
Industrial engineering
OT cybersecurity, connected-product compliance and industrial data integration: we work where you have to touch the hardware, go on site and answer for a system’s security.
Services
Fixed-scope, fixed-price engagements that turn a regulatory obligation into an action plan.
Positioning
AI already writes code, including PLC code. It remains weak whenever work happens in the physical world, when someone must be legally accountable for a system’s safety, or when equipment is old, isolated or certified. That is where we position ourselves.
Plants run equipment designed to last 20 to 50 years. It has to be connected and secured without replacing it or stopping production.
CRA, NIS2, Machinery Regulation: each requires documented evidence and an accountable party. An assistant can draft; it does not sign.
Proprietary protocols, on-target testing, debugging at the boundary between software and electronics: this work happens on the hardware, not on a screen.
AI automates what happens on screen. Our value lies where you have to go on site, test on hardware and commit to security.
Regulatory calendar
The 2026-2027 deadlines to prepare for now
Since 11 Sept 2026
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours.
7 Oct 2026
Debated in plenary session at the French National Assembly. Obligations will apply once the law, its decrees and orders are published.
20 Jan 2027
New requirements on protecting control systems against corruption and on machinery with evolving behaviour.
11 Dec 2027
All essential cybersecurity requirements apply to products placed on the EU market.
Industries
Where regulatory deadlines and the shortage of IT + OT profiles add up.
Method
A call to understand your site or product, your production constraints and your regulatory deadlines.
Site visit, inventory of equipment and flows, interviews with production, maintenance and IT.
Risk and gap analysis against the applicable frameworks (IEC 62443, CRA, EN 18031, Machinery Regulation).
Report, prioritised and costed roadmap, then implementation support if you wish.
Our foundation
Before industry, we built software platforms, cloud infrastructure and DevOps pipelines for our clients. Those are exactly the skills connected industrial systems now require.
Segmentation, firewalls, monitoring, deployment automation: the basis of OT cybersecurity.
CI/CD, SBOM, dependency and vulnerability management: the core of the CRA requirements.
Data pipelines, historians, sovereign architectures: the prerequisite for any industrial AI.
Guides
Practical guides to the regulations reshaping industrial cybersecurity in 2026-2027, and where to start.
FAQ
OT (Operational Technology) cybersecurity protects the systems that control physical processes: PLCs, SCADA, HMIs and industrial networks. Unlike business IT, the priority is availability and plant safety, often with legacy equipment that cannot easily be stopped or patched.
NIS2 covers many sectors including energy, water, food production and part of manufacturing, above size thresholds. In France it is being transposed by the Resilience Act, currently before Parliament. An initial assessment confirms your status and prepares the expected measures.
If your products contain digital elements (software, connectivity) and are placed on the EU market, yes. Reporting obligations have applied since 11 September 2026 and the full requirements apply on 11 December 2027. The Machinery Regulation, applicable on 20 January 2027, adds its own cybersecurity requirements.
Yes. Our assessments include a site visit or work on the physical product. We follow your safety rules and, when needed, work outside production hours.
Rarely. The preferred approach is to segment, monitor and harden what exists, and to connect data through separate interfaces (OPC UA, MQTT) rather than modifying PLCs.
Our assessments are sold at a fixed price, on quotation, depending on the size of the site or product scope. We quote after an initial scoping call.
Let’s talk about your site or product. One call is enough to know where to start.
