Securing industrial facilities, from the field to the digital

OT environment mapping, cyber-risk visualisation and IEC 62443 compliance. Ultrametrix helps industrial operators understand and secure their critical facilities.

100% passive
SPAN/TAP listening · zero packets emitted
IEC 62443
Compliance · NIS2
Sovereign
Open-core · air-gap
UMX Risk Manager - dashboard: overall score, inherent and analysed risk, segmentation findings

Decoded protocols - passive listening only

Modbus/TCPSiemens S7EtherNet/IP · CIPDNP3IEC-104OPC UAPROFINET DCPBACnet/IPGOOSE · IEC 61850EtherCATMQTTHART-IPCC-Link IELLDP / CDP

Our cyber modules

Two tools dedicated to industrial cybersecurity, from visibility to OT risk control.

UMX Explorer

Open source · 100% passive

Cyber mapping of OT environments

Passive probe and mapping console for industrial facilities. It identifies and structures the equipment, systems and interconnections of an OT environment - through 100% passive network listening, without emitting a single packet towards production.

  • Automatic asset inventory: PLCs, HMIs, SCADA, historians, network equipment
  • 14 industrial protocol families decoded (Modbus/TCP, S7, EtherNet/IP, OPC UA, DNP3...)
  • Continuously built Purdue architecture map, levels 0 to 4, subnets and channels
  • Cross-level flow detection: who talks to whom, over which protocol
  • Deploys on a mirrored port (SPAN/TAP): no agent, no production impact
  • Runs offline, in isolated environments - no telemetry

Passive probe with open, auditable source code - zero impact on production.

UMX Risk Manager

Cyber-risk management & IEC 62443 compliance

Builds on the UMX Explorer map to turn visibility into decisions: a clear reading of exposures, sensitive zones and security priorities, all the way to a report ready to present.

  • IEC 62443 zones & conduits built from the site’s real map
  • Cyber-HAZOP analysis: threats, vulnerabilities, risk scenarios per zone
  • Inherent then residual risk scoring, aligned with your corporate matrix
  • Target security levels (SL-T) and 62443-3-3 requirement coverage
  • Complete analysis reports in one click, for management and auditors alike
  • Optional CTI / EASM module: external attack-surface monitoring

One deployment per industrial site - runs offline, air-gap compatible.

Our solutions in action

Real captures of UMX Explorer and UMX Risk Manager - from the network map to the compliance dashboard.

UMX Explorer - Purdue architecture and communicationsUMX Explorer - live dashboardUMX Explorer - asset inventoryUMX Risk Manager - IEC 62443 compliance dashboardUMX Risk Manager - network graph and at-risk channelsUMX Risk Manager - asset inventory and criticality

Real interfaces, demo data - from the UMX Explorer map to the UMX Risk Manager dashboard.

Risk scoring

Industrial cyber risk, scored and ready to present

We score the cyber risk of your OT environments clearly, quickly and exhaustively: every zone and every conduit receives an inherent then residual risk score, aligned with your corporate matrix and IEC 62443. The result reads at a glance - and turns into a complete analysis report, ready to present to your management or an auditor.

Inherent & residual scoreBefore and after countermeasures, per zone and for the whole site.
IEC 62443 alignedThreats, vulnerabilities, scenarios, target security levels (SL-T) and requirement coverage.
Report ready to presentA complete document in one click - summary, risk scenarios, countermeasures and rationale.
Risk assessment report - cover page
Site Risk Assessment - cover
Inherent vs analysed risk score summary
Summary - inherent vs analysed risk
Zone register with security levels
Zone register - SL-T / SL-A
IEC 62443-3-3 requirement coverage
62443-3-3 requirement coverage
Zone risk analysis summary
Zone analysis - summary
Threat x vulnerability risk scenarios
Risk scenarios
Countermeasures and recommendations
Countermeasures & recommendations

Excerpts from a demo report - scroll horizontally.

Independent OT cyber expertise

Our commitment: making OT cybersecurity accessible, sovereign and verifiable.

Sovereignty & transparencyAccessible to mid-size industryNo impact on productionCompliance by design (IEC 62443, NIS2)Risk control over time

Map the OT estate

  • Automated inventory of assets, protocols and flows (UMX Explorer, open source)
  • Full visibility with zero impact on production (passive listening)
  • A reliable knowledge base

Diagnose & prioritise risks

  • Threat and vulnerability analysis grounded in your real context
  • Risk assessment and prioritised remediation plan (UMX Risk Manager)
  • Alignment with IEC 62443, NIS2 and other frameworks

Independent, sovereign, open-core products and services

Working with us

Three ways to start - each one begins with a conversation.

1
Discover your network

A demonstration of UMX Explorer on your site: the probe listens to a mirrored port for half a day and you walk away with the real map of your facility.

2
Score your risk

UMX Risk Manager turns the map into an IEC 62443 risk analysis: zones and conduits, scenarios, scoring and a report ready to present.

3
Get guided

Our experts carry out or co-produce your risk analysis with your teams, from mapping to the final report - and make you autonomous.

Write to us through the form at the bottom of the page: we reply within 48 hours.

Consulting & guidance

Ultrametrix is not only about tools: we can carry out or co-produce your IEC 62443 risk analysis, combining field expertise, technical understanding and decision support.

The goal: moving from visibility to action.

  • Delivery of the IEC 62443 risk analysis (zones & conduits, HAZOP, report)
  • Mapping of industrial environments
  • Security hardening guidance & prioritisation support
  • Support for transformation and compliance programmes

Why Ultrametrix

01

Deep knowledge of industrial environments

02

A combined field, security and risk perspective

03

Tools dedicated to industrial cybersecurity

04

Operational guidance and consulting

Let's talk

OT mapping, cyber risk or IEC 62443 compliance - let's discuss your challenges.

Write to us

Describe your need - facility, scope, deadlines - and we will get back to you within 48 hours.

Let's talk about your industrial site

Mapping, risk analysis, NIS2 / IEC 62443 compliance: every journey starts with a half-hour conversation about your context. No commitment.