Skip to main content
This page is displayed using automated translation. View in US English instead?
Company Core Technologies

Cybersecurity and Trust

Cybersecurity and Trust advances technologies that protect Siemens products and solutions against cyber threats, strengthen resilience, support regulatory compliance and address the specific security needs of OT environments across the Siemens portfolio.

What if communication and cybersecurity were integrated in increasingly complex OT environments?

As industrial systems become more connected, autonomous, software-defined and AI-enabled, cybersecurity and trust become mission-critical. A key research focus is how AI can be used to detect incidents and vulnerabilities in real time, and how industrial systems can automatically adapt and restore security in critical operational environments.

In an era of evolving threat landscapes and growing operational complexity, what matters are security concepts and trust mechanisms that help keep critical infrastructure, products, operations and AI-driven systems secure, resilient and trustworthy.

Split image showing a futuristic AI microchip on the left and a woman writing on a glass whiteboard on the right
A female IT technician holding a clipboard and walking down a server room hallway lined with tall black data racks

Our Cybersecurity & Trust research spans the full industrial security stack, from identities, communications and compute platforms to secure operations, DevSecOps, and lifecycle practices. It enables trusted data exchange and verifiable collaboration across technical and organizational boundaries, while helping control and safeguard AI-driven autonomous behavior to build and operate resilient, trustworthy industrial ecosystems.

This Company Core Technology comprises applications and systems that secure modern industrial environments across every operational layer. They protect cloud platforms like Xcelerator, edge ecosystems and industrial data spaces. Operational technology is safeguarded using zone-and-conduit segmentation, zero-trust rules and secure protocols such as PROFINET and IEC 62351‑8.
Crypto-agility ensures readiness for post-quantum transitions, while Security Operations Center capabilities and vulnerability management handle emerging threats. Finally, trust models secure supplier ecosystems, enabling safe deployment of AI solutions and engineering copilots.

Icon for Cybersecurity & Trust
Publications

Explore our featured papers


Attesting the trustworthiness of a credential issuer

Published in: IARIA Cyber 2025 conference
Rainer Falk, Steffen Fries

Locally issued device certificates in industrial settings often lack the trust of those from centralized security infrastructures. To bridge this gap, we propose embedding a cryptographically verifiable integrity attestation of the credential issuer directly into issued authentication certificates. This allows relying parties to easily verify the issuer's trustworthiness during routine credential validation.
View at publisher's page


Optimizing certificate validation in OT environments by caching certificate validation results

Submitted to: NAIC '25: 2026 IARIA Journal on Advances in Security, vol 19, no 1&2
Rainer Falk, Steffen Fries, Andreas Güttinger

Certificate-based user and device authentication is vital in Operational Technology (OT), but validating full certificate chains strains resource-constrained devices. While offloading validation logic reduces computational overhead, efficiency gains remain limited. This paper reviews existing certificate handling techniques and offloading optimizations, proposing a novel approach to further boost validation efficiency in industrial OT environments.
View at publisher's page


Fault attacks against UOV-based signatures

Published in: IACR 2025
Sven Bauer

Unbalanced Oil and Vinegar (UOV) underpins key post-quantum signature schemes in NIST's standardization. This paper introduces single fault injection attacks on deterministic UOV variants, targeting MAYO and PROV on ARM Cortex-M4 processors. Requiring no precise fault injection or timing, cheap clock glitching recovers secret keys from just 2–3 signatures, exposing a severe implementation security threat.
View at publisher's page