Sectors
Sector-specific security for operators of critical infrastructure.
Every sector brings its own rules.
Systems, protocols and regulation differ by sector. General security consulting falls short here.
Systems of their own
A substation, an interlocking and a control unit in a vehicle have little in common. Every sector has its own systems, its own protocols and its own regulation.
A vocabulary of their own
We work with the vocabulary of the sector in question and know its standards. What holds in rail technology differs fundamentally from the financial sector.
Tested on hardware
For several sectors we run demonstrators of our own in the OT lab. We try procedures on real hardware before they go to an operator.
Six sectors.
Each sector placed in a sentence and linked. The full picture is on the sector page itself.
- Energy and utilities Protection equipment, smart meter gateways, substations and control rooms of the energy networks.
- Rail and transport Signalling and control technology, ETCS, interlocking environments, for operators and suppliers alike.
- Finance and insurance DORA implementation, SIEM build, third-party risk and regulatory reporting duties.
- Automotive and mobility E/E architectures, gateways, V2X and backend services to UN R155 and ISO 21434.
- Industry and manufacturing PLC and plant penetration tests, hardening to IEC 62443, brownfield migrations without downtime.
- Public administration IT-Grundschutz, municipal KRITIS structures and the German Online Access Act in federal states and municipalities.
Three sectors with a demonstrator of their own.
For energy, rail and automotive we run real demonstrators in the OT lab. On them we try sector-specific attacks and defences before applying them at an operator.
YekCity
Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.
YekTrain
Vehicle systems on MVB and CANopen, built from recordings of real trains. Attacks and their detection can be shown on it reproducibly.
YekCar
Emulated control units with CAN, UDS and keyless entry, with an attacker dashboard and an IDS monitor in the same case.
Standards differ from sector to sector.
Every sector is measured against its own frameworks. Which ones are relevant we settle in the first conversation.
KRITIS
German duties for operators of critical infrastructure.
NIS2
EU-wide cyber resilience, with a wider circle of operators.
IEC 62443
The technical model for OT security.
DORA
Operational resilience in the financial sector.
UN R155 / ISO 21434
Cybersecurity in vehicle development.
Discuss your sector.
Tell us what environment you work in. We will place your situation and show which test makes sense in that sector.