Security Research Labs
SRLabs is a Berlin-based cybersecurity consultancy delivering offensive testing, defensive engineering, and strategic advisory services to enterprise clients in telecommunications, financial services, and technology, with proprietary open-source fuzzing tools and offices in Berlin and Hong Kong as part of the Allurity Group.
- Company typePrivate
- Founded2018
- HeadquartersBerlin, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Security Research Labs does
Security Research Labs (SRLabs) is a Berlin-based cybersecurity consultancy operating in offensive security testing, defensive engineering, and strategic advisory for enterprise clients. The firm's service portfolio spans Red Teaming (adversary emulation, TIBER/DORA TLPTs, Purple Teaming), Telco Security (SS7/Diameter, SIM/SMS, RAN, IMS/RCS/VoLTE), Device Testing (IoT, smartphones, automotive, industrial firmware), Software Assurance (fuzzing-powered code audits with AFL++, Honggfuzz, libAFL, and proprietary tools CosmFuzz, Ziggy, and GoLibAFL), Incident Response (24/7 across DE/UK/CH/SE/DK), Vulnerability Prioritization, Security Team Incubation, and Security Maturity Reviews. Customer segments are primarily large enterprises in telecommunications, financial services, and technology, with named engagements including major telcos in Japan, India, and Germany, a Malaysian financial group scaled from 40 to 80 security experts, and lead-auditor work for the Polkadot blockchain ecosystem since 2019 yielding over 1,000 identified security issues.
SRLabs generates revenue through professional services engagements with custom scoping and direct consulting sales; there is no productized or self-serve offering, and pricing is not publicly disclosed. The firm sells primarily through thought leadership (research blog, BlackHat/DEF CON presentations, DEF CON CTF participation) and direct enterprise outreach via [email protected]. The go-to-market is sales-led and consultative, targeting enterprise CISOs and security leadership in telecom, financial services, and technology. A notable internal innovation is the integration of generative AI tooling (GitHub Copilot via OpenRouter backend, Deepwiki repository summaries, an internal SRLabs AI server for closed-source confidentiality) into the code audit workflow at three levels: repository summary, code insights, and QA second reviewer, with public acknowledgment that ~80% of AI findings require human verification.
SRLabs is a member of the Allurity Group, a pan-European cybersecurity conglomerate comprising 12 companies, 42 offices in 18 countries, and approximately 780 security experts. The company maintains direct offices in Berlin (Revaler Strasse 29, 10245 Berlin) and Hong Kong (Room 605, Tai Tung Building, Wan Chai). Legal entity is SR Security Research Labs GmbH (HRB 128449 B, Berlin-Charlottenburg), with a separate APAC entity Security Research Partners Ltd. Managing directors are Dr. Wolf Richter, Dr. Karsten Nohl, Frida Westerberg, and Åsa Agerman. No venture or growth equity funding rounds have been disclosed; the firm operates as an organic, profitable consultancy under the Allurity umbrella.
Security Research Labs firmographics
Firmographics- Name
- Security Research Labs
- Legal name
- SR Security Research Labs GmbH
- Website
- https://srlabs.de
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SRLabs is a Berlin-based cybersecurity consultancy delivering offensive testing, defensive engineering, and strategic advisory services to enterprise clients in telecommunications, financial services, and technology, with proprietary open-source fuzzing tools and offices in Berlin and Hong Kong as part of the Allurity Group.
- Ownership category
- akta.pro rank
Security Research Labs industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Other Scientific and Technical Consulting Services (54169), Other Computer Related Services (541519), Testing Laboratories and Services (541380)
- SIC
- Services-Engineering Services (8711), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE), Vulnerability Assessment & Scanning (HDADAHAA), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
Keywords
Where Security Research Labs is headquartered
LocationHeadquarters
- HQ city
- Berlin
- HQ country
- Germany
- HQ region
- Europe
Offices2 records
Markets served
Security Research Labs business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Cybersecurity Consulting Services: Professional services revenue generated through security consulting engagements including red teaming, device testing, software assurance, vulnerability prioritization, incident response, security maturity reviews, and security team incubation.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Security Research Labs product offering
Product offeringCore offering
Security Research Labs is a Berlin-based cybersecurity consultancy delivering offensive security, defensive security, and strategic advisory services to enterprise clients. Core offerings include red teaming (adversary emulation, TIBER/DORA TLPTs), telco security (SS7/Diameter/RAN pentesting), device testing (IoT, automotive, smartphones), software assurance (fuzzing-powered code audits), 24/7 incident response, vulnerability prioritization, security team incubation, and security maturity reviews.
Product overview
Security Research Labs (SRLabs) is a cybersecurity consultancy offering a portfolio of offensive security, defensive security, and strategic advisory services. The core offensive offerings include Red Teaming (adversary emulation, TIBER/DORA TLPTs, Purple Teaming), Telco Security (mobile network penetration testing, SS7/Diameter, RAN), and Device Testing (IoT, smartphones, automotive firmware analysis). Defensive services encompass Software Assurance (fuzzing-powered code audits), Incident Response (24/7 crisis support), and Vulnerability Prioritization (data aggregation and remediation support). Advisory services include Security Team Incubation and Security Maturity Review. The company also conducts security research published on their blog and develops open-source fuzzing tools including CosmFuzz, GoLibAFL, and Ziggy. SRLabs is part of the Allurity Group with offices in Berlin and Hong Kong.
Differentiator
Problem solved
Functional benefit
Products and services
- Red Teaming End-to-end attack simulations validating enterprise security controls, including adversary emulation, TIBER exercises, DORA-mandated TLPTs, Purple Teaming, and Active Directory reviews. Targeted at enterprise security teams.
- Telco Security Mobile network security services including exposure scans, SS7/Diameter pentesting, SIM/SMS security tests, RAN security checks, IMS/RCS/VoLTE security tests, and telco platform penetration testing. Targeted at mobile network operators and telecom companies.
- Device Testing Holistic hardware security testing covering IoT/Consumer devices, routers, smartphones, wearables, automotive, and industrial/medical devices with threat modeling, firmware analysis, reverse engineering, and vulnerability exploitation. Targeted at device manufacturers and OEMs.
- Software Assurance Attacker-minded code audits combining threat modeling, manual 4-eyes code review, coverage-guided fuzzing (AFL++, Honggfuzz, libAFL, Ziggy), invariant testing, and CI integration for SDLC security. Targeted at software companies and protocol developers.
- Incident Response 24/7 hacking incident support with forensic investigation, incident management, and long-term resilience building. Available across Germany, UK, Switzerland, Sweden, and Denmark. Targeted at enterprises facing active security breaches.
- Vulnerability Prioritization Vulnerability data aggregation and filtering from sources like Nessus, Qualys, and Netsparker, with root cause clustering and remediation support via autobahn.security. Targeted at enterprises overwhelmed by vulnerability noise.
- Security Team Incubation Building entire security teams from scratch for new large-scale ventures, including team ramp-up, interim operations, hands-on training, and phase-out support. Targeted at large enterprises and new telecom ventures.
- Security Maturity Review Organizational and technical security maturity assessment covering scoped testing, holistic security review, root cause mapping, and strategic security roadmap development. Targeted at enterprise CISOs and security leadership.
Quantifiable outcome
- Over 1,000 security issues uncovered as lead auditors for Polkadot blockchain ecosystem since 2019
- +2 more outcomes
Companies that use Security Research Labs
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
Security Research Labs technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability4 records
Feature3 records
Security Research Labs partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- Allurity GroupcoreSRLabs is a member of the Allurity family, a pan-European group of trusted cybersecurity services companies. Allurity comprises 12 companies with 42 offices in 18 countries and 780+ security experts. The group enables SRLabs to offer unparalleled expertise across Europe while maintaining its independent brand and research focus.
- CSISminorSister company within Allurity Group offering complementary cybersecurity services. Together with SRLabs and Securix, CSIS provides unparalleled immediate assistance with hacking incidents around the clock.
- SecurixminorSister company within Allurity Group. Together with CSIS and SRLabs, forms a coordinated incident response network providing 24/7 emergency support across Europe.
- ILIAS eLearningminorVendor relationship where SRLabs conducted security research discovering vulnerabilities in ILIAS learning management system (CVE-2025-11344, CVE-2025-11345, CVE-2025-11346). Vulnerabilities were disclosed through responsible disclosure process and patches were released.
Scale indicators5 records
Recent moves8 records
Expansion highlights5 records
Security Research Labs competitors and assessment
Company assessmentDirect peers
- Cure53: Berlin-based boutique security research firm offering penetration testing, code audits, and vulnerability research with a similar researcher-driven brand and small expert team — the closest direct competitor in the German-speaking market.
- Trail of Bits: US-based security research firm focused on software assurance, fuzzing, and blockchain audits — the closest analogue to SRLabs' software assurance and Polkadot/Web3 audit practice, with similar open-source tooling DNA.
- NVISO Security: European cybersecurity consultancy delivering red teaming, threat-led penetration testing, and security advisory across regulated industries — directly comparable boutique competitor with similar TIBER/DORA positioning.
- Pen Test Partners: UK-based penetration testing firm with strong IoT, hardware, and telecommunications security practices — comparable to SRLabs' Device Testing and Telco Security services in scope and boutique scale.
- Bishop Fox: US-based offensive security firm combining research-led services (red teaming, application testing) with published research and open-source tools — a strong analogue for SRLabs' research-driven consulting model.
- OpenZeppelin: Blockchain security firm offering smart contract audits, security tooling, and ongoing monitoring for Web3 protocols — directly comparable to SRLabs' Polkadot/CosmWasm audit practice and a key competitor for Web3 security budgets.
Broad incumbents
- NCC Group: UK-listed global cybersecurity consultancy delivering red teaming, managed detection, software assurance, and telecom security — overlaps broadly with SRLabs' portfolio but at materially greater scale and geographic reach.
- SEC Consult: European cybersecurity consultancy with a comparable mix of penetration testing, secure code review, incident response, and IoT/telco assessments — competes head-to-head for enterprise security testing work in DACH and wider EMEA.
- Kudelski Security: Swiss-headquartered cybersecurity division of the Kudelski Group offering managed security, incident response, and advisory — comparable DACH/EMEA incumbent with broader managed services portfolio.
- TÜV Rheinland (Cybersecurity Services): Global testing, inspection, and certification body with a cybersecurity and IoT device assessment practice — competes for device testing and certification-driven security assessments in Europe, particularly with regulated buyers.
Market position
Strengths5 records
Weaknesses2 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
Security Research Labs social profiles
Digital presenceSecurity Research Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
Security Research Labs leadership team
Management profileNumber of profiles
Profiles19 records
Security Research Labs funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Security Research Labs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Security Research Labs
What does Security Research Labs do?
Security Research Labs is a Berlin-based cybersecurity consultancy delivering offensive security, defensive security, and strategic advisory services to enterprise clients. Core offerings include red teaming (adversary emulation, TIBER/DORA TLPTs), telco security (SS7/Diameter/RAN pentesting), device testing (IoT, automotive, smartphones), software assurance (fuzzing-powered code audits), 24/7 incident response, vulnerability prioritization, security team incubation, and security maturity reviews.
Is Security Research Labs a public or private company?
Security Research Labs is a private company. It is classified as corporate owned and is currently operating.
When was Security Research Labs founded?
Security Research Labs was founded in 2018. It employs 11 to 50 people.
Where is Security Research Labs based?
Security Research Labs is headquartered in Berlin, Germany, in the Europe region.
How does Security Research Labs make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Security Research Labs's main competitors?
Direct peers on record are Cure53, Trail of Bits, NVISO Security, Pen Test Partners, Bishop Fox and OpenZeppelin. Broad incumbents are NCC Group, SEC Consult, Kudelski Security and TÜV Rheinland (Cybersecurity Services).
Does Security Research Labs have an API?
No public API is recorded for Security Research Labs.
What industry is Security Research Labs in?
Security Research Labs's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 54169 and its SIC code is 8711.