VEO launches VEOCyber: vulnerability monitoring for critical systems
21.09.2026VEO’s new service keeps energy and automation operators informed of cybersecurity risks in their systems, without the need for network-connected sensors or manual monitoring.

”Cybersecurity risks in automation and energy systems are growing faster than any team can manage manually. With VEOCyber, we take that responsibility off our customers’ shoulders,” says Olav Lundström, Service Manager at VEO.
Daily watch, proactive response
Manually tracking vulnerabilities across hundreds of components is no longer feasible. VEOCyber does it automatically. At the core of the service is a complete inventory of hardware and software installed at customers’ facilities. VEOCyber cross-references all components daily against internationally recognised and trusted vulnertability sources. When new vulnerabilities are published, the service immediately identifies which components are affected and prioritises them by severity. If a critical risk is found, VEO contacts the customer directly and recommends action.
VEO can test patches and updates in a sandbox environment before deployment in customers’ systems. A full audit trail records all vulnerabilities, actions taken and system changes – providing the traceability that regulations such as NIS2 increasingly demand from operators in critical sectors.
”NIS2 has moved cybersecurity documentation from a nice-to-have to a requirement. VEOCyber’s audit trail is built with exactly that in mind,” Lundström explains.

Offline approach reduces risk
What sets VEOCyber apart from competing solutions is its offline approach. With no network-connected sensors required, the service minimises external connectivity and reduces the attack surface, a significant advantage in environments where security cannot be compromised.
”Most cybersecurity solutions require continuous network connectivity, which in itself introduces risk. Our approach is different: we deliver the same level of protection without adding unnecessary exposure,” says Lundström.
The offline approach relies on close cooperation to keep the service effective. To maintain full coverage, customers are asked to notify VEO of any changes to their systems, such as component replacements or firmware updates carried out independently. This ensures the inventory remains accurate and that no vulnerabilities go undetected.
Built for critical operational environments
VEOCyber is especially relevant for critical infrastructure and industrial environments where cybersecurity and operational continuity are essential, and where disruptions can have significant operational, financial, or safety-related consequences.
”VEOCyber is a natural extension of what we already do for our customers. We build their systems, we maintain them, and now we also help keep them secure,” Lundström concludes.
The service is included for customers with a service agreement and available as a standalone service for others, and can also be extended to systems and components supplied by other vendors.
For more information on VEOCyber, contact:



