Services · Cybersecurity and compliance
Assessment and remediation of the cybersecurity of radio networks and monitoring systems, to ISA/IEC 62443-3-3 SL2 and the NIS2 directive.
We examine the installation from a cybersecurity standpoint: separation between the plant network and the corporate IT network, management of user accounts and remote access, encryption of the links, updating of the equipment, event logging, and service recovery. We deliver a report on the state we find and on the gaps against the requirements of ISA/IEC 62443-3-3 Security Level 2 and of the NIS2 directive, together with a remediation plan ordered by priority.

Radio and monitoring systems started life as isolated installations, and today they are connected to the IT network of whoever runs them. On site surveys we keep finding the same things: devices reachable from the office network, management interfaces still on the manufacturer’s credentials, one account shared by every engineer, remote access opened for a supplier and never closed again. In day-to-day operation nobody notices. The bill arrives when someone gets into the installation who has no right to be there.
We start from the installation as it really is, not from a questionnaire. We survey the devices present on the network, the links between them and towards the outside, the active accounts and the remote access paths, then we compare what we find against the requirements of ISA/IEC 62443-3-3 Security Level 2 and of the NIS2 directive (EU 2022/2555). We deliver a report on the gaps and a remediation plan ordered by priority; if the customer asks, we carry out the work and verify the outcome with their engineers. We do not issue compliance certificates: that stays with the organization that runs the infrastructure, and our contribution is the technical part we build and maintain. ISO 27001 certification of our information security management system is in progress.

How we work.
The three ways we work on the cybersecurity of an installation, from the assessment of a system already in service to the requirements for a new one.
Assessment of an installation in service
We survey the devices, links, user accounts, and remote access paths of a system already in service, compare what we find against the requirements of ISA/IEC 62443-3-3 Security Level 2 and of the NIS2 directive, and describe every gap naming the device or the link it refers to.
Remediation of the installation
We carry out the work approved by the customer within the operating windows: separation between the plant network and the corporate IT network, review of user accounts and remote access, encryption of the links, centralized event collection, and backups of the configurations.
Security in new installations
In the systems we design and build, we set the cybersecurity requirements in the specification and in the network architecture from the start, and we verify them at acceptance testing alongside the radio measurements.
What we check on the installation.
The points we examine during the assessment and act on during the remediation, grouped by area.
Network architecture and segmentation
- Separation between the radio plant network and the customer’s corporate IT network
- Up-to-date diagram of the links, with the networks, the devices, and the ports actually in use
- Connection points towards the outside: supplier remote access, links between sites and to the cloud
- Firewall rules and traffic allowed between the network segments
- Identification of devices on the network that appear in no inventory
Accounts, access, and identity
- Active accounts on devices and platforms, with the role assigned to each one
- Manufacturer default credentials still in use and accounts shared between engineers
- Accounts belonging to staff who have left the organization or changed role
- Multi-factor authentication and integration with corporate single sign-on (SSO), where the devices allow it
- Traceability of actions per operator on the control room consoles
Encryption of communications and data
- Encryption of the links between devices, platforms, and operator positions: on Respondr, communications are encrypted with TLS 1.3 and AES-256
- Unencrypted management protocols still enabled on the devices: web interfaces in the clear, SNMP v1 and v2c
- Encryption on the air interface, where the radio technology in use provides it
- Certificate and key management: issuing, replacement, and expiry dates
- Protection of the call recordings and of the data stored on the platforms
Devices, firmware, and known vulnerabilities
- List of the devices with model, location, and installed firmware version
- Comparison between the installed versions and those released by the manufacturers, checked against the published security advisories
- Services and ports enabled on the devices, with the unused ones disabled
- Update planning within the operating windows, with a functional test before the return to service
- Operator workstations: operating system, installed software, and use of removable media
Event logging and log retention
- Events logged by the radio equipment, by the network equipment, and by the supervisory platforms
- Centralized log collection over Syslog and SNMP, instead of local logging on the device alone
- Time synchronization across all devices: without a common clock, logged events cannot be compared
- Retention of the logs and of the call recordings for the period agreed with the customer
- Forwarding of relevant events to the control room and to the contacts named by the customer
Service continuity and recovery
- Backups of the configurations of devices, terminals, and consoles, kept off site
- Restore test of a device from the stored backup, to verify that the backup is usable
- Redundancy of devices, links, and operator positions, compared with what the design specified
- Written service recovery procedure, with the roles assigned and the contacts to call
- Behavior of the installation on mains failure and on loss of the links towards the outside
Control room and communication platforms
- Dispatch consoles and operator positions: accounts, role-based profiles, and actions logged per operator
- Voice recorder: access to the recordings, search, and backups
- Links between the platforms, the radio networks, the gateways, and the customer’s systems
- Platform installation model (cloud, on premise, or hybrid) and where the data resides
- Monitoring units installed in the field (TP-CELLX, TP-RFX, TP-CCV2) and how they connect to the plant network
Compliance and documentation
- ISA/IEC 62443-3-3 Security Level 2 requirements applied to the architecture of the installation
- Technical measures required by the NIS2 directive (EU 2022/2555) on the part of the installation we build and maintain
- Roles and responsibilities agreed between the customer and Teleproject for each measure
- Cybersecurity requirements referenced in tender specifications and in maintenance contracts
- Technical documentation of the installation, to attach to the customer’s compliance checks
How an engagement runs.
The cycle we follow, from the first survey in the field to the final check on the work carried out.
- Step 01
Survey of the installation
We take stock of devices, links, user accounts, and remote access together with the customer’s engineers, and we collect the network documentation and the configurations already available.
- Step 02
Comparison against the requirements
We compare what we found against the requirements of ISA/IEC 62443-3-3 Security Level 2 and of the NIS2 directive, then describe every gap naming the device or the link it refers to.
- Step 03
Report and remediation plan
We deliver the report on the gaps we found and the remediation plan ordered by priority, separating the work that can be done in service from the work that requires a shutdown of the installation.
- Step 04
Remediation of the installation
We carry out the work approved by the customer within the agreed operating windows: network separation, review of the accounts, encryption of the links, centralized event collection, and backups of the configurations.
- Step 05
Verification and handover
We verify together with the customer that every item has been carried out, update the documentation of the installation, and put the outcome on record. On request we train the staff who manage the equipment.
What you receive.
The documents that stay with the customer, useful in operation, for compliance checks, and at audits and tenders.
- Security status report
The state we found, device by device and link by link, with the gaps against the requirements of ISA/IEC 62443-3-3 Security Level 2 and of the NIS2 directive.
- Network and link diagram
The up-to-date diagram of the links between the devices of the installation and the customer’s systems, with the networks, the ports used, and the access points from outside.
- Remediation plan
The work proposed, ordered by priority, marking what can be done in service and what requires an agreed operating window.
- List of devices and firmware versions
Model, location, and firmware version of every device on the network: it is the basis for planning the updates and for assessing the security advisories published by the manufacturers.
- Register of accounts and profiles
The active accounts on devices and platforms, the role assigned to each one, and the agreed rules for creating, changing, and disabling them.
- Documentation for audits and tenders
The technical documents to attach to the customer’s compliance checks and to tender bids, together with the service recovery procedures.
Which sectors use this service.
The sectors that turn to this service most often.

Highways and tunnels
We design, install, and maintain the radio coverage and monitoring systems for Autostrade per l’Italia, SITMB, SAV, RAV, Asti-Cuneo, and many other concessionaires. Over more than twenty years we have equipped more than 500 km of routes and over 100 tunnels.

Utilities and industry
We design, install, and maintain professional radio networks, ATEX-certified PoC devices, and LoRaWAN sensor networks for energy operators, utilities, and high-risk industrial environments. For clients like Iren, we bring over twenty years of experience in mission-critical communications.

Public safety
We design, build, and maintain mission-critical radio networks and control rooms for law enforcement, emergency medical services, and Protezione Civile: TETRA, DMR, and P25 networks, powered by the Respondr dispatch platform and over twenty years of experience in communications where failure is not an option.
Frequently asked questions.
The questions we hear most often about this service.
Does the NIS2 directive apply to our radio network as well?
The NIS2 directive (EU 2022/2555) applies to organizations, not to individual devices: it identifies the entities subject to the obligations on the basis of sector and size, and each Member State transposes it into its own national law. If the organization falls within that scope, the radio network and the monitoring systems that support the service have to be secured along with the rest of the IT infrastructure. Establishing whether the obligation applies is up to the organization itself: we work on the technical measures for the part of the installation we build and maintain.
Is a security assessment needed even if the radio network is not connected to the internet?
Yes, because a truly isolated network is rare. On site surveys we almost always find remote access left open for a supplier, a link to the office IT network or to another site, or the removable media and laptops engineers use when they work on the equipment. Isolation, in any case, does not fix the faults we see most often: manufacturer default credentials still active, a single account shared by every engineer, and configurations nobody keeps a copy of.
Does a device too old to meet the requirements always have to be replaced?
Not always. When a device cannot do multi-factor authentication, or exposes only unencrypted management protocols, the risk is reduced by working on the rest of the installation: segmenting the network the device sits on, allowing access only from identified workstations, disabling unused services, and collecting events centrally. Almost all of this work is done with the installation in service; anything that needs a restart is agreed within an operating window. When even these measures are not enough, the report states the residual gap and the reasons for planning the replacement, so the customer can put it in the investment plan instead of facing it as an emergency.
How often should the security assessment be repeated?
There is no fixed deadline: the assessment has to be repeated when the installation changes. A new link towards the outside, a supplier granted remote access, replaced equipment or an added site all change the picture recorded earlier and make the report out of date on those points. Where a maintenance contract is in place, the periodic check of user accounts, firmware versions, and backups can be agreed within it.
Request a quote for cybersecurity and compliance.
One of our Project Managers analyzes your specific project requirements and prepares a dedicated technical and commercial proposal.