration tests, hardening to IEC 62443, brownfield migrations without downtime.
Read moreFinance and insurance
DORA implementation, SIEM build, third-party risk and regulatory reporting duties.
Read morePublic administration
IT-Grundschutz, municipal KRITIS structures and the German Online Access Act in federal states and municipalities.
Read moreReferences anyone can check
In this business, client names usually stay confidential. Our research work is the counterpart: it is published, citable and peer-reviewed.
In the FINESSE joint project we built intrusion detection for vehicle fleets from July 2022 to December 2025, with DB Systemtechnik, ETAS, Fraunhofer SIT, INCYDE and the University of Passau, funded under reference 16KIS1584K. Out of it came the VATT&EK attack classification and four publications at ACM CSCS, IEEE CNS, SECURWARE and in the Springer LNCS. The monitoring ran in the advanced TrainLab of DB Systemtechnik on a moving vehicle.
We have shown our demonstrators YekCar, YekTrain and YekCity publicly, among other places at it-sa in Nuremberg, at IT-Sicherheitstag NRW, and at the Nationale Konferenz IT-Sicherheitsforschung in 2025.
Certifications and memberships
The certifications are practical examinations, not multiple choice tests. Who tests on your project, and what that person holds, is named in the proposal.
Talk to us about your project.
We will tell you frankly whether we are the right partner.