I help mid-sized companies in the process industry make their production OT visible, assessable and secure — pragmatically, without disrupting ongoing operations and without the overhead of large consultancies. My focus: passive OT visibility as the foundation for NIS2 readiness.
No risk management without a complete picture of your production OT. I establish that foundation — passively, non-intrusively and without interfering with ongoing operations.
Since the NIS2 implementation act came into force, risk management and demonstrable OT security have become mandatory for many companies. I get you to an audit-ready state — pragmatically.
Visibility becomes security: segmentation, anomaly detection and OT monitoring that fits the reality of your plant — assessed vendor-neutrally.
I don't work from off-the-shelf slide templates. Every engagement starts with your concrete context — plant, architecture, threat landscape, existing tooling — and ends with a decision you can actually implement, without the overhead of large consultancies.
My background is in industrial OT cyber security — at the intersection of strategic planning, technical implementation and vendor-neutral assessment. That depth is the basis for neutral advice.
In production environments, every active scan is a risk. My approach builds the asset inventory and network topology exclusively from passively captured traffic — no intervention, no disruption to ongoing operations. Exactly the foundation that NIS2 risk management requires.
I've compared the leading OT/CPS security platforms in detail — from Claroty and Nozomi to Dragos, Armis and Forescout. No commissions, no vendor bias. The recommendation follows your architecture, your risk and your budget, not a partner program.
NIS2 and IEC 62443 needn't be a paperwork battle when approached the right way. I translate the requirements into concrete, prioritized measures for your production OT — with an eye for what is actually achievable in mid-sized companies and what comes first.
As an engineer, I built my own tool from the real needs of industry: a portable, purely passive appliance that listens to a plant network, automatically builds a complete asset inventory, reports anomalies in plain language and delivers the finished audit evidence — entirely on-premise, no cloud. It embodies exactly the approach that defines my consulting.
See the appliance in detail →/* Independent · vendor-neutral · no commissions. Initial consultation with no obligation. */
Active scans that are routine in IT can cause damage in a production plant. Why non-intrusive methods in OT are not a convenience but a necessity — and how far they take you.
Many companies start NIS2 with documentation and processes. Why that's the wrong order — and why, without a reliable picture of production OT, any risk management is built on sand.
Claroty, Nozomi, Dragos, Armis, Forescout — on paper the platforms look alike. Which criteria make the difference in practice and how to reach a decision that fits your own plant.
Cyber security in industrial environments lives on attention to detail — and on recommendations that hold up when they meet the reality of a running plant.
I'm an engineer and built my cyber security experience over years at international DAX-listed corporations — at the intersection of strategic planning, technical implementation and vendor-neutral platform assessment. From this work I know the leading OT security tools not from data sheets but from real comparison — and I know how wide the gap between glossy promises and plant reality can be.
This combination of engineering mindset and hands-on corporate experience shapes my consulting. Today I independently help process-industry companies make their production OT visible, assessable and NIS2-compliant — pragmatically, without disrupting operations and without vendor bias. With one clear focus: passive OT visibility as the foundation everything else builds on.
An initial conversation is straightforward and free of charge. Tell me where your production OT stands today — I'll get back to you within 24 hours.