Navigation

Get in touch
Logo
News

Industries / Nuclear

Critical facilities. Controlled connections.

Protect sensitive facilities with secure zone architectures and hardware cryptography.

Consulting. Integration. Operations.

Four large concrete cooling towers emitting steam under a dark cloudy sky — illustrative image

Built around your industry.

  • Operators in decommissioning
  • Interim storage and waste management
  • Fuel cycle facilities and research reactors
  • I&C vendors and service providers

Your priorities

Understand the challenge. Shape the solution.

We segment plant networks according to IEC 62443, secure data flows with data diodes, and detect anomalies in I&C without intervening in protection systems.

01

Zone architecture and intrusion detection for the I&C

Zone and conduit model with classification of all systems

More on this
02

Controlled interfaces and remote access

Interface catalog with data flows and zones

More on this
03

Data platform for operational and security data

Data platform connected to historian and network sensors

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Zone architecture and intrusion detection for the I&CIEC 62443 · IEC 62645 · OPSWAT MetaDefender NetWall

Our approach

A zone architecture divides the facility into areas with graded protection needs and governs every transition through defined conduits. We classify I&C systems by the security degrees of IEC 62645 and the security levels of IEC 62443, separate safety I&C strictly from operational I&C and the office network, and let data leave only through data diodes. Removable media are checked at kiosks before use, and passive sensors detect anomalies in network traffic without sending a single packet into the I&C. The result meets the duty to run intrusion detection under the BSI Act and the IAEA's expectations of a graded defensive architecture.

Full scope
  • Inventory of all I&C systems, network transitions and data flows, classified under IEC 62645 and IEC 62443
  • Zone and conduit model with data diodes for outbound process data and industrial firewalls between zones
  • Media kiosks with multi-engine scanning and content disarming for updates and maintenance laptops
  • Passive intrusion detection in the I&C network, connected to the SIEM and to reporting paths under the BSI Act and NIS2
  • Protection concept, operating instructions and evidence for the regulator, technical experts and the KRITIS audit

An operator in decommissioning introduces media kiosks and data diodes; decommissioning contractors receive plant data from a zone with no path back into the I&C.

What you get

  • Zone and conduit model with classification of all systems
  • Media kiosks and data diodes in operation with operating instructions
  • Intrusion detection with reporting paths and KRITIS evidence
Discuss this topic
02Signed software and PKI with hardware security modulesUtimaco u.trust GP HSM Se-Series · Thales Luna Network HSM · Entrust nShield 5c

Our approach

Software, firmware and configurations for the I&C reach the facility through vendors, contractors and removable media, and every change must be verifiable for origin and integrity. We build a signing chain in which vendors sign their deliveries, your engineering workstations verify the signature before loading, and your own approvals are made with keys in hardware security modules. The same PKI issues certificates for remote maintenance, site links and data diodes. We advise vendor-neutrally on Utimaco u.trust GP HSM, Thales Luna and Entrust nShield 5 and plan key ceremonies with roles, quorums and records.

Full scope
  • Signing concept for software, firmware and configurations with roles for vendors, technical experts and the operator
  • PKI with offline root CA and issuing CA in the HSM, certificates for remote maintenance, site links and devices
  • HSM selection under FIPS 140-3 and Common Criteria, key ceremonies with quorums, witnesses and record templates
  • Signature verification at the media kiosk and the engineering workstation as a step in the modification procedure
  • Operations manual for key rotation, firmware levels, disaster recovery and review by technical experts

An interim storage site requires signed updates from its I&C vendor; the kiosk verifies the signature, and the approval to load is made with a key from the operator's HSM.

What you get

  • Signing and PKI concept with roles and certificate profiles
  • HSM in operation with recorded key ceremonies
  • Operations manual with recovery and audit evidence
Discuss this topic
03Controlled interfaces and remote accessOPSWAT MetaDefender OT Access · Data diode · Privileged access management

Our approach

Plant management, maintenance, radiation protection and reporting need data from the facility but must not open a return path into the I&C. We integrate process data, document management and ERP through interfaces that start behind the data diode, are versioned, have an owner and log every access. Remote maintenance by vendors runs through jump servers with multi-factor authentication, session recording and per-job approval by your staff, not through standing access that stays open after the job.

Full scope
  • Interface catalog with data flows, direction, owners and zone per interface
  • Process data historian and integration layer behind the data diode, connected to ERP, maintenance and document management
  • Remote maintenance architecture with jump server, multi-factor authentication, session recording and per-job approval
  • Authorization concept for decommissioning contractors with time-limited accounts and the four-eyes principle
  • Automated tests, versioning and modification procedure per interface, monitoring in regular operation

An operator links its maintenance system and process data historian through a data diode; maintenance staff see readings in the office network without any connection into the I&C.

What you get

  • Interface catalog with data flows and zones
  • Remote maintenance architecture with jump server and session recording in operation
  • Authorization and approval concept with log evidence
Discuss this topic
04Signed long-term archives for decommissioning and operationBSI TR-03125 (TR-ESOR) · RFC 3161 timestamps · PDF/A

Our approach

Decommissioning records, clearance measurements, waste package data and operating logs must remain complete, unaltered and readable for decades, longer than any file format and any signature algorithm. We build archives that sign every record on entry, add a qualified timestamp and store it encrypted, and that preserve evidential value under BSI TR-03125 through re-signing. The signing keys live in the HSM, the formats follow PDF/A and XML with a documented schema, and access is role-based and logged for the regulator and its experts.

Full scope
  • Archive concept with retention classes, formats under PDF/A and XML and protection needs per document type
  • Signing and timestamp service with keys in the HSM, preservation of evidence under BSI TR-03125 with re-signing
  • Encryption of the storage with LAN Crypt or storage encryption, keys under the operator's control
  • Migration from document management, measurement systems and legacy archives with completeness checks
  • Operation with recovery tests, format migration and evidence for the regulator and waste management partners

An operator in decommissioning moves clearance measurements and dismantling records into a signed archive; every record carries timestamp and signature, and re-signing is scheduled as a service.

What you get

  • Archive concept with retention classes and formats
  • Signed and encrypted archive with timestamp service in operation
  • Evidence of preservation with recovery tests
Discuss this topic
05Data platform for operational and security dataApache Kafka · Apache Spark · Lakehouse

Our approach

Process data, I&C alarms, network traffic data and maintenance history sit in separate systems and are rarely analyzed together. Behind the data diode we build a data platform that merges these sources, and on it we train models that flag deviations in plant behavior and network traffic early. Models give hints to shift staff and the security team but decide nothing themselves, and every analysis is versioned and documented traceably with a model card and data lineage.

Full scope
  • Data platform behind the data diode, connected to the historian, I&C alarms, network sensors and maintenance
  • Anomaly models for plant behavior and network traffic, validated against past disturbances and maintenance events
  • Analyses for maintenance, radiation protection and reporting with roles and logging
  • Model operations with versioning, monitoring of data drift and controlled retraining
  • Documentation under the EU AI Act and clear separation from the plant's safety functions

An operator analyzes pump data and network traffic of the operational I&C together; a model flags a device that opens connections outside maintenance windows before anyone notices the incident.

What you get

  • Data platform connected to historian and network sensors
  • Versioned anomaly models with model card
  • Analyses and reports for maintenance and the security team
Discuss this topic
06Post-quantum readiness for signatures and archivesML-DSA (FIPS 204) · ML-KEM (FIPS 203) · XMSS (RFC 8391)

Our approach

Capable quantum computers will break RSA and elliptic curves, on which software signatures, remote maintenance certificates and archive signatures rest today. For archives that must stay valid for decades this is not a distant problem, because a signature that later becomes forgeable loses its evidential value. We inventory algorithms, keys and certificates across I&C, PKI and archive, rely on hash-based schemes such as XMSS and LMS for long-term signatures, and plan the PKI migration to ML-DSA and hybrid certificates in stages, tied to hardware refresh and the modification procedure.

Full scope
  • Crypto inventory across signing services, PKI, remote maintenance, data diodes and archive, rated by protection lifetime
  • Hash-based signatures under XMSS and LMS for archive and firmware with state management in the HSM
  • Check of the HSMs for firmware with ML-KEM, ML-DSA, XMSS and LMS, migration path for legacy devices
  • Hybrid certificates and migration plan for root CA, issuing CA and device identities
  • Staged roadmap by data protection lifetime, device lifetime and the plant's modification procedure

An operator switches the signatures of its decommissioning archive to XMSS and keeps the existing PKI for remote maintenance until the next hardware refresh, for which hybrid certificates are prepared.

What you get

  • Crypto inventory with risk rating by protection lifetime
  • Migration roadmap for PKI, HSMs and archive signatures
  • Signing service with hash-based schemes in operation
Discuss this topic
gray asphalt road between green grass field under blue sky during daytime — illustrative image
Nuclear

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Nuclear

Zone architecture at an operator in decommissioning

Decommissioning contractors need plant data, network transitions have grown over decades, the regulator asks for the IT protection concept.

Solution

Inventory and classification under IEC 62645, zones with data diodes and kiosks, remote maintenance through jump servers with per-job approval.

Documented protection concept, controlled access for all contractors, evidence for the regulator and its experts.

Discuss this topic

02 / Nuclear

Signed updates at an interim storage site

I&C updates arrive on removable media without verifiable origin, approvals are given by signature on paper.

Solution

Signing chain with vendor signature, verification at the kiosk, approval keys in the operator's HSM, ceremony records.

Every update verifiable for origin and integrity, approvals traceable in the modification procedure, HSM in operation.

Discuss this topic

03 / Nuclear

Long-term archive at a fuel cycle facility

Operating logs and measurement data sit in file systems without signatures, the legacy archive runs on software without vendor support.

Solution

Signed archive with timestamp service, preservation of evidence under BSI TR-03125, hash-based signatures, migration from the legacy archive.

Evidential value for decades, re-signing as a service, recovery tested and documented.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    I&C systems, network transitions, media paths, archives and evidence gaps

    Inventory with classification under IEC 62645, crypto inventory, gap analysis for KRITIS and NIS2
  2. 02

    Concept

    Zones, conduits, signing chain, archive, operating model

    Protection concept, zone model, PKI and archive concept, operating model, modification requests
  3. 03

    Implementation

    Measures in maintenance windows and through the modification procedure, stage by stage

    Zones, kiosks, HSMs, interfaces and archive in operation, tests, documentation, approval per stage
  4. 04

    Operations

    Monitoring, re-signing, audits, knowledge transfer

    Intrusion detection in regular operation, key and archive maintenance, KRITIS evidence, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What is cybersecurity for nuclear facilities?

Six fields of action from the zone architecture of the I&C to the signed long-term archive for decommissioning, planned, implemented and operated by OTOKO®. No measure interferes with licensed safety systems, and every one can be evidenced to the regulator and its experts. The entire solution runs in German data centers.

Cybersecurity for nuclear facilities protects instrumentation and control, operational data and access paths against manipulation without touching nuclear safety. It applies to plants in decommissioning, interim storage sites, research reactors and fuel cycle facilities as much as to power plants in operation, in Germany and for operators abroad. OTOKO® covers six fields of action: zone architecture and intrusion detection for the I&C, signed software and PKI with hardware security modules, controlled interfaces and remote access, signed long-term archives for decommissioning and operation, a data platform for operational and security data, and post-quantum readiness for signatures and archives.

The difference from a pure consulting project lies in separation and evidence. Protective measures are built outside the licensed safety I&C, and every change passes through your modification procedure and receives a record, a version and the documents that the regulator, its technical experts and the BSI require. Cryptography and hardware security modules are our core competence. Signing keys for software, remote maintenance and archives therefore live in certified devices rather than in software.

Why OTOKO® for nuclear facilities

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Signing keys for I&C software, remote maintenance and archives live in certified hardware security modules with recorded ceremonies.

  • German data centers

    The entire solution runs in German data centers, from the hosted HSM and the timestamp service to the long-term archive for decommissioning.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the nuclear regulator, technical experts, the BSI and information security expect of a protection concept and its evidence.

  • One team through to operations

    One team accompanies you from consulting to operations. Security architects, cryptography specialists and integration developers stay your contacts from concept through implementation in maintenance windows to operation.

Delivery and details

Most operators do not fail on technology but on network transitions that grew over decades, unclear responsibilities between I&C and IT, and evidence that exists only on paper.

Network transitions without inventory

Over decades, connections between I&C, plant management and the office network have emerged that nobody has fully documented and that undermine every zone boundary.

Removable media and remote maintenance without control

Vendors bring updates on USB sticks and laptops, remote maintenance runs on individual agreements and no log shows who changed what and when.

Intrusion detection only in the office network

The intrusion detection system sees email and servers but not the network traffic of the I&C, and nobody dares to place sensors there.

Archive without evidential value

Decommissioning records, clearance measurements and operating logs sit in file systems without signature, timestamp or a procedure for re-signing over decades.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationPlant and your data center, I&C data stays on siteData centers in Germany under ISO 27001 for archive, data platform and office systemsAzure, AWS or Google Cloud only for systems without plant data
OperationYour team or OTOKO® as managed service inside your zonesOTOKO®, with audit rights and reporting paths under KRITIS and NIS2Shared, platform services by the provider
ToolsData diodes, kiosks, HSMs and sensors in the plantHosted HSMs, signing and timestamp service, archive, data platformManaged data services, collaboration, test and training environments
Suited forI&C zones, signature verification, remote maintenanceLong-term archive, data platform, PKI for several sitesProject management, documentation without protection needs, training
ComplianceFull control, evidence from protection concept and ISMSProcessing agreement under GDPR, KRITIS evidence, location GermanyProcessing agreement, standard contractual clauses, approval per data class

Collaboration

Project

Clearly scoped undertaking such as a zone architecture, a signing chain or an archive with a defined result, milestones and acceptance by operations and technical experts.

  • Assessment, concept, implementation in maintenance windows, handover
  • Fixed price or effort by milestone
  • Suited for decommissioning projects, KRITIS evidence and archive setup

Team reinforcement

Security architects, cryptography specialists or integration developers work in your teams, tools and modification procedures, on request on site and with a reliability check to your requirements.

  • Onboarding into plant, zones and modification procedure
  • Scalable with project progress and decommissioning phase
  • Suited for operators with their own team and capacity gaps

Managed service

OTOKO® operates intrusion detection, HSMs, archive or data platform as a managed service with agreed service levels, regular reports, audit rights and the reporting paths that KRITIS and NIS2 require.

  • Monitoring, key rotation, re-signing, updates and support
  • Audit rights, service levels and exit plans in the contract
  • Suited for sites with a small crew in decommissioning or interim storage

Five requirements that shape cybersecurity in nuclear facilities, with what they demand and what we deliver for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
IEC 62645Cybersecurity program for I&C and electrical systems in nuclear power plants, classification into security degrees, graded measures and coordination with nuclear safety under IEC 62859Classification of all I&C systems, zone and measures concept per security degree, documentation for technical experts and the regulator
IEC 62443Zones and conduits, security levels and requirements for operators, integrators and components in industrial automation systemsZone and conduit model, data diodes and firewalls, supplier requirements, evidence under IEC 62443-2-1 and 62443-3-3
IAEA Nuclear Security SeriesGraded defensive architecture with security levels and zones, computer security program and handling of removable media under NSS No. 17-T and NSS No. 33-TDefensive architecture under the graded approach, media kiosks, program documentation and review against the guidance
KRITIS and BSI ActMeasures in line with the current state of technology, intrusion detection systems, evidence to the BSI at fixed intervals and reporting of significant disruptionsIntrusion detection in the I&C network, reporting paths, evidence documentation and support during the audit
NIS2Risk management, supply chain security, staged incident reporting and accountability of the managementRisk analysis, requirements for suppliers and remote maintenance, reporting processes, reports for the management

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which cybersecurity services for nuclear facilities does OTOKO® offer?

The portfolio covers zone architecture and intrusion detection for the I&C, signed software and PKI with hardware security modules, controlled interfaces and remote access, signed long-term archives for decommissioning and operation, a data platform for operational and security data, and post-quantum readiness for signatures and archives. Each field of action can be commissioned on its own or as a package, with operation in German data centers.

How do you make sure that measures do not touch nuclear safety?

All protective measures are built outside the licensed safety I&C: data diodes, kiosks and passive sensors change neither hardware nor software of the protection systems. Where a change to the I&C is necessary, it runs exclusively through your modification procedure with review, technical experts and approval. The coordination of safety and security follows IEC 62859, and every measure is assessed for side effects beforehand.

Why does a facility in decommissioning still need cybersecurity?

Fuel assemblies, storage areas, radiation protection and ventilation systems remain in the facility for years after power operation and stay under regulatory supervision. Decommissioning also brings new contractors, devices and remote access into the facility, and clearance measurements and decommissioning records must remain verifiably unaltered for decades. We work with operators of critical infrastructure and regulated industries. Decommissioning is a regular case for us, not a special one.

How do vendor software updates get into the I&C securely?

The vendor signs its delivery, the media kiosk verifies signature and content with several scanners, and the approval to load is made with a key from your HSM as part of the modification procedure. Every step is logged, so technical experts can trace origin, verification and approval of an update. Vendors without their own signature are covered through an incoming inspection under the four-eyes principle.

How do archive records stay evidential for decades?

Every record receives a signature and a qualified timestamp on entry, and the archive renews the evidence under BSI TR-03125 before an algorithm or certificate weakens. For long-term signatures we use hash-based schemes such as XMSS, which by today's knowledge withstand quantum computers as well. Formats such as PDF/A and documented XML schemas keep the data readable, and recovery tests regularly prove that the archive works.

What evidence do KRITIS and NIS2 require from nuclear facilities?

Operators must implement measures in line with the current state of technology, run intrusion detection systems, report significant disruptions and present evidence to the BSI at fixed intervals. NIS2 adds risk management, supply chain security and the accountability of the management. We deliver the protection concept, intrusion detection in the I&C network, reporting paths and the documentation that auditors expect.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Zone model, protection concept, evidence for the regulator. Cryptography specialist: Signing chain, HSMs, PKI, PQC roadmap. OT engineer: I&C inventory, data diodes, sensors, modification procedure. Integration developer: Interfaces, historian, archive migration. Data engineer: Data platform, anomaly models, analyses. Project lead: Milestones, maintenance windows, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

I&C systems, network transitions, media paths, archives and evidence gaps Inventory with classification under IEC 62645, crypto inventory, gap analysis for KRITIS and NIS2

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a zone architecture, a signing chain or an archive with a defined result, milestones and acceptance by operations and technical experts. Team reinforcement: Security architects, cryptography specialists or integration developers work in your teams, tools and modification procedures, on request on site and with a reliability check to your requirements. Managed service: OTOKO® operates intrusion detection, HSMs, archive or data platform as a managed service with agreed service levels, regular reports, audit rights and the reporting paths that KRITIS and NIS2 require.

What happens at handover to operations?

Monitoring, re-signing, audits, knowledge transfer Intrusion detection in regular operation, key and archive maintenance, KRITIS evidence, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Nuclear

Let's discuss your next step.

Let us discuss how your facility can be protected verifiably without touching nuclear safety.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.