Drone Shot von Geländewagen in der Natur auf Schotterstraße
OPERATE · ASSESS · MAINTAIN
Operations & Assessment

Safe in operation.
Free for the future.

We take on monitoring, updates and assessments across the entire product lifecycle, so your team has the bandwidth for what really matters: the next generation of products.

— Positioning

We've got your back.

Cybersecurity, safety and compliance do not end when a product reaches the market. New vulnerabilities surface in the field, standards tighten, components slide into obsolescence, and the responsibility for all of it stays with the manufacturer.

We take on that part. Monitoring, incident response, independent assessments, update and maintenance management, set up so your engineering team can focus on the next generation of products rather than on what is already out in the field.

— Three areas

What we take on after launch.

Three service areas that work together: continuous monitoring, independent assessment and long-term maintenance.

Monitoring & incident management

Automated vulnerability monitoring and a structured PSIRT service: we spot security incidents early, assess them and coordinate the response.

Independent Assessment & Audits

Independent security and safety assessments to IEC 62443, ISO/SAE 21434, IEC 81001 and IEC 61508, giving you a solid attestation for approval, audits and customer requirements.

Maintenance & update management

HW/SW maintenance, security updates, obsolescence management and PKI operation, so that safety-related system parts stay available across the entire product lifecycle.

PSIRT / SLA · LIFECYCLE
Ingenieur beim Monitoring mit Dashboard
Monitoring & Incident Management

Product Security Incident Response Service.

Our PSIRT service helps you respond to reported security incidents and vulnerabilities in your products in a structured and fast way, across the entire product lifecycle.

We handle monitoring, analysis and assessment, along with the coordination and communication of the right measures. That way you not only meet regulatory requirements, but also strengthen your customers’ trust in the security of your products.

  • Monitoring, analysis and assessment of reported incidents
  • Coordination and communication of the response
  • A range of SLAs, from basic monitoring to prioritised response
  • Meeting regulatory requirements (CRA, NIS2, IEC 62443)
Make an enquiry
— Cybersecurity packages

From basic to full service.

You choose the depth, we deliver the right package, or put together a custom one for your needs.

Work-PackageWP Basic
Work-PackageWP Monitoring & ReportingRecommended
Work-PackageWP Full-Service
Vulnerability monitoring
Vulnerability notification
Mitigation Planning
Threat Analysis and Risk Assessment
HW/SW maintenance
Security Update Management
Work-Package

WP Basic

  • Vulnerability monitoring
  • Vulnerability notification
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW maintenance
  • Security Update Management
Work-Package

WP Monitoring & Reporting

Recommended
  • Vulnerability monitoring
  • Vulnerability notification
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW maintenance
  • Security Update Management
Work-Package

WP Full-Service

  • Vulnerability monitoring
  • Vulnerability notification
  • Mitigation Planning
  • Threat Analysis and Risk Assessment
  • HW/SW maintenance
  • Security Update Management
TESTAT / CRA · NOTIFIED-BODY
ITSecurityTestat
— Independent Assessment

Independent proof of security and compliance.

With requirements such as the Cyber Resilience Act or rules set by EU Notified Bodies, traceable security assessments are becoming ever more important. NewTec carries out structured assessments to international standards.

The result is a solid attestation: it serves as independent proof of a product’s technical security and supports approvals, customer requirements and audits.

  • IEC 62443: industrial cybersecurity
  • ISO/SAE 21434: automotive cybersecurity
  • IEC 81001: health software security
  • IEC 61508: functional safety
Request an assessment
PKI / X.509 · ROOT-CA · OCSP
Laptop mit PKI Management Software und Steuergerät
— PKI management & hosting

PKI management and hosting.

We offer a powerful toolchain for the central management of a product-related Public Key Infrastructure (PKI), built for the demands of industrial and connected products. You benefit from secure certificate management, digital device identity and encrypted communication, compliant with IEC 62443, EN 18031, CRA and NIS2. Our solution meets core requirements from current standards and laws. It helps you prove the authenticity, integrity and trustworthiness of your products in an audit-ready way, with no infrastructure or operating effort of your own.

With our offering you create the foundation for secure communication, software authenticity and regulatory compliance: ready to run, scalable and future-proof.

  • Provision and operation of a complete X.509 certificate infrastructure (Root CA, OCSP, CRL)
  • Certificate management toolchain for issuance, renewal and revocation
  • Multi-tenant solution, hosted in KRITIS-compliant data centres in Germany
  • Technical and organisational integration into OT and product environments
  • Optional: connection to IAM and security platforms (e.g. access control, signature verification)
Book an initial call
ACADEMY / TRAININGS · WORKSHOPS
Ingenieur hält Workshop in einem Meeting Raum mit Teilnehmern
— NewTec Academy

Enable your teams!

Regulations such as the Cyber Resilience Act (CRA), NIS2 and IEC 62443 explicitly require proof of qualified staff. Sometimes the fastest lever is not a service package but targeted training, so your team keeps the topic in-house.

At NewTec Academy we bring our knowledge together in open and in-house formats: compact, hands-on and led by trainers who work on live projects.

  • Webinars and training on CRA, NIS2, IEC 62443 and the Secure Development Lifecycle
  • Tailored to development, product management or procurement
  • Training materials and checklists to work from
  • Documentation of all training measures, audit-proof towards authorities
To NewTec Academy
Industries

Safe operation wherever you are.

Our industry experts are happy to help.

Talk

Let’s talk about your operating model.

Tell us what tends to pile up for you post-launch, and we will propose the right service setup so your team gets its bandwidth back.