Shape

Industrial engineering

Engineering connected, secure industrial systems, from sensor to cloud

OT cybersecurity, connected-product compliance and industrial data integration: we work where you have to touch the hardware, go on site and answer for a system’s security.

Industrial cybersecurity
OT cybersecurity
Connected products
CRA compliance
Data and edge
Industrial data

Positioning

Where AI is not enough

AI already writes code, including PLC code. It remains weak whenever work happens in the physical world, when someone must be legally accountable for a system’s safety, or when equipment is old, isolated or certified. That is where we position ourselves.

The field and the installed base

Plants run equipment designed to last 20 to 50 years. It has to be connected and secured without replacing it or stopping production.

Signed accountability

CRA, NIS2, Machinery Regulation: each requires documented evidence and an accountable party. An assistant can draft; it does not sign.

The hardware

Proprietary protocols, on-target testing, debugging at the boundary between software and electronics: this work happens on the hardware, not on a screen.

AI automates what happens on screen. Our value lies where you have to go on site, test on hardware and commit to security.

Regulatory calendar

The regulatory calendar industrial companies face

The 2026-2027 deadlines to prepare for now

  1. Since 11 Sept 2026

    Cyber Resilience Act: reporting obligations

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, notification within 72 hours.

    Read the guide
  2. 7 Oct 2026

    French Resilience Act (NIS2 transposition)

    Debated in plenary session at the French National Assembly. Obligations will apply once the law, its decrees and orders are published.

    Read the guide
  3. 20 Jan 2027

    Machinery Regulation applies

    New requirements on protecting control systems against corruption and on machinery with evolving behaviour.

    Read the guide
  4. 11 Dec 2027

    Cyber Resilience Act: full requirements

    All essential cybersecurity requirements apply to products placed on the EU market.

    Read the guide

Method

Our method

  1. 1

    Scope

    A call to understand your site or product, your production constraints and your regulatory deadlines.

  2. 2

    Observe on site

    Site visit, inventory of equipment and flows, interviews with production, maintenance and IT.

  3. 3

    Analyse

    Risk and gap analysis against the applicable frameworks (IEC 62443, CRA, EN 18031, Machinery Regulation).

  4. 4

    Report and equip

    Report, prioritised and costed roadmap, then implementation support if you wish.

Our foundation

Our foundation: software, cloud and security

Before industry, we built software platforms, cloud infrastructure and DevOps pipelines for our clients. Those are exactly the skills connected industrial systems now require.

See our software projects

Networking and DevOps

Segmentation, firewalls, monitoring, deployment automation: the basis of OT cybersecurity.

Software supply-chain security

CI/CD, SBOM, dependency and vulnerability management: the core of the CRA requirements.

Data and cloud

Data pipelines, historians, sovereign architectures: the prerequisite for any industrial AI.

FAQ

Frequently asked questions

What is OT cybersecurity?

OT (Operational Technology) cybersecurity protects the systems that control physical processes: PLCs, SCADA, HMIs and industrial networks. Unlike business IT, the priority is availability and plant safety, often with legacy equipment that cannot easily be stopped or patched.

Is my company in scope of NIS2?

NIS2 covers many sectors including energy, water, food production and part of manufacturing, above size thresholds. In France it is being transposed by the Resilience Act, currently before Parliament. An initial assessment confirms your status and prepares the expected measures.

I build machines: does the Cyber Resilience Act apply to me?

If your products contain digital elements (software, connectivity) and are placed on the EU market, yes. Reporting obligations have applied since 11 September 2026 and the full requirements apply on 11 December 2027. The Machinery Regulation, applicable on 20 January 2027, adds its own cybersecurity requirements.

Do you work on site?

Yes. Our assessments include a site visit or work on the physical product. We follow your safety rules and, when needed, work outside production hours.

Do we need to replace our equipment to secure it?

Rarely. The preferred approach is to segment, monitor and harden what exists, and to connect data through separate interfaces (OPC UA, MQTT) rather than modifying PLCs.

How much does an assessment cost?

Our assessments are sold at a fixed price, on quotation, depending on the size of the site or product scope. We quote after an initial scoping call.

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape