PRODUCT AND OT CYBERSECURITY

Before a customer, auditor or regulator asks, get the evidence in order.

We establish what your organisation can demonstrate today across the CRA, IEC 62443, KSC/NIS2, PSIRT/SBOM and cyber insurance. You receive a clear account of the gaps, the material you can show and the decisions to take next.

See a sample report

01 Method

From signal to decision

We follow the same sequence whatever the topic: facts first, then evidence, and decisions last.

Signal

What triggered the work?

Review

Where does fact end and assertion begin?

Evidence

What can be shown safely?

Decision

What needs doing now, and what can wait?

02 Situations

Where do you start?

Choose the situation closest to yours. We will point to the right service and the topic to raise. Every answer is visible straight away.

CRA Snapshot for manufacturers

We establish the product class, the gaps against Annex I and readiness for art. 14 of the Cyber Resilience Act.

See the service →

OT / IEC 62443 Mini-Gap

An assessment of your OT security in the IEC 62443 language your customer or group function expects.

See the service →

Cyber Insurance Evidence Check

We turn the declarations in the cyber questionnaire into concrete evidence of controls before you speak to a broker.

See the service →

PSIRT / SBOM Starter

A working vulnerability-handling process and an SBOM you can show to customers and auditors.

See the service →

KSC/NIS2 Exposure Check

We check whether and how you fall under KSC/NIS2 and which evidence is worth preparing.

See the service →

Introductory call

A short call to establish where to start and which piece of evidence is most urgent.

Book a call →

03 Services

Four paths that end in evidence

Each one delivers concrete evidence and a 60–90 day action plan.

CRA Snapshot for manufacturers

Product with digital elements

A fixed-price assessment of 1–2 product families against the Cyber Resilience Act: classification, gaps against Annex I, readiness for art. 14, an SBOM-lite and an action plan.

See the CRA Snapshot →

OT / IEC 62443 Mini-Gap

OT/ICS security

A short OT security assessment: remote access, segmentation, updates, vulnerabilities, logging and the evidence required by industrial customers, brokers and auditors.

See OT / IEC 62443 →

Cyber Insurance Evidence Check

Cyber questionnaire for a policy

From declarations in the cyber questionnaire to concrete evidence of controls: MFA, backups, EDR/logs, remote access, an incident procedure and a plan of first fixes before the conversation with your broker.

See the Evidence Check →

KSC/NIS2 Exposure Check

Regulatory exposure

Check whether your company may fall under KSC/NIS2 and what evidence is worth preparing for the board, a customer, an auditor or an insurer. Facts and deadlines, not scare tactics.

See the KSC/NIS2 Check →

04 Sample report

What an evidence dossier looks like

DEMO – sample structure, not a client result

Scenario: an unnamed manufacturer; a connected device with firmware, a mobile application and a cloud service.

Dossier
demo
03 records
  1. 01

    Vulnerability intake

    A public reporting route is documented; ownership and response evidence is incomplete.

    Priority: HIGH
  2. 02

    Component inventory

    An SBOM exists for the current build; the release-to-SBOM trace is inconsistent.

    Priority: HIGH
  3. 03

    Security logging

    Product events are defined; retention and customer-export evidence is missing.

    Priority: MEDIUM
Decision strip

0–30 days: establish owners and reproducible evidence. 31–60 days: close the highest-risk gaps. 61–90 days: rehearse and package the evidence.

DEMO – sample structure, not a client result.

05 Process

How we work

Short, concrete and with evidence you can show to a customer, an auditor or an insurer.

01

We check and map

We set the scope, classify the product or entity and map the current state against the requirements of the CRA, IEC 62443, KSC/NIS2 or a cyber questionnaire.

02

We identify the gaps

We show what is missing and what is risky, separate the technical part from the legal interpretation and organise the evidence.

03

We prepare evidence and a 60–90 day plan

You get an evidence pack and a concrete action plan with priorities, ready for a conversation with a customer, a broker or an auditor.

06 R&D

We build our own R&D prototypes

In industrial cybersecurity, documentation alone is not enough. We build prototypes to better understand OT/IT separation, event monitoring, compliance evidence and vulnerability handling.

  • One-way OT→IT data gateway

    A prototype for passing selected logs and telemetry from OT to IT/SIEM while limiting the return path.

  • Local OT monitoring node

    A local monitoring node for smaller industrial environments that builds an evidence trail without the public cloud.

  • Product evidence organisation tool

    An internal tool for organising product evidence, an SBOM-lite and mapping to the CRA, IEC 62443 and KSC/NIS2.

  • Local AI assistant for documentation

    Experiments with local AI and RAG to analyse documentation without sending data to public models.

These are research and development prototypes, proof of practice rather than products for sale.

See the R&D solutions →

07 Person and company

Who runs it

Helena Czarnecka · CISSP · GCFE · ISO 27001 Lead Auditor · ISA Senior Member.

We have been operating since 2014. We specialise in industrial and product cybersecurity: OT/ICS, product security, CRA, PSIRT/SBOM and preparing evidence for KSC/NIS2 and cyber insurance questionnaires. We serve manufacturers, industrial companies and the regulated sector, including civil aviation and defence.

We separate the technical part from the legal part so that it is clear what is a technical assessment and what is a legal interpretation. On matters that require a legal opinion, we work with advisers and law firms. On cyber policies we do not broker insurance sales; we help prepare the technical answers and evidence.

Trusted by, among others

Civil Aviation Authority of Poland Ministry of Sport and Tourism Polish Air Force University in Deblin

08 FAQ

Frequently asked questions

Who does the Cyber Resilience Act (CRA) apply to?

The CRA (EU Regulation 2024/2847) applies to manufacturers, importers and distributors of products with digital elements, meaning hardware and software that connects to a device or network. Full application and CE marking apply from 11 December 2027, and vulnerability reporting obligations (art. 14) from 11 September 2026.

Is IEC 62443 mandatory in Poland?

IEC 62443 is usually not a legally mandatory standard for every company with OT. It is, however, a recognised language of security evidence for industrial systems and products that industrial customers, auditors and insurers increasingly expect.

Is KSC 2.0 a directive or an act?

KSC is the act on the national cybersecurity system, which implements the EU NIS 2 directive. The obligations of Polish entities stem from the act, not directly from the directive.

What is worth preparing before a cyber insurance questionnaire?

The most commonly needed items are evidence of controls: multi-factor authentication (MFA), backups with a restore test, EDR and logs, management of remote access and privileged accounts, and an incident response procedure. We help prepare the technical answers and evidence; we do not broker insurance sales.

See the full FAQ →

09 Contact

Discuss your case

Briefly describe your situation. We will get back to you and determine whether and how we can help.

Only provide this if you prefer a phone call.