itrust consulting s.à r.l., a 12-years-old, recognized actor in Luxembourg’s and Europe’s Information Security field, certified according to ISO/IEC 27001, consults its customers coming from public, financial, and private sector to protect their information against divulgation, manipulations and unavailability. The company acquires know-how in engineering and sciences, enabling it to find the economically appropriate solution for a specific security requirement. It applies and develops research projects, norms, security controls and information processing techniques, covering topics such as information security management systems, risk management, business continuity management, incident management, digital signature, cryptology, network security, internet security, critical infrastructure protection, space, computer forensic, etc.
PRODUCTS & SERVICES
Consulting services, sourcing and innovation studies
Management and guidance of security projects. Critical Infrastructure protection. Technology integration and assistance (PKI, VoIP, virtualisation, etc.). Risk analysis (TRICK Service™). Forensic and malware analysis. Personal data protection, Data Privacy Impact Assessment (DPIA) following GDPR. Assistance to CISO and Data Privacy officer. Managerial monitoring of security issues. Incident response team.
Penetration testing and vulnerability assessment of hardware (network, server mobile devices, smart cards, firmware), software, web applications, and access security.
ISO 2700x. ISO 20000. ISO 27799. IEC 62443. Business referentials (PSF, PSDC). Legal referential (EU directives, grand-ducal regulations, CSSF). Protection of personal data (CNPD).
Code review (OWASP, SANS, etc.). Equipment configuration review. Critical Infrastructure, SCADA. Wireless infrastructure. Data Protection. PCI-DSS. ISO 15408 (Common Criteria). CSSF Compliance. EuroPriSe. CNPD compliance.
Elaboration of security tools & services
LASP: provide assurance to location services that locations indicated are trustworthy. TRICK Service™ (risk assessment). TRICK Cockpit (real-time risk monitoring).
Introduction and practical advice to comply with GDPR – Data Privacy; GDPR foundation certification – principles, legal framework and compliance; Data Protection Officer (DPO) – certified; Risk Manager certified for DPIA (guided by ISO/IEC 27005); ISO/IEC 270xx workshop; Lead Implementer ISO/IEC 27001 – certified; ISMS Lead Auditor ISO/IEC
27001 – certified; PSDC – eArchiving training session; Security awareness 4 your employees; etc.
TRICK Tester (penetration testing platform). Galileo receiver. GPS repeater.
EU institutions, financial service providers, energy distributors, ESA, Lux. Ministries, etc.
MAJOR SPACE PROJECTS
LuxLAUNCH projects (opportunity studies - Galileo applications):
Applications and Services on Broadband handheld devices. Standards, specifications & processes for space. Localization Authority. Lux. Testbed with Pseudolites. Machine-to-machine (M2M) satellite communication (energy sector). Media Access Certified System (MACS). ALIDADE - Study & POC on car-pooling & open location-based data. MEBOS – management platform optimizing bus occupancy based on geo-localization of buses and travellers.
ESA LASP project: Localisation assurance service provider. Software/ service to verify/certify the user’s location. This service was developed in partnership with ESA & the Lux. University.
CIPS SPARC project: The Space Awareness for Critical Infrastructure project analysed space phenomena (space weather, debris and near-Earth objects) as threats for Critical Infrastructures and their direct effect on ground infrastructures, and indirectly, causing failures in space assets, failures propagating at ground level.
H2020: bIoTope: creating an innovative Systems-of-Systems (SoS) platforms for connected smart objects (IoT). ATENA: Advanced Tools to assEss and mitigate the criticality of ICT compoNents and their dependencies over Critical InfrAstructures.
QUARTZ project: QUARTZ aims to develop an innovative, commercially viable Quantum Key Distribution (QKD) system to distribute cryptographic keys to end users via satellite optical links. itrust consulting has a major role in the secure design of the ground station system components that manage the concrete distribution and lifecycle of the QKD keys for its end-users on site so that they may seamlessly be integrated to applications.