Cybersecurity your team masters across every pillar

Implement ISO 21434, IEC 62443, ISO 27001 and prEN 18282 with confidence – we facilitate the analysis and build the capability within your team.

ISO 21434 = international standard for cybersecurity in product development (products). IEC 62443 = series of standards for cybersecurity in industrial automation and control systems (production). ISO 27001 = international standard for information security management systems (organizations). prEN 18282 = draft European standard for the cybersecurity of AI systems.

[01] — WHERE YOU STAND

Three pillars, one picture: where does your organization stand?

Products – ISO 21434Cybersecurity as part of product development, from threat analysis through to release.
Production – IEC 62443Protecting automation and control systems during live operation.
Organizations – ISO 27001An information security management system for the entire company.
AI cybersecurity – prEN 18282New, specific requirements for the cybersecurity of AI systems – an addition to the three pillars, not a fourth pillar of equal rank.
Up to 10x cheaper Rule of thumb from quality engineering: a cybersecurity risk caught during development costs far less to fix than a correction after launch – every late-stage iteration you avoid saves time and budget.
[02] — THE SHIFT

From clutter to clarity

The status quo

Cybersecurity requirements are scattered across product development, production and IT – often without a shared methodology.
Each standard brings its own terms and procedures (TARA, Zones and Conduits, ISMS) – teams end up talking past each other.
AI systems add further new requirements under prEN 18282 that hardly anyone knows yet.
Audits keep piling up, with no repeatable process behind them.
With our approach

One shared risk-analysis methodology connects products, production, organization and AI systems.
Your team learns the terminology of all four standards in the same workshop format.
We prepare you for prEN 18282 early on, instead of scrambling to catch up right before the audit.
A repeatable process you can apply again on every new project.
[03] — OUR APPROACH

Our approach: cybersecurity across every pillar

Cybersecurity is no longer a pure IT topic. Products need a threat analysis before they go to market, production systems need protection against manipulation during live operation, and the organization behind both needs a management system that supports them. We facilitate the risk analysis across all three pillars – plus the new requirements for AI systems – and build the capability within your team, rather than simply handing over a one-off result.

01 — Product TARAISO 21434: securing products consistentlyFor products with a software or connectivity component, we facilitate the Threat Analysis and Risk Assessment (TARA) under ISO 21434 – from the first threat identification through to documented risk treatment. Participants typically span development, systems architecture and quality management together, because product security emerges at the intersection of these roles. The result is audit-ready documentation that holds up under external review too.
02 — OT securityIEC 62443: protecting production and OT robustlyProduction faces different risks than the office: control systems, machinery and networks that need protection during live operation, often running on decades-old hardware. We analyze your automation and control systems under IEC 62443, identify protection zones and transitions (Zones and Conduits), and build a practical security concept with your team – complemented by training content from the IEC 62443 Academy.
03 — Building an ISMSISO 27001: giving the organization an ISMS to stand onSo that product and production security don’t remain isolated, we also turn to the Information Security Management System (ISMS) for the entire organization under ISO 27001. This creates a shared framework that brings together policies, responsibilities and evidence across every area – instead of parallel, overlapping individual initiatives.
04 — AI cybersecurityprEN 18282: preparing AI systems earlyAI systems bring their own attack surfaces – from manipulated training data to model theft. prEN 18282 is the emerging European standard that addresses exactly that. We identify early which of your AI systems are affected and align your existing cybersecurity work so it covers this new requirement too – instead of building yet another parallel structure.

CASE EXAMPLE FROM PRACTICE

What this looks like in practice

An anonymized excerpt from a threat analysis for AI systems under prEN 18282, of the kind the EU AI Act requires for high-risk systems.

EXAMPLEExcerpt from a threat analysis for AI systems under prEN 18282 – asset classification and impact
CASE EXAMPLE 01Assessing assets and impact systematicallyFor every asset, we capture protection goals and impact categories systematically – not as gut feeling, but as a traceable, audit-ready assessment.Excerpt from a threat analysis for AI systems under prEN 18282 – asset classification, protection goals and impact per asset.
EXAMPLEExcerpt from a threat analysis for AI systems under prEN 18282 – damage scenario, circumstances, domain and threat type
CASE EXAMPLE 02Linking damage scenarios with contextCircumstances, domain and threat type need to be considered together – only then does an observation become a robust scenario.Excerpt from a threat analysis for AI systems under prEN 18282 – damage scenario, circumstances, domain and threat type in context.
EXAMPLEExcerpt from a threat analysis for AI systems under prEN 18282 – STRIDE threat model and attack path
CASE EXAMPLE 03Modeling threats along the attack pathFrom the STRIDE framework through the vulnerability to the concrete attack path – considered systematically, not case by case.Excerpt from a threat analysis for AI systems under prEN 18282 – STRIDE threat model, vulnerability and attack path.
[04] — TRACK RECORD

Decades of experience, connected across three pillars

We’ve supported cybersecurity threat analyses and management-system development for decades – across startups, mid-sized companies, global corporations and public authorities. We consistently carry that same methodological foundation over to all three pillars and to AI systems, backed by hands-on experience with current regulation such as the Cyber Resilience Act and the EU AI Act, so risk analysis and compliance evidence fit together instead of being treated separately.

[05] — NEXT STEP

Ready to get cybersecurity under control across every pillar?

Let’s use an initial call to figure out where your organization stands and what the next sensible step is.