Vertical
Cybersecurity
Where process availability weighs as much as data confidentiality, and where the equipment to be protected has been installed for fifteen years.
Cybersecurity market, scope South America, per Mordor Intelligence. Public figure compiled in 2026. Another analyst firm publishes a considerably lower figure on a different scope definition; we cite one source and say which, because figures from different houses placed side by side cannot be compared. This is market context, not this company's results.
Segmentation
The network that carries physical security is usually the most exposed
A network of cameras, card readers and controllers is installed so that it works, and it works. It usually stays flat, with factory credentials, with firmware from the installation date, and reachable from the corporate network. It is one of the most repeated audit findings, and it is a comfortable way in: the device has little defence of its own and nobody is watching it.
The correction is not sophisticated. Separate device traffic from management traffic, permit only the flows the system needs instead of blocking the ones someone remembers, leave a single controlled crossing point toward the corporate network rather than several, move administration off the production network, and change what came from the factory. The hard part is not the design: it is that somebody owns the inventory and the update cycle once the system has been handed over.
So segmentation is written into the tender for the video or access system, together with who maintains it, rather than left as a later task for another supplier.
OT
An industrial network is not run like an office one
In operational technology the order of priorities is inverted. Process availability comes first, data integrity second and confidentiality last. A security measure that stops a production line is not a security measure for whoever runs that line, and that difference explains most of the projects that get approved and never implemented.
The equipment has a service life of a decade or more and is not patched live: the maintenance window is negotiated with production and may be months away. Many industrial protocols were designed for an isolated network and do not authenticate whoever issues a command: anyone who reaches the segment can write to the process. That shifts the weight of control toward what is connected where, rather than toward the endpoint.
Inventory is the starting point and usually the real gap. You cannot protect what is not inventoried, and in OT the inventory is built passively, by observing traffic. An active scan of the kind used on an office network can take an old controller out of service, and that is an incident caused by the audit itself.
The most frequent vector is not a targeted attack: it is the supplier's remote access. A permanent, open channel, shared among technicians, with flat access to the plant network. The alternative is concrete: individual access with a second factor, enabled by time window, restricted to the relevant equipment and with the session recorded. It is a contractual condition with the integrator, not merely a configuration.
Where telemetry has to reach the corporate network without opening a path back, a physically one-way route exists. It is expensive and not justified in every case; in installations where an unauthorised write has a physical consequence, it is.
Detection and response
What gets measured is time, not the number of alerts
A monitoring platform produces alerts from day one. That is not detection. Detection is somebody watching, knowing what they are looking at, and holding a written instruction on what to do. The two figures that matter are how long the organisation takes to notice and how long it takes to contain. Everything else is a dashboard.
From there come the questions we ask before sizing anything: who is on duty outside working hours, with what authority to disconnect equipment without waiting for approval, and what happens when the person who has to decide is on leave. A contracted operations centre that cannot act on the customer's network delivers reports, not containment.
Recovery closes the loop and is the part most often skipped. Backups have to sit beyond the reach of the credential that administers the system, because extortion malware looks for the copies before the data. And what gets tested is the restore, not the copy: a backup nobody ever restored is an assumption. The recovery time objective is agreed with the function that runs the process, and it defines how much has to be invested, not the other way round.
Portfolio
What we specify and integrate
Firewalls and segmentation
Perimeter and segment firewalls, control of flows between zones, and separation of management traffic. The rule is written by permitting what the system needs, not by blocking what someone remembers.
Industrial and OT network security
Passive asset inventory, industrial protocol visibility, zone and conduit segmentation, and a one-way route where an unauthorised write has a physical consequence. With maintenance windows agreed with production.
Remote access and identity
Supplier and staff access with a second factor, by time window, restricted to the relevant equipment and with the session recorded. It includes privileged credential and service account management, which is where the access nobody revokes usually lives.
Security of the physical-security network
Hardening and segmentation of the camera, reader and controller network, with a firmware update cycle assigned to an owner. It is the video surveillance vertical seen from the network that carries it.
Detection and response
Log collection, endpoint and network detection, and a written response procedure with defined levels of authority. Sized by target detection and containment time, not by alert volume.
Backup and recovery
Copies beyond the reach of the administrative credential, defined retention, and periodic documented restore testing. The recovery time objective is agreed with whoever runs the process.
How we work
How we enter a cybersecurity project
We represent and integrate product. We do not audit a customer in order to sell them the remedy for what we found: where an independent assessment is needed, it is contracted separately.
- Inventory and connection map What is connected, what it talks to and who administers it, built passively where industrial equipment is involved. Without this, any sizing is an estimate.
- Zone and flow definition Which segments exist, what is allowed to cross between them and where administration enters. Written before equipment is chosen, because it determines how many control points are needed and of what capacity.
- Agreed implementation window With production and with the operating function, not only with the technology function. A network change in a plant is scheduled with the same seriousness as a maintenance shutdown.
- Written response procedure Who detects, who decides, who disconnects and who communicates, with hours covered and authority defined. A platform without this document delivers alerts and does not reduce containment time.
- Restore testing A real restore, measured against the agreed objective and documented. It is the only way to know the backup exists.
National and regional government · Banking and insurance · Energy and utilities · Mining and industry · Ports and critical infrastructure