24/7 incident response phone: 24/7 incident response · +34 902 540 891

Industrial cybersecurity · OT / ICS

Your plant cannot stop. That is our starting point.

We protect industrial control systems —PLC, SCADA and DCS— in plants that operate continuously. Since 2016, our engineers have spoken both the language of operations and security, guided by one fixed rule: the process comes first.

Where to start

Four ways to begin

The route changes depending on whether you come to us because of a regulatory requirement, a security scare or a new project. The destination is the same: know what you have, protect it and be able to prove it.

Services

From the initial assessment to incident response. Services organised into six families, always within the constraints of the production process.

View services

Compliance

NIS2, IEC 62443, ENS and the CRA translated into specific plant decisions: what they require, what evidence they demand and which service addresses them.

View regulatory frameworks

Industries

Twelve industrial sectors. A chemical plant and a brewery do not share the same risks, but they may both have a control network that nobody ever inventoried.

View industries

Products

Rutile for asset visibility, and Helion, Factra and Khemis for an SOC with explainable AI. Our own software, built because we needed it in our plants. Other solutions.

View products
Method

How we work

Four stages, in this order. Skipping the first is why most OT security projects fail.

01

Discover

A passive and active inventory of what is actually on the network: assets, connections and remote access. Without touching the process.

02

Prioritise

Each finding is weighted according to its impact on the physical process, not a scanner's generic score.

03

Protect

Segmentation, hardening and access control, implemented in stages and within existing shutdown windows.

04

Sustain

Continuous monitoring, prepared response and compliance evidence that is generated automatically, not during the week before an audit.

Why Titanium

Security delivered by people who know plants

Most cybersecurity companies come to industry from IT. We took the opposite route: we were founded in 2016 within an industrial group, INZU Group.

You can see that in practical details. We do not scan a control network without understanding the process behind it. We do not propose stopping a line to install an agent. We do not deliver a report of 200 vulnerabilities ranked by CVSS: we deliver a short list of what could stop your plant and the order in which it should be fixed.

And when a service needs tools that the market does not offer, we build them. That is how Rutile was born and why we maintain Ti Lab, a laboratory with real control equipment where we test before touching anything in production.

Experience · Real facilities

  • NuclearSpanish nuclear power plants
  • Power generation800 MWe combined-cycle plant · nine solar thermal and photovoltaic plants
  • GasLNG regasification at 800,000 m³(n)/h · storage capacity of 900,000 m³
  • ChemicalEthylene oxide plant · automotive additives in Spain, the United Kingdom and Belgium
  • FoodMultinational brewery · canned foods
  • PharmaceuticalGeneric medicines
Proprietary product

Rutile: the inventory your plant does not have

Rutile listens to the control network passively and actively, and builds what almost no plant has: a living inventory, the actual topology, the vulnerabilities that really affect its equipment, PLC configuration backups and continuous compliance evidence. We developed it because we needed it in every assessment; today it is a product in its own right.

Compliance

The regulations that affect you, translated into plant decisions

Frameworks do not provide protection on their own, but they structure the work and set deadlines. These are the ones driving European industry today.

NIS2

EU Directive 2022/2555. Risk management and incident reporting obligations for essential and important entities. Management is personally accountable.

What NIS2 requires

IEC 62443

The reference series for automation system security: zones and conduits, security levels and role-based requirements.

What IEC 62443 requires

ENS

Spanish Royal Decree 311/2022. Mandatory for the public sector and its suppliers; it also applies to infrastructure operated for public authorities.

What the ENS requires

CRA

EU Regulation 2024/2847. If you manufacture a product with digital elements, it governs access to the European market. We work with your R&D team.

For manufacturers
First step

Start by knowing what you have

An OT assessment is the first service we recommend to almost everyone, because everything else depends on it. Within a few weeks, you will know what is connected to your control network, where an attacker could get in and what should be fixed first.

Without stopping the process. Without installing agents on control equipment. Without committing to anything else.

Request an OT assessment

OT assessment · Service details
DurationFrom 4 weeks, depending on plant size
Process impactNone: traffic capture is passive
Client involvementInterviews and on-site support, approximately 8 to 16 hours in total
DeliverableVerified inventory, actual network map and prioritised action plan
SupportsNIS2 · IEC 62443-2-1 · ENS
Titanium · Legal information
Titanium · Legal information
Titanium · Legal information