Resilient Web Infrastructure for Energy Sector

TEDOM manufactures cogeneration units and provides comprehensive energy solutions. The company operates four production and development facilities in the Czech Republic and nine international branches. Over the past few years, it has grown from a small Czech company into a major global player. However, the growing number of customers exposed the limits of its web infrastructure. The original solution could no longer handle increasing traffic or meet growing security requirements.

After a targeted DDoS attack, improving the protection and stability of web services became critical. MasterDC therefore designed a new infrastructure that meets the security requirements of the Yanmar Group, of which TEDOM is a part, while supporting the company’s continued growth and operational resilience.

Key Outcomes

Deployed Services

When Web Hosting Reaches Its Limits

Companies that outgrow traditional web hosting solutions typically face slowdowns during traffic peaks, outages, or limited scalability and growth opportunities.

In TEDOM’s case, web services gradually became a crucial part of its operations, directly affecting both business continuity and customer services. At the same time, security requirements increased as the energy sector is subject to stricter obligations under the NIS2 directive.

The turning point came with a targeted DDoS attack reaching tens of gigabits per second. Mitigation efforts were unsuccessful, highlighting the need for a more resilient setup. Given that TEDOM delivers independent energy solutions to locations with damaged infrastructure, similar threats had to be expected in the future. Thus, it became necessary to replace the original web hosting environment with a custom-built infrastructure capable of handling higher load and prepared for crisis scenarios.

Challenges We Solved

Challenge

Solution

Security Risks Affecting Web Services

Cyberattacks threatened the availability of TEDOM’s websites, internal systems, and customer services, creating a direct risk to day-to-day operations. At the same time, the existing environment no longer met the group’s security standards or the stricter requirements introduced by the new Act on Cybersecurity and the NIS2 directive.

We deployed the services on MasterDC cloud platform listed in the Czech eGovernment cloud catalog and reinforced the environment with DDoS protection and application-layer security for web services.

Limited Scalability Under Increased Load

The original web hosting environment struggled to keep up with growing traffic and sudden load spikes. During peak periods, important web and customer services slowed down or became unavailable at times when the business depended on them most. The existing setup also made it difficult to plan future growth or respond quickly to changing traffic patterns and DDoS-related situations.

As part of the cloud hosting service, we guarantee availability of at least 99.99%. The platform responds to changing traffic demands in real time, while horizontal and vertical scaling can be performed without disrupting operations. As a result, TEDOM gained a more stable environment capable of handling traffic peaks and extraordinary situations without service outages.

Fragmented Infrastructure and Operational Complexity

The infrastructure consisted of several separate environments without a unified architecture. Coordinating operations across multiple systems slowed down incident response, made change management more difficult, and increased the risk of human error.

Consolidation into a single cloud environment unified the previously fragmented infrastructure into a transparent and manageable platform. MasterDC’s specialized team now manages the infrastructure and its further development, allowing TEDOM’s internal IT team to focus on its core priorities and step in only when changes or new requirements are needed.

Dependence on a Limited Number of IT Specialists

The operation of web services relied heavily on a small group of specialists holding most of the system knowledge. Limited team coverage made it more difficult to handle unexpected situations and introduced additional risks for service availability and security.

By involving the MasterDC team, we expanded operational capacity and improved operational coverage. Clearly defined responsibilities streamlined cooperation between MasterDC, TEDOM, and the application developers. As a result, security measures are implemented more consistently, and the environment is better prepared for future updates and service releases.

TEDOM – Logo

“We appreciate that MasterDC provides a highly professional team with broad operational coverage and reliable 24/7 support. Their ability to handle many aspects of the infrastructure independently has reduced the operational burden on our internal IT team and allowed us to focus more on our own priorities and development activities.”

Martin Pidrman
CIO TEDOM

Migration from Web Hosting to Cloud

1
2
3
4

Defining Scenarios

We defined how the infrastructure should respond to increased load, cyberattacks, and other critical situations. Responsibilities for each phase of the migration were then clearly divided between MasterDC, TEDOM, and web developers.

Migration Coordination

We planned the migration to minimize operational impact on TEDOM and avoid disruptions to the company’s services. Regular status meetings helped coordinate all parties involved and kept the project aligned throughout the migration process.

Building the New Environment

The new environment was built in parallel with the existing infrastructure, allowing all components to be thoroughly tested and the applications to be prepared for a smooth transition.

Transition to Production

After confirming the functionality of the infrastructure and applications, we completed the migration to the new environment within the agreed service window without impacting critical services or requiring involvement from TEDOM’s internal IT team.

New Infrastructure for TEDOM

TEDOM’s web services now run on the MasterDC cloud platform, which meets the strict security standards of Czech eGovernment cloud computing catalogue. The architecture is fully scalable and can respond flexibly to sudden increases in traffic.

Network protection is provided by the RioRey solution, which specializes in DDoS mitigation, while application-layer security is built on a combination of Web Application Firewall and Web Reverse Proxy technologies. Together, these components act as an intelligent filtering layer that allows only legitimate traffic and helps protect application integrity.

Backups run automatically via Nakivo Backup & Replication, with data stored in a geographically separate location for greater resilience.

What TEDOM Value in the Cooperation

Migration with Minimal Downtime

One of TEDOM’s key priorities was to complete the migration with minimal impact on critical systems. A clearly defined scope and phased approach ensured that the transition had virtually no effect on day-to-day operations.

Clear Processes & Communication

“The migration was well managed, and the same applies to change management and operational interventions. We agree on everything in advance, schedule the execution, and can rely on it being delivered on time,” says Martin Pidrman, CIO at TEDOM.

Reduced Burden on Internal IT

Infrastructure management covers daily operations, security implementation, and ongoing development, significantly easing the workload of TEDOM’s internal IT team. Equally important is MasterDC’s 24/7 responsiveness in addressing incidents and security-related issues.

Stable & Secure Infrastructure

“The new solution from MasterDC delivered a more transparent architecture and provides the contractual guarantees we need. The infrastructure can handle peak loads and is ready for further growth, which means everything works as it should and we don’t have to worry about it – and that is the best possible outcome,” concludes Pidrman.

TEDOM – Logo

“The web is one of the most common entry points for attacks. From our experience, without regular maintenance and security testing, it can quickly become a weak point. An outage or compromise of a website typically has a direct impact on the business and the services that depend on it. That is why it was essential for us to have an infrastructure prepared for these scenarios and designed to handle them in a structured and reliable way.”

Martin Pidrman
CIO TEDOM

Looking for a secure solution for your web services?

Connect with our team today to discuss your needs and schedule a meeting.



    Nevidíte vaši vysněnou pozici?

    Pošlete nám životopis, a my se vám ozveme!

      * Povinný údaj
      Zasláním životopisu souhlasím se zpracováním osobních údajů za účelem náboru a výběrového řízení.