A problem found is not
yet a risk resolved

Prioritise findings and plan updates to suit your operating systems and plants.

Long lists of findings are of little help if criticality and impact on production remain unclear. Even an available update first has to be checked for relevance and compatibility.

IQstruct Engineering assesses vulnerabilities with regard to exposure, plant criticality and possible consequences for operation. Manufacturer notices and patch notes feed into update planning. Tests in a suitable environment, announced maintenance windows and prepared rollbacks support the rollout.

Start now at no cost

In a free first conversation we clarify which systems are checked and what a maintenance window looks like in your operation.

See the person in charge

Scope of services

Prioritise findings by risk

Technical severity and actual use are assessed together.

Test updates before production

Staging or test instances support the functional test.

Deal with legacy systems specifically

Compensating measures or a planned replacement reduce remaining risks.

From finding to resolved vulnerability

IQstruct Engineering assesses vulnerabilities with regard to exposure, plant criticality and possible consequences for operation.

The CVSS score describes the technical severity. For the order of measures, what also counts is how reachable a system is, how critical the affected plant is and what consequences an intervention would have for production. Known software versions and an SBOM make it easier to assign new manufacturer notices.

Relevant updates are first tested on a staging or test instance and rolled out in announced maintenance or downtime windows. A functional test and a prepared rollback are part of the release, and follow-up checks and documentation accompany the work.

Person working at a monitor and a notebook with source code

Vulnerability management

The most urgent risk is resolved first

Exposure, criticality and consequences for operation determine the order of measures.

Approach in the project

  1. Two people record the network diagram with office, production, servers and transitions on the screenAi

    1

    Record the network inventory

    Office IT, production, servers, NAS and transitions are shown in one network diagram.

  2. Two administrators set up vulnerability scanning and log monitoring on the screenAi

    2

    Set up monitoring

    Vulnerability scanning and separate SIEM or log monitoring are configured.

  3. An employee follows traffic and device states in the monitoring while a colleague works at the network rackAi

    3

    Monitor the network

    Traffic, states and security findings are reviewed in monitoring.

  4. An employee discusses the evaluation of the findings on the screen while a colleague checks at the server rackAi

    4

    Document findings

    Analysis, measures and evidence are discussed together.

When no update is available

Limit communication

Rules permit only necessary sources, targets, ports and protocols.

Isolate

The system sits behind an additional security layer.

Replace

A documented migration plan replaces the system with a current one.

Information security

Protecting confidential project data reliably

In the automotive industry, TISAX creates a common basis for handling confidential information.

Manufacturers and suppliers exchange design data, software and further sensitive project information. TISAX makes it possible to assess information security against common criteria and to share the results with business partners. As an engineering service provider in this supply chain, IQstruct Engineering likewise commits to protecting the information entrusted to it and holds a TISAX label. Clear access rights, governed data exchange and traceable responsibilities are therefore part of the cooperation in a project as well.

IT operations

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Can production plants be tested during operation?

Test scope and interventions depend on the systems concerned. We coordinate active tests of running production plants separately.

Is every vulnerability patched immediately?

Every update is checked for relevance and compatibility and applied in the suitable maintenance window.

Which tools do you use?

We choose the tools to suit your environment. What matters is the assessment of the findings in the context of operation.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Joint planning of a segmented IT and OT infrastructure on a network diagramAi

    2

    We discuss your requirements

  3. Discussion of a security analysis with a network diagram and a list of measuresAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

IT operations and managed services

Combine monitoring, updates and support in one agreed operating model.

Product compliance

Make components, licence terms and updates traceable.

OT security

Connect machine knowledge with segmentation, access protection and planned operation.