“Every day, somewhere in the world, a factory shuts down not because of a mechanical fault, but because of a cyberattack,” explained Maurizio Ghisolfi, head of Mon5 in Luxembourg, during his pitch to the jury. (Photo: EY)

“Every day, somewhere in the world, a factory shuts down not because of a mechanical fault, but because of a cyberattack,” explained Maurizio Ghisolfi, head of Mon5 in Luxembourg, during his pitch to the jury. (Photo: EY)

The Italian start-up Mon5, which has had an office in Luxembourg since the start of the year, won the national final of the Startup World Cup on Thursday evening in Luxembourg, organised by Pegasus Ventures at EY. The start-up, which specialises in industrial cybersecurity, will now represent Luxembourg in San Francisco, where the competition’s global final will be held.

One thing is certain: Luxembourg won’t be winning the Startup World Cup final in San Francisco! Even though the Italian-founded startup, which has been based in Luxembourg since January, won the Luxembourg round of this competition--which offers a million dollars to the overall winner--it deals with the dirty work that industrial sites have to face. Not always very glamorous in a competition of this kind, even when it’s effective.

Not only does the platform presented by Mon5 resemble dozens of other industrial cybersecurity dashboards already available on the market--OT asset mapping, network traffic monitoring, behavioural detection and real-time alerts having become industry standards--but the start-up has not really managed to demonstrate, throughout its pitch, what would set its technology apart from far more established players such as Claroty, Nozomi Networks or Dragos. Apart from the fact that it is lightweight enough for smaller industrial organisations.

Above all, the team has not fully addressed the key issue regarding critical industrial infrastructure: in many factories, power stations or essential networks, the problem is not merely detecting an intrusion, but the operational capacity to correct or patch systems--a process that can take five to seven years, given the heavy constraints of certification, availability and production continuity. Consequently, the promise of real-time detection only solves part of the problem. So what then? Perhaps the mention of Leonardo, the Italian defence giant and a particularly prominent name in the OT world, was enough to make the eyes of the five judges--tasked with deciding between the seven startups in the running on Thursday evening at EY--light up.

Detect it sooner – that’s the promise

“Every day, somewhere in the world, a factory shuts down not because of a mechanical fault, but because of a cyberattack,” explained Maurizio Ghisolfi, head of Mon5 in Luxembourg, during his pitch to the jury. “That factory may produce consumer goods, but it could also be manufacturing components for medical equipment or critical infrastructure. It is no longer just a question of economic losses; it is a question of security.”

Cyberattacks on industrial environments no longer affect only traditional IT systems. They can now bring production lines to a standstill, disrupt critical infrastructure or compromise components used in sensitive sectors such as healthcare or aerospace. This is the field in which Mon5, a young company founded in Italy and now also operating in Luxembourg, aims to establish itself.

The company is developing a cybersecurity platform designed specifically for OT environments – that is, ‘Operational Technology’ – which refers to the industrial systems that directly control machinery, PLCs or production lines. This is a very different world from traditional IT systems, with specific protocols and stringent business continuity requirements.

At the heart of industrial machine protocols

The first step in the solution involves mapping all the connected devices in a factory. “Sometimes, small businesses don’t even know exactly what’s connected to their network,” explained the executive. Once this mapping is complete, Mon5 analyses data flows in real time to detect abnormal behaviour, such as unexpected connections, unauthorised access or unusual communications between machines.

“When something no longer matches the normal behaviour of the equipment, we can send an alert and respond automatically,” explained Maurizio Ghisolfi. The start-up claims, in particular, to have developed its own capabilities for reverse-engineering the industrial protocols used by programmable logic controllers (PLCs) from manufacturers such as Siemens. “Now that we work with the majority of these protocols, we can detect virtually all types of threats,” he assured.

The market is attracting increasing attention from investors and industry players. According to figures presented by Mon5 during its presentation, global spending on cybersecurity exceeded $200bn in 2025, whilst industrial cybersecurity alone accounted for nearly 23% of incidents recorded worldwide.

However, the start-up believes that small and medium-sized enterprises remain largely ill-equipped to deal with cyber threats. “For large corporations, there are already dedicated platforms and in-house teams. For small manufacturers, there was often nothing: no visibility, no security,” summarised Maurizio Ghisolfi. Mon5 claims to have developed a lighter version of its technology for this market segment, at a time when regulatory requirements are also tightening for SMEs.

An annual subscription and a major fundraising campaign

The company operates on an annual subscription model, to which service fees may be added depending on the complexity of the deployments. It already boasts several industrial clients in Italy and elsewhere in Europe, including Leonardo, the Italian defence giant. “Initially, Leonardo was looking for something very specific for its PLCs. They then became very interested in our technical team,” said Maurizio Ghisolfi. “We started with a proof of concept before moving into production.”

Mon5 has announced that it has recently raised €1.7m from Primo Space and industry investors to accelerate its international expansion. The team currently comprises twelve people based in Italy and Luxembourg. Despite the rapid emergence of new artificial intelligence tools capable of accelerating both the detection and creation of cyberattacks, Mon5 believes it still holds a technological lead in the OT sector. “We also use AI to accelerate our R&D,” explained Maurizio Ghisolfi. “But OT remains a very different world from IT, with its own specific protocols. There is still a lot of work to be done.”

When asked about longer-term ambitions, such as a possible sale to a major player in the sector, the CEO preferred to play it safe. “Perhaps one day we’ll give it some thought. But for now, we want to continue growing on our own, as there are huge opportunities in this market.”