Everything on one page
This page holds the same text as the network map, linear and printable.
Attacks run at machine speed, defence at human speed
Detection is well served today. Response, and above all recovery, is not.
View in the networkAn attack goes undetected for 287 days on average. Europe is short of 500,000 security professionals. Those are the familiar numbers, and they describe the time before the alarm.
The expensive time comes after it. The industry has become excellent at detecting attacks. Nobody has solved response, and above all recovery.
In a wiper attack there is nothing to decrypt
The only way back is restoration.
View in the networkWith ransomware there is at least a key. With a wiper there is none. Nothing to negotiate, nothing to decrypt, nobody to pay. The only way back is restoration.
Two cases, both publicly documented:
Both companies had detection. Both had backups. What was missing was the layer in between: a verified, ordered, automatic return to operation.
The plant engineer knows the rule. No product does
In OT the decisive knowledge sits in people's heads, not in systems.
View in the networkIn IT you can shut a compromised system down if you have to. In production you cannot. Which asset may be isolated, which must never be, and in what order things have to come back up so that nothing breaks: the plant engineer knows.
That knowledge is rarely documented and never machine-readable. Which is exactly why restoration stays manual work, under time pressure, with unclear backup quality.
“The attack was detected hours ago. But how do I get our production systems back online? That’s the part nobody helps me with.”
Illustrative system-administrator persona from our user research. Not a customer quote.
Regulation and downtime cost drive this at the same time
Two independent reasons to act now.
View in the networkOn top of that come the CRA, the EU Machinery Regulation and the AI Act, which apply from 2027. All of them demand the same thing: demonstrable transparency and demonstrable effectiveness.
The obligation comes from the legislator, the pressure from the balance sheet. Both point the same way.
Mycelia occupies the recovery layer
The autonomous, risk-based return of compromised IT and OT systems to a verifiably safe operating state.
View in the networkThe platform carries the incident autonomously from detection through to restoration. The IT team stays supervisor rather than fire brigade.
Three capabilities that no vendor bundles today:
- Clean before fast. We only restore once the state is demonstrably clean.
- Order, not chaos. Systems come back up in correct dependency order.
- A network that heals itself. A clean node brings an affected neighbour back.
Every autonomous action stays inside normative guard rails (ISO 27001, IEC 62443, ISO 42001) and is auditable.
Clean before fast
Restoring quickly is worthless if you restore the infection with it.
View in the networkThe fastest way back is worthless if it brings the infection along. The most expensive surprise during a restoration is usually not the missing backup, it is the compromised one.
Mycelia only restores once the restoration state is demonstrably clean, and refuses infected backups.
How that is verified is not something we describe publicly. This mechanism is the subject of ongoing IP work.Order, not chaos
Bringing one system up in the wrong order takes two others down with it.
View in the networkSystems come back up in correct dependency order: from identity through core services to applications and endpoints.
“I brought the restored server back online, and it took down two other services because the network wasn’t ready.”
Illustrative network-administrator persona from our user research. Not a customer quote.
This is not an edge case. In the interviews we ran, restart orchestration was one of the two largest pain points, right beside backup integrity.
A network that heals itself
A clean node brings an affected neighbour back. Even when the centre is gone.
View in the networkA clean node brings an affected neighbour back, autonomously, even when the link to the centre has failed.
This is the point where the name stops being a metaphor and starts describing the architecture. Anyone running a fleet of sites has exactly one problem after a major incident: too few people for too many plants. A network in which the healthy part recovers the sick part is what scales there.
Hence the name: heal one, heal all.
A closed, auditable decision cycle
Local agents at the plant, a platform above them, swappable models.
View in the networkMycelia has two parts. AI agents run at the plant, inside the respective network segment. Above them sits a platform that correlates between agents, keeps the audit trail and reports.
The decision engine combines language models with retrieval-augmented generation. The models are swappable, commercial or open source, local or cloud. No model lock-in.
Observe, understand, assess, decide, act, learn
A patent application on this method is under examination at the DPMA.
View in the networkSix steps that run as a circle, not as a chain:
Observe → Understand → Assess → Decide → Act → Learn → back to Observe.
The last step is the one playbooks do not have. What was learned in one incident changes how the next one is assessed.
Every step runs inside normative, auditable guard rails. A patent application on this method is under examination at the DPMA.
Modular skills act where they are needed
From the PLC to the client, from Modbus to the hypervisor.
View in the networkWhat the platform actually does:
- Isolate a segment
- VM snapshot and rollback
- Restart from a verified state
- C2 sinkhole
- Lock credentials, after approval
- Audit trail and NIS2 report
Depth covered: from PLC and Modbus via OPC UA and MES through to hypervisor, containers, firewall and client.
Not every one of these actions may go equally far. What runs fully autonomously and what needs an approval is not our decision, it is yours.
No data leaves the site
Local agents, local models, on-premises or hybrid operation.
View in the networkAI agents run locally in the network segment, trained on two to four weeks of normal operation of that specific plant. They therefore know their plant’s normal behaviour, its permitted communication and its critical assets.
No data leaves the site. On-premises or hybrid operation.
For European critical infrastructure this point is not negotiable, and it is also why the models have to be swappable: if you sell data sovereignty, you cannot delegate it to a single vendor.
We integrate established building blocks
Backup vault, identity recovery and imaging are solved problems.
View in the networkBackup vault, identity recovery and imaging are solved problems. Good products exist, and in most target environments they are already in place.
So we integrate established building blocks rather than rebuilding them. What is missing, and what we build, is the layer above: deciding which state is clean, in what order things come back, and how far the system may go on its own while doing it.
For integrators that means no rip and replace, but a layer on top of the estate you already look after at your customers.
Autonomy with demonstrable limits
Autonomy without demonstrable limits cannot be sold into critical infrastructure.
View in the networkThe most common objection to autonomous response is not “that doesn’t work”. It is “I will not allow that in my plant”. That is the right objection.
Our answer is not “trust us”. Our answer is a dial you operate yourself, and a record with which you can afterwards show what happened and why.
Law, standards and threat knowledge in one layer
A machine-readable layer brings law, standards and threat knowledge together.
View in the networkBeneath the platform sits a machine-readable governance layer. It brings together:
- Law: NIS2, CRA, AI Act
- Standards: ISO 27001, IEC 62443, ISO 42001
- Threat knowledge: MITRE ATT&CK for IT and ICS
From these it derives a traceable autonomy ceiling for each action: from fully autonomous, through approval by a human, to explicitly never autonomous.
A firewall block runs fully autonomously. Handing a controller back to a running process never does.
That is useful twice over. Every autonomous decision can be justified to an auditor, and the compliance evidence is produced in operation rather than in a consulting project.
Because standards age, this layer is designed as a versioned, living artefact.
Four levels, set per measure
The level does not apply to the whole system. It applies to each individual measure.
View in the networkThe important part: the level does not apply to the whole system, it applies per measure. And you start cautiously and only move up a level once you have seen what the system does.
No pause when blocking. A pause when restoring.
Containment stops damage and is reversible. Typical level: HOTL or FULL.
Restoration intervenes in running operations. Here the responsible person wants to be asked. Typical level: HITL.
Everything else: what is not on the approval list is not executed. The system can only do what you have approved.
Every incident leaves a chain
Detected, decided, acted, taken effect, restored.
View in the networkEvery step timestamped, every decision with a reason. The chain cannot be altered after the fact, and it can be exported for the report to the competent authority.
The practical difference is one of timing. Normally compliance evidence is produced afterwards, in a consulting project, from reconstructed logs. Here it is produced in operation, as a by-product of acting.
To an auditor that is the difference between a claim and a record.
And who protects Mycelia?
A system allowed to intervene autonomously is a worthwhile target. That is not a footnote.
View in the networkA system that may isolate segments and reset machines is worth more to an attacker than the machines themselves. Anyone who does not raise this has not thought about it.
- An approval list before every action. What is not approved is not possible. Not “is blocked”, but does not exist for the system.
- Your organisation sets the limits, not the vendor.
- It runs in your house. No cloud, no data egress.
- On uncertainty the system hands over to the human. That is the normal case, not the exception.
- Every action is reconstructable, including the system’s own.
What we measured, and what we have not
Lab results, not a customer pilot. We say where the boundary is.
View in the networkSecurity marketing tends to make lab numbers sound like operational numbers. We do not do that here, because the people we want as customers know the difference.
What follows was measured in the lab. What is missing is stated alongside it.
2,261 autonomous tests on real hardware
In the Fraunhofer IPA industrial OT lab.
View in the networkIn all tested scenarios the detected threat was contained autonomously and without human intervention.
What this figure applies to. The 7.5 minutes is a mean time to recover for delimited single incidents in the lab, such as port scans and detected malware. It is not a fleet-recovery figure, and we do not extrapolate it into a speed-up multiplier.
Peer-reviewed publications, patent application under examination
Independently reviewed rather than self-asserted.
View in the network- Peer-reviewed at ECAI 2025 and as a paper in wt Werkstattstechnik online
- Patent application at the DPMA on the autonomous decision cycle, under examination
- Three signed letters of intent from critical infrastructure, Industry 4.0 and IT engineering
We do not name the three partners publicly while we do not have their clearance to do so.
Validated demonstrator at TRL 3
The next step is a pilot-tested functional prototype at TRL 5.
View in the networkA Fraunhofer IPA spin-off project, currently in the AHEAD Deeptech Incubator.
What is missing is operation at a pilot customer. That is what we are looking for partners for.
If you run a converged IT/OT environment and want to know how long your production would really stand still after a wiper attack, that is the point where a conversation is worth something to both sides.
Market and business model
No established product returns compromised IT and OT systems autonomously and demonstrably in line with standards.
View in the networkNo established product returns compromised IT and OT systems autonomously, and demonstrably in line with standards, to a safe target state. That is precisely the layer Mycelia occupies.
Five things make it defensible:
- Recovery autonomy: restoration as a product function, not rework after the alarm
- Standards-based decision logic: every action traceable to ISO and IEC controls
- OT-native: response down to the control level, with explicit approval
- Data sovereignty: local models, the data stays in the plant
- Scientifically validated: lab validation, peer-reviewed publication, patent application under examination
Regulated industrial companies with converged IT/OT
The personas are CISOs and system and network administrators.
View in the networkFour segments:
- Manufacturing and automotive
- Pharma and chemicals
- Energy and utilities
- Public administration and critical-infrastructure IT
The personas are CISOs and system and network administrators.
“We detected the attack in minutes. But it took us four days to recover. That’s what cost millions.”
Illustrative CISO persona from our user research. Not a customer quote.
Market potential 2030
Our own estimate, based on market analyses.
View in the networkThe window is opened by regulation, not by technology. NIS2 is in force; the CRA and the AI Act apply from 2027. Those who have to comply are looking now.
Subscription with feature-based scaling
A three-tier subscription. Autonomous recovery is the core.
View in the networkLicensed autonomous response and recovery modules, integrated into existing plants. A subscription with feature-based scaling in three tiers: autonomous recovery is the core, compliance and governance modules are the value-determining tiers. That carries from the upper Mittelstand to the large enterprise.
We scale through reusable decision logic rather than through data, with no lock-in on the AI model.
Go-to-market in three stages: first three to five lighthouse pilots through the Fraunhofer network, then scaling through OT integrators and MSSPs, and long term insurers and certification as the moat.
What partners bring and what we deliver
Entry is always through a joint pilot customer.
View in the networkPartners bring: customer access, sector and integration expertise, and sales.
Mycelia delivers: technology and IP, scientific validation, presales, training and level-3 support.
Entry is always through a joint pilot customer, proof of value, then a framework agreement.
We deliberately do not rebuild the layers you already look after at your customers. Backup, identity recovery and imaging are integrated. See Integrate, don’t rebuild.
Audit, OT security and AI architecture in one team
The combination is rare, and it is why we can build this layer.
View in the networkStandards-based decision logic can only be built by people who know both sides: the audit practice that decides what is demonstrable, and the systems architecture that decides what is automatable.
This team came together on exactly that seam.
The founders
Two founders, a lead developer, a legal mentor.
View in the networkMax Geyer, CEO, is responsible for cyber defence and compliance: around ten years of professional experience, five of them as a certified auditor, Fraunhofer IPA, PhD candidate at the University of Stuttgart. Deep expertise in ISO 27001, IEC 62443 and ISO 42001 and in the auditable implementation of regulatory requirements, plus entrepreneurial practice as an independent auditor.
Jannik Schwab, CTO, is responsible for the platform and autonomous systems design: nine years developing AI-based software and systems architectures, Fraunhofer IPA, plus industry experience and experience in building companies.
Florian Strohm, co-founder and lead developer: doctorate in computer science from the University of Stuttgart, Fraunhofer IPA, focused on machine learning and human-AI interaction, complemented by industry experience in software development.
A legal mentor supports contract, IP and strategy questions.
Where we come from
The measurements come from the institute's industrial OT lab.
View in the networkMycelia is a Fraunhofer IPA spin-off project and is currently in the AHEAD Deeptech Incubator.
For this layer that is more than a line of provenance. Autonomous response in a production plant cannot be validated at a desk. The 2,261 tests ran in the institute’s industrial OT lab, on real hardware.
Note: this site is operated privately by the founders. It is not an offering of the Fraunhofer-Gesellschaft. See [legal notice](/en/legal-notice/).One role is still missing
We have the engineering and the standards. What we lack is the commercial side.
View in the networkWe say this openly, because it is obvious anyway: nobody on this team does sales for a living. For a product with a six-to-eighteen-month sales cycle into regulated industry, that is the biggest gap we have.
Wanted: a co-founding commercial role. Business model, first customers, investor conversations. Ideally with experience selling technically demanding products into industry or the public sector.
Also of interest: engineers who want to work on autonomous systems and OT protocols.
Honest about the stage: we are pre-incorporation, at the institute, with a funding path. That is a different entry than joining a funded company, with different risk and different room to shape things.
The market sounds like war. We build the opposite
Our name does not sell an enemy. It stands for life.
View in the networkThreat, attack, kill chain. Dark pages, red alerts, hooded figures. Cyber security’s visual language has been selling fear for twenty years, and selling it well.
We build the opposite: systems that heal themselves. A brand that sells fear cannot carry a product whose entire point is composure.
That is why this page is light.
Mycelia: three layers, one word
A single fungal network, kilometres across, invisible underground, keeping an entire forest alive.
View in the networkFirst, the fungus. The largest living organism on earth is a fungus: a single fungal network, kilometres across, thousands of years old, invisible underground, keeping an entire forest alive. Mycelia is the mycelium itself, the network beneath the forest.
Second, one helps all. The trees are connected through that network. What happens to one does not stay with it.
Third, network and life. Mycel and Zelle, the German for cell, share the same letters: cel. A living network of living cells.
In the architecture that means something concrete: a clean node brings an affected neighbour back. See A network that heals itself.
Heal one, heal all.
Prevention fails. Recovery doesn't
The question is no longer whether a system gets compromised, but how it behaves when it does.
View in the networkAttacks happen, mistakes happen, the unexpected happens. Quality shows in how a system deals with it.
Prevention-first security no longer scales. In complex systems resilience matters more than perfection. The question is no longer whether a system gets compromised, but how it behaves when it does.
Attacks happen. Downtime is optional.
Cut it. It grows back.
Recovery is not an afterthought. It is a design principle.
BUILT TO RECOVER.
Looking for a pilot site and partners
The entry point is deliberately small: a joint workshop on your real recovery pain points.
View in the networkWe are looking for partners who will walk the road from a pilot site to industrial readiness with us: pilot users with converged IT/OT, CISO contacts in regulated industry, and investors with industrial cyber experience.
The entry point is deliberately small: a joint workshop on your real recovery pain points, then a letter of intent and a trial at one plant.
jannik.schwab@mycelia-security.de
Start a conversation
If you want to know, let's talk about it.
View in the networkThe entry point is a workshop, not a sales pitch. We walk through where your restoration gets stuck today, and you get to see whether we understand the problem.
Or directly to jannik.schwab@mycelia-security.de
Discuss the partner model
For OT integrators and MSSPs. Entry through a joint pilot customer.
View in the networkYou bring customer access, sector and integration expertise. We bring technology, IP, validation, presales, training and level-3 support.
Or directly to jannik.schwab@mycelia-security.de
Contact for investors
For investors with experience in industrial cyber or OT.
View in the networkWe talk to investors who know industrial cyber or OT. Specific funding figures are something we discuss in conversation, not on this page.
Or directly to jannik.schwab@mycelia-security.de
Co-found
Above all for the commercial role we are missing.
View in the networkNo form, no application process. Write and tell us what interests you about this.
Or directly to jannik.schwab@mycelia-security.de
Legal notice
Information pursuant to § 5 DDG (German Digital Services Act).
View in the networkService provider
Jannik Schwab
Pfaffenweg 5b
70180 Stuttgart
Germany
Contact
Email: jannik.schwab@mycelia-security.de
Responsible for content
Jannik Schwab
Pfaffenweg 5b
70180 Stuttgart
Note on the relationship with Fraunhofer IPA
Mycelia is a spin-off project of the Fraunhofer Institute for Manufacturing Engineering and Automation IPA. This website is a private offering by the founders and is not an offering of the Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V.
Liability for content and links
As a service provider we are responsible for our own content on these pages under general law. The respective provider is responsible for the content of external links. At the time of linking, no legal violations were apparent.
Privacy notice
This site sets no cookies, embeds nothing from third parties and measures no visits.
View in the networkController
Jannik Schwab
Pfaffenweg 5b
70180 Stuttgart
Germany
What this site does not do
- No cookies. We set no cookies, not even strictly necessary ones.
- No analytics. No analytics tool is embedded, neither Google Analytics nor Matomo nor any other.
- No external embeds. Fonts, images and scripts are served from this server. There is no call to a content delivery network, no Google Fonts, no embedded videos, no social media plugins.
- No contact form. Contact runs through your own email client.
Local storage in your browser
The site remembers in your browser which nodes you have already opened, whether you
prefer the linear view and whether you have turned motion off. This information stays
exclusively in your browser (localStorage and sessionStorage), is never
transmitted, and is not visible to us. It is strictly necessary within the meaning of
§ 25(2) TDDDG and therefore does not require consent. You can delete it at any time via
your browser’s site data.
Server log data
This website is hosted by Webgeyer. The server is located in the European Union.
When a page is requested, the server automatically records the usual access data: IP address, date and time of the request, the file requested, the amount of data transferred, whether the request succeeded, and the requesting software. This data is required in order to deliver the site and to keep it running securely. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website.
Log data is deleted after seven days at the latest and is not combined with any other data.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority.
Accessibility statement
This site is designed as a spatial map. That is why it also exists as a linear document.
View in the networkTarget status
We aim for conformance with WCAG 2.1 level AA and EN 301 549.
What we have implemented
- The entire site is fully readable without JavaScript. Every node is its own document with complete text.
- The linear view presents all content as one continuous, printable document. It is reachable from every page.
- The map’s nodes are real links in a nested list. Tab order follows the editorial structure, not the arrangement on screen.
- Reduced motion is respected (
prefers-reduced-motion), and there is a visible toggle in addition. - Body text is set throughout at a colour contrast of at least 4.5:1.
Known limitations
- The map view relies on space and movement. The complete, equivalent alternative is the linear view.
- What has been checked so far is the accessibility tree, not how it sounds. Roles, names, states, focus handling and order were tested against the assurances above and hold: the skip link is the first tab stop, the map is a nested list of 39 real links in editorial order, the open node reports itself as the current page, focus moves to the heading after navigating and the page change is announced, the overview map is a single tab stop when closed and returns focus after Escape, and the search field walks its results as a combobox. The manual check with an actual screen reader is still outstanding.
Feedback
If you notice a barrier, please write to us: jannik.schwab@mycelia-security.de