R&D as four proof records

We build our own prototypes, because in industrial cybersecurity documentation alone is not enough. They help us understand our clients' problems better: OT/IT separation, event monitoring, evidence of compliance and vulnerability handling. Below are four records covering the problem, what we are testing, what it demonstrates and its status. None of them is a product ready for sale, a deployment or a client project; they are proof of practice and a starting point for a conversation about services, a pilot or technical requirements.

Proof records

One-way OT→IT data gateway

R&D prototype / OT-IT separation / monitoring

Problem
How to send selected logs, events and telemetry from the OT network to an IT environment or SIEM without opening a return path from IT to OT.
What we are testing
The design of a one-way gateway: data minimisation, whitelisting, event queuing and an architecture for Wazuh/SIEM and evidence material.
What it demonstrates
An understanding of the OT/IT boundary and a practical approach to monitoring without opening a two-way channel.
Status: prototype
This is a research prototype, not a certified data diode, and it does not replace solutions for critical infrastructure.

Local OT monitoring node

R&D prototype / edge monitoring

Problem
Small and medium industrial environments rarely have the budget or team for a full 24/7 SOC, yet still need a trail of security events.
What we are testing
Collecting selected logs, statuses and security signals locally, an initial triage of alerts, and building an evidence trail without sending sensitive process data to the public cloud.
What it demonstrates
A practical approach to OT monitoring for smaller companies and experience with Wazuh/SIEM, agents and alerts.
Status: prototype
This is a prototype; we do not provide a full 24/7 SOC, we do not promise detection of every incident, and the local AI does not replace an analyst.

Product evidence organisation tool

Internal R&D tool / CRA / evidence

Problem
Product compliance evidence (requirements, gaps, SBOM, vulnerability handling) is scattered across many documents and hard to run consistently in advisory work.
What we are testing
Organising product families, requirements, gaps, SBOM-lite, the vulnerability handling process and advisory templates, and mapping them to CRA, IEC 62443 and KSC/NIS2.
What it demonstrates
Experience in building workflows and documentation systems, and a practical approach to evidence, not just descriptions in a PDF.
Status: prototype
This is an internal tool; we do not sell it as a platform or a BPM system, and it does not promise automatic CRA compliance.

Local AI assistant for documentation

R&D prototype / local AI / RAG

Problem
Analysing documentation, mapping requirements and working with evidence material are time-consuming, and sending sensitive data to public AI models is often unacceptable.
What we are testing
Using local language models and RAG to speed up documentation analysis, requirements mapping and alert summarisation, without sending data to public models.
What it demonstrates
Practical use of local AI with source control and an understanding of model limitations, including hallucinations and the need for verification.
Status: prototype
This is a supporting tool for an expert; AI does not make legal or security decisions on behalf of a human, and it does not replace an auditor or an analyst.

What these records say about our approach

These records are not a separate product offering. They are the way we test architecture, constraints and the practical problems of our clients. Thanks to this, our CRA Snapshot, OT / IEC 62443 Mini-Gap, PSIRT / SBOM Starter and Cyber Insurance Evidence Check services rest not only on checklists, but also on experience from building tools, integrations and working with technical data.

Book a short call →