Navigation

Get in touch
Logo
News

Industries / Defense

Sensitive information. Consistent protection.

Protect sensitive information with hardware cryptography and controlled access.

Consulting. Integration. Operations.

four helicopters over mountain at daytime — illustrative image

Built around your industry.

  • Armed forces and procurement offices
  • Security authorities
  • Defense industry
  • Suppliers and research partners

Your priorities

Understand the challenge. Shape the solution.

We integrate hardware security modules into PKI, signing, and encryption services, build sovereign platforms in data centers located in Germany, and design security architectures based on zero trust.

01

HSMs and PKI for classified information

Target architecture with device selection and migration plan

More on this
02

Zero trust, domain separation and attack detection

Zero trust architecture with domain concept

More on this
03

Secure software supply chain and applications

Development and supply chain concept with threat model

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01HSMs and PKI for classified informationUtimaco CryptoServer · Utimaco u.trust GP HSM · Thales Luna

Our approach

Hardware security modules generate and store keys in a certified environment that no key leaves in plain text. For classified information up to VS-NfD, EU RESTRICTED and NATO RESTRICTED we deploy HSMs with the matching BSI approval, such as Utimaco CryptoServer with the VS-NfD package, and plan the move to successor devices before end of support. On this foundation we build PKI, signing and encryption services whose algorithms follow BSI TR-02102. Key ceremonies with roles, quorums and records are part of every commissioning.

Full scope
  • Target architecture with device selection by classification level, redundancy across sites and a migration path from CryptoServer to the u.trust GP HSM Se-Series
  • PKI setup with offline root CA, issuing CAs, OCSP and CRL on EverTrust PKI or Microsoft ADCS with HSM connection over PKCS#11
  • Key ceremonies for root and issuing keys with roles, quorums, witnesses and record templates
  • Crypto concept under BSI TR-02102 with algorithms, key lengths and lifetimes per protection need
  • Operations manual for key rotation, firmware levels, monitoring and recovery in the HSM cluster

A defense supplier replaces the software keys of its PKI with VS-NfD approved HSMs; the root CA is created in a recorded ceremony and the issuing CAs issue certificates for people, devices and code.

What you get

  • Target architecture with device selection and migration plan
  • Recorded key ceremonies and crypto concept under BSI TR-02102
  • Operations manual for HSM cluster and PKI
Discuss this topic
02Sovereign hosting in German data centersKubernetes · Terraform · OpenStack

Our approach

Sovereign hosting means that data, keys and operations stay under German control and no provider outside the EU gains access. We build private and hybrid platforms in data centers in Germany, separate network zones by protection need and automate provisioning and operations with Kubernetes and Terraform. Data at rest is encrypted with keys from the HSM, and every change to the platform remains traceable through code and logs.

Full scope
  • Platform architecture with zones by protection need, physically separated environments for classified information and connection to your network
  • Infrastructure as code with Terraform, Kubernetes clusters with hardened nodes and signed container images
  • Encryption of data at rest and backups with keys in the HSM, recovery tested with Veeam
  • Operation under ISO 27001 and BSI IT-Grundschutz with logging, patch process and four-eyes principle for administrators
  • Exit and handover concept so that platform and data can return to your data center at any time

A security authority moves collaboration and specialist applications from a provider outside the EU to a platform in a German data center; the keys sit in its own HSM and the location can be proven.

What you get

  • Platform architecture with zone concept
  • Provisioned platform as code with operations documentation
  • Evidence of location, encryption and recovery
Discuss this topic
03Zero trust, domain separation and attack detectionOPSWAT MetaDefender NetWall · Microsoft Sentinel · Splunk

Our approach

Zero trust verifies every access individually by identity, device and context instead of trusting an internal network by default. We design security architectures on this principle, harden systems under BSI IT-Grundschutz and separate domains of different classification with data diodes and gateways that inspect content and enforce release rules. For exchange with allies we label data under STANAG 4774 and bind the label to the content under STANAG 4778. A SIEM detects attacks across all systems, and a rehearsed incident response process reacts to them.

Full scope
  • Zero trust architecture with identity verification via smartcards and FIDO2, device posture and microsegmentation
  • Domain separation with data diodes and cross-domain gateways such as OPSWAT MetaDefender NetWall, content inspection with Deep CDR
  • Confidentiality labeling under STANAG 4774 and binding under STANAG 4778 for exchange with partners
  • Security monitoring with SIEM, use cases for state-sponsored attackers and incident response with exercises
  • Penetration tests and red teaming against networks, applications and gateways with report and retest

An authority exchanges situational data with partners through a gateway with content inspection; every file carries a confidentiality label and leaves the domain only after a defined release.

What you get

  • Zero trust architecture with domain concept
  • Configured gateways and data diodes with release rules
  • SIEM use cases and incident response plan
Discuss this topic
04File and disk encryption approved for VS-NfDUtimaco LAN Crypt · Utimaco DiskEncrypt · Utimaco ESKM

Our approach

Classified information on notebooks, file servers and removable media needs encryption that the BSI has approved for the respective level. We roll out Utimaco LAN Crypt for files and folders and Utimaco DiskEncrypt for hard disks, both approved for VS-NfD and usable for EU RESTRICTED and NATO RESTRICTED. Roles separate administration and security officers, smartcards hold the users' keys and policies encrypt transparently without users changing the way they work.

Full scope
  • Encryption concept with classification levels, storage locations, key hierarchy and roles for administration and security officers
  • Rollout of Utimaco LAN Crypt with policies for local, network and cloud storage, connected to Active Directory or Entra ID
  • Disk encryption with Utimaco DiskEncrypt and smartcard login before the operating system starts
  • Key custody and recovery with documented procedures, on request with Utimaco ESKM as key manager
  • Evidence for industrial security audits with configuration states, approval documents and rollout records

A supplier under industrial security clearance rules rolls out LAN Crypt and DiskEncrypt to all project devices; the security audit receives approval documents, policies and configuration evidence.

What you get

  • Encryption concept with roles and key hierarchy
  • Encryption rolled out on devices and file storage
  • Audit file with approvals, policies and records
Discuss this topic
05Secure software supply chain and applicationsGitLab CI · CycloneDX SBOM · Sigstore Cosign

Our approach

Software in operational systems must prove what it consists of, who built it and that it arrives unchanged at the user. We develop and operate specialist applications with build pipelines that record every component in a software bill of materials, check dependencies for known vulnerabilities and sign artifacts with keys from the HSM. Air-gapped environments without network connection are supplied through verified transfer paths, and development, test and operational environments stay separate.

Full scope
  • Secure development under OWASP SAMM with threat model, code review and separate environments for development, test and operations
  • Build pipeline with software bill of materials in CycloneDX, vulnerability scanning and release under the four-eyes principle
  • Code and container signing with keys in the HSM, signature verification before every deployment
  • Transfer into air-gapped environments via OPSWAT MetaDefender Kiosk and file inspection with multiscanning
  • Operation and maintenance of the applications with logging, patch process and documented changes

A maker of operational software introduces signed builds with a bill of materials; the client verifies signature and component list before every installation in the air-gapped environment.

What you get

  • Development and supply chain concept with threat model
  • Build pipeline with bill of materials and HSM signing
  • Release and transfer procedure for air-gapped environments
Discuss this topic
06Post-quantum roadmap and interoperabilityML-KEM (FIPS 203) · ML-DSA (FIPS 204) · SLH-DSA (FIPS 205)

Our approach

Classified information stays sensitive for decades, longer than RSA and elliptic curves are expected to remain secure by current assessment. We inventory algorithms, keys and certificates across HSMs, PKI, VPN and applications and rate them by protection period. We plan the migration to ML-KEM and ML-DSA in hybrid modes, as BSI TR-02102 recommends for the transition period. Because allies follow their own timelines, every algorithm stays aligned with partners and replaceable.

Full scope
  • Crypto inventory across HSMs, PKI, VPN, TLS, signatures and applications with rating by protection period of the data
  • Check of HSM firmware for ML-KEM, ML-DSA and SLH-DSA, for example Utimaco Quantum Protect or Thales Luna
  • Hybrid certificates and migration plan for root CA, issuing CAs and device certificates
  • Crypto agility in applications and gateways so that algorithms stay replaceable without rebuilding
  • Alignment of algorithms and timelines with partners and NATO structures, roadmap in stages

A procurement office inventories the cryptography across PKI, VPN and device certificates; the root CA moves to hybrid certificates first, the gateways follow with the next device refresh.

What you get

  • Crypto inventory with risk rating
  • Migration roadmap for HSMs, PKI and gateways
  • Crypto agility concept with partner alignment
Discuss this topic
silver-colored god tags hanging on hooks shallow focus photography — illustrative image
Defense

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Defense

PKI renewal at a defense supplier

The PKI issues certificates with software keys, the client demands keys in approved hardware and a crypto concept.

Solution

VS-NfD approved HSMs, root CA in a recorded ceremony, issuing CAs on EverTrust PKI, crypto concept under BSI TR-02102.

Keys in certified hardware, complete ceremony records, crypto concept for the industrial security audit.

Discuss this topic

02 / Defense

Sovereign platform for a security authority

Specialist applications and collaboration run with a provider outside the EU, the keys sit with the provider, the data location cannot be proven.

Solution

Platform in a German data center with zones by protection need, keys in the authority's own HSM, infrastructure as code, operation under ISO 27001.

Provable location, key sovereignty with the authority, documented operation with exit concept.

Discuss this topic

03 / Defense

Security audit at a research partner

A client's classified information sits on notebooks without approved encryption, and the audit is imminent.

Solution

Encryption concept, rollout of LAN Crypt and DiskEncrypt with smartcards, roles for administration and security officers.

Approved encryption on all project devices, audit file with approvals and configuration evidence.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Classification, protection needs, systems and gaps in approval and operation

    Prioritized list of measures, crypto inventory, requirements for approval and operation
  2. 02

    Concept

    Security architecture, crypto concept, operating model

    Target architecture, device selection, crypto concept under BSI TR-02102, operating model
  3. 03

    Implementation

    HSMs, PKI, platform and encryption in stages

    Integrated systems, recorded ceremonies, tests, documentation, acceptance per stage
  4. 04

    Operations

    Monitoring, key maintenance, audits, knowledge transfer

    Monitoring, key and certificate maintenance, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for defense and security?

Six fields of action from HSMs and PKI for classified information to a post-quantum roadmap, planned, integrated and operated by OTOKO®. BSI approvals and interoperability with allies are requirements of the architecture, not checkpoints added later. The entire solution runs in German data centers.

IT solutions for defense and security process classified information only in components approved for the respective level, keep key material and data under German control and remain interoperable with allies and NATO structures. OTOKO® covers six fields of action: HSMs and PKI for classified information, sovereign hosting in German data centers, zero trust with domain separation and attack detection, file and disk encryption approved for VS-NfD, a secure software supply chain, and a post-quantum roadmap with interoperability for partners.

The difference to a pure consulting project lies in approval, operations and evidence. Every component, key ceremony and release gets a record, a version and the documents that security officers, BSI IT-Grundschutz and auditors ask for. Cryptography and hardware security modules are our core competence. Keys for PKI, signatures and encryption therefore live in approved devices instead of software.

Why OTOKO® for defense and security

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. BSI approved HSMs, PKI and key ceremonies are planned and operated the way security clearance rules and BSI TR-02102 demand.

  • German data centers

    The entire solution runs in German data centers. From the HSM to the collaboration platform, with a provable location and key sovereignty on your side.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what security officers, clearance authorities and auditors expect from a provider.

  • One team through to operations

    One team accompanies you from consulting to operations. Cryptography specialists, platform engineers and developers stay on without handover to third parties.

Delivery and details

Most organizations do not fail on technology but on standard tools without approval, keys in software and supply chains without evidence.

Classified information on standard IT

Classified documents sit on ordinary file servers and notebooks, the encryption is not approved for VS-NfD and nobody can prove the protection.

Keys in software

PKI, signing services and VPN gateways keep private keys in working memory, where malware and memory dumps can extract them.

Supply chain without evidence

Software arrives without a bill of materials, builds are unsigned and dependencies from external sources flow unchecked into operational systems.

Cloud without sovereignty

Collaboration and documents run with providers outside the EU, the keys sit with the provider and the location of the data cannot be proven.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour data center, your HSMs, physically separated zonesData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, unclassified data only, region Germany
OperationYour team or OTOKO® as managed serviceOTOKO®, access under the four-eyes principle and loggedShared, platform services by the provider
ToolsCryptoServer or Luna on site, LAN Crypt, DiskEncrypt, KubernetesHosted HSMs and PKI, sovereign platform, data diodes to your networkCloud HSM services, collaboration and analytics for unclassified data
Suited forClassified information, PKI root, operational systemsAuthorities and contractors with sovereignty needsUnclassified data, training, scaling at peak load
ComplianceFull control, evidence from your ISMS and security clearance rulesProcessing agreement under GDPR, location Germany, IT-Grundschutz evidenceProcessing agreement, standard contractual clauses, no classified data

Collaboration

Project

Clearly scoped undertaking such as a PKI setup on HSMs or the rollout of VS-NfD encryption with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for PKI setup, encryption rollout and audit preparation

Team reinforcement

Cryptography specialists, platform engineers or developers work in your teams, tools and release processes, on request on site in your shielded environment.

  • Onboarding into your processes, systems and security rules
  • Scalable as the project progresses
  • Suited for organizations with their own team and capacity gaps

Managed service

OTOKO® operates HSMs, PKI or platform with agreed service levels, reports, logged access and an exit concept that describes the return to your data center.

  • Monitoring, key rotation, updates and support
  • Logged access, reports and exit concept in the contract
  • Suited for organizations without their own operations team for HSMs or platform

What each regulation in defense and security requires and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
VS-NfD and security clearance rulesProcessing of classified information only in products and environments the BSI has approved for the level, with access control, encryption and documentationArchitecture with approved HSMs, LAN Crypt and DiskEncrypt, role concept, configuration evidence and documents for the industrial security audit
BSI IT-GrundschutzProtection needs assessment, modeling with building blocks, implementation of the requirements and evidence in the security conceptProtection needs analysis, security concept with building blocks, hardened systems and operating procedures under IT-Grundschutz
BSI TR-02102Cryptographic algorithms, key lengths and protocols according to the BSI recommendations, including hybrid modes for the transition to PQCCrypto concept with algorithms per protection need, HSM configuration, PKI profiles and post-quantum roadmap under the guideline
ISO 27001Information security management system with risk assessment, controls, internal audits and continual improvementOperation under ISO 27001, risk register for platform and HSMs, evidence for your own certification
NIS2Risk management, reporting of significant incidents, supply chain security and accountability of managementRisk analysis, reporting process with SIEM connection, supply chain evidence with software bill of materials, documents for management

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for defense and security does OTOKO® offer?

The portfolio covers HSMs and PKI with BSI approval for classified information, sovereign hosting in German data centers, zero trust with domain separation and attack detection, file and disk encryption approved for VS-NfD, secure software supply chains and a post-quantum roadmap. Each field of action can be commissioned on its own or as a package, on request with operation by OTOKO®.

Does OTOKO® hold an approval for processing classified information?

BSI approvals apply to products and to the operating environment, not to a service provider as such. We design architectures so that approved components are integrated correctly and the evidence for an evaluation is produced. Whether a program requires industrial security clearance or clearances for individual people is clarified with your security officer before the project starts.

Why is software encryption not enough for classified data?

With pure software encryption, keys sit in working memory where malware and memory dumps can extract them. An HSM keeps keys in a tamper-protected environment, performs operations inside it and logs every use. For classified information the BSI requires approved products depending on the level, and that approval presupposes certified hardware.

How do we exchange data with allies without violating classifications?

The exchange runs through gateways with content inspection and release rules that define which information may leave a domain. Every file carries a confidentiality label under STANAG 4774 that is bound to the content under STANAG 4778. Identities from the PKI prove who is sending and who is receiving, and the SIEM logs every transition.

Does the entire solution run in German data centers?

Yes. HSMs, PKI, platform and encryption services run in your data center or in German data centers that are operated under ISO 27001. Hyperscalers are an option for unclassified data only, for example training or analytics. We work with operators of critical infrastructure and regulated industries. There a provable location is standard.

When should we start with post-quantum cryptography?

Now, with the inventory. Classified information has protection periods that exceed the expected arrival of capable quantum computers, and attackers already store encrypted data today for later decryption. The inventory shows which HSMs, certificates and gateways must migrate first, and the roadmap ties the migration to device refreshes and partner timelines.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Target architecture, zero trust, domain concept. Cryptography specialist: HSMs, PKI, key ceremonies, post-quantum roadmap. Platform engineer: Sovereign platform, infrastructure as code, operations. Developer: Specialist applications, build pipeline, signing. Compliance consultant: IT-Grundschutz, BSI TR-02102, audit documents. Project lead: Milestones, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Classification, protection needs, systems and gaps in approval and operation Prioritized list of measures, crypto inventory, requirements for approval and operation

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a PKI setup on HSMs or the rollout of VS-NfD encryption with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, platform engineers or developers work in your teams, tools and release processes, on request on site in your shielded environment. Managed service: OTOKO® operates HSMs, PKI or platform with agreed service levels, reports, logged access and an exit concept that describes the return to your data center.

What happens at handover to operations?

Monitoring, key maintenance, audits, knowledge transfer Monitoring, key and certificate maintenance, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Defense

Let's discuss your next step.

Let us discuss confidentially how cryptography and sovereign hosting protect your classified data.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.