24/7 incident response phone: 24/7 incident response · +34 902 540 891

Rutile, the plant's source of truth

Rutile brings together the inventory, topology, configurations and lifecycle of every industrial asset and keeps them up to date. We built it ourselves in Europe because every assessment needed it and the market did not provide it in the form we required.

What it is

At the heart of Rutile is a digital twin: the control network transformed into a navigable graph where the actual topology leads into each asset, showing which vulnerabilities genuinely affect it, the status and age of its backups, available patches and its level of compliance. Context—what the device communicates with and the function it performs—is what changes the priority of a decision.

How it works

Rutile combines two sources that are usually presented as mutually exclusive. It listens to the network passively from a SPAN port or TAP, without touching equipment or interfering with the process, and discovers assets, communications and topology. When more detail is required—installed software, versions and network equipment—it makes active, controlled queries only to the assets that provide the most context.

The client remains in control: you define the scope, credentials and windows, and no query or change occurs without explicit approval.

Where the data resides

It is deployed within the industrial perimeter, without agents on plant equipment, and integrates with your SIEM and CMDB through controlled interfaces. Developed in Europe and deployed on-premises, the data remains under the client's control, in line with the Cybersecurity Made in Europe label.

And it is built by people who work on plant floors: the same team that performs industrial penetration testing and operates an OT SOC. Rutile came from that practice, not from a whiteboard.

A living record for every asset

What it brings together for each device

What it is, where it is, what it communicates with, what it needs and what can be demonstrated about it. Six views of the same asset and the same history, for operations, maintenance, engineering, security and compliance.

Inventory de activos

The manufacturer, model, firmware, protocols, addressing, role and location of each device, inferred from actual traffic rather than a spreadsheet.

Digital twin

A navigable graph of communications, routes and protocols onto which everything else is projected: the control network as it really is.

Contextualised vulnerabilities

CVEs and manufacturer advisories prioritised by actual exposure in the topology, not by CVSS alone. Unsupported devices remain visible together with their compensating controls.

Configuration backups

The latest known-good configuration for each device, its age and what has changed since. The basis for recovering a controller after a failure.

Patches subject to approval

It compares what is installed with what is available and schedules every change for an authorised window, with evidence before and after. Nothing is applied without approval.

Continuous compliance

The inventory and its history become living evidence for NIS2, IEC 62443, ENS, CRA and ISO 27001. They do not need to be reconstructed in a spreadsheet every year.

Two routes

The product or the outcome

Rutile has its own website, with interface screenshots, technical questions and a demo request: rutileics.com. You will find full details there, along with the option to license it and operate it with your own team.

If you prefer the outcome without operating the tool, choose our managed inventory service: Titanium deploys Rutile in your plant and operates it for you, with compliance evidence ready for every audit.

Titanium · Legal information
Titanium · Legal information
Titanium · Legal information