Zone architecture and intrusion detection for the I&C
Zone and conduit model with classification of all systems
More on thisIndustries / Nuclear
Protect sensitive facilities with secure zone architectures and hardware cryptography.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We segment plant networks according to IEC 62443, secure data flows with data diodes, and detect anomalies in I&C without intervening in protection systems.
Zone and conduit model with classification of all systems
More on thisInterface catalog with data flows and zones
More on thisData platform connected to historian and network sensors
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
A zone architecture divides the facility into areas with graded protection needs and governs every transition through defined conduits. We classify I&C systems by the security degrees of IEC 62645 and the security levels of IEC 62443, separate safety I&C strictly from operational I&C and the office network, and let data leave only through data diodes. Removable media are checked at kiosks before use, and passive sensors detect anomalies in network traffic without sending a single packet into the I&C. The result meets the duty to run intrusion detection under the BSI Act and the IAEA's expectations of a graded defensive architecture.
An operator in decommissioning introduces media kiosks and data diodes; decommissioning contractors receive plant data from a zone with no path back into the I&C.
Our approach
Software, firmware and configurations for the I&C reach the facility through vendors, contractors and removable media, and every change must be verifiable for origin and integrity. We build a signing chain in which vendors sign their deliveries, your engineering workstations verify the signature before loading, and your own approvals are made with keys in hardware security modules. The same PKI issues certificates for remote maintenance, site links and data diodes. We advise vendor-neutrally on Utimaco u.trust GP HSM, Thales Luna and Entrust nShield 5 and plan key ceremonies with roles, quorums and records.
An interim storage site requires signed updates from its I&C vendor; the kiosk verifies the signature, and the approval to load is made with a key from the operator's HSM.
Our approach
Plant management, maintenance, radiation protection and reporting need data from the facility but must not open a return path into the I&C. We integrate process data, document management and ERP through interfaces that start behind the data diode, are versioned, have an owner and log every access. Remote maintenance by vendors runs through jump servers with multi-factor authentication, session recording and per-job approval by your staff, not through standing access that stays open after the job.
An operator links its maintenance system and process data historian through a data diode; maintenance staff see readings in the office network without any connection into the I&C.
Our approach
Decommissioning records, clearance measurements, waste package data and operating logs must remain complete, unaltered and readable for decades, longer than any file format and any signature algorithm. We build archives that sign every record on entry, add a qualified timestamp and store it encrypted, and that preserve evidential value under BSI TR-03125 through re-signing. The signing keys live in the HSM, the formats follow PDF/A and XML with a documented schema, and access is role-based and logged for the regulator and its experts.
An operator in decommissioning moves clearance measurements and dismantling records into a signed archive; every record carries timestamp and signature, and re-signing is scheduled as a service.
Our approach
Process data, I&C alarms, network traffic data and maintenance history sit in separate systems and are rarely analyzed together. Behind the data diode we build a data platform that merges these sources, and on it we train models that flag deviations in plant behavior and network traffic early. Models give hints to shift staff and the security team but decide nothing themselves, and every analysis is versioned and documented traceably with a model card and data lineage.
An operator analyzes pump data and network traffic of the operational I&C together; a model flags a device that opens connections outside maintenance windows before anyone notices the incident.
Our approach
Capable quantum computers will break RSA and elliptic curves, on which software signatures, remote maintenance certificates and archive signatures rest today. For archives that must stay valid for decades this is not a distant problem, because a signature that later becomes forgeable loses its evidential value. We inventory algorithms, keys and certificates across I&C, PKI and archive, rely on hash-based schemes such as XMSS and LMS for long-term signatures, and plan the PKI migration to ML-DSA and hybrid certificates in stages, tied to hardware refresh and the modification procedure.
An operator switches the signatures of its decommissioning archive to XMSS and keeps the existing PKI for remote maintenance until the next hardware refresh, for which hybrid certificates are prepared.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Nuclear
Decommissioning contractors need plant data, network transitions have grown over decades, the regulator asks for the IT protection concept.
Inventory and classification under IEC 62645, zones with data diodes and kiosks, remote maintenance through jump servers with per-job approval.
Documented protection concept, controlled access for all contractors, evidence for the regulator and its experts.
02 / Nuclear
I&C updates arrive on removable media without verifiable origin, approvals are given by signature on paper.
Signing chain with vendor signature, verification at the kiosk, approval keys in the operator's HSM, ceremony records.
Every update verifiable for origin and integrity, approvals traceable in the modification procedure, HSM in operation.
03 / Nuclear
Operating logs and measurement data sit in file systems without signatures, the legacy archive runs on software without vendor support.
Signed archive with timestamp service, preservation of evidence under BSI TR-03125, hash-based signatures, migration from the legacy archive.
Evidential value for decades, re-signing as a service, recovery tested and documented.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
I&C systems, network transitions, media paths, archives and evidence gaps
Zones, conduits, signing chain, archive, operating model
Measures in maintenance windows and through the modification procedure, stage by stage
Monitoring, re-signing, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from the zone architecture of the I&C to the signed long-term archive for decommissioning, planned, implemented and operated by OTOKO®. No measure interferes with licensed safety systems, and every one can be evidenced to the regulator and its experts. The entire solution runs in German data centers.
Cybersecurity for nuclear facilities protects instrumentation and control, operational data and access paths against manipulation without touching nuclear safety. It applies to plants in decommissioning, interim storage sites, research reactors and fuel cycle facilities as much as to power plants in operation, in Germany and for operators abroad. OTOKO® covers six fields of action: zone architecture and intrusion detection for the I&C, signed software and PKI with hardware security modules, controlled interfaces and remote access, signed long-term archives for decommissioning and operation, a data platform for operational and security data, and post-quantum readiness for signatures and archives.
The difference from a pure consulting project lies in separation and evidence. Protective measures are built outside the licensed safety I&C, and every change passes through your modification procedure and receives a record, a version and the documents that the regulator, its technical experts and the BSI require. Cryptography and hardware security modules are our core competence. Signing keys for software, remote maintenance and archives therefore live in certified devices rather than in software.
Cryptography and hardware security modules are our core competence. Signing keys for I&C software, remote maintenance and archives live in certified hardware security modules with recorded ceremonies.
The entire solution runs in German data centers, from the hosted HSM and the timestamp service to the long-term archive for decommissioning.
We work with operators of critical infrastructure and regulated industries. We know what the nuclear regulator, technical experts, the BSI and information security expect of a protection concept and its evidence.
One team accompanies you from consulting to operations. Security architects, cryptography specialists and integration developers stay your contacts from concept through implementation in maintenance windows to operation.
Most operators do not fail on technology but on network transitions that grew over decades, unclear responsibilities between I&C and IT, and evidence that exists only on paper.
01
Over decades, connections between I&C, plant management and the office network have emerged that nobody has fully documented and that undermine every zone boundary.
02
Vendors bring updates on USB sticks and laptops, remote maintenance runs on individual agreements and no log shows who changed what and when.
03
The intrusion detection system sees email and servers but not the network traffic of the I&C, and nobody dares to place sensors there.
04
Decommissioning records, clearance measurements and operating logs sit in file systems without signature, timestamp or a procedure for re-signing over decades.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Plant and your data center, I&C data stays on site | Data centers in Germany under ISO 27001 for archive, data platform and office systems | Azure, AWS or Google Cloud only for systems without plant data |
| Operation | Your team or OTOKO® as managed service inside your zones | OTOKO®, with audit rights and reporting paths under KRITIS and NIS2 | Shared, platform services by the provider |
| Tools | Data diodes, kiosks, HSMs and sensors in the plant | Hosted HSMs, signing and timestamp service, archive, data platform | Managed data services, collaboration, test and training environments |
| Suited for | I&C zones, signature verification, remote maintenance | Long-term archive, data platform, PKI for several sites | Project management, documentation without protection needs, training |
| Compliance | Full control, evidence from protection concept and ISMS | Processing agreement under GDPR, KRITIS evidence, location Germany | Processing agreement, standard contractual clauses, approval per data class |
Collaboration
Project
Clearly scoped undertaking such as a zone architecture, a signing chain or an archive with a defined result, milestones and acceptance by operations and technical experts.
Team reinforcement
Security architects, cryptography specialists or integration developers work in your teams, tools and modification procedures, on request on site and with a reliability check to your requirements.
Managed service
OTOKO® operates intrusion detection, HSMs, archive or data platform as a managed service with agreed service levels, regular reports, audit rights and the reporting paths that KRITIS and NIS2 require.
Five requirements that shape cybersecurity in nuclear facilities, with what they demand and what we deliver for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| IEC 62645 | Cybersecurity program for I&C and electrical systems in nuclear power plants, classification into security degrees, graded measures and coordination with nuclear safety under IEC 62859 | Classification of all I&C systems, zone and measures concept per security degree, documentation for technical experts and the regulator |
| IEC 62443 | Zones and conduits, security levels and requirements for operators, integrators and components in industrial automation systems | Zone and conduit model, data diodes and firewalls, supplier requirements, evidence under IEC 62443-2-1 and 62443-3-3 |
| IAEA Nuclear Security Series | Graded defensive architecture with security levels and zones, computer security program and handling of removable media under NSS No. 17-T and NSS No. 33-T | Defensive architecture under the graded approach, media kiosks, program documentation and review against the guidance |
| KRITIS and BSI Act | Measures in line with the current state of technology, intrusion detection systems, evidence to the BSI at fixed intervals and reporting of significant disruptions | Intrusion detection in the I&C network, reporting paths, evidence documentation and support during the audit |
| NIS2 | Risk management, supply chain security, staged incident reporting and accountability of the management | Risk analysis, requirements for suppliers and remote maintenance, reporting processes, reports for the management |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers zone architecture and intrusion detection for the I&C, signed software and PKI with hardware security modules, controlled interfaces and remote access, signed long-term archives for decommissioning and operation, a data platform for operational and security data, and post-quantum readiness for signatures and archives. Each field of action can be commissioned on its own or as a package, with operation in German data centers.
All protective measures are built outside the licensed safety I&C: data diodes, kiosks and passive sensors change neither hardware nor software of the protection systems. Where a change to the I&C is necessary, it runs exclusively through your modification procedure with review, technical experts and approval. The coordination of safety and security follows IEC 62859, and every measure is assessed for side effects beforehand.
Fuel assemblies, storage areas, radiation protection and ventilation systems remain in the facility for years after power operation and stay under regulatory supervision. Decommissioning also brings new contractors, devices and remote access into the facility, and clearance measurements and decommissioning records must remain verifiably unaltered for decades. We work with operators of critical infrastructure and regulated industries. Decommissioning is a regular case for us, not a special one.
The vendor signs its delivery, the media kiosk verifies signature and content with several scanners, and the approval to load is made with a key from your HSM as part of the modification procedure. Every step is logged, so technical experts can trace origin, verification and approval of an update. Vendors without their own signature are covered through an incoming inspection under the four-eyes principle.
Every record receives a signature and a qualified timestamp on entry, and the archive renews the evidence under BSI TR-03125 before an algorithm or certificate weakens. For long-term signatures we use hash-based schemes such as XMSS, which by today's knowledge withstand quantum computers as well. Formats such as PDF/A and documented XML schemas keep the data readable, and recovery tests regularly prove that the archive works.
Operators must implement measures in line with the current state of technology, run intrusion detection systems, report significant disruptions and present evidence to the BSI at fixed intervals. NIS2 adds risk management, supply chain security and the accountability of the management. We deliver the protection concept, intrusion detection in the I&C network, reporting paths and the documentation that auditors expect.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: Zone model, protection concept, evidence for the regulator. Cryptography specialist: Signing chain, HSMs, PKI, PQC roadmap. OT engineer: I&C inventory, data diodes, sensors, modification procedure. Integration developer: Interfaces, historian, archive migration. Data engineer: Data platform, anomaly models, analyses. Project lead: Milestones, maintenance windows, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
I&C systems, network transitions, media paths, archives and evidence gaps Inventory with classification under IEC 62645, crypto inventory, gap analysis for KRITIS and NIS2
Project: Clearly scoped undertaking such as a zone architecture, a signing chain or an archive with a defined result, milestones and acceptance by operations and technical experts. Team reinforcement: Security architects, cryptography specialists or integration developers work in your teams, tools and modification procedures, on request on site and with a reliability check to your requirements. Managed service: OTOKO® operates intrusion detection, HSMs, archive or data platform as a managed service with agreed service levels, regular reports, audit rights and the reporting paths that KRITIS and NIS2 require.
Monitoring, re-signing, audits, knowledge transfer Intrusion detection in regular operation, key and archive maintenance, KRITIS evidence, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Nuclear
Let us discuss how your facility can be protected verifiably without touching nuclear safety.
Book a first consultation