Services
From the initial assessment to incident response. Services organised into six families, always within the constraints of the production process.
View servicesWe protect industrial control systems —PLC, SCADA and DCS— in plants that operate continuously. Since 2016, our engineers have spoken both the language of operations and security, guided by one fixed rule: the process comes first.
The route changes depending on whether you come to us because of a regulatory requirement, a security scare or a new project. The destination is the same: know what you have, protect it and be able to prove it.
From the initial assessment to incident response. Services organised into six families, always within the constraints of the production process.
View servicesNIS2, IEC 62443, ENS and the CRA translated into specific plant decisions: what they require, what evidence they demand and which service addresses them.
View regulatory frameworksTwelve industrial sectors. A chemical plant and a brewery do not share the same risks, but they may both have a control network that nobody ever inventoried.
View industriesRutile for asset visibility, and Helion, Factra and Khemis for an SOC with explainable AI. Our own software, built because we needed it in our plants. Other solutions.
View productsFour stages, in this order. Skipping the first is why most OT security projects fail.
A passive and active inventory of what is actually on the network: assets, connections and remote access. Without touching the process.
Each finding is weighted according to its impact on the physical process, not a scanner's generic score.
Segmentation, hardening and access control, implemented in stages and within existing shutdown windows.
Continuous monitoring, prepared response and compliance evidence that is generated automatically, not during the week before an audit.
Most cybersecurity companies come to industry from IT. We took the opposite route: we were founded in 2016 within an industrial group, INZU Group.
You can see that in practical details. We do not scan a control network without understanding the process behind it. We do not propose stopping a line to install an agent. We do not deliver a report of 200 vulnerabilities ranked by CVSS: we deliver a short list of what could stop your plant and the order in which it should be fixed.
And when a service needs tools that the market does not offer, we build them. That is how Rutile was born and why we maintain Ti Lab, a laboratory with real control equipment where we test before touching anything in production.
Experience · Real facilities
Rutile listens to the control network passively and actively, and builds what almost no plant has: a living inventory, the actual topology, the vulnerabilities that really affect its equipment, PLC configuration backups and continuous compliance evidence. We developed it because we needed it in every assessment; today it is a product in its own right.
Frameworks do not provide protection on their own, but they structure the work and set deadlines. These are the ones driving European industry today.
EU Directive 2022/2555. Risk management and incident reporting obligations for essential and important entities. Management is personally accountable.
What NIS2 requiresThe reference series for automation system security: zones and conduits, security levels and role-based requirements.
What IEC 62443 requiresSpanish Royal Decree 311/2022. Mandatory for the public sector and its suppliers; it also applies to infrastructure operated for public authorities.
What the ENS requiresEU Regulation 2024/2847. If you manufacture a product with digital elements, it governs access to the European market. We work with your R&D team.
For manufacturersAn OT assessment is the first service we recommend to almost everyone, because everything else depends on it. Within a few weeks, you will know what is connected to your control network, where an attacker could get in and what should be fixed first.
Without stopping the process. Without installing agents on control equipment. Without committing to anything else.
| Duration | From 4 weeks, depending on plant size |
| Process impact | None: traffic capture is passive |
| Client involvement | Interviews and on-site support, approximately 8 to 16 hours in total |
| Deliverable | Verified inventory, actual network map and prioritised action plan |
| Supports | NIS2 · IEC 62443-2-1 · ENS |