# IT/OT Architect | Max Kayr

> Hey there, I'm Max. I build systems: zone concepts, industrial security, and the software I keep missing at work.

URL: https://maxkayr.de/en

## Hey there, I'm Max.

*IT/OT Architect*

Good to have you here. Fancy a coffee? I'm a consultant and I build systems. And you?

## Always the same job. It just looks different every time.

*What I've done so far*

Presales consultant for OT networks, consultant for IT/OT convergence, industrial security expert, founder, programmer. Five different jobs on paper. In reality it was always the same one: I develop topics. I build systems.

What draws me to industrial security isn't the firewall, it's the structure behind it: plants, networks and people that all have to talk to each other. What draws me to programming isn't the code, it's the architecture. Building one app is easy. Building fifty apps that scale... Now that's a challenge.

### Group-wide zone concepts

*Concepts*

A zone concept that applies to every plant in a group and still stays usable in each individual one.

Steel, pharma, chemicals, food, automotive: lots of industries, the same question. How do you define group-wide what's allowed to talk to what, when every plant grew differently and none of them can stand still?

A group-wide zone concept isn't a network diagram, it's a language. It has to be coarse enough to apply everywhere and precise enough that two people derive the same firewall rule from it. The work isn't in the drawing, it's in pinning down the terms.

A concept nobody can apply without me isn't a concept.

### Plant zoning, all the way into implementation

*Concepts*

Around ten detailed zone concepts for a steel plant and its sister companies, seen through to rollout.

After the group-wide framework came the plant. About ten facilities, each with its own history: networks that grew over time, machines from manufacturers that in some cases don't exist anymore, and maintenance people who know exactly why a cable runs where it runs.

I didn't hand the concepts over, I stayed with them into implementation. That's the part where you find out whether one works: when someone stands there with a cable in their hand and asks which zone this goes into now.

A concept isn't finished until it has run up against reality once.

### OT network design

*Concepts*

Networks for plants that aren't allowed to stop. The part of the job I started out with.

I started in automation engineering: production networks, switches, redundancy. An office network can drop out for a moment. A production line can't.

So network design in OT is less about bandwidth and more about determinism. How long does a failover take, what happens when a cable breaks, and who notices first, the control room or IT?

In production, availability isn't a goal, it's the precondition.

### Firewall reviews

*Operations*

Reading rule sets that have grown over years and working out what any of it is still needed for.

Firewall rule sets grow by themselves: something is always added and nothing is ever thrown away, because nobody remembers what that rule from eight years ago was once for. And better not to switch it off.

So a review is archaeology in a way. You read the rule set, hold it against the zone concept and then go through the cases where the two don't match. Usually with someone who knows the plant. If all else fails, disable it and see who screams.

### Migrations during production

*Operations*

Firewall migrations and switch changes in the steel industry, with production running.

A steel plant doesn't stand still so IT can rebuild something. So the new firewall had to go in while everything was running: every rule checked, every change with a way back, every switchover in a window set by production, not by us.

The technology is the smaller part of that. The bigger one: sitting down with maintenance, the control room and IT and agreeing what happens when, and who you can call.

### Anomaly detection

*Operations*

A system that reports when something happens in the production network that doesn't belong there.

Anomaly detection in OT sounds like AI and is legwork first: you have to know what normal is before you can measure deviation. In a production network that's doable in theory, because roughly the same thing really does happen there every day.

But how do we know what's allowed to happen? What do we alert on? What is normal?

Talking it through and learning together is everything.

### Product vision and requirements

*Product*

Product management for a firewall management software: defining what it has to do and how that gets sexy.

For a large automation manufacturer I helped develop the vision and requirements for the management software of their industrial firewalls. Across several workshops, all the way to the requirements and design document.

That's the same work as a zone concept, just one floor up: you define how people will work later on. The difference is that a product ships that decision a thousand times over and has to work for more scenarios.

### Sales enablement

*Product*

A concept that lets a sales organisation explain a network management software without selling it.

In practice, sales enablement means the people who talk to customers should understand what a product is good for. And just as much, what it isn't. The second part usually falls by the wayside.

So I didn't build a slide deck, I sorted the cases. Which customer situation, which question, which answer? In plain language and to the point.

### IT/OT convergence training

*Products*

Several training sessions for the sales team of a large automation manufacturer. Two worlds that like to think the other one is the problem.

IT and OT talk about the same plant differently. One worries about patches, the other about keeping the line running. Both are right, and both think the other side is the problem.

So the training was less about technology than about translation. What does a maintenance engineer hear when someone says "patch cycle"? What does an IT manager hear when someone says you can't switch that off?

### Portals, apps, dashboards

*Software*

Client projects in our software company, from the product decision through to monitoring.

Since 2023 I've been building software for clients with my oldest friend: portals, apps, dashboards. We do the whole stretch: product design, feature design, code, operations and monitoring.

That's deliberate. If you also run a piece of software, you design it differently.

### Internal tools and websites

*Software*

Tools only one team uses, and public websites everyone sees.

Programming internal tools is a lot of fun. There's no target group, just actual people who use the tool every day and tell you right away when something doesn't fit. The same goes for websites. They don't just have to look good and work. They have to be usable, too.

### Low-code (Nordcraft)

*Software*

Deeply involved in Nordcraft: in product design, in the code and in the documentation.

With [Nordcraft](https://nordcraft.com), a low-code platform, we didn't just build on it, we helped build it. Product design, code and docs.

Building a platform is the factory case: you're not building the application, you're building the thing other people build their applications with. Every decision gets inherited by everyone, including the bad ones. At platform level, a convenient shortcut is a mistake thousands of people have to live with.

### Open source, EU-sovereign

*Software*

Moved the entire company and tool landscape to open source. Every tool, every server, every AI.

A year ago I moved our whole tool landscape over: every tool, every server, every AI, EU-sovereign. Because I want to know where our customers' data sits.

It's inconvenient, but necessary. You trade comfort for control and quickly notice how many things you take for granted depend on someone else running it for you. Sovereignty isn't just a stance, it's an operational decision with a business impact.

### Talks on industrial security

*Speaking*

Several talks at customer events. Among them "Don't get me started on cyber security" (translated) and "Hack me baby, one more time".

Die Titel sind kein Witz, sondern die These. Wer im Werk steht, hat von Cyber-Security meistens genug gehört, und zwar von Leuten, die noch nie erlebt haben, was ein Produktionsstillstand kostet.

Also fange ich nicht bei der Bedrohungslage an, sondern bei der Anlage. Wenn klar ist, was schiefgehen kann und für wen, redet man über Maßnahmen ganz von allein. Man gewinnt einen Saal nicht mit Zahlen, sondern mit einer Geschichte.

### Vision workshops on security

*Speaking*

A multi-day vision workshop with a sales organisation that ended with a live illustrator having painted one huge picture.

Several days, an entire sales organisation and the question of where the portfolio is actually meant to go. At the end there was a huge picture on the wall that a live illustrator had drawn along the way.

The picture was the result. It made visible what everyone agreed on and, above all, what they didn't. Far more powerful than a slide deck.

### ICS security training

*Speaking*

Workshop on industrial control systems and ICS security at a car manufacturer.

For a car manufacturer I put together a workshop and training concept on ICS security and delivered the sessions. With the people who are responsible for the plant.

## Yes, I spilled something on my shirt. I'll still give you a really good talk.

*How I work*

For me, professionalism has always shown in the work, not in the suit and not in the long words. I talk straight, and I'm human: I make mistakes. I've given more than one talk with goulash on my shirt because I hit the canteen before my slot like a rookie. Went great anyway.

But I'm also the one who thinks the whole thing through again from scratch when it isn't working. You can call me on a Friday evening with something that's still a mess in your head. You can throw unsorted requirements at me. I'll structure it.

## I'm the guy who spends a weekend writing software to plan his week.

*What drives me*

I'd tried everything before that: Excel, Airtable, Notion, Fibery, Trello, Asana, Todoist, Obsidian, Wunderlist, Budibase… and those are just the ones I can think of right now. Nothing fit my week, so I built it myself. Programming was never the goal, always the means. At some point it turned into a second career: since 2023, a small software company with my oldest friend.

I need challenges. Not every day, but consistently. A year ago I moved our entire company and tool landscape to open source. Every tool, every server, every AI, EU-sovereign. Because I want to know where our customers' data sits.

## I can write concepts. That alone doesn't challenge me anymore.

*Where I see myself*

Building a table is boring. Designing a factory that builds tables is exciting. That's the level that challenges me: defining how concepts get written. In definitions and in software.

I'm interested in the places where it's decided how work gets done. Whether that's called architecture, portfolio or strategy doesn't matter to me. I'm sure you've already come up with a cool name for it.

## They're ususally not this nice.

*My friends on me (translated)*

> »What I appreciate about Max is how direct and honest he is. He says it clearly when something doesn't sit right with him, but he's just as open about it when he likes something. You can absolutely rely on him. And the fun doesn't fall short either, ideally over a relaxed beer 😉«
>
> — Franz, Enjoys a beer.

> »Lots of doing, few words, and when there are words, they're clear and direct. Working with Max isn't just fun, it creates clarity. He decides, he speaks up, he structures and, most importantly, he'll tell you when something doesn't fit or is heading in the wrong direction. Either you reject his way of working as unconventional, or — and I can say this from my own experience — you love tinkering away with him on your own goals and results. Max doesn't work, he creates projects and turns visions into reality in his field.«
>
> — Chris, Writes a lot.

> »Max always knows exactly what he wants and keeps his goals firmly in sight. I can come to him any time with whatever is on my mind and ask for advice. He always has an open ear for me. And his taste in music is top notch 🤘«
>
> — Ben, Thinks he has good taste in music.

## CV.

*For the sake of completeness*

- **2018 – today** — Self-employed, Consulting and architecture for IT/OT: zone concepts, industrial security, workshops and talks
- **2018** — Manager Cyber Risk, Deloitte GmbH: industrial cyber security, presales and portfolio responsibility
- **2016 - 2018** — IT Consultant, Computacenter AG: blueprints, migration plans and OT networks
- **2014 - 2016** — Presales Consultant, SIEMENS AG: SCALANCE, network design for production facilities, training for sales and end customers
- **2012 - 2014** — Staatlich geprüfter Industrietechnologe, SIEMENS Technik Akademie: automation engineering with a focus on process data processing.

## Yes, I did those once

Not renewed.

CCNP Routing & Switching · CCNA Routing & Switching · CISSP Associate · Cisco IoT Manufacturing System Engineer · Siemens Certified Professional for Industrial Networks (Switching & Routing, Wireless LAN)

## I like working with …

*Who I like working with*

- Managers who sometimes have oil on their shoes because they went down to the production line to check on something.
- Engineers whose eyes light up when they explain how some niche solution nobody understands made them two percent more effective.
- Team leads who showed up half an hour early so the coffee is ready when the workshop starts.
- Workers who make plenty of mistakes but take something away from every single one.

## Coffee's on me.

*Contact*

Tell me what it's about. I'll get back to you, usually the same day.
