How ifm masters rising cyberattacks with our Managed SOC Services.
24/7 monitoring that takes pressure off the internal security team, sharpens response times, and strengthens protection across a global corporate group.

The challenge
More signals, more alerts, shorter response windows: like many companies, ifm faces the challenge of an increasingly complex threat landscape. Unlike many companies, though, security has been a high priority at ifm for years – not just in IT, but in its own hardware and software products as well.
To that end, the global company had already built its own internal SOC, bringing information security, IT security, product security, industrial security, and security operations together under the Global Security Services umbrella. Even so, one question remained: could the 24/7 SOC monitoring that had become essential be delivered with in-house resources alone – and sustained over the long term?
“We noticed that attacks were increasing rapidly, and our old processes no longer worked the way we needed them to. Covering 24/7 with our own team alone would have brought a whole new set of challenges.“
Daniel Bitzer, Director Global Security Services, ifm
At the same time, ifm wanted to deploy its internal security expertise where it delivers the most strategic value: product security, AI security, and safeguarding new technologies.
The solution
Against this backdrop, ifm weighed several options: expanding the internal SOC further, adding resources at international locations, or partnering with an external provider. The decision fell deliberately on water – because ifm was looking for a partner who could operate as a technical equal and adapt individually to the requirements of a global company.
“There are plenty of large providers on the market. What mattered to us was finding a flexible partner who understands how security is changing – and who evolves together with us.”
Dietmar Schettgen, Vice President Global Security Services, ifm
During the transition phase, water was granted the necessary access, presented its own processes, and carried out assessments within the ifm environment. Together, the two teams defined communication channels, escalation processes, and documentation requirements.
water didn’t start from scratch. ifm already had Microsoft Sentinel and the full Microsoft Defender suite in place, along with deep security know-how built up through its internal SOC. This strong foundation set the pace: the two teams could move straight into transition, process design, and 24/7 monitoring together.
The result: workshops began in April, and by July water had already taken over monitoring – considerably earlier than originally planned.
“The project was originally planned to take much longer. That water was able to take it over so early is also thanks to the strong commitment of our own team – for us, this is a real flagship project.”
Daniel Bitzer, Director Global Security Services, ifm
water also brought a fresh outside perspective, expanded automation further, and used targeted optimizations to get even more out of the Microsoft security products already in place.


The benefits
Today, ifm benefits from genuine 24/7 coverage – and with it, more security at a time when a fast response is critical. With water, incidents are assessed and filtered around the clock, and only handed over to the internal team where action is truly needed.
“The most important thing is that we’ve made ifm more secure. Today we have true 24/7 coverage – and that was my central goal.“
Dietmar Schettgen, Vice President Global Security Services, ifm
For the internal security team, this brings noticeable relief. Instead of reviewing a large volume of alerts and false positives every day, the team can focus more on strategic topics: product security, IT security architectures, AI security, and new requirements coming from the market.
“With water, only what’s truly relevant reaches our team. That gives us more time to focus on what really matters to us.“
Georgian Nacu, Manager SOC, ifm
This is also reflected in KPIs such as MTTR, which has fallen continuously. At the same time, the bar remains just as high: ifm wants to maintain the security level it has achieved and keep building on it.
With water, ifm has found a partner that is just as agile as ifm itself, responds flexibly to new requirements – and always keeps an eye on the security challenges of tomorrow.

About ifm
The family-owned ifm group has been developing sensors, controllers, software, and systems for industrial automation and digitalization since 1969. With more than 9,100 employees, ifm operates in over 140 countries and connects automation technology with Industry 4.0 solutions – from sensor to ERP.

