Enhancement of Cybersecurity of TTO THERMOTECHNIK d.o.o.

Project title

Enhancement of Cybersecurity of TTO THERMOTECHNIK d.o.o.

Project code

184

Brief project description

The project “Enhancement of Cybersecurity of TTO THERMOTECHNIK d.o.o.” is implemented with the support of the Digital Europe Programme, with the aim of strengthening the resilience of information systems and ensuring business continuity of the manufacturing company.

Within the framework of the project, activities are being implemented aimed at increasing the level of cybersecurity, including the introduction of solutions for protection against ransomware attacks and other cyber threats that may cause disruption of digital business processes. Through the implementation of the project, the security of digital infrastructure will be improved, the risk of security incidents will be reduced, and more reliable and secure business operations will be ensured.

The project also contributes to meeting regulatory requirements in the field of cybersecurity, including compliance with the Cybersecurity Act and the related Regulation, as the company is classified as an important entity in the sector of machinery and equipment manufacturing with a medium level of risk.

Objectives and expected results

The project will implement activities aimed at comprehensive improvement of the company’s cybersecurity through:

  • Conducting an information security risk assessment
  • Business Impact Analysis (BIA)
  • Assessment of key suppliers
  • Preparation of mandatory documentation in accordance with the Regulation
  • Security testing and vulnerability management
  • Employee training on cybersecurity fundamentals

The implementation of this project represents a key milestone in strengthening the company’s cybersecurity and will bring measurable and long-term improvements in the management of information risks, business continuity and data security through:

  • professionally established, documented and proactive cybersecurity management system aligned with the Cybersecurity Act, NIS2 requirements and industry standards
  • comprehensive overview of threats and vulnerabilities that may affect business operations
  • establishment of a risk register and risk management methodology
  • timely planning of cybersecurity investments
  • continuous monitoring of risk reduction
  • systematic supply chain risk management
  • formalized policies and procedures for incident management, access control, change management, development processes and physical security
  • enhanced cybersecurity culture through employee education
  • transition from a reactive to a proactive risk management approach

The sustainability of the achieved results after project completion will be ensured through:

  • maintaining the achieved level of cybersecurity
  • maintaining cybersecurity policies and procedures
  • regular updating of the risk register
  • maintaining technical security through 24/7 monitoring of security events, incident response, alert triage and classification, digital forensics, and expert recommendations for remediation
  • periodic security testing, vulnerability scanning and verification of the effectiveness of security controls
  • annual employee cybersecurity training, including threat recognition training, phishing simulations and refresher training sessions

The final beneficiaries of the project are:

  • employees of the company who use digital and production information systems
  • company management through reduced risk of business disruption, data loss and financial damage
  • customers through more reliable product delivery and reduced risk of production downtime
  • suppliers through more secure data exchange and a more stable supply chain
  • other stakeholders through increased resilience of an important entity and reduced risk of cybersecurity incidents spreading

Total project value: 64,130.45 €
Amount of grant funding: 32,065.22 €
Project implementation period: 09 February 2026 – 01 February 2027