Independent OT Security Consulting · Pharma · Chemical · Life Sciences · Rhine-Main / DACH
Make production OT visible. Operate it securely.
I bring mid-sized companies in the process industry to an audit-ready NIS2 state — vendor-neutral, with the tools that fit your plant, and without disrupting ongoing operations.
01 The Entry Point
A defined first step: the OT situational picture.
No framework agreement, no consulting subscription. The entry point at Aganum is a clearly scoped assessment: a structured survey of your production OT as a reliable foundation for your NIS2 risk management. Vendor-neutral — I work with the systems and data sources you already have, and add only where gaps exist: non-intrusively, without interfering with operations.
- Your effortOne point of contact and access to existing data sources — no agents, no installation, no preparatory work.
- Your operationsPurely passive methodology — no intervention in running or qualified systems, GxP-compatible, no re-validation risk.
- Your scopeScope and duration are defined in the intro call — after that you have a concrete proposal with a clearly defined outcome.
The OT picture stands on its own: you can build on it internally — or with me. No commitment beyond the assessment.
Asset inventory
Every communicating device in the captured network — passively recorded, with zone assignment. The foundation every audit asks for first.
Communication matrix
Who talks to whom, over what — including the zone transitions that appear in no documentation.
Vulnerability overview
The identified systems matched against CVE and KEV data — prioritized by real-world exposure, not score cosmetics.
Management report
An audit-ready report as the working basis for your NIS2 risk management — clear to executive management and the plant alike.
02 Services
Three building blocks — each with a result you can hold in your hands.
NIS2 Readiness & Risk Management
You become audit-ready: gap analysis, risk management and exactly the evidence an audit demands — prioritized by what is actually achievable in mid-sized companies.
- Gap analysis against the NIS2 target state
- Risk management for production OT
- Controls per IEC 62443
- Building evidence & documentation
- Standards: NIS2 · IEC 62443 · ISO 27001/27019 · BSI
OT Visibility & Asset Discovery
At the end you know reliably what exists in your OT network and what talks to what — the foundation NIS2 demands first. With the systems you already have.
- Use of existing data sources & platforms
- Passive capture only where gaps exist
- Asset inventory & network topology
- Vulnerability & CVE matching
- GxP-compatible: no intervention in qualified systems
OT Security & Monitoring
Visibility becomes operations: segmentation, detection and monitoring your team can actually sustain — with the platform that fits your plant, not a partner program.
- Network segmentation & zoning
- Anomaly & threat detection in OT
- Claroty · Nozomi · Dragos · Armis · Forescout — compared neutrally
- Integration with existing SOC/SIEM
- Incident readiness for OT environments
03 Approach
Pragmatic. Deep. Vendor-neutral.
I don't work from off-the-shelf slide templates. Every engagement starts with the concrete context — plant, architecture, threat landscape, existing tooling — and ends with a decision you can actually implement.
-
→ 01
Diagnosis
Taking stock of assets, tools, processes and organization — no assumptions, only evidence.
Result: a reliable picture instead of assumptions.
-
→ 02
Assessment
Structured comparison of options against your risk, architecture and operational criteria.
Result: options that fit your risk, plant and budget.
-
→ 03
Decision basis
A clear recommendation with costs, effort, risks and trade-offs — ready to present to the board and steering committee.
Result: a basis that carries weight with executive management and the plant alike.
-
→ 04
Implementation
Support from PoC to roll-out — operational depth instead of PowerPoint consulting.
Result: measures that reach operations and hold up there.
How the entry works in practice
- 01Intro call, 30 minutes, free of charge. We clarify your starting position, your NIS2 classification and whether the OT picture is the right step for you.
- 02On-site survey. With the methodology that fits your plant — existing systems and data sources first, passive capture only where gaps exist.
- 03Report & recommendation. You receive the assessment and a prioritized recommendation — then you decide how to proceed.
Why independent?
- No commissions. I take no money from any vendor — the recommendation follows your plant, not a margin.
- No staffing model. You always talk to the person doing the analysis — no junior teams, no hand-offs.
- The recommendation is yours. Every decision basis is built so you can implement it without me.
04 Engineering Proof
I don't just consult — I build.
Out of engineering practice I developed a portable, purely passive OT audit appliance: it listens to a plant network via the mirror port, automatically builds an inventory of the communicating devices, detects anomalies and produces the audit-ready report — entirely on site, without any cloud.
I use it in assessments wherever it is the fastest route to the OT picture — and at the same time it is proof of how I work: passive, on-premise, transparent. For continuous operation I recommend, vendor-neutrally, the platform that fits your plant.
Purely passive
Never sends a packet into the plant network — production cannot technically be disrupted.
On-premise
No cloud backend, no phoning home. All data stays at the plant — including the findings.
OT-native
Understands the plant's protocols — Modbus, S7, PROFINET, OPC UA, DNP3 and more.
Audit report
An audit-ready report at the push of a button — mapped to NIS2, IEC 62443 and BSI.
05 Insights
Observations from practice.
Why passive visibility is the only acceptable approach in OT.
Active scans that are routine in IT can cause damage in a production plant. Why non-intrusive methods are not a convenience but a necessity.
NIS2 for mid-sized companies: visibility first, then compliance.
Many companies start NIS2 with documentation and processes. Why that's the wrong order — and why any risk management without an OT picture is built on sand.
Choosing an OT platform without vendor bias — what matters.
Claroty, Nozomi, Dragos, Armis, Forescout — on paper the platforms look alike. Which criteria make the difference in practice.
06 About
Consulting that comes from practice.
Cyber security in industrial environments lives on attention to detail — and on recommendations that hold up when they meet the reality of a running plant.
I'm an engineer (electrical engineering) and focused on cyber security as early as my studies. For more than seven years I have worked in cyber security at international industrial and DAX-listed corporations — most recently as a Senior Cyber Security Expert for OT and IT security: building and steering security operations centers, OT security architectures and IT/OT segmentation, use-case engineering, threat intelligence and incident response. Before that, at Siemens Digital Industries, I analyzed the security risks of industrial IoT components and performed penetration tests.
From this work I know the leading OT security tools not from data sheets but from real-world use. Today I independently help process-industry companies make their production OT visible, assessable and NIS2-compliant — based in Frankfurt am Main, on site across the Rhine-Main region, and DACH-wide on a project basis.
Security doesn't come from the right platform, but from the right decisions about the right platform.
07 FAQ
What decision-makers want to know before the first conversation.
Are we even affected by NIS2?
Many mid-sized process-industry operations are — as an “important” or “particularly important” entity under the German implementation act. The classification depends on sector, size and role in the supply chain. In the intro call we clarify where you stand — and regardless of the outcome: a reliable OT picture is the foundation of every risk assessment the legislator demands.
We already run an OT security platform — do we still need you?
Especially then it can pay off. I am vendor-neutral: I don't replace Claroty, Nozomi, Dragos & Co. — I work with what is there, and turn the existing data into solid NIS2 evidence, a clean zoning concept and a prioritized roadmap. And where no platform is in place yet, I help select the one that fits your plant — no commissions, no partner program.
Is the survey really non-intrusive?
Yes — by design, not as a promise. I work passively as a matter of principle: with existing data, exports and logs; where network traffic is captured, it happens via a mirror port (SPAN) or TAP — not a single packet is sent into the plant network. Unlike active scans, which pose a real downtime risk in OT, the plant cannot even notice the capture.
We are a GxP-regulated operation. Is this even possible?
Especially then. The survey does not intervene in qualified systems and changes nothing on the plant — no re-validation risk arises. I align approach and documentation with your QA in advance, so that the evidence of non-intrusiveness is formally sound as well.
What do you need from us?
Very little: one point of contact and access to the existing data sources — depending on the starting position, e.g. exports from existing systems, firewall/switch logs or a mirror port on the relevant switch. No agents, no software installation on your systems, no preparatory work on your side.
What does it cost?
That depends on scope — number of sites, segments, the question at hand. So there is no price list, but no open end either: after the intro call you receive a concrete proposal with a clear scope and a clearly defined outcome. You decide on that basis — the intro call itself is free of charge and without obligation.
What happens to our data and findings?
They belong to you. Analysis runs on-premise at your plant; there is no cloud backend and no data sharing. On request I sign a non-disclosure agreement before the first appointment — and topics such as the works council and GDPR are settled before the first capture starts.
08 Contact
The next step is a conversation — not a contract.
Tell me where your production OT stands. I'll get back to you within 24 hours — and in the intro call we clarify whether and how I can help you.
- Short message — informal, by email or LinkedIn. Two sentences on your starting position are enough.
- Intro call, 30 minutes, free of charge — starting position, NIS2 classification, a sensible next step.
- Concrete proposal — scope, process and outcome in black and white. You decide.
Confidential from the very first email. On request I sign a non-disclosure agreement before the first appointment. Your findings stay with you — on-premise, no cloud, no sharing.
PROJECT START FROM Q3 2026 · INTRO CALLS ANYTIME