Navigation

Get in touch
Logo
News

Industries / Emergency

Securely connected. When it matters.

Connect dispatch centres and operate critical emergency systems reliably.

Consulting. Integration. Operations.

yellow and white van on road during daytime — illustrative image

Built around your industry.

  • Integrated control rooms
  • Municipal authorities and joint authorities
  • Ambulance services and relief organizations
  • Fire departments and civil protection

Your priorities

Understand the challenge. Shape the solution.

We connect dispatch systems, call handling, BOS digital radio, and external data sources through secured interfaces, operate the platform redundantly in data centers located in Germany, and harden your control room against attacks.

01

Control room integration and call handling

Interface catalog with data flows and owners

More on this
02

High availability and disaster recovery

Redundancy and recovery concept with defined objectives

More on this
03

Identity, encryption and key custody for response data

Crypto concept with key hierarchy and roles

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Control room integration and call handlingNG112 and eCall · IVENA eHealth · Apache Kafka

Our approach

A control room combines call taking, dispatch system, alerting, radio and geodata from systems of several vendors. We connect these components through an integration layer with versioned interfaces, attach external sources such as hospital capacities via IVENA and emergency calls under NG112 with eCall, and test every interface under load before it goes into live operation. Changes run in stages so that call handling and alerting keep working throughout.

Full scope
  • Interface catalog with data flows, owners and dependencies between dispatch system, radio, alerting and geodata
  • Integration layer with middleware and event processing so that systems exchange response data without direct coupling
  • Call handling under NG112 with eCall, location transmission and connection of the German emergency call app nora
  • Connection of hospital capacities via IVENA, geodata via OGC services and weather warnings
  • Load and failure tests per interface, release process and staged rollout outside peak response times

An ambulance service authority eliminates double entry between dispatch system and hospital link; capacities from IVENA appear directly at the dispatcher, and every handover is logged.

What you get

  • Interface catalog with data flows and owners
  • Tested, versioned interfaces with release process
  • Operating model with monitoring and change procedures
Discuss this topic
02BOS digital radio, alerting and mobile response dataTETRA · POCSAG · Android and iOS

Our approach

BOS digital radio under TETRA delivers voice, status messages and positions, and alerting reaches crews through pagers and apps. We develop applications that take status messages and positions from the radio network into the dispatch system, trigger alerts over POCSAG, TETRA and app in parallel and show crews current response data on vehicles and tablets. The applications keep working when the network drops and synchronize data as soon as the connection is back.

Full scope
  • Connection of BOS digital radio through the control room interface for status messages, short messages and positions under TETRA LIP
  • Alerting service with triggering over POCSAG pagers, TETRA and app, with acknowledgment and escalation
  • Mobile applications for vehicles and tablets with offline mode, response data, navigation and response documentation
  • Roles and login with device certificates and mobile device management, encryption of data on the device
  • Operation of the applications with monitoring, updates in agreed windows and support for control room and crews

A fire department replaces separate alerting over radio and phone lists with a service that triggers pagers, TETRA and app at the same time; acknowledgments appear in the dispatch system.

What you get

  • Radio and alerting concept with escalation levels
  • Applications for radio connection, alerting and mobile response data
  • Operations and support documentation for control room and crews
Discuss this topic
03High availability and disaster recoveryKubernetes · PostgreSQL with Patroni · Veeam

Our approach

High availability means that call handling and the dispatch system keep running when individual components, a site or a network fail. We plan redundant sites with geo-redundant data storage, automated failover procedures and tested recovery plans and operate the platform in German data centers or in your control room. Recovery time and data loss objectives are defined with you under ISO 22301 and rehearsed regularly.

Full scope
  • Redundancy concept with two sites, separate network paths, emergency power and priorities per system
  • Geo-redundant data storage with PostgreSQL and Patroni, Kubernetes clusters across sites, automated failover
  • Backup and recovery with Veeam, immutable backups against ransomware, tested recovery plans
  • Business continuity management under ISO 22301 with emergency manual, fallback levels and exercises under load
  • Monitoring with alerts to the on-call service, capacity planning and maintenance in agreed windows

Two control rooms of a network back each other up; in an exercise the second site takes over call handling while the first restarts without data loss.

What you get

  • Redundancy and recovery concept with defined objectives
  • Redundant platform with automated failover
  • Emergency manual with exercise records
Discuss this topic
04IT security for control rooms as critical infrastructureMicrosoft Sentinel · Splunk · OPSWAT MetaDefender Kiosk

Our approach

Control rooms are targets for extortion and sabotage, and KRITIS and NIS2 require attack detection, reporting processes and regular evidence. We assess the security posture under BSI IT-Grundschutz, segment networks between call handling, administration and the internet, harden systems and set up a SIEM with use cases for control rooms. Removable media is inspected before connection, and a rehearsed incident response process keeps the reporting deadlines.

Full scope
  • Security assessment under BSI IT-Grundschutz with protection needs per system and prioritized list of measures
  • Network segmentation between call handling, dispatch system, administration and internet gateways with firewalls
  • Security monitoring with SIEM, attack detection under the requirements for KRITIS operators and on-call service
  • Inspection of removable media with OPSWAT MetaDefender Kiosk, endpoint protection and patch process
  • Incident response plan with reporting process under NIS2, exercises and evidence for the BSI and the supervisory authority

A municipal control room sets up attack detection and a reporting process; the evidence for the BSI rests on SIEM logs, exercise reports and the updated risk analysis.

What you get

  • Security concept under BSI IT-Grundschutz with risk analysis
  • Segmented network with SIEM and attack detection
  • Incident response plan with reporting process and exercise evidence
Discuss this topic
05Identity, encryption and key custody for response dataUtimaco u.trust GP HSM · Thales Luna · Entrust nShield

Our approach

Response and health data need particular protection, and GDPR and KRITIS require encryption, access control and logging. We build a PKI for dispatchers, vehicles and devices, keep its keys in an HSM and encrypt databases, backups and mobile devices with keys from this custody. Dispatchers log in with smartcard or FIDO2, administrators work under the four-eyes principle, and every use of a key is logged.

Full scope
  • Crypto concept with key hierarchy, roles and algorithms under BSI TR-02102 for databases, backups and devices
  • PKI with offline root CA and issuing CA on HSM, certificates for dispatchers, vehicles, tablets and services
  • Vendor-neutral HSM selection and integration, for example Utimaco u.trust GP HSM, Thales Luna or Entrust nShield
  • Login with smartcard or FIDO2, privileged access management for administrators, logging of every key use
  • Encryption of files and devices with Utimaco LAN Crypt, key custody and recovery documented

An ambulance service encrypts response documentation and tablets with keys from the HSM; the data protection officer receives crypto concept, roles and log evidence.

What you get

  • Crypto concept with key hierarchy and roles
  • PKI and HSM in operation with recorded commissioning
  • Data protection evidence with encryption and logs
Discuss this topic
06Data platform and AI for response planningApache Kafka · PostgreSQL and PostGIS · Apache Spark

Our approach

Response data from several years shows when and where which incidents occur and how long vehicles are on the road. We merge response, vehicle and geodata in a data platform, train models on it for incident volume and station planning and provide analyses for demand planning, quality management and exercises. Personal data is pseudonymized, and every model is documented under the EU AI Act and reviewed regularly.

Full scope
  • Data platform connected to dispatch system, vehicle data, geodata and population statistics, data stored in Germany
  • Models for incident volume by time and area, analysis of response time targets and simulation of station variants
  • Analyses for demand planning, quality management and reports to the authority and the supervisor
  • Pseudonymization, deletion concept and data protection impact assessment under GDPR
  • Model operations with versioning, monitoring of data quality and documentation under the EU AI Act

An authority simulates station variants for ambulance stations based on response data from several years; demand planning rests on traceable analyses instead of estimates.

What you get

  • Data platform connected to response and geodata
  • Versioned models with model card and review record
  • Analyses and reports for demand planning and quality management
Discuss this topic
clear glass jar with orange liquid — illustrative image
Emergency

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Emergency

Backup site for a control room network

Two control rooms work separately, the backup site was never tested under load, recovery times are not defined.

Solution

Redundancy concept with mutual takeover, geo-redundant data storage, automated failover, emergency manual under ISO 22301, exercise under load.

Tested takeover of call handling, documented recovery times, exercise records for the authority and the supervisor.

Discuss this topic

02 / Emergency

Interface consolidation at an ambulance service authority

Dispatch system, radio status, alerting and hospital link run separately, dispatchers enter data several times.

Solution

Interface catalog, integration layer with event processing, connection of BOS digital radio, IVENA and alerting, load tests per interface.

One situational picture in the dispatch system, no double entry, versioned interfaces with release process.

Discuss this topic

03 / Emergency

NIS2 implementation at a municipal control room

Classification as an entity under NIS2 is due, risk analysis, attack detection and reporting process are missing.

Solution

Security assessment under BSI IT-Grundschutz, network segmentation, SIEM with use cases, incident response plan with reporting process, exercise.

Auditable risk analysis, attack detection in operation, reporting process with rehearsed deadlines.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    System landscape, outage risks, protection needs and gaps under KRITIS and NIS2

    Prioritized list of measures, interface catalog, risk analysis, gap analysis for KRITIS and NIS2
  2. 02

    Concept

    Target architecture, redundancy concept, security measures, operating model

    Target architecture, redundancy and recovery concept, security concept, operating model
  3. 03

    Implementation

    Interfaces, redundancy, security and applications in stages outside peak response times

    Integrated systems, tested failover, attack detection, documentation, acceptance per stage
  4. 04

    Operations

    Monitoring, on-call service, exercises, audits, knowledge transfer

    Monitoring, maintenance in windows, exercise records, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for emergency services?

Six fields of action from control room integration to a data platform for response planning, planned, integrated and operated by OTOKO®. Every change is carried out so that call handling and alerting keep working. The entire solution runs in German data centers.

IT solutions for emergency services keep call handling, the dispatch system and alerting available around the clock, connect control room, radio and crews through secured interfaces and prove protective measures to the BSI and the supervisory authority. OTOKO® covers six fields of action: control room integration and call handling, BOS digital radio and alerting with mobile response data, high availability and disaster recovery, IT security under KRITIS and NIS2, identity and encryption for response data, and a data platform with AI for response planning.

The difference to a pure consulting project lies in operations and evidence. Every interface, failover and recovery gets a record, a version and the documents that KRITIS, NIS2 and BSI IT-Grundschutz require. The entire solution runs in German data centers. Redundant across two sites and with key sovereignty at your control room.

Why OTOKO® for emergency services

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Keys for response and health data, device certificates and backups therefore sit in certified hardware.

  • German data centers

    The entire solution runs in German data centers. Redundant across two sites, from the integration layer to the data platform.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the BSI, supervisory authorities, operating authorities and data protection officers expect.

  • One team through to operations

    One team accompanies you from consulting to operations. Integration developers, platform engineers and security specialists stay on without handover to third parties.

Delivery and details

Most control rooms do not fail on technology but on isolated systems, untested redundancy and missing evidence for the supervisory authority and the BSI.

Maintenance only during live operations

There is no maintenance window because the emergency line never pauses, and every change to the dispatch system carries the risk of interrupting call handling.

Isolated systems from several vendors

Dispatch system, radio, alerting, geodata and hospital links come from different vendors, and dispatchers type data in twice.

Redundancy on paper

A backup site exists, but the failover was never rehearsed under load, and the recovery times are not defined anywhere.

Missing evidence for KRITIS and NIS2

Protective measures are in place, but without the risk analysis, attack detection and reporting process that the BSI and the supervisory authority want to see proven.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour control room, your data center, your HSMsData centers in Germany, two sites, operated under ISO 27001Azure, AWS or Google Cloud, region Germany, for analytics and exercises
OperationYour team or OTOKO® as managed serviceOTOKO®, with on-call service and agreed maintenance windowsShared, platform services by the provider
ToolsDispatch system, radio connection, PostgreSQL, Kubernetes on siteHosted integration layer, geo-redundant data storage, HSMManaged data services, analytics, cloud HSM services
Suited forCall handling, dispatch system, radio connectionControl room networks with a need for redundancy and evidenceData platform, simulations, training
ComplianceFull control, evidence from your ISMSProcessing agreement under GDPR, location Germany, KRITIS evidenceProcessing agreement, standard contractual clauses, no emergency call data

Collaboration

Project

Clearly scoped undertaking such as an interface consolidation or the setup of a backup site with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for system replacements, backup sites and evidence preparation

Team reinforcement

Integration developers, platform engineers or security specialists work in your teams, tools and release processes, aligned with the shifts of the control room.

  • Onboarding into your procedures, systems and response rules
  • Scalable as the project progresses
  • Suited for authorities with their own IT team and capacity gaps

Managed service

OTOKO® operates integration layer, platform or security monitoring with agreed service levels, on-call service around the clock and the reports that KRITIS and NIS2 require.

  • Monitoring, on-call service, updates and support
  • Reports, exercise records and evidence in the contract
  • Suited for control rooms without their own operations team for platform or security

What each regulation for control rooms and ambulance services requires and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
KRITISAppropriate technical and organizational precautions, attack detection systems, reporting of significant disruptions and regular evidence to the BSISecurity concept with measures, SIEM with attack detection, reporting process and documents for the evidence
NIS2Risk management, reporting of significant incidents within deadlines, supply chain security, business continuity and accountability of managementRisk analysis, reporting process with deadlines, supply chain review, emergency manual and documents for management
GDPRLegal basis, data minimization, encryption and access control for health data, processing agreements, data protection impact assessmentCrypto concept, roles and logs, pseudonymization in the data platform, processing agreement, support for the impact assessment
ISO 22301Business continuity management with analysis of critical processes, recovery objectives, emergency plans and regular exercisesRedundancy concept, defined recovery objectives, emergency manual, exercises under load with records
BSI IT-GrundschutzProtection needs assessment, modeling with building blocks, implementation of the requirements and evidence in the security conceptProtection needs analysis per system, security concept with building blocks, hardened systems and operating procedures under IT-Grundschutz

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for emergency services does OTOKO® offer?

The portfolio covers the integration of control rooms with call handling, dispatch system and external sources, the connection of BOS digital radio and alerting with mobile applications, highly available operations with disaster recovery, IT security under KRITIS and NIS2, encryption and PKI for response data, and data platforms for response planning. Each field of action can be commissioned on its own or as a package, on request with operation by OTOKO®.

How does the control room stay operational during an IT outage?

Redundant systems at two sites take over when a component, a site or a network fails, and the failover runs automatically under tested procedures. Fallback levels such as a backup site or prepared manual procedures keep call handling running until the technology is back. Exercises under ISO 22301 show regularly whether recovery times and procedures hold in a real emergency.

How do you connect BOS digital radio to the dispatch system?

Through the control room interface of the TETRA network we take status messages, short messages and vehicle positions into the dispatch system and send response orders back. The connection runs through an integration layer that detects radio network outages and synchronizes data as soon as the connection is back. Alerts are triggered in parallel over pagers, radio and app.

What do KRITIS and NIS2 mean for our control room?

KRITIS requires technical and organizational precautions, attack detection and regular evidence to the BSI, and NIS2 adds risk management, reporting deadlines for significant incidents, supply chain security and the accountability of management. An inventory shows which gaps to close first. We work with operators of critical infrastructure and regulated industries. There this path is standard.

How is patient health data protected?

Health data is encrypted in databases, backups and on mobile devices with keys from an HSM, access runs through roles and smartcard or FIDO2, and every key use is logged. In the data platform, models work with pseudonymized data. Crypto concept, roles and logs form the evidence for the data protection officer.

How do changes run without interrupting live operations?

Every change is verified in a test environment with the control room's interfaces, rolled out in stages outside peak response times and equipped with a rollback plan. Redundant systems allow one site to be updated while the other carries call handling. Maintenance windows, escalation paths and releases are agreed with control room management.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Target architecture, security concept, KRITIS and NIS2 evidence. Integration developer: Interfaces, middleware, radio and alerting connection. Platform engineer: Redundant platform, failover, recovery. Cryptography specialist: PKI, HSM, encryption of response data. Data engineer: Data platform, models, analyses. Project lead: Milestones, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

System landscape, outage risks, protection needs and gaps under KRITIS and NIS2 Prioritized list of measures, interface catalog, risk analysis, gap analysis for KRITIS and NIS2

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as an interface consolidation or the setup of a backup site with a defined result, milestones and acceptance. Team reinforcement: Integration developers, platform engineers or security specialists work in your teams, tools and release processes, aligned with the shifts of the control room. Managed service: OTOKO® operates integration layer, platform or security monitoring with agreed service levels, on-call service around the clock and the reports that KRITIS and NIS2 require.

What happens at handover to operations?

Monitoring, on-call service, exercises, audits, knowledge transfer Monitoring, maintenance in windows, exercise records, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Emergency

Let's discuss your next step.

Let us discuss how your control room can be integrated resiliently and protected as critical infrastructure.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.