Navigation

Get in touch
Logo
News

Industries / Manufacturing

Connect production. Protect know-how.

Connect MES, ERP and production while protecting industrial control systems.

Consulting. Integration. Operations.

a factory filled with lots of orange machines — illustrative image

Built around your industry.

  • Machine and plant builders
  • Automotive and supplier industry
  • Electronics and device manufacturers
  • Series manufacturers with several plants

Your priorities

Understand the challenge. Shape the solution.

We integrate MES and ERP into one continuous data chain, bring machine and quality data together on data platforms and develop models for predictive maintenance and planning.

01

Industrie 4.0 data platform with MES, ERP and OPC UA

Integration architecture with interface catalog and data contracts

More on this
02

Secure remote maintenance for plants and vendors

Access concept with roles, approval process and contract annex for vendors

More on this
03

Predictive maintenance and quality prediction with machine learning

Data platform with asset model and connected sources

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Industrie 4.0 data platform with MES, ERP and OPC UAOPC UA · MQTT and Sparkplug B · ISA-95

Our approach

The manufacturing execution system (MES) runs production, the ERP manages orders, material and finance, and machines report their states over OPC UA. We place an integration layer to ISA-95 with versioned interfaces between these levels so that orders reach the shop floor automatically and confirmations flow back without rework. Older equipment is connected through retrofitted gateways without touching the controller. Master data, bills of materials and batches stay consistent in one system of record.

Full scope
  • Interface catalog to ISA-95 with data contracts, owners and dependencies between MES, ERP and shop floor
  • Machine connectivity over OPC UA, MQTT with Sparkplug B and retrofitted gateways for equipment without an interface
  • Event processing with Apache Kafka and a time-series store for states, cycle times and quality characteristics
  • Order download, confirmations and batch traceability between MES and ERP, such as SAP S/4HANA, over versioned interfaces
  • Automated tests, release process and monitoring per interface, changes in the plant's maintenance window

A series manufacturer replaces nightly file exports between MES and ERP with an integration layer; planning sees machine states and confirmations at the same pace as production.

What you get

  • Integration architecture with interface catalog and data contracts
  • Tested, versioned interfaces between MES, ERP and shop floor
  • Operations manual with monitoring and change procedures
Discuss this topic
02OT security with zones and conduits to IEC 62443IEC 62443-3-3 · OPSWAT MetaDefender NetWall · OPSWAT MetaDefender Kiosk

Our approach

IEC 62443 divides a plant into zones with the same protection need and conduits for the controlled traffic between them, and each zone gets a target security level. We inventory equipment, controllers and data flows, assess risks to IEC 62443-3-2 and separate production networks from the office network with segmentation, firewalls and data diodes. Passive network monitoring detects new devices and unusual connections without loading the controllers. Removable media and maintenance laptops pass a checkpoint before they enter a zone.

Full scope
  • Asset inventory with controllers, HMIs, network and remote access points as the basis for zones and conduits
  • Risk assessment and zone model to IEC 62443-3-2 with a target security level per zone to IEC 62443-3-3
  • Segmentation with industrial firewalls, data diodes and a DMZ between office IT and production along the Purdue model
  • Passive OT monitoring with asset inventory, anomaly detection and connection to the SIEM
  • Checkpoint for removable media and maintenance laptops, hardening of engineering workstations and backup of controller programs

An automotive supplier separates press shop, paint shop and assembly into zones with their own conduits; an incident in office IT has since had no effect on the lines.

What you get

  • Zone and conduit model with risk assessment to IEC 62443-3-2
  • Segmented production network with firewall rule set and checkpoint
  • OT monitoring with asset inventory and alerting in the SIEM
Discuss this topic
03Secure remote maintenance for plants and vendorsPrivileged access management · FIDO2 and passkeys · OpenID Connect

Our approach

Machine vendors, integrators and your own maintenance staff need access to controllers, often at night and from outside the plant. We replace permanent VPN tunnels and shared passwords with a central access platform with personal accounts, multi-factor authentication and approval per job. Every session terminates on a jump host inside the zone, is recorded and ends automatically when the ticket closes. External companies reach only the machine named in the ticket and only for the agreed time.

Full scope
  • Access concept with roles for vendors, integrators and maintenance, approval per job through a ticket, for example in Jira Service Management
  • Central access platform with identity provider, multi-factor authentication with FIDO2 and personal accounts for external companies
  • Jump hosts and privileged access management with session recording, time windows and automatic termination
  • Conduits for remote maintenance to IEC 62443 with protocol filtering, without a permanent tunnel into the zone
  • Replacement of vendor routers and modems at the machine with a documented migration plan per line

A plant consolidates the remote access of several machine vendors on one access platform; every job is tied to a ticket, recorded and available for the customer audit.

What you get

  • Access concept with roles, approval process and contract annex for vendors
  • Operational access platform with jump hosts per zone
  • Session logs and reports for customer audits and NIS2
Discuss this topic
04Device identities and firmware signing with an HSM-backed PKIEntrust nShield 5c · Utimaco u.trust GP HSM Se-Series · Thales Luna 7 Network HSM

Our approach

The Cyber Resilience Act requires secure updates for products with digital elements throughout the support period. We build a device PKI whose root CA and issuing CA keep their keys in an HSM certified to FIPS 140-3 Level 3. Firmware is signed from the build pipeline with separation of roles, approval and a record per release. Every device receives its own identity to IEEE 802.1AR on the production line, which it later presents to cloud, remote maintenance and the update server. Vendor-neutrally we choose between Entrust nShield 5c, Utimaco u.trust GP HSM and Thales Luna 7, depending on certification, throughput and operating model.

Full scope
  • PKI architecture with offline root CA, issuing CA per product line and key custody in an HSM certified to FIPS 140-3 Level 3
  • Firmware signing in the CI/CD pipeline with separation of roles, four-eyes approval and a signing record per release
  • Device identities to IEEE 802.1AR with key generation in the device and certificate issuance over EST or SCEP on the production line
  • Certificate lifecycle with EverTrust CLM, renewal in the field, revocation and evidence for the Cyber Resilience Act
  • Secure boot and update verification in the device, SBOM per firmware version and vulnerability process to Annex I of the CRA

A manufacturer of drive controllers moves its signing key from the build server into an HSM; every release is signed after approval and every device leaves the factory with its own certificate.

What you get

  • PKI architecture with certificate policy and HSM concept
  • Signing service in the build pipeline with record evidence
  • Device enrollment on the production line with lifecycle process
Discuss this topic
05Predictive maintenance and quality prediction with machine learningTimescaleDB · scikit-learn · XGBoost

Our approach

Machines deliver vibration, temperature, current and cycle times, test stations deliver measurements and scrap reasons. We merge these series with order and maintenance data and train two kinds of models on them. One detects anomalies in bearings, spindles and pumps days before a failure, the other predicts the quality of a batch from process parameters. Every prediction names the features that triggered it so that maintenance and quality assurance can check it. Models run versioned in production, with drift monitoring and controlled retraining after a tool change or a recipe change.

Full scope
  • Data platform for time series from OPC UA, test stations, MES and maintenance system with one common asset model
  • Anomaly detection for bearings, spindles, pumps and drives with vibration and current analysis, validated against historical failures
  • Quality prediction per batch from process parameters with an explanation of the strongest influencing factors
  • Integration of predictions into maintenance orders and inspection plans, alerting with thresholds per asset
  • Model operations with versioning, drift monitoring and documentation under the EU AI Act for systems that touch worker safety

A manufacturer of plastic parts predicts scrap per batch from temperature, pressure and cycle time; setters correct parameters before the test station reports the problem.

What you get

  • Data platform with asset model and connected sources
  • Versioned models for anomaly detection and quality prediction with model card
  • Operations dashboard with alerts and drift monitoring
Discuss this topic
06Post-quantum readiness for long-lived machine identitiesML-KEM (FIPS 203) · ML-DSA (FIPS 204) · LMS and XMSS (SP 800-208)

Our approach

Machines stay in the field for twenty years, yet their certificates and signatures rely on RSA and elliptic curves, which capable quantum computers will break. We inventory the cryptography in controllers, device PKI, remote maintenance and firmware signing and rate each use by device lifetime and the effort of a replacement. Firmware signatures move first, because hash-based schemes such as LMS and XMSS are standardized today and run in HSMs. Device identities and TLS follow with ML-DSA and ML-KEM in hybrid certificates as soon as controllers and libraries support them.

Full scope
  • Crypto inventory across controllers, device PKI, remote maintenance, TLS and firmware signing, on request with EverTrust CPM
  • Rating per use by device lifetime, replacement effort in the field and protection period of the data
  • Migration of firmware signing to LMS or XMSS under NIST SP 800-208 with state management in the HSM
  • Hybrid certificates with ML-DSA for device identities and tests of controllers for memory and runtime of the new schemes
  • Crypto agility in update client and PKI so that schemes can change without a hardware swap, roadmap in stages

A manufacturer of field devices signs new firmware additionally with LMS; devices of the next generation verify both signatures, older devices keep the classical check until replacement.

What you get

  • Crypto inventory with risk rating per product line
  • Migration roadmap for firmware signing, device PKI and remote maintenance
  • Crypto agility concept for update client and PKI
Discuss this topic
a line of electrical equipment in a factory — illustrative image
Manufacturing

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Manufacturing

CRA preparation at a machine builder

New machine generation with network connectivity, firmware updates unsigned, signing key as a file on the build server, no SBOM.

Solution

Device PKI with HSM, signing service in the build pipeline with approval per release, device identities from the factory, SBOM and vulnerability process to the CRA.

Signed updates with records, technical documentation for the conformity assessment, reporting process for exploited vulnerabilities in place.

Discuss this topic

02 / Manufacturing

OT segmentation at an automotive supplier

One network from office to press, remote maintenance over vendor routers at the machine, customer audit to IEC 62443 announced.

Solution

Zone and conduit model with risk assessment, firewalls and a data diode between office IT and production, central access platform with session recording.

Customer audit passed, remote access approved and logged per ticket, incidents in office IT without effect on the lines.

Discuss this topic

03 / Manufacturing

Quality prediction at a plastics processor

Scrap shows up only at the test station, MES and ERP exchange data in nightly runs, process data sits unused in the controllers.

Solution

Integration layer between MES and ERP, time-series platform over OPC UA, quality model per batch with explanation of influencing factors.

Confirmations at the pace of production, parameter correction before inspection, versioned models with drift monitoring in operation.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Equipment, systems, interfaces, data flows and regulatory gaps

    Asset inventory, interface catalog, crypto inventory, gap analysis for IEC 62443, NIS2 and CRA, prioritized list of measures
  2. 02

    Concept

    Zone model, integration architecture, PKI and operating model

    Zone and conduit model, integration architecture, PKI and HSM concept, data model, operating model, test concept
  3. 03

    Implementation

    Segmentation, interfaces, signing service and models in maintenance windows

    Segmented network, tested interfaces, signing service with records, models in operation, documentation and acceptance per stage
  4. 04

    Operations

    Monitoring, certificates, audits, knowledge transfer

    OT monitoring, certificate renewal, model monitoring, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for manufacturing?

Six modules from MES and ERP integration to post-quantum readiness, planned, integrated and operated by OTOKO®. Production networks, remote maintenance and products with digital elements meet IEC 62443, NIS2 and the Cyber Resilience Act with evidence that holds up in audits. The entire solution runs in German data centers.

IT solutions for manufacturing connect machines, manufacturing execution systems and business software into one continuous data chain and protect operational technology and connected products against attacks. OTOKO® covers six modules: an Industrie 4.0 data platform with MES, ERP and OPC UA, OT security to IEC 62443, secure remote maintenance, device identities and firmware signing with an HSM-backed PKI, predictive maintenance and quality prediction with machine learning, and post-quantum readiness for long-lived machine identities.

What sets OTOKO® apart from a consultancy is the path into operations. Zone model, interfaces, models and releases come with records, version history and the documents that customer audits, NIS2 and the Cyber Resilience Act ask for. Cryptography and hardware security modules are our core competence. Signing keys and the root of your device PKI therefore live in certified hardware, not as a file on a build server.

Why OTOKO® for manufacturing

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Firmware signing keys and the root of your device PKI live in certified HSMs rather than as a file on a build server.

  • German data centers

    The entire solution runs in German data centers, from the data platform through the PKI to the remote maintenance platform.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know customer audits to IEC 62443, TISAX assessments and what information security and production expect from a plant.

  • One team through to operations

    One team accompanies you from consulting to operations. OT security architects, integration developers and data engineers stay on, aligned with shifts and maintenance windows.

Delivery and details

Most plants do not fail on technology but on flat networks, data silos and obligations that arrive faster than the next maintenance window.

Flat network from office to controller

Controllers, HMI panels and office PCs share one network, remote maintenance lands directly on the machine and a ransomware incident in IT reaches production unhindered.

Data silos between shop floor and office

Machine data sits in vendor formats, the MES reports quantities to the ERP by file export and bills of materials are maintained by hand in both systems.

Signing key on the build server

Firmware is signed with a key that sits as a file on the build server, without separation of roles, a record or a plan for the day it is compromised.

Obligations without an owner

NIS2 demands risk management and reporting channels, the Cyber Resilience Act signed updates and vulnerability handling, yet operational technology and product development sit outside the information security management system.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour plant and your data center, OT data stays in the zoneData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region selectable
OperationYour team or OTOKO® as managed serviceOTOKO®, with audit rights for you and your customersShared, platform services by the provider
ToolsHSM, PKI and access platform in the plant, Kafka and time-series store at the edgeHosted HSMs, PKI as a service, data platform and remote maintenance platformCloud HSM services, IoT services, managed data services
Suited forController-level data, signing keys, plants without a stable connectionManufacturers with customer audits and a need for sovereigntyFleet data across sites, model training, load peaks
ComplianceFull control, evidence from your ISMS and zone modelProcessing agreement under GDPR, location Germany, evidence for TISAX assessmentsProcessing agreement, standard contractual clauses, exit scenario per service

Collaboration

Project

Clearly scoped undertaking such as a zone model to IEC 62443, an MES connection or a signing service with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for zone models, interfaces and CRA preparation

Team reinforcement

OT security architects, integration developers or data engineers work in your teams, tools and release processes, aligned with shifts and maintenance windows.

  • Onboarding into your equipment, systems and release processes
  • Scalable as the project progresses
  • Suited for plants with their own IT and capacity gaps in OT and data

Managed service

OTOKO® operates access platform, PKI and signing service, data platform or OT monitoring with agreed service levels, reports and the evidence that customer audits and NIS2 require.

  • Monitoring, certificate renewal, updates and support
  • Audit rights, service levels and exit scenarios in the contract
  • Suited for manufacturers without their own operations team for PKI, HSM or platform

Five regulations that affect plants and product manufacturers, with what they demand and what OTOKO® delivers for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
IEC 62443Zones and conduits, risk assessment and target security levels for plants, secure development and component requirements for manufacturers, obligations for service providersZone and conduit model to 62443-3-2, segmentation and monitoring to 62443-3-3, remote maintenance to 62443-2-4, development process to 62443-4-1 for your products
Cyber Resilience ActSecurity by design, no known exploitable vulnerabilities at delivery, secure updates throughout the support period, SBOM, reporting of actively exploited vulnerabilities within 24 hours, CE conformitySigning service with HSM, device PKI, update mechanism, SBOM per release, vulnerability and reporting process, technical documentation for the conformity assessment
NIS2Risk management with supply chain security, incident handling, cryptography and access control, reporting of significant incidents, management accountability, for machinery, electrical equipment and vehicle manufacturing as important entitiesOT inside the ISMS scope, zone model and monitoring, reporting channels with deadlines, evidence for remote maintenance and suppliers, documents for the registration with the BSI
ISO 27001Information security management system with risk assessment, statement of applicability, Annex A controls, internal audits and management reviewExtension of the scope to production and product development, risk register for OT, controls and evidence, operation of our services under ISO 27001
TISAXInformation security assessment against the VDA ISA catalog with assessment levels, prototype protection and data protection, exchange of results over the ENX platformGap analysis against VDA ISA, controls for network separation, access and remote maintenance, evidence for the assessment level your customers require

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for manufacturing does OTOKO® offer?

The portfolio covers the integration of MES, ERP and machines over OPC UA, OT security to IEC 62443, secure remote maintenance, device PKI and firmware signing with HSMs, predictive maintenance and quality prediction, and post-quantum readiness for machine identities. Each module can be commissioned on its own or as a package, with operation in German data centers.

Does the Cyber Resilience Act also apply to machine and plant builders?

Yes, as soon as a machine contains control software or has a network connection and is placed on the EU market. The manufacturer then has to demonstrate security by design, handle and report vulnerabilities, maintain an SBOM and provide security updates throughout the support period. The reporting obligations have applied since September 2026, the remaining obligations apply from December 2027, and signing service, device PKI and update process need lead time before that.

Can an older machine park be connected without changing the controllers?

Usually yes. Equipment without OPC UA is connected through retrofitted gateways or additional sensors that read signals without touching the controller program. We check for each machine which data is available and which route is economical, and we plan the zone and the conduit for the gateway from the start.

How does remote maintenance by machine vendors become secure?

Instead of a router or VPN tunnel at the machine, every external technician gets a personal account with multi-factor authentication and an approval per job, tied to a ticket and a time window. The session runs over a jump host inside the zone, is recorded and ends automatically. We work with operators of critical infrastructure and regulated industries. There, this procedure is the precondition for any remote access.

Why do firmware signing keys belong in an HSM?

A signing key that exists as a file can be copied without anyone noticing, and a stolen key lets attackers pass off their own firmware as the manufacturer's software. In an HSM certified to FIPS 140-3 Level 3 the key never leaves the device, every signature is recorded and approval follows a separation of roles. The Cyber Resilience Act asks for exactly this evidence for the update mechanism.

When should machine identities become quantum-safe?

Now, with the inventory. Devices shipped today stay in service longer than the expected time until capable quantum computers arrive, and a change of algorithms in the field needs firmware updates, memory in the controller and lead time across several product generations. Firmware signatures with LMS or XMSS can be introduced right away, device identities follow with hybrid certificates as soon as the target hardware can process ML-DSA.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

OT security architect: Zone model, remote maintenance, evidence to IEC 62443. Integration developer: MES and ERP interfaces, OPC UA, gateways. Cryptography specialist: Device PKI, HSM, signing service, PQC roadmap. Data engineer: Time-series platform, models, drift monitoring. Compliance consultant: CRA, NIS2, TISAX, audit files. Project lead: Milestones, maintenance windows, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Equipment, systems, interfaces, data flows and regulatory gaps Asset inventory, interface catalog, crypto inventory, gap analysis for IEC 62443, NIS2 and CRA, prioritized list of measures

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a zone model to IEC 62443, an MES connection or a signing service with a defined result, milestones and acceptance. Team reinforcement: OT security architects, integration developers or data engineers work in your teams, tools and release processes, aligned with shifts and maintenance windows. Managed service: OTOKO® operates access platform, PKI and signing service, data platform or OT monitoring with agreed service levels, reports and the evidence that customer audits and NIS2 require.

What happens at handover to operations?

Monitoring, certificates, audits, knowledge transfer OT monitoring, certificate renewal, model monitoring, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Manufacturing

Let's discuss your next step.

Let us work out together how to connect machines, MES and ERP while securing your operational technology.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.