OT/IT convergence and control system security under IEC 62443
Asset inventory with zones and conduits model
More on thisIndustries / Chemicals
Protect industrial control systems and connect production facilities securely to IT.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We secure process control systems based on IEC 62443 with zones, hardened remote access, and anomaly detection, integrate plant and corporate IT through controlled interfaces, and protect formulations, firmware, and access with hardware security modules.
Asset inventory with zones and conduits model
More on thisData model and integration architecture under ISA-95
More on thisProtection needs analysis and cryptography concept for recipes
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Process control systems, safety controllers and analyzers are now connected to MES, ERP and cloud services and can therefore be reached from the office network. We record every component and connection, divide the plant network into zones and conduits under IEC 62443-3-2 and set a target security level for each zone. Data diodes, industrial firewalls and anomaly detection put this model into practice without touching the control loops of the plant. Safety instrumented systems get a zone of their own and an IT risk assessment under NAMUR NA 163.
A specialty chemicals producer separates its control system from the office network with a data diode; process data still reaches the MES, while access in the opposite direction is physically impossible.
Our approach
Vendors of control systems, analyzers and compressors need access to their equipment, often at short notice and around the clock. We replace scattered VPN connections and remote maintenance software with a central access point in the DMZ, where every session is requested, approved, recorded and ended when it expires. Service providers log in with personal accounts and a second factor and reach only the zone they are approved for. Update files pass through a data lock that checks them for malware before transfer.
A chemical park consolidates the remote access of control system and analyzer vendors at one access point; every session needs approval from the control room and is recorded.
Our approach
Batch data is created in many systems: recipes and sequence control in the control system, process values in the historian, test results in the LIMS and orders in the ERP. We connect these systems under the ISA-95 layer model over OPC UA and versioned interfaces into one data platform that shows every batch from raw material to certificate of analysis. The plant sends data outward only, and there is no return path into the control system. Quality, production and customer service access the same verified data with roles and logging.
An additives producer generates certificates of analysis directly from LIMS and process data; in a complaint, the affected batch with its raw materials and process values is narrowed down without searching several systems.
Our approach
Pumps, compressors, agitators and heat exchangers often announce failures long in advance in vibration, temperature and pressure data. We merge historian and maintenance data and train models that detect wear and fouling so that maintenance is planned before the failure. Soft sensors estimate quality values that the laboratory measures only hours later and help find operating modes with less energy and scrap. The models give recommendations to the control room and maintenance and do not intervene in the control loops.
An operator of polymerization plants detects increasing fouling in a heat exchanger from temperature and pressure trends and moves the cleaning into the next planned shutdown.
Our approach
Recipes, process parameters and research data stay valuable for decades and are a target for industrial espionage. We encrypt file shares, databases and recipe management systems and keep the keys in hardware security modules from Utimaco, Thales or Entrust, so that administrators see no plaintext without approval. Because attackers could store encrypted data today and decrypt it later with quantum computers, we plan hybrid schemes with ML-KEM for long-lived recipes. Firmware and recipes for controllers are signed so that the plant loads only approved versions.
A coatings manufacturer encrypts its recipe database with keys in an HSM pair at two sites; releases to toll manufacturers are time-limited and logged.
Our approach
Producers of chemical substances fall under NIS2 above the size thresholds, and chemical parks with their own power, steam or water supply can also be KRITIS operators. We clarify applicability and registration, build an ISMS under ISO 27001 with IEC 62443-2-1 for the plants and set up the reporting process with an early warning within 24 hours, a notification within 72 hours and a final report. Security monitoring and incident response cover IT and OT together. Emergency drills combine a cyberattack with a major accident so that the plant fire brigade, control room and IT know the same procedures.
A chemical park clarifies its status under NIS2 and KRITIS, introduces a joint reporting process for site operator and tenants and drills an attack on the control system with the plant fire brigade.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Chemicals
Control system, safety controllers and office IT in one flat network, undocumented firewall rules, inspection under the Major Accidents Ordinance announced.
Passive inventory, zones and conduits model under IEC 62443-3-2, data diode to the MES, anomaly detection, cutover in the planned shutdown.
Documented zones with security levels, no access from the office network into the control system, evidence for the authority.
02 / Chemicals
Many vendors and tenants with their own VPN connections, shared accounts, no session recording.
Central access point in the DMZ, personal accounts with FIDO2, approval by the control room, data lock for updates.
Every access requested, approved and recorded, old VPN connections shut down, IEC 62443-2-4 requirements in the contracts.
03 / Chemicals
Recipes unencrypted on file servers, releases to toll manufacturers by email, suspected leak of know-how.
Protection needs analysis, encryption with keys in the HSM, time-limited releases, migration plan for post-quantum cryptography.
Recipes in plaintext only with approval, every access logged, roadmap for data with long protection periods.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Plant networks, remote access, data flows and regulatory obligations
Zone model, target architecture, operating model
Segmentation, access, data platform and HSMs in stages
Monitoring, drills, evidence
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from IEC 62443 process control security to NIS2 incident reporting, planned, integrated and operated by OTOKO®. Work on the plant network is scheduled into maintenance windows and shutdowns. The entire solution runs in German data centers.
Cybersecurity for the chemical industry protects process control systems, laboratory and production data and recipes at sites where manipulation can endanger people and the environment. OTOKO® covers six fields of action: OT/IT convergence and control system security under IEC 62443, secure remote maintenance for plants and suppliers, data platforms for batch, quality and laboratory data, predictive maintenance with machine learning, protection of recipes with HSMs and post-quantum cryptography, and compliance and incident response under KRITIS and NIS2.
Besides planning and integration, OTOKO® takes over operations and documents every zone, remote access path and model with its version and the evidence that Seveso III, NIS2 and auditors require. Cryptography and hardware security modules are our core competence. Keys for recipes, device certificates and firmware signatures are therefore held in certified devices instead of files.
Cryptography and hardware security modules are our core competence. Keys for recipes, firmware signatures and device certificates are managed in certified hardware.
The entire solution runs in German data centers, from the batch data platform to the SIEM for the plant network.
We work with operators of critical infrastructure and regulated industries. We know what authorities, inspectors and plant management expect as evidence of plant safety.
One team accompanies you from consulting to operations. OT security architects, integration developers and cryptography specialists stay on the project without handover to third parties.
Chemical sites rarely lack tools but are held back by long-lived plants, pressure on availability and unclear responsibilities between automation and IT.
01
Control system, safety controllers and office IT share one network, firewall rules have grown over years and nobody knows every connection.
02
Vendors and service providers use their own VPN connections, remote maintenance software runs on engineering stations and shared accounts leave no log.
03
Quality data sits in the LIMS, process data in the historian and batches in the ERP, so every certificate of analysis takes manual work across several systems.
04
Formulations and process parameters sit unencrypted on file servers and in recipe management systems, and nobody analyzes access by partners and laboratories.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your plant, control system, historian and HSMs in your own data center | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, German region selectable |
| Operation | Your team or OTOKO® as managed service with access through the DMZ | OTOKO®, with audit rights for your company | Shared, platform services by the provider |
| Tools | Data diodes, industrial firewalls, HSMs and remote access point on site | Hosted data platform, SIEM and HSM as a service in Germany | Managed data and ML services, cloud HSM, SIEM as a service |
| Suited for | Control systems, safety instrumented systems, recipe keys | Batch and laboratory data, monitoring, sovereign recipe protection | Cross-site analytics, machine learning, peak loads |
| Compliance | Full control, evidence from your ISMS and safety management system | Processing agreement under GDPR, location Germany, evidence for the NIS2 supply chain | Processing agreement, standard contractual clauses, no connection into the control system |
Collaboration
Project
Clearly scoped undertaking such as IEC 62443 segmentation or a central remote maintenance access point, with a defined result, milestones and acceptance.
Team reinforcement
OT security architects, integration developers or data scientists work in your teams, with your tools and under your permit rules for the plant network.
Managed service
OTOKO® operates remote access, anomaly detection, HSMs or the data platform with agreed service levels, reports and the evidence NIS2 requires for the supply chain.
What each regulation requires from chemical sites and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| IEC 62443 | Asset owner security program, zones and conduits with target security levels, system requirements and obligations for integrators and maintenance providers | Risk assessment and zone model under IEC 62443-3-2, measures under IEC 62443-3-3, remote maintenance under IEC 62443-2-4, security program under IEC 62443-2-1 |
| Seveso III | Major accident prevention policy with safety management system, for upper-tier establishments a safety report and internal emergency plans, consideration of unauthorized interference | Assessment of unauthorized interference via IT under the German KAS-51 guideline, input to safety report and emergency plans, joint drills with the plant fire brigade |
| NIS2 | Risk management measures, supply chain security, reporting of significant incidents in three stages, registration and accountability of management | Applicability analysis, catalog of measures, reporting process with templates, supplier requirements, management training |
| KRITIS | State-of-the-art safeguards, attack detection systems, regular evidence to the BSI and reporting of disruptions | Attack detection for IT and OT, evidence documents for the audit, reporting process, remediation plan for identified deficiencies |
| ISO 27001 | Information security management system with risk treatment, Annex A controls, internal audits and management review | ISMS setup or extension to the plants, statement of applicability, audit support, operation of our own services under ISO 27001 |
FAQ
15 answers about your industry, the project and ongoing operations.
OTOKO® secures control systems under IEC 62443, builds secure remote maintenance and integrates data platforms for batch and laboratory data. Predictive maintenance, recipe protection with HSMs and post-quantum cryptography, and compliance and incident response under KRITIS and NIS2 complete the portfolio. Each field of action can be commissioned on its own and runs in your plant, in German data centers or at a hyperscaler.
Largely yes. Inventory, anomaly detection and the remote access point are built during running operations because they only read the network passively or sit at the boundary of the plant network. Changes to controllers and firewall rules in the control system are scheduled into maintenance windows and planned shutdowns and tested beforehand in a test environment.
The manufacture and distribution of chemical substances is a NIS2 sector, and companies from medium size upward are covered. KRITIS applies in addition when a site operates power, water or gas supply facilities that reach the thresholds of the German KRITIS ordinance. We check both per legal entity and site and support the registration with the BSI.
Recipes are stored encrypted, and the keys sit in a hardware security module instead of on the server. Only approved roles get access, every retrieval is logged and unusual patterns stand out in monitoring. For data that must stay confidential for decades, we plan the move to quantum-safe methods.
In Germany the Major Accidents Ordinance implements Seveso III and requires operators to consider unauthorized interference as a hazard source. This includes attacks on control systems and safety controllers. We deliver the assessment under the German KAS-51 guideline, input to the safety report and drills in which a cyberattack and a major accident are rehearsed together.
On request the same team that built it. One team accompanies you from consulting to operations, with monitoring, updates, key rotation and support for NIS2 incident reports. Alternatively we hand over step by step to your automation and IT team, with an operations manual and training.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
OT security architect: Zone model, segmentation, IEC 62443. Integration architect: Data platform, LIMS, MES, ERP. Data scientist: Condition models, soft sensors, model operations. Cryptography specialist: HSMs, recipe protection, PQC roadmap. Compliance consultant: NIS2, KRITIS, Seveso III, ISO 27001. Project lead: Milestones, shutdown planning, acceptance.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Plant networks, remote access, data flows and regulatory obligations Asset inventory, risk assessment, NIS2 and KRITIS applicability, prioritized measures
Project: Clearly scoped undertaking such as IEC 62443 segmentation or a central remote maintenance access point, with a defined result, milestones and acceptance. Team reinforcement: OT security architects, integration developers or data scientists work in your teams, with your tools and under your permit rules for the plant network. Managed service: OTOKO® operates remote access, anomaly detection, HSMs or the data platform with agreed service levels, reports and the evidence NIS2 requires for the supply chain.
Monitoring, drills, evidence Monitoring of IT and OT, reporting support, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Chemicals
Let us work out together where your plant and IT networks are vulnerable and how that can change.
Book a first consultation