Navigation

Get in touch
Logo
News

Industries / Chemicals

Secure processes. Protected knowledge.

Protect industrial control systems and connect production facilities securely to IT.

Consulting. Integration. Operations.

A factory with a lot of pipes and tanks — illustrative image

Built around your industry.

  • Chemical and specialty chemical producers
  • Chemical parks and site operators
  • Operators of Seveso establishments
  • Formulators and toll manufacturers

Your priorities

Understand the challenge. Shape the solution.

We secure process control systems based on IEC 62443 with zones, hardened remote access, and anomaly detection, integrate plant and corporate IT through controlled interfaces, and protect formulations, firmware, and access with hardware security modules.

01

OT/IT convergence and control system security under IEC 62443

Asset inventory with zones and conduits model

More on this
02

Data platform for batches, quality and laboratory

Data model and integration architecture under ISA-95

More on this
03

Protection of recipes and IP with HSMs and post-quantum cryptography

Protection needs analysis and cryptography concept for recipes

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01OT/IT convergence and control system security under IEC 62443IEC 62443-3-2 · OPSWAT MetaDefender NetWall · OPSWAT MetaDefender Industrial Firewall

Our approach

Process control systems, safety controllers and analyzers are now connected to MES, ERP and cloud services and can therefore be reached from the office network. We record every component and connection, divide the plant network into zones and conduits under IEC 62443-3-2 and set a target security level for each zone. Data diodes, industrial firewalls and anomaly detection put this model into practice without touching the control loops of the plant. Safety instrumented systems get a zone of their own and an IT risk assessment under NAMUR NA 163.

Full scope
  • Inventory of control system, controllers, engineering stations and connections with passive network analysis, without active scans during the running process
  • Zones and conduits model under IEC 62443-3-2 with risk assessment and target security level per zone
  • Segmentation with industrial firewalls and data diodes between control system, MES and corporate network
  • Anomaly detection in the plant network, connected to the SIEM with alerting agreed with the control room
  • IT risk assessment of safety instrumented systems under NAMUR NA 163 and hardening under IEC 62443-3-3

A specialty chemicals producer separates its control system from the office network with a data diode; process data still reaches the MES, while access in the opposite direction is physically impossible.

What you get

  • Asset inventory with zones and conduits model
  • Segmentation concept with firewall rule set and security level per zone
  • Anomaly detection in operation with alerting concept
Discuss this topic
02Secure remote maintenance for plants and suppliersOPSWAT MetaDefender OT Access · OPSWAT MetaDefender Kiosk · Privileged Access Management

Our approach

Vendors of control systems, analyzers and compressors need access to their equipment, often at short notice and around the clock. We replace scattered VPN connections and remote maintenance software with a central access point in the DMZ, where every session is requested, approved, recorded and ended when it expires. Service providers log in with personal accounts and a second factor and reach only the zone they are approved for. Update files pass through a data lock that checks them for malware before transfer.

Full scope
  • Central remote access in the DMZ with request, approval by the plant managers and time-limited sessions
  • Personal accounts with FIDO2 or smartcard instead of shared vendor accounts
  • Session recording and logging with forwarding to the SIEM
  • Data lock with multiscanning for firmware, recipes and service files before transfer into the plant
  • Requirements for service providers under IEC 62443-2-4 in contracts, onboarding and regular review

A chemical park consolidates the remote access of control system and analyzer vendors at one access point; every session needs approval from the control room and is recorded.

What you get

  • Remote maintenance architecture with DMZ and central access point
  • Approval process and role concept for vendors and service providers
  • Session logs and recordings as audit evidence
Discuss this topic
03Data platform for batches, quality and laboratoryISA-95 · OPC UA · Apache Kafka

Our approach

Batch data is created in many systems: recipes and sequence control in the control system, process values in the historian, test results in the LIMS and orders in the ERP. We connect these systems under the ISA-95 layer model over OPC UA and versioned interfaces into one data platform that shows every batch from raw material to certificate of analysis. The plant sends data outward only, and there is no return path into the control system. Quality, production and customer service access the same verified data with roles and logging.

Full scope
  • Data model under ISA-95 and ISA-88 for batches, recipes, materials and test characteristics
  • Connection of control system and historian over OPC UA with data flowing out of the plant only
  • Integration of LIMS, MES and SAP S/4HANA over versioned interfaces and data contracts
  • Electronic batch record and automatically generated certificates of analysis
  • Roles, logging and retention periods for complaints, audits and requests from authorities

An additives producer generates certificates of analysis directly from LIMS and process data; in a complaint, the affected batch with its raw materials and process values is narrowed down without searching several systems.

What you get

  • Data model and integration architecture under ISA-95
  • Data platform connected to control system, LIMS, MES and ERP
  • Electronic batch record with certificates of analysis
Discuss this topic
04Predictive maintenance and process optimization with machine learningAVEVA PI System · OPC UA · Apache Kafka

Our approach

Pumps, compressors, agitators and heat exchangers often announce failures long in advance in vibration, temperature and pressure data. We merge historian and maintenance data and train models that detect wear and fouling so that maintenance is planned before the failure. Soft sensors estimate quality values that the laboratory measures only hours later and help find operating modes with less energy and scrap. The models give recommendations to the control room and maintenance and do not intervene in the control loops.

Full scope
  • Data preparation from AVEVA PI System or other historians, maintenance notifications and laboratory values
  • Condition models for pumps, compressors and heat exchangers with thresholds set jointly by operations and maintenance
  • Soft sensors for quality variables, validated against laboratory measurements
  • Recommendations to control room and maintenance without write access to the control system
  • Model operations with versioning, data drift monitoring and documentation under the EU AI Act

An operator of polymerization plants detects increasing fouling in a heat exchanger from temperature and pressure trends and moves the cleaning into the next planned shutdown.

What you get

  • Condition models with validation report
  • Dashboard with recommendations for control room and maintenance
  • Model card and operating concept for retraining
Discuss this topic
05Protection of recipes and IP with HSMs and post-quantum cryptographyUtimaco u.trust GP HSM Se-Series · Thales Luna 7 Network HSM · Entrust nShield 5c

Our approach

Recipes, process parameters and research data stay valuable for decades and are a target for industrial espionage. We encrypt file shares, databases and recipe management systems and keep the keys in hardware security modules from Utimaco, Thales or Entrust, so that administrators see no plaintext without approval. Because attackers could store encrypted data today and decrypt it later with quantum computers, we plan hybrid schemes with ML-KEM for long-lived recipes. Firmware and recipes for controllers are signed so that the plant loads only approved versions.

Full scope
  • Protection needs analysis for recipes, process parameters and research data with confidentiality period per data type
  • Encryption of file shares with LAN Crypt and of databases with keys in the HSM
  • HSM selection and integration with roles, quorums and key ceremonies, on-premises or as a service
  • Signing of firmware, controller programs and recipes with verification before loading into the plant
  • Crypto inventory and migration plan to ML-KEM and ML-DSA for data with long protection periods

A coatings manufacturer encrypts its recipe database with keys in an HSM pair at two sites; releases to toll manufacturers are time-limited and logged.

What you get

  • Protection needs analysis and cryptography concept for recipes
  • Integrated HSMs with recorded key ceremonies
  • Migration plan for post-quantum cryptography
Discuss this topic
06Compliance and incident response under KRITIS and NIS2Microsoft Sentinel · Splunk · Veeam

Our approach

Producers of chemical substances fall under NIS2 above the size thresholds, and chemical parks with their own power, steam or water supply can also be KRITIS operators. We clarify applicability and registration, build an ISMS under ISO 27001 with IEC 62443-2-1 for the plants and set up the reporting process with an early warning within 24 hours, a notification within 72 hours and a final report. Security monitoring and incident response cover IT and OT together. Emergency drills combine a cyberattack with a major accident so that the plant fire brigade, control room and IT know the same procedures.

Full scope
  • Applicability analysis under NIS2 and KRITIS thresholds with registration at the BSI
  • ISMS under ISO 27001 with a security program for the plants under IEC 62443-2-1
  • Reporting process with early warning, notification and final report, roles and templates
  • Security monitoring with SIEM for IT and OT, incident response and forensic preservation
  • Emergency and recovery plans with joint drills of IT, control room and plant fire brigade

A chemical park clarifies its status under NIS2 and KRITIS, introduces a joint reporting process for site operator and tenants and drills an attack on the control system with the plant fire brigade.

What you get

  • Applicability analysis and registration documents
  • ISMS documentation with reporting process and templates
  • Drill reports and tested recovery plans
Discuss this topic
brown and grey building during daytime — illustrative image
Chemicals

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Chemicals

Segmentation at a specialty chemicals producer

Control system, safety controllers and office IT in one flat network, undocumented firewall rules, inspection under the Major Accidents Ordinance announced.

Solution

Passive inventory, zones and conduits model under IEC 62443-3-2, data diode to the MES, anomaly detection, cutover in the planned shutdown.

Documented zones with security levels, no access from the office network into the control system, evidence for the authority.

Discuss this topic

02 / Chemicals

Remote maintenance in a chemical park

Many vendors and tenants with their own VPN connections, shared accounts, no session recording.

Solution

Central access point in the DMZ, personal accounts with FIDO2, approval by the control room, data lock for updates.

Every access requested, approved and recorded, old VPN connections shut down, IEC 62443-2-4 requirements in the contracts.

Discuss this topic

03 / Chemicals

Recipe protection at a coatings manufacturer

Recipes unencrypted on file servers, releases to toll manufacturers by email, suspected leak of know-how.

Solution

Protection needs analysis, encryption with keys in the HSM, time-limited releases, migration plan for post-quantum cryptography.

Recipes in plaintext only with approval, every access logged, roadmap for data with long protection periods.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Plant networks, remote access, data flows and regulatory obligations

    Asset inventory, risk assessment, NIS2 and KRITIS applicability, prioritized measures
  2. 02

    Concept

    Zone model, target architecture, operating model

    Zones and conduits model, remote maintenance and data architecture, cryptography concept, shutdown planning
  3. 03

    Implementation

    Segmentation, access, data platform and HSMs in stages

    Implemented measures per stage, tests, documentation, acceptance in the planned maintenance window
  4. 04

    Operations

    Monitoring, drills, evidence

    Monitoring of IT and OT, reporting support, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What is cybersecurity for the chemical industry?

Six fields of action from IEC 62443 process control security to NIS2 incident reporting, planned, integrated and operated by OTOKO®. Work on the plant network is scheduled into maintenance windows and shutdowns. The entire solution runs in German data centers.

Cybersecurity for the chemical industry protects process control systems, laboratory and production data and recipes at sites where manipulation can endanger people and the environment. OTOKO® covers six fields of action: OT/IT convergence and control system security under IEC 62443, secure remote maintenance for plants and suppliers, data platforms for batch, quality and laboratory data, predictive maintenance with machine learning, protection of recipes with HSMs and post-quantum cryptography, and compliance and incident response under KRITIS and NIS2.

Besides planning and integration, OTOKO® takes over operations and documents every zone, remote access path and model with its version and the evidence that Seveso III, NIS2 and auditors require. Cryptography and hardware security modules are our core competence. Keys for recipes, device certificates and firmware signatures are therefore held in certified devices instead of files.

Why OTOKO® for the chemical industry

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Keys for recipes, firmware signatures and device certificates are managed in certified hardware.

  • German data centers

    The entire solution runs in German data centers, from the batch data platform to the SIEM for the plant network.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what authorities, inspectors and plant management expect as evidence of plant safety.

  • One team through to operations

    One team accompanies you from consulting to operations. OT security architects, integration developers and cryptography specialists stay on the project without handover to third parties.

Delivery and details

Chemical sites rarely lack tools but are held back by long-lived plants, pressure on availability and unclear responsibilities between automation and IT.

Flat plant network

Control system, safety controllers and office IT share one network, firewall rules have grown over years and nobody knows every connection.

Remote maintenance without control

Vendors and service providers use their own VPN connections, remote maintenance software runs on engineering stations and shared accounts leave no log.

Batch data in silos

Quality data sits in the LIMS, process data in the historian and batches in the ERP, so every certificate of analysis takes manual work across several systems.

Recipes as open files

Formulations and process parameters sit unencrypted on file servers and in recipe management systems, and nobody analyzes access by partners and laboratories.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour plant, control system, historian and HSMs in your own data centerData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, German region selectable
OperationYour team or OTOKO® as managed service with access through the DMZOTOKO®, with audit rights for your companyShared, platform services by the provider
ToolsData diodes, industrial firewalls, HSMs and remote access point on siteHosted data platform, SIEM and HSM as a service in GermanyManaged data and ML services, cloud HSM, SIEM as a service
Suited forControl systems, safety instrumented systems, recipe keysBatch and laboratory data, monitoring, sovereign recipe protectionCross-site analytics, machine learning, peak loads
ComplianceFull control, evidence from your ISMS and safety management systemProcessing agreement under GDPR, location Germany, evidence for the NIS2 supply chainProcessing agreement, standard contractual clauses, no connection into the control system

Collaboration

Project

Clearly scoped undertaking such as IEC 62443 segmentation or a central remote maintenance access point, with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for segmentation, remote maintenance and NIS2 readiness

Team reinforcement

OT security architects, integration developers or data scientists work in your teams, with your tools and under your permit rules for the plant network.

  • Onboarding into plants, work permits and safety instruction
  • Scalable with project progress and shutdown planning
  • Suited for sites with their own automation team and capacity gaps

Managed service

OTOKO® operates remote access, anomaly detection, HSMs or the data platform with agreed service levels, reports and the evidence NIS2 requires for the supply chain.

  • Monitoring, updates, key rotation and support
  • Support with incident reports under NIS2
  • Suited for sites without their own OT security team

What each regulation requires from chemical sites and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
IEC 62443Asset owner security program, zones and conduits with target security levels, system requirements and obligations for integrators and maintenance providersRisk assessment and zone model under IEC 62443-3-2, measures under IEC 62443-3-3, remote maintenance under IEC 62443-2-4, security program under IEC 62443-2-1
Seveso IIIMajor accident prevention policy with safety management system, for upper-tier establishments a safety report and internal emergency plans, consideration of unauthorized interferenceAssessment of unauthorized interference via IT under the German KAS-51 guideline, input to safety report and emergency plans, joint drills with the plant fire brigade
NIS2Risk management measures, supply chain security, reporting of significant incidents in three stages, registration and accountability of managementApplicability analysis, catalog of measures, reporting process with templates, supplier requirements, management training
KRITISState-of-the-art safeguards, attack detection systems, regular evidence to the BSI and reporting of disruptionsAttack detection for IT and OT, evidence documents for the audit, reporting process, remediation plan for identified deficiencies
ISO 27001Information security management system with risk treatment, Annex A controls, internal audits and management reviewISMS setup or extension to the plants, statement of applicability, audit support, operation of our own services under ISO 27001

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which cybersecurity services does OTOKO® offer for the chemical industry?

OTOKO® secures control systems under IEC 62443, builds secure remote maintenance and integrates data platforms for batch and laboratory data. Predictive maintenance, recipe protection with HSMs and post-quantum cryptography, and compliance and incident response under KRITIS and NIS2 complete the portfolio. Each field of action can be commissioned on its own and runs in your plant, in German data centers or at a hyperscaler.

Can OT security be introduced without stopping production?

Largely yes. Inventory, anomaly detection and the remote access point are built during running operations because they only read the network passively or sit at the boundary of the plant network. Changes to controllers and firewall rules in the control system are scheduled into maintenance windows and planned shutdowns and tested beforehand in a test environment.

Does our chemical company fall under NIS2 or KRITIS?

The manufacture and distribution of chemical substances is a NIS2 sector, and companies from medium size upward are covered. KRITIS applies in addition when a site operates power, water or gas supply facilities that reach the thresholds of the German KRITIS ordinance. We check both per legal entity and site and support the registration with the BSI.

How do we protect recipes against industrial espionage?

Recipes are stored encrypted, and the keys sit in a hardware security module instead of on the server. Only approved roles get access, every retrieval is logged and unusual patterns stand out in monitoring. For data that must stay confidential for decades, we plan the move to quantum-safe methods.

What role does Seveso III play in cybersecurity?

In Germany the Major Accidents Ordinance implements Seveso III and requires operators to consider unauthorized interference as a hazard source. This includes attacks on control systems and safety controllers. We deliver the assessment under the German KAS-51 guideline, input to the safety report and drills in which a cyberattack and a major accident are rehearsed together.

Who looks after the solution after rollout?

On request the same team that built it. One team accompanies you from consulting to operations, with monitoring, updates, key rotation and support for NIS2 incident reports. Alternatively we hand over step by step to your automation and IT team, with an operations manual and training.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

OT security architect: Zone model, segmentation, IEC 62443. Integration architect: Data platform, LIMS, MES, ERP. Data scientist: Condition models, soft sensors, model operations. Cryptography specialist: HSMs, recipe protection, PQC roadmap. Compliance consultant: NIS2, KRITIS, Seveso III, ISO 27001. Project lead: Milestones, shutdown planning, acceptance.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Plant networks, remote access, data flows and regulatory obligations Asset inventory, risk assessment, NIS2 and KRITIS applicability, prioritized measures

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as IEC 62443 segmentation or a central remote maintenance access point, with a defined result, milestones and acceptance. Team reinforcement: OT security architects, integration developers or data scientists work in your teams, with your tools and under your permit rules for the plant network. Managed service: OTOKO® operates remote access, anomaly detection, HSMs or the data platform with agreed service levels, reports and the evidence NIS2 requires for the supply chain.

What happens at handover to operations?

Monitoring, drills, evidence Monitoring of IT and OT, reporting support, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Chemicals

Let's discuss your next step.

Let us work out together where your plant and IT networks are vulnerable and how that can change.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.