Key Management for Cyber-Physical Systems
How to build a key management system that is tailored to your needs. Typical use cases, requirements, and solutions.
Hi, I am Tobias.
I help secure cyber-physical systems. Cybersecurity isn't just my profession. It's my passion, and it has been for over 15 years. Delivered with efficiency, reliability, and excellence.
Consistent, high-quality delivery that earns your trust. That's the standard I hold myself to.
OT and embedded environments demand reliability, data authenticity, and service availability. Limited resources and the presence of legacy systems set them apart from typical IT landscapes. I can help you build a strong cybersecurity architecture for OT and embedded systems that is compliant with relevant regulation (IEC 62443, CRA) and tailored to your actual protection needs.
IEC 62443 · Risk Analyses · Supply Chain SecurityCryptography is the backbone of cybersecurity. For your transition to post-quantum cryptography, I bring eight years of cutting-edge research in the field. I can help you build secure public-key infrastructures and HSM-backed key management systems, and support you to achieve crypto-agility as standards evolve.
PQC · PKI · HSM · KMSAs the pace of transformation in the automotive industry continues to accelerate, security has never mattered more. A single incident can halt a manufacturer's production for weeks and cause billions in damages. I bring seven years of experience in the automotive industry and have helped customers achieve ISO/SAE 21434 certification. I can help you secure your in-vehicle systems as well as the surrounding infrastructure.
ISO/SAE 21434 · UN ECE R 155 · SDV · Autonomous DrivingThe EU Cyber Resilience Act turns product security from good practice into a legal obligation, with real penalties for getting it wrong. Manufacturers of products with digital elements must now prove security across the entire lifecycle, from design to end of support. I help you meet those obligations efficiently, building security into your products and preparing technical documentation that holds up under scrutiny.
Security by Design · Vulnerability Management · SBOMStrong security starts with people who understand it. I deliver trainings across every area of cybersecurity for cyber-physical systems, from foundational principles to advanced, domain-specific topics. With more than a decade of teaching experience spanning university students and industry professionals, I can build your team's capabilities at any level.
A rare mix of deep technical expertise and a way of working built around your needs.
Cybersecurity is a discipline I studied deeply and formally, not a field I drifted into. I know its ins and outs, in all their breadth and depth. As incidents like the 2025 Jaguar Land Rover attack showed, cybersecurity is too consequential to leave to improvisation.
Wherever possible, I work for a fixed price against a clearly defined deliverable, rather than an open-ended stream of billable hours. You can plan your budget with confidence and know exactly what you're paying for, with no risk of costs quietly running away.
Committing to a large security project is a leap of faith. That's why I offer a defined pilot: a scoped work package of one to three months, before any long-term engagement. You see the quality of my work first-hand and decide from there, with no obligation to continue.
No large consultancy behind me means no rigid playbooks and no overhead loaded onto your invoice. My focus is purely on getting the job done. I'm also technologically independent: my practice runs on a fully European tech stack, free of US big-tech dependencies.
Selected highlights from my professional experience. A full project list and list of references is available upon request.
EnquireLed a team of five engineers to achieve IEC 62443-4-2 compliance for the client. I directed the design of the OT security architecture for their power plants and supervised the implementation of the specified security controls.
Brought the client's product to cybersecurity series-production readiness. I supported the client in achieving ISO/SAE 21434 certification, specified and implemented the IT/OT cybersecurity architecture, and acted as the central point of coordination across the client's internal teams, suppliers, and customers, keeping everyone aligned.
Teaching university students and industry professionals. Selected courses and seminars:
Analyzed the practicality of novel post-quantum cryptographic algorithms on embedded platforms such as microcontrollers and FPGAs. I optimized the algorithms' resource use and developed side-channel protection measures.
Sharing knowledge is something I've always valued. Below are a few whitepapers drawn from my work in industry. Request one and I'll send it to your inbox. For my academic publications, see my DBLP page.
How to build a key management system that is tailored to your needs. Typical use cases, requirements, and solutions.
Facing a deadline, or starting a platform from a blank page?
I'll help you find the right path forward.