Control room integration and call handling
Interface catalog with data flows and owners
More on thisIndustries / Emergency
Connect dispatch centres and operate critical emergency systems reliably.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We connect dispatch systems, call handling, BOS digital radio, and external data sources through secured interfaces, operate the platform redundantly in data centers located in Germany, and harden your control room against attacks.
Interface catalog with data flows and owners
More on thisRedundancy and recovery concept with defined objectives
More on thisCrypto concept with key hierarchy and roles
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
A control room combines call taking, dispatch system, alerting, radio and geodata from systems of several vendors. We connect these components through an integration layer with versioned interfaces, attach external sources such as hospital capacities via IVENA and emergency calls under NG112 with eCall, and test every interface under load before it goes into live operation. Changes run in stages so that call handling and alerting keep working throughout.
An ambulance service authority eliminates double entry between dispatch system and hospital link; capacities from IVENA appear directly at the dispatcher, and every handover is logged.
Our approach
BOS digital radio under TETRA delivers voice, status messages and positions, and alerting reaches crews through pagers and apps. We develop applications that take status messages and positions from the radio network into the dispatch system, trigger alerts over POCSAG, TETRA and app in parallel and show crews current response data on vehicles and tablets. The applications keep working when the network drops and synchronize data as soon as the connection is back.
A fire department replaces separate alerting over radio and phone lists with a service that triggers pagers, TETRA and app at the same time; acknowledgments appear in the dispatch system.
Our approach
High availability means that call handling and the dispatch system keep running when individual components, a site or a network fail. We plan redundant sites with geo-redundant data storage, automated failover procedures and tested recovery plans and operate the platform in German data centers or in your control room. Recovery time and data loss objectives are defined with you under ISO 22301 and rehearsed regularly.
Two control rooms of a network back each other up; in an exercise the second site takes over call handling while the first restarts without data loss.
Our approach
Control rooms are targets for extortion and sabotage, and KRITIS and NIS2 require attack detection, reporting processes and regular evidence. We assess the security posture under BSI IT-Grundschutz, segment networks between call handling, administration and the internet, harden systems and set up a SIEM with use cases for control rooms. Removable media is inspected before connection, and a rehearsed incident response process keeps the reporting deadlines.
A municipal control room sets up attack detection and a reporting process; the evidence for the BSI rests on SIEM logs, exercise reports and the updated risk analysis.
Our approach
Response and health data need particular protection, and GDPR and KRITIS require encryption, access control and logging. We build a PKI for dispatchers, vehicles and devices, keep its keys in an HSM and encrypt databases, backups and mobile devices with keys from this custody. Dispatchers log in with smartcard or FIDO2, administrators work under the four-eyes principle, and every use of a key is logged.
An ambulance service encrypts response documentation and tablets with keys from the HSM; the data protection officer receives crypto concept, roles and log evidence.
Our approach
Response data from several years shows when and where which incidents occur and how long vehicles are on the road. We merge response, vehicle and geodata in a data platform, train models on it for incident volume and station planning and provide analyses for demand planning, quality management and exercises. Personal data is pseudonymized, and every model is documented under the EU AI Act and reviewed regularly.
An authority simulates station variants for ambulance stations based on response data from several years; demand planning rests on traceable analyses instead of estimates.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Emergency
Two control rooms work separately, the backup site was never tested under load, recovery times are not defined.
Redundancy concept with mutual takeover, geo-redundant data storage, automated failover, emergency manual under ISO 22301, exercise under load.
Tested takeover of call handling, documented recovery times, exercise records for the authority and the supervisor.
02 / Emergency
Dispatch system, radio status, alerting and hospital link run separately, dispatchers enter data several times.
Interface catalog, integration layer with event processing, connection of BOS digital radio, IVENA and alerting, load tests per interface.
One situational picture in the dispatch system, no double entry, versioned interfaces with release process.
03 / Emergency
Classification as an entity under NIS2 is due, risk analysis, attack detection and reporting process are missing.
Security assessment under BSI IT-Grundschutz, network segmentation, SIEM with use cases, incident response plan with reporting process, exercise.
Auditable risk analysis, attack detection in operation, reporting process with rehearsed deadlines.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
System landscape, outage risks, protection needs and gaps under KRITIS and NIS2
Target architecture, redundancy concept, security measures, operating model
Interfaces, redundancy, security and applications in stages outside peak response times
Monitoring, on-call service, exercises, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from control room integration to a data platform for response planning, planned, integrated and operated by OTOKO®. Every change is carried out so that call handling and alerting keep working. The entire solution runs in German data centers.
IT solutions for emergency services keep call handling, the dispatch system and alerting available around the clock, connect control room, radio and crews through secured interfaces and prove protective measures to the BSI and the supervisory authority. OTOKO® covers six fields of action: control room integration and call handling, BOS digital radio and alerting with mobile response data, high availability and disaster recovery, IT security under KRITIS and NIS2, identity and encryption for response data, and a data platform with AI for response planning.
The difference to a pure consulting project lies in operations and evidence. Every interface, failover and recovery gets a record, a version and the documents that KRITIS, NIS2 and BSI IT-Grundschutz require. The entire solution runs in German data centers. Redundant across two sites and with key sovereignty at your control room.
Cryptography and hardware security modules are our core competence. Keys for response and health data, device certificates and backups therefore sit in certified hardware.
The entire solution runs in German data centers. Redundant across two sites, from the integration layer to the data platform.
We work with operators of critical infrastructure and regulated industries. We know what the BSI, supervisory authorities, operating authorities and data protection officers expect.
One team accompanies you from consulting to operations. Integration developers, platform engineers and security specialists stay on without handover to third parties.
Most control rooms do not fail on technology but on isolated systems, untested redundancy and missing evidence for the supervisory authority and the BSI.
01
There is no maintenance window because the emergency line never pauses, and every change to the dispatch system carries the risk of interrupting call handling.
02
Dispatch system, radio, alerting, geodata and hospital links come from different vendors, and dispatchers type data in twice.
03
A backup site exists, but the failover was never rehearsed under load, and the recovery times are not defined anywhere.
04
Protective measures are in place, but without the risk analysis, attack detection and reporting process that the BSI and the supervisory authority want to see proven.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your control room, your data center, your HSMs | Data centers in Germany, two sites, operated under ISO 27001 | Azure, AWS or Google Cloud, region Germany, for analytics and exercises |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with on-call service and agreed maintenance windows | Shared, platform services by the provider |
| Tools | Dispatch system, radio connection, PostgreSQL, Kubernetes on site | Hosted integration layer, geo-redundant data storage, HSM | Managed data services, analytics, cloud HSM services |
| Suited for | Call handling, dispatch system, radio connection | Control room networks with a need for redundancy and evidence | Data platform, simulations, training |
| Compliance | Full control, evidence from your ISMS | Processing agreement under GDPR, location Germany, KRITIS evidence | Processing agreement, standard contractual clauses, no emergency call data |
Collaboration
Project
Clearly scoped undertaking such as an interface consolidation or the setup of a backup site with a defined result, milestones and acceptance.
Team reinforcement
Integration developers, platform engineers or security specialists work in your teams, tools and release processes, aligned with the shifts of the control room.
Managed service
OTOKO® operates integration layer, platform or security monitoring with agreed service levels, on-call service around the clock and the reports that KRITIS and NIS2 require.
What each regulation for control rooms and ambulance services requires and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| KRITIS | Appropriate technical and organizational precautions, attack detection systems, reporting of significant disruptions and regular evidence to the BSI | Security concept with measures, SIEM with attack detection, reporting process and documents for the evidence |
| NIS2 | Risk management, reporting of significant incidents within deadlines, supply chain security, business continuity and accountability of management | Risk analysis, reporting process with deadlines, supply chain review, emergency manual and documents for management |
| GDPR | Legal basis, data minimization, encryption and access control for health data, processing agreements, data protection impact assessment | Crypto concept, roles and logs, pseudonymization in the data platform, processing agreement, support for the impact assessment |
| ISO 22301 | Business continuity management with analysis of critical processes, recovery objectives, emergency plans and regular exercises | Redundancy concept, defined recovery objectives, emergency manual, exercises under load with records |
| BSI IT-Grundschutz | Protection needs assessment, modeling with building blocks, implementation of the requirements and evidence in the security concept | Protection needs analysis per system, security concept with building blocks, hardened systems and operating procedures under IT-Grundschutz |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers the integration of control rooms with call handling, dispatch system and external sources, the connection of BOS digital radio and alerting with mobile applications, highly available operations with disaster recovery, IT security under KRITIS and NIS2, encryption and PKI for response data, and data platforms for response planning. Each field of action can be commissioned on its own or as a package, on request with operation by OTOKO®.
Redundant systems at two sites take over when a component, a site or a network fails, and the failover runs automatically under tested procedures. Fallback levels such as a backup site or prepared manual procedures keep call handling running until the technology is back. Exercises under ISO 22301 show regularly whether recovery times and procedures hold in a real emergency.
Through the control room interface of the TETRA network we take status messages, short messages and vehicle positions into the dispatch system and send response orders back. The connection runs through an integration layer that detects radio network outages and synchronizes data as soon as the connection is back. Alerts are triggered in parallel over pagers, radio and app.
KRITIS requires technical and organizational precautions, attack detection and regular evidence to the BSI, and NIS2 adds risk management, reporting deadlines for significant incidents, supply chain security and the accountability of management. An inventory shows which gaps to close first. We work with operators of critical infrastructure and regulated industries. There this path is standard.
Health data is encrypted in databases, backups and on mobile devices with keys from an HSM, access runs through roles and smartcard or FIDO2, and every key use is logged. In the data platform, models work with pseudonymized data. Crypto concept, roles and logs form the evidence for the data protection officer.
Every change is verified in a test environment with the control room's interfaces, rolled out in stages outside peak response times and equipped with a rollback plan. Redundant systems allow one site to be updated while the other carries call handling. Maintenance windows, escalation paths and releases are agreed with control room management.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: Target architecture, security concept, KRITIS and NIS2 evidence. Integration developer: Interfaces, middleware, radio and alerting connection. Platform engineer: Redundant platform, failover, recovery. Cryptography specialist: PKI, HSM, encryption of response data. Data engineer: Data platform, models, analyses. Project lead: Milestones, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
System landscape, outage risks, protection needs and gaps under KRITIS and NIS2 Prioritized list of measures, interface catalog, risk analysis, gap analysis for KRITIS and NIS2
Project: Clearly scoped undertaking such as an interface consolidation or the setup of a backup site with a defined result, milestones and acceptance. Team reinforcement: Integration developers, platform engineers or security specialists work in your teams, tools and release processes, aligned with the shifts of the control room. Managed service: OTOKO® operates integration layer, platform or security monitoring with agreed service levels, on-call service around the clock and the reports that KRITIS and NIS2 require.
Monitoring, on-call service, exercises, audits, knowledge transfer Monitoring, maintenance in windows, exercise records, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Emergency
Let us discuss how your control room can be integrated resiliently and protected as critical infrastructure.
Book a first consultation