Industrial asset visibility and governance

Know the plant. Govern its reality.

Rutile brings together the inventory, topology, configurations and lifecycle of every asset. One source of truth to support operations and prove regulatory compliance.

Passive discovery + controlled active queryingOn-premise deploymentDeveloped in Europe
Rutile in operation Rutile · product interface

One network, complete context

The digital twin

Rutile’s digital twin turns the reality of the industrial network into a single, navigable view that always remains connected to the process.

Starting from the real topology, we can open any asset to see which vulnerabilities affect it, the risk they represent in context, the status and age of its backups, available patches and its compliance position. Every decision is therefore based on the complete relationship between the asset, its communications and its industrial function.

  • Network topology
  • Vulnerabilities by asset
  • Contextual risk
  • Backup status
  • Patches
  • Compliance

Capabilities

A living record for every asset

What it is, where it is, what it communicates with, what it needs and what can be proven about it.

Asset inventory

Manufacturer, model, firmware, protocols, addressing, role and location derived from real traffic.

Digital twin

A navigable graph of communications, routes and protocols on which all other data is projected.

Vulnerabilities

CVEs and manufacturer advisories prioritised by actual exposure in the topology, not by CVSS alone.

Patches

Versions, availability, approval, maintenance window and before-and-after evidence.

Backups

Configuration copies, age, version comparison and last known good backup.

Compliance

Inventory and history turned into continuous evidence for regulatory frameworks and audits.

Two sources, one reality

Passive discovery and active querying. Together.

Rutile’s real strength lies in combining what the network reveals on its own with what only a direct query can confirm. These are not competing modes: they are two layers of the same industrial knowledge.

Continuous observation · Passive

The network tells us how the plant operates

Rutile analyses traffic from a SPAN port or TAP to discover assets, communications, protocols and topology without directly accessing plant devices.

  • Continuous visibility without interfering with the process.
  • Actual relationships between assets, not an isolated inventory.
  • Coverage of legacy, heterogeneous or difficult-to-query equipment.
Selective enrichment · Active

Rutile asks what the network cannot tell us

Active querying completes visibility and is required, at a minimum, for an in-depth understanding of network infrastructure. Not every endpoint needs to be accessed: controlled queries target those that add the most context.

  • Installed software and actual versions.
  • Vulnerabilities linked to the specific asset.
  • Configurations, status and additional technical detail.
  • Scope, credentials and windows defined by the customer.

Passive + activeBy combining network context with asset-level detail, Rutile ICS builds a living, verifiable digital twin that supports operational decisions from a shared view.

Exposure with context

Vulnerabilities you can prioritise

Rutile correlates the identified asset with CVEs and manufacturer advisories. It then adds its function, communications and the routes that lead to it.

  • Model and firmware support the correlation.
  • The topology reveals actual exposure.
  • Unsupported devices remain visible together with their compensating controls.
Industrial vulnerabilities ordered by actual exposure in the topology
Vulnerabilities with actual exposure context
Configuration backup status projected onto the Rutile digital twin
Last known good configuration

Operational recovery

Backups and status in the twin

See which parts of the plant retain a last known good configuration, when it was obtained and what has changed since.

- Profinet name: PLC-LINEA-03
+ Profinet name: PLC-LINEA-03A
  Firmware: 2.9.2 · verified checksum

Change under approval

Patch management and deployment

Rutile compares installed and available versions and takes each change to an authorised window. Nothing is applied without approval.

VERSIONInstalled state
AVAILABLEManufacturer advisory
APPROVALScheduled window
EVIDENCEBefore / after
Patch planning and maintenance windows in Rutile
Authorised and traceable change

Evidence that stays current

Regulatory and standards compliance

Inventory, changes and controls leave an audit-ready trail. Evidence stays current instead of being rebuilt in a spreadsheet every year.

Regulatory compliance report generated in Rutile
Continuous evidence by compliance framework
NIS2

Documented inventory, risk management, incidents and continuity.

IEC 62443

Zones, conduits, assets and technical controls linked to the topology.

ENS · RD 311/2022

Asset status, applied measures and a verifiable change log.

CRA

Versions, vulnerabilities and remediation lifecycle by product.

ISO 27001

Inventory, owners, risks and operational control evidence.

On-premise architecture

Inside the industrial perimeter

No agents on plant devices.

Passive capture through a SPAN port or TAP.

Distinct, optional and scoped active querying.

SIEM and CMDB integration through controlled interfaces.

Industrial contexts

A different reality in every plant

Nuclear

Strict traceability, long-lived assets and authorised changes.

Chemical

Process continuity and visibility across instrumented systems.

Rail

Distributed infrastructure and versions coexisting for decades.

Oil & gas

Remote sites, third parties and high operational criticality.

Renewables

Geographically distributed sites and multi-vendor equipment.

Manufacturing

Heterogeneous lines where availability and maintenance take precedence.

Water and wastewater

Treatment plants, pumping stations and distributed control systems delivering an essential 24/7 service.

Power grids and substations

Control centres, protection systems and remote assets where availability and visibility are critical.

Pharmaceutical and biotechnology

Validated environments where every configuration, change and item of evidence must be traceable.

Food and beverage

Continuous production, traceability and equipment from multiple generations and vendors.

Mining and metallurgy

Continuous processes, remote facilities and assets operating under demanding conditions.

Ports and logistics

Terminals, cranes, automated warehouses and distributed systems that cannot stop.

Product interface

Product decisions

Why Rutile

One record, multiple functions

Operations, maintenance, engineering, security and compliance work on the same asset and the same history.

Context changes priority

A vulnerability is assessed with its route, exposure and plant function, not just an isolated score.

The customer remains in control

Queries and changes require an explicit scope, window and approval.

A product grounded in OT practice

Developed in Europe by a team that performs penetration testing and operates an industrial SOC.

Data inside the perimeter

On-premise deployment and controlled integration with the required corporate systems.

European digital sovereignty

Developed in Europe and deployed on-premise: data remains under the customer’s control, in line with Cybersecurity Made in Europe.

Information by need

Explore Rutile ICS in depth

Focused pages for evaluating the product, its deployment and its fit in an industrial environment.

Product

OT asset inventory

Identity, communications, software, configurations and exposure in a living record.

Context

Industrial sectors

Twelve operational realities where priorities and evidence differ.

Architecture

On-premise deployment

Passive discovery, controlled active queries and no agents on plant devices.

Technical questions

Before connecting anything

Demo request

See Rutile ICS in the context of your plant

Tell us briefly about your environment and what you need to solve. Our team will contact you to prepare a focused, useful demonstration.

Zoho CAPTCHA code