SEC Consult
SEC Consult is an Austrian cybersecurity consultancy, subsidiary of Atos/Eviden, delivering penetration testing, IoT/embedded security, red teaming, incident response, and compliance advisory (NIS2, DORA, ISO 27001) to enterprises in sensitive sectors across DACH.
- Company typePrivate
- Founded2002
- HeadquartersVienna, Austria
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SEC Consult does
SEC Consult is an Austria-headquartered cybersecurity consulting firm founded in 2002 and now operating as a wholly-owned subsidiary of Atos (via the Eviden brand), with primary operations in Vienna and a German subsidiary in Berlin. The firm delivers professional services across four practice areas: Security Testing (web, mobile, cloud, IT infrastructure, SAP, IoT/embedded, and red teaming), Processes & Organisation (Information Security Management, OT security, secure software development, training, and program management), Incident Response (24/7 SEC Defence team), and a Vulnerability Lab that publishes coordinated security advisories and original research. SEC Consult serves enterprise customers in sensitive sectors — government, healthcare, financial services, critical infrastructure, and industrial operators — with named reference clients including Swiss space company Beyond Gravity and physical-security manufacturer dormakaba, where its researchers disclosed 20+ vulnerabilities in the exos 9300 access control system.
The company monetizes through project-based and retainer consulting engagements priced on a quote basis, with no packaged software products, public APIs, or self-serve offerings. Distribution is primarily direct enterprise sales, supplemented by technical content marketing via the website, published advisories, and industry recognition (ranked top 25 European cybersecurity firms in 2026 by atlantsecurity). SEC Consult holds ISO/IEC 27001 certification through both BSI and CREST and has Great Place to Work certifications in Austria and Germany. Tech differentiation rests on the in-house Vulnerability Lab, a dedicated Hardware Laboratory in Vienna, and specialized expertise in embedded systems, OT/SCADA, and physical access control security — areas where generic MSSPs do not field comparable research depth.
SEC Consult firmographics
Firmographics- Name
- SEC Consult
- Legal name
- SEC Consult Unternehmensberatung GmbH
- Website
- https://sec-consult.com
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SEC Consult is an Austrian cybersecurity consultancy, subsidiary of Atos/Eviden, delivering penetration testing, IoT/embedded security, red teaming, incident response, and compliance advisory (NIS2, DORA, ISO 27001) to enterprises in sensitive sectors across DACH.
- Ownership category
- akta.pro rank
SEC Consult industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Management Consulting Services (54161), Other Management Consulting Services (541618), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
- akta.pro secondary industry
- Executive/Board Security Advisory & Risk Briefings (BPAKADAK)
Keywords
Where SEC Consult is headquartered
LocationHeadquarters
- HQ city
- Vienna
- HQ country
- Austria
- HQ region
- Europe
Offices2 records
Markets served
SEC Consult business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Cybersecurity Consulting Services: Professional services revenue from security testing, penetration testing, compliance audits, incident response, and security consulting engagements. Services are typically project-based or retainer engagements with enterprise clients.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
SEC Consult product offering
Product offeringCore offering
SEC Consult is a professional cybersecurity consulting firm delivering security testing, penetration testing, compliance advisory, incident response, and secure software development services for enterprise clients. The firm operates specialized practices for IoT/embedded hardware security, OT/SCADA environments, SAP security, red team adversary simulation, and a 24/7 incident response team (SEC Defence), supported by an in-house Vulnerability Lab that publishes security advisories.
Product overview
SEC Consult is a cybersecurity consulting firm, part of Atos-owned Eviden, offering professional services organized around four practice areas: Security Testing (web, mobile, cloud, infrastructure, IoT/embedded, red teaming), Processes & Organization (ISM, OT security, secure software development, training), Incident Response (SEC Defence), and Vulnerability Lab research. The company is ISO 27001 and CREST certified and does not sell packaged software products. Services are delivered by consultants with accompanying technical reports and advisories.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Application Security Security testing of web applications to identify vulnerabilities such as injection flaws, authentication weaknesses, and misconfigurations. Delivered as an assessment service for enterprise software teams and application owners.
- Penetration Testing Controlled cyber attacks that simulate real-world attack scenarios to identify and exploit security weaknesses in systems and networks. Delivered as a project-based testing engagement for enterprise IT and security teams.
- Mobile Security Security assessment of mobile applications across iOS and Android platforms, including reverse engineering and runtime analysis. Delivered for mobile app developers and enterprise mobility programs.
- Cloud Pentesting Security testing of cloud environments including AWS, Azure, and GCP, covering configuration, IAM, and workload security. Delivered for enterprise cloud and DevSecOps teams.
- IT Infrastructure Security Assessment of network infrastructure, servers, and enterprise systems for security vulnerabilities and configuration weaknesses. Delivered for enterprise IT and security operations teams.
- Security for SAP Services Specialized security testing for SAP environments including ABAP and Java stacks, S/4HANA, and SAP Gateway. Delivered for enterprises running mission-critical SAP landscapes.
- IoT and Embedded Systems Security Hardware and firmware security testing including PCB analysis, debug interface assessment, memory extraction, and protocol analysis for IoT and embedded devices. Delivered for IoT manufacturers, vendors of consumer hardware, and embedded product teams.
- Red Teaming Full-scope adversary simulation combining cyber, physical, and social engineering attack vectors to test organizational security posture. Delivered as a multi-week engagement for enterprise security leadership.
- Information Security Management (ISM) Advisory on establishing and operating information security management systems aligned with ISO 27001 and other standards. Delivered as consulting engagements for CISOs and compliance teams.
- OT Security Security assessments and consulting for operational technology environments including industrial control systems and SCADA. Delivered for industrial operators and critical infrastructure owners.
- Secure Software Development Consulting Advisory on integrating security into software development lifecycles, including threat modeling, secure coding practices, and security testing integration. Delivered for enterprise development organizations.
- SEC Trainings Cybersecurity training programs for technical staff covering topics such as penetration testing, secure coding, and incident response. Delivered as instructor-led courses for enterprise security and development teams.
- Project- and Program Management Advisory on managing cybersecurity projects and programs, including resource planning, risk management, and stakeholder coordination. Delivered for enterprise security program leadership.
- SEC Defence 24/7 incident response and digital forensics service for organizations that have been breached or are experiencing active cyber attacks. Delivered as an emergency response engagement for enterprise clients.
- Vulnerability Lab Internal research team conducting security assessments of consumer and enterprise products, publishing vulnerability advisories, and performing coordinated disclosure. Engaged by enterprises and vendors seeking independent vulnerability research and responsible disclosure support.
Quantifiable outcome
- Over 20 vulnerabilities discovered in dormakaba exos 9300 access control system affecting thousands of customers across Europe
- +1 more outcomes
Companies that use SEC Consult
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
SEC Consult technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
SEC Consult partnerships and signals
Strategic signalScale indicators1 record
Recent moves6 records
Expansion highlights5 records
SEC Consult competitors and assessment
Company assessmentEmerging players
- Bishop Fox: US-based offensive security firm known for high-end penetration testing, red teaming, and security research with continuous published disclosures. Comparable to SEC Consult in research-led brand and offensive security depth, though primarily North America focused and recently pivoting toward product offerings.
- SR Labs (Security Research Labs): Berlin-based security research and consulting firm focused on telecom, IoT, and embedded security with strong research publications. Highly comparable to SEC Consult's IoT/embedded and Vulnerability Lab focus, serving similar European enterprise clients in sensitive sectors.
Direct peers
- NetSPI: Penetration testing and attack surface management firm operating in North America and Europe with enterprise clients in financial services and technology. Comparable in pentest-led service model and enterprise GTM, with overlapping offerings in web, cloud, and infrastructure security testing.
- NVISO Security: European cybersecurity consultancy with offices across Belgium, the Netherlands, Germany, and Austria offering penetration testing, security assessments, and incident response. Directly comparable in DACH footprint, service mix, and enterprise client orientation, often competing head-to-head for the same mid-market and enterprise engagements.
- Cure53: Berlin-based boutique cybersecurity firm specializing in penetration testing, source code audits, and security research with deep technical focus. Highly comparable to SEC Consult's Vulnerability Lab-driven, specialist approach; a direct competitor for high-end European pentesting engagements.
- Kudelski Security: Swiss-headquartered cybersecurity consultancy and managed security services provider with strong DACH and broader European presence. Offers penetration testing, managed detection and response, and compliance advisory directly overlapping SEC Consult's portfolio, and serves similar enterprise clients in sensitive sectors.
- NCC Group: UK-headquartered global cybersecurity consultancy offering penetration testing, managed detection and response, and software resilience services. Closely comparable to SEC Consult in offensive security testing, regulated compliance work (ISO 27001, NIS), and vulnerability research publishing, and operates across Europe with similar enterprise client bases.
Broad incumbents
- Orange Cyberdefense: Cybersecurity services arm of Orange Group providing managed security, consulting, threat intelligence, and incident response across Europe. Comparable as a large-scale European MSSP and consultancy with overlapping penetration testing, GRC, and IR offerings, though much broader in scope than SEC Consult.
- Trustwave: Global cybersecurity firm offering managed security services, penetration testing, database security, and incident response. Comparable in penetration testing and IR capabilities but operates at much larger scale and broader portfolio; competes with SEC Consult for enterprise security testing engagements.
- WithSecure (formerly F-Secure Consulting): Finnish-headquartered cybersecurity firm offering consulting, managed detection and response, and software products across Europe. Comparable in penetration testing, incident response, and compliance advisory offerings, with deeper enterprise SaaS product portfolio than SEC Consult.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
SEC Consult social profiles
Digital presenceSEC Consult compliance and trust
Trust signalCompliance2 records
SEC Consult financial estimates
Financial estimateRevenue estimate
Valuation estimate
SEC Consult leadership team
Management profileNumber of profiles
Profiles9 records
SEC Consult subsidiaries and ownership
Company hierarchySubsidiaries1 record
SEC Consult funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SEC Consult M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SEC Consult
What does SEC Consult do?
SEC Consult is a professional cybersecurity consulting firm delivering security testing, penetration testing, compliance advisory, incident response, and secure software development services for enterprise clients. The firm operates specialized practices for IoT/embedded hardware security, OT/SCADA environments, SAP security, red team adversary simulation, and a 24/7 incident response team (SEC Defence), supported by an in-house Vulnerability Lab that publishes security advisories.
Is SEC Consult a public or private company?
SEC Consult is a private company. It is classified as corporate owned and is currently operating.
When was SEC Consult founded?
SEC Consult was founded in 2002. It employs 11 to 50 people.
Where is SEC Consult based?
SEC Consult is headquartered in Vienna, Austria, in the Europe region.
How does SEC Consult make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are SEC Consult's main competitors?
Emerging players on record are Bishop Fox and SR Labs (Security Research Labs). Direct peers are NetSPI, NVISO Security, Cure53, Kudelski Security and NCC Group. Broad incumbents are Orange Cyberdefense, Trustwave and WithSecure (formerly F-Secure Consulting).
Does SEC Consult have an API?
No public API is recorded for SEC Consult.
What industry is SEC Consult in?
SEC Consult's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory, with a secondary code of BPAKADAK, Executive/Board Security Advisory & Risk Briefings. Its NAICS code is 54161 and its SIC code is 8742.