Why we are joining the OIXIO Group — and what it means for our customers

Author

Category

Estimated reading time

Some decisions are made based on a situation. Others are made because you can see where things are heading. Ours is the second kind. Since 1 July 2026, erminas GmbH has been part of the OIXIO Group, and from today we operate publicly under that name. In this post I want to explain how it came about, why I believe it is the right step, and what changes for our customers in practice

The starting point: a project no longer begins at the machine

When we started more than 19 years ago, an IIoT project was a reasonably contained affair: get data out of a machine, move it into a system, analyze it, and integrate in processes. Today, a typical conversation with a manufacturing company looks different. It might start with “we know too little about our changeover times” — and twenty minutes later we are discussing network segmentation, who actually secures remote access to the PLC, NIS2, whether the data should sit in Azure or in the customer’s own data centre, and whether the same data could not also feed a company-wide Power BI report

These are all legitimate questions. They belong together. And they reveal a pattern that has intensified over the past few years: the boundary between OT, IT and security has effectively disappeared. Work on one side and you need to understand the others.

For a long time our answer was a partner network. That works — up to a point. Beyond a certain project size, and especially in international roll-outs across multiple plants, coordinating several independent service providers becomes the main project risk. Customers notice. And they increasingly ask for one partner who takes responsibility for the whole picture.

Where the spectrum reaches beyond our core business

Building secure and performant software has always been our standard. erPUB and erTRACE are designed for security, and we actively help customers make their products compliant with the Cyber Resilience Act. What is added today sits one layer below: secure software only delivers its full value on equally secure infrastructure. Hardening networks, managing identities, running a Security Operations Centre, responding to incidents — that is a discipline of its own, with its own specialists and round-the-clock operations.

We could have spent years building that discipline ourselves. It is faster — and considerably better for our customers — to join forces with a house that has been among Europe’s most experienced in exactly that for years.

Why Estonia

We met at Hannover Messe 2025. A trade fair conversation turned into a longer exchange, and that exchange turned into an agreement to join our competences we signed in April 2026 — again at Hannover Messe.

That it turned out to be an Estonian company is no coincidence. Estonia has digitalized its public administration almost completely. It is also the country that experienced one of the first large-scale, state-attributed cyber attacks against an entire nation in 2007, and drew consequences from it. NATO runs its Cooperative Cyber Defence Centre of Excellence in Tallinn. In Estonia and Lithuania, cyber security is not a compliance exercise — it is daily practice under genuine pressure, with public institutions and companies under constant cyber-attacks.

You can buy that level of experience in Germany, but rarely at that concentration. For our customers in industrial mid-market manufacturing, that is a tangible advantage.

Much of what usually raises questions about foreign ownership simply does not arise here. Estonia has been an EU member since 2004, part of the eurozone since 2011, and is in both Schengen and NATO. The same GDPR applies, the same European contract and procurement law, the same currency. Data stays in the EU; third-country transfer is not a topic at all. Practically, Tallinn is a little over two hours’ flight away with a one-hour time difference — the working day overlaps completely, which in international cooperation is worth more than any cost calculation.

The second point is the country’s own level of digitalization. Estonia runs its public administration almost entirely online, the digital signature is legally equivalent to a handwritten one, and a trip to a government office is the exception. It is no accident that the EU chose Tallinn as the seat of eu-LISA — the agency responsible for operating its large-scale IT systems, including the technology behind Schengen. A country that runs its state digitally produces professionals for whom digitalization is not a project topic but everyday practice.

Estonia’s strong technical expertise is built on solid foundations: Estonian students consistently rank among Europe’s top performers in PISA assessments. At the same time, a country of just 1.4 million people has produced a remarkable number of successful technology companies, including Skype, Wise, Pipedrive and Bolt. We see this combination of excellent education and strong technological expertise reflected in our collaboration with our Estonian colleagues

There is also a strong fit on a personal level. Estonians and Northern Germans share a similar temperament: rather reserved and pragmatic, with a direct and reliable approach to working together. Perhaps some of this affinity has historical roots: Tallinn and Tartu were Hanseatic cities with close ties to Northern Germany for centuries. For us, one thing quickly became clear: the match is not only professional, but cultural as well.

Who OIXIO is

The OIXIO Group is headquartered in Tallinn and employs around 300 people across seven offices in Estonia (Tallinn, Tartu), Lithuania (Vilnius, Kaunas) and Germany (Oldenburg, Mönchengladbach), plus staff in further European countries. More than 1,000 active customers are served across four areas:

  • Managed IT Services managed workplace, cloud infrastructure (Microsoft 365, Dynamics 365, Azure), on-premises infrastructure, end-user support
  • Digital — software solutions built on Microsoft: Dynamics 365 F&O and Business Central, Azure, Power BI, Power Apps, Copilot and AI
  • Cyber Security — audits, design and operation of secure infrastructure, user training, SOC operations, ongoing threat reporting
  • Advisory — digital workflows and processes, frequently the starting point of a customer engagement

The group’s guiding idea — We empower businesses with smart digitalization and IT services — matches what we have always done. That mattered more to us than any number in a term sheet.

What erminas becomes within the group

We are the OIXIO Group’s center of excellence for Industrial IoT and custom business applications. That is not a courtesy title. It means our expertise is now available not only to German customers but also to the group’s 1,000+ customers across Europe and beyond — and that erPUB and erTRACE face a considerably larger market than before.

The team stays in Oldenburg. The management stays. The way we work — close to the customer, starting from the business case rather than from the technology — stays as well.

What customers get on top

For existing customers, nothing changes in day-to-day operations: same contacts, same contracts, same terms, same location. What is added is a portfolio that previously sat outside our core business:

  • Cyber security at full breadth — From audit through secure infrastructure design to a 24/7 SOC. For companies in scope of NIS2, or whose products must be CRA-compliant by December 2027, this is no longer optional.
  • Managed IT Services — The infrastructure you run on can be operated by the same people who built the solution. Secure, reliable, and always available.
  • The full Microsoft portfolio — Primarily we were into Azure, Data & AI, Digital & App Innovation und Business Central. Now the other areas of Microsoft technologies, especially infrastructure and security are part of our portfolio.
  • Business intelligence and AI — The production data is already there. The reporting and AI capacity to get more out of it now comes from the group.
  • Advisory — Structured process consulting before the project, not during it.
  • International roll-outs — With teams in many countries and experience in worldwide projects.

Conversely, OIXIO Group customers gain access to Industrial IoT as a new service area, German-speaking support located in Germany, and custom software development for web and mobile.

AI: the real work starts after the experiment

Few topics are used as widely and thought through as rarely as artificial intelligence. Almost every company we speak to now has Copilot licenses, a few ChatGPT and Claude accounts and at least one colleague who has built something impressive. Getting from there to productive use that measurably saves time or money is a different step — and it is not a question of which model you pick. Three things decide it:

  • Does it actually deliver? An assistant that drafts text is pleasant. An assistant that knows three years of fault reports and, when an error occurs, gives the maintenance technician the three most likely causes along with the spare part number changes a process. The difference is not the model but where it sits in the workflow and which data it can reach — and therefore whether that data exists in a usable form at all. That is exactly where our IIoT projects have started for years.
  • Is it integrated, or just another window? AI that requires switching applications stops being used after two weeks. Value appears where it sits inside Business Central, the ticketing system, the shop floor interface or the document process — in the tool that is already open.
  • Is it secure and traceable? Which data leaves the building? Who is allowed to see which answer? Can you reconstruct what an answer was based on? For production, HR and customer data this is not an academic question but an architectural one — and therefore also a question about the infrastructure it all runs on.

That intersection is where the combination pays off. We bring the process and data understanding from manufacturing, and from our business applications work we know where in a workflow a function has to sit for people to actually use it. The group adds the full Microsoft platform — Azure, Power BI, Power Platform, Copilot — the experience from a large number of data and AI projects in the Baltics and beyond, and the governance and security side. Together that is a foundation on which AI moves from experiment to tool.

Part of that is telling customers where AI is currently not the best answer. A cleanly automated process usually beats an AI assistant bridging an unclear responsibility.

The Cyber Resilience Act as a concrete example

One topic illustrates the benefit well. The Cyber Resilience Act applies to every company placing products with digital elements on the EU market — which, in machinery and plant engineering, means practically everyone. Reporting obligations for actively exploited vulnerabilities take effect on 11 September 2026; the full requirements apply from 11 December 2027.

The product side has always been our home ground: secure development, SBOM, vulnerability management, documentation. The second half of the task sits in operations — the processes and infrastructure needed to actually file a report within 24 hours, and the monitoring needed to notice an incident in time. That is what the group brings

Finally

Selling a company you have built over 19 years is not a casual decision. We made it because we are convinced that our customers and our team will benefit — not despite the change, but because of it. The alternative would have been to serve a noticeably wider set of requirements with an unchanged toolbox.

Important for us was to stay on board. Not only erminas but also we are now part of the OIXIO group. Together, we build the future of the group.

If you have questions — about your ongoing project, about the new capabilities, or simply about how all this feels — call us. The number has not changed.

Hilmar Bunjes and Dr. Yvette Teiken Managing Directors, OIXIO erminas GmbH — part of the OIXIO Group

More articles

Published on