spotit
Spotit is Belgium's largest independent managed security services provider (MSSP), delivering 24/7 SOC and NOC services, OT/IT security, pentesting, governance, and compliance assessments to Belgian and European enterprises across critical infrastructure and mid-to-large organizations.
- Company typePrivate
- Founded2014
- HeadquartersMerelbeke, Belgium
- Headcount101–250
- GTM typeB2B
- OfferingServices
What spotit does
Spotit is a Belgian managed security services provider (MSSP) headquartered in Merelbeke-Melle with a secondary office in Herk-de-Stad and approximately 100+ employees, self-positioned as Belgium's largest independent MSSP. The company delivers cybersecurity and networking services organized around the NIST framework across Identify (assessments, pentesting, governance), Prevent & Protect (managed NOC/SOC, NaaS, security governance), Detect & Respond (SOC monitoring, CSIRT, OT monitoring), and Recover (CISO/DPO-as-a-Service). Core technology assets include an in-house 24/7 Security Operations Center and Network Operations Center with ML/AI-driven anomaly detection, an OT-specific threat monitoring practice, and integrated tooling across a broad partner ecosystem (Cisco Gold, Microsoft, Palo Alto Networks, Nozomi Networks, Tenable, Netskope, CyberArk, F5, One Identity, and Xona). ISO 27001:2022 certified, with compliance assessment practices covering NIS2, GDPR, ISO 27001, and DORA.
The company monetizes through a mix of recurring managed services contracts (SOC, NOC, NaaS, CISO/DPO/ISO-as-a-Service, User Behavior Analytics) and project-based assessment and pentest work (€5,000–€15,000 per pentest). Spotit is sales-led and consultative, acquiring customers via website intake forms, direct sales, thought-leadership content (blog, whitepapers, NIS2 Decision Tree tool, Spotit Inspire 2026 event), and partner channel co-sell. Customers are primarily Belgian and European enterprises in critical infrastructure sectors (energy/utilities, manufacturing, pharmaceuticals) and mid-to-large organizations (500+ employees), with named logo Fluvius. In December 2025 the company formalized an OT-focused European partnership with Xona extending managed secure access delivery for OT/ICS environments.
Ownership is private with no disclosed institutional investors, no funding rounds, and no revenue figures publicly available. Management includes CEO Steven Vynckier, CTO Frederik Rasschaert, and Strategic Architect Dries Wouters. Operating geographies are Belgium-primary with stated European expansion intent via the Xona partnership.
spotit firmographics
Firmographics- Name
- spotit
- Legal name
- Spotit BV
- Website
- https://spotit.be
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Spotit is Belgium's largest independent managed security services provider (MSSP), delivering 24/7 SOC and NOC services, OT/IT security, pentesting, governance, and compliance assessments to Belgian and European enterprises across critical infrastructure and mid-to-large organizations.
- Ownership category
- akta.pro rank
spotit industry classification
Industry- Product category
- Managed Security Services
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Security Services (MSSP) & 24/7 SOC Operations (BPAKAHAA)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Managed OT Security Services (MSSP/MDR for ICS/OT) (HDADAJAN), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
Keywords
Where spotit is headquartered
LocationHeadquarters
- HQ city
- Merelbeke
- HQ country
- Belgium
- HQ region
- Europe
Offices2 records
Markets served
spotit business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services (SOC & NOC): Spotit provides 24/7 managed SOC and NOC services under subscription-style monthly contracts. The SOC monitors IT and OT environments, detects threats, and eliminates incidents. The NOC manages network and security components proactively. Services are delivered as managed or co-managed solutions. Customers pay a fixed monthly fee per managed environment, with service levels structured around maturity assessments and gradual coverage expansion.
- Security Assessments & Penetration Testing: Spotit offers a portfolio of one-time assessment services including Fundamental Security Assessments, Ethical Hacking/Penetration Tests (external infrastructure, internal infrastructure, OT, web application, physical, Azure cloud), Red & Blue Teaming, GDPR assessments, NIS2 assessments, ISO 27k assessments, and OT/IoT assessments. Pentest prices range from €5,000 to €15,000 depending on scope and organization size. These are project-based, one-time services that generate upfront revenue and often lead to recurring managed services engagements.
- Network as a Service (NaaS): NaaS provides state-of-the-art network technology accessible against low operational costs. Customers pay either a monthly OPEX cost or a CAPEX investment with a clear, predictable price. The service includes complete network infrastructure management via a centralized dashboard and lifecycle management of all equipment.
- Governance Services (CISO, DPO, ISO): Spotit offers executive and advisory services including CISO as a Service, DPO as a Service, Information Security Officer (ISO) consultancy, and Security Awareness Training. These are typically retainer or subscription-based engagements providing ongoing governance support.
- OT Security & Networking Optimization: Specialized services including OT network segmentation, industrial connectivity, secure remote access for OT, wireless/wired networking, and endpoint security. These are project-based professional services or part of ongoing managed service engagements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | Penetration Testing Services (one-time) |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels4 records
spotit product offering
Product offeringCore offering
Spotit is Belgium's largest independent managed security services provider (MSSP), delivering cybersecurity and networking services organized around the NIST framework: Identify (assessments, pentesting, governance), Prevent & Protect (managed NOC/SOC, NaaS, OT segmentation), Detect & Respond (24/7 SOC, CSIRT, OT threat monitoring), and Recover (CISO, DPO, ISO as a Service). The portfolio covers both IT and OT/ICS environments with a 100+ strong team, 24/7 SOC/NOC operations, and deep NIS2, GDPR, ISO 27001, and DORA compliance expertise.
Product overview
Spotit is Belgium's largest independent managed security services provider (MSSP), offering a comprehensive cybersecurity and networking portfolio structured around the NIST framework: Identify (assessments and governance), Prevent & Protect (managed services and security optimization), Detect & Respond (SOC, CSIRT, OT monitoring), and Recover (post-incident support). Core managed services include a 24/7 SOC and NOC, Network as a Service (NaaS), CISO/ISO as a Service, and DPO as a Service. Specialized offerings span OT/IoT security, Secure Remote Access for OT, Industrial Connectivity, Ethical Hacking, Red & Blue Teaming, and CSIRT incident response. The company also provides compliance-focused assessments for NIS2, GDPR, and ISO 27k, alongside security awareness training and user behavior analytics — all delivered as managed services.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Operations Center (SOC) 24/7 managed SOC service that monitors, detects, reports, and eliminates cybersecurity threats across IT and OT environments. Uses AI and machine learning for automated threat detection, integrates multiple log sources, and includes threat hunting plus escalation to a dedicated CSIRT team. Marketed as Belgium's largest independent MSSP SOC offering.
- Network Operations Center (NOC) Managed NOC service providing proactive management, maintenance, and troubleshooting of network and security components with 24/7 monitoring, corrective remote support, governance modeling, and reporting. Operates per ITIL incident, problem, change, configuration, release, and service management processes.
- Network as a Service (NaaS) Subscription-based networking model that delivers modern, automated, hierarchical network infrastructure with predictable OPEX or CAPEX pricing. Includes complete network infrastructure management via a centralized dashboard and full lifecycle management of all equipment.
- OT Threat Monitoring & Response Real-time monitoring and analysis of OT system security using machine learning and AI for automated OT-specific threat intelligence. Detects anomalies, assigns automated risk scores, and provides incident response for industrial control systems, supporting NIS2 and IEC 62443 compliance.
- Cyber Security Incident Response Team (CSIRT) Retainer-based incident response service providing a 24/7 emergency hotline, early warning honey pot (Canary service), breach readiness assessment, and multidisciplinary team activation for rapid containment and recovery from cybersecurity incidents.
- User Behavior Analytics (UBA) Analytics service providing automated insight into user behavior on the network, alerting when abnormal or risky behavior occurs. Uses machine learning to baseline behavior and can be integrated with SOC services for complete detect and response.
- Fundamental Security Assessment Evaluation process that assesses an organization's current cybersecurity posture against best practices and standards, identifying strengths, weaknesses, and improvement areas. Covers operational and technical measures and produces a detailed report with findings, scoring, prioritization, and an action plan.
- Ethical Hacking & Penetration Test Proactive security audit simulating realistic cyberattacks to identify vulnerabilities before malicious actors can exploit them. Offers external infrastructure, internal infrastructure, OT, web application, physical, and Azure Cloud penetration tests, with detailed reporting and remediation recommendations. Prices range from €5,000 to €15,000 depending on scope and organization size.
- OT/IoT Security Assessment Assessment for operational technology environments that maps the current security situation and provides advice on short- and long-term safety measures. Uses frameworks such as ISA/IEC 62443, covering technology, people, and processes.
- Red & Blue Teaming Practical cybersecurity exercise where a red team (attackers) and blue team (defenders) compete to identify vulnerabilities and optimize the organization's security posture, combining offensive and defensive perspectives.
- Microsoft Identity Assessment Assessment of Microsoft Entra ID and Active Directory environments based on Microsoft and spotit best practices. Covers authentication protocols, application permissions, privileged accounts, and anomalies. Delivers a detailed report with over 100 checked security items and a management summary.
- NIS2 Decision Tree Free online self-service tool that helps organizations determine whether they fall under NIS2 legislation, based on industry, number of employees, and turnover. Provides an indicative result to guide compliance planning.
- GDPR Assessment In-depth assessment evaluating whether an organization's current measures comply with GDPR legislation. Includes gap analysis, recommendations, and an action plan, supported by the spotit Data Protection Team.
- NIS2 Assessment Expert-led assessment evaluating an organization's technical, organizational, and physical security measures against NIS2 requirements. Delivers a comprehensive report including alignment scorecard, gap assessment, and concrete recommendations for NIS2 compliance.
- ISO 27k Assessment Assessment of an organization's information security management measures against ISO 27001 standards. Includes gap analysis, workshop-based evaluation, and a detailed roadmap with action points and priorities for ISO 27001 certification preparation.
- Social Engineering Services Practical training and simulation services that raise employee awareness of social engineering tactics. Includes phishing and spear-phishing tests, physical ICT security checks, and awareness campaigns delivered by spotit specialists.
- Security & Network Assessment Comprehensive assessment of network environment and IT security from an objective technical and operational standpoint, evaluating compliance with latest standards and best practices. Identifies misconfigurations, vulnerabilities, performance issues, and end-of-life systems.
- OT/IoT Network Assessment Assessment for OT network environments covering technology, people, and processes. Maps the current environment and provides short- and long-term security recommendations using frameworks such as ISA/IEC 62443.
- Security Governance Advisory service focused on strategy, responsibilities, procedures, control mechanisms, and communication for information security. Complemented by DPO as a Service, CISO as a Service, and Security Awareness Training.
- Chief Information Security Officer (CISO) as a Service External certified security professional who manages all information security-related business processes. Provides strategy development, action plans, and implementation support, backed by the full spotit team.
- Information Security Officer (ISO) Service
- Security Awareness Training Practical training programs (physical or e-learning) that raise employee awareness of information security importance and correct computing behavior. Tailored to end users, IT staff, and C-level executives.
- M365 Information Protection & Governance Data classification service protecting sensitive data across cloud, applications, and endpoint devices. Includes a 3-day Microsoft workshop for data flow insights and proof of concept, with automation to minimize manual effort.
- Data Protection Officer (DPO) as a Service External Data Protection Officer who oversees GDPR compliance for organizations. Provides advisory and supervisory role, preparing necessary documents, declarations, and registers, backed by spotit's Data Protection Team with legal and IT skills.
- OT Network Segmentation Cybersecurity strategy that divides OT networks into smaller, isolated segments to prevent lateral spread of cyberattacks. Covers architecture to implementation including firewall zoning, microsegmentation, and PVLAN concepts. Supports NIS2 and IEC 62443 compliance.
- Secure Remote Access for OT OT-specific remote access solution based on Zero-Trust Network Access (ZTNA), secure authentication, session monitoring and recording, and clientless and agent-based ZTNA. Manages access for internal and external users with granular Who/What/Where/When/How controls.
- Industrial Connectivity Integrated wired and wireless network infrastructure for industrial environments. Uses Cisco IE switches supporting industrial protocols (PROFINET, EtherNet/IP), designed for harsh conditions with Layer 2/3 features, enterprise-grade security, and multi-domain IT/OT management.
- AmIphished Phishing reporting service allowing employees to easily report suspicious messages and receive immediate expert feedback. Helps organizations reduce phishing risk through continuous employee engagement.
Quantifiable outcome
- The average cyber attack takes 256 days to detect. Spotit's managed SOC helps organizations detect and respond to threats faster, reducing the detection window significantly.
- +1 more outcomes
Companies that use spotit
Customer profileNamed customers1 record
Segments4 records
Ideal customer profiles3 records
spotit technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability6 records
Feature5 records
spotit partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- XonacoreXona, a vendor of secure access for critical infrastructure, partnered with spotit to deliver secure access to operational technology (OT) and industrial control systems (ICS) across Europe. Spotit integrates the Xona browser-based secure access platform (Xona Gateway and Centralizer) as part of its Zero Trust and OT/IoT security portfolio. The partnership targets critical sectors including energy, manufacturing, pharmaceuticals, and utilities, helping operators meet NIS2 Directive requirements without altering existing network architecture. Spotit offers the Xona Platform as a managed or co-managed solution, delivering full lifecycle governance for remote users and third-party vendors. The partnership is now active.
- CiscocoreCisco is listed as a Gold Certified Partner on spotit's contact page. The partnership involves Cisco networking and security technologies being incorporated into spotit's managed services offerings.
- MicrosoftcoreMicrosoft is listed as a technology partner on spotit's contact page. Spotit conducts Microsoft Identity assessments (Entra ID and Active Directory), Azure cloud penetration testing, and offers M365 Information Protection & Governance services, indicating a deep Microsoft technology partnership.
- Palo Alto NetworkscorePalo Alto Networks is listed as a partner on spotit's contact page, indicating technology integration in spotit's security solutions.
- Nozomi NetworkscoreNozomi Networks is listed as a partner on spotit's contact page. The company specializes in OT/IoT security, control room visibility, and threat detection for industrial environments, aligning with spotit's OT security service offerings.
- WestconminorWestcon is listed as a partner on spotit's contact page. Westcon is a global technology distributor and specialty aggregator.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
spotit competitors and assessment
Company assessmentDirect peers
- NVISO: Belgian-headquartered cybersecurity consulting and managed detection/response firm with a similar talent-led, mid-market and enterprise focus across Belgium and neighboring markets — the closest direct peer to Spotit.
- Toreon: Belgian cybersecurity firm offering penetration testing, security assessments, and managed security services with strong overlap in the mid-market and regulated segments Spotit serves.
- Orange Cyberdefense: Large European MSSP operating a 24/7 SOC portfolio with strong Belgian and Benelux presence, directly competing for managed security, OT, and compliance engagements in Spotit's home market.
Regional players
- Proximus (security services): Belgian telecom incumbent with bundled cybersecurity, managed SOC, and compliance offerings to its large enterprise base — a regional competitor that can leverage connectivity customers for security upsell in Spotit's home market.
- Realdolmen (Geva Group): Belgian IT services and security provider (part of Geva Group) delivering managed infrastructure and security services to enterprise and mid-market customers in Belgium — competing regionally for similar managed security deals.
Broad incumbents
- Secureworks: Global pure-play MSSP offering managed detection and response, vulnerability management, and compliance services — a broader incumbent benchmark for Spotit's managed SOC/NOC business.
- Sopra Steria Cybersecurity: European IT services group with a sizeable cybersecurity practice covering managed security, compliance, and OT — competing for the same Belgian and pan-European mid-market and enterprise accounts.
- IBM Security / IBM Managed Security Services: Global incumbent offering managed SOC, XDR, compliance, and OT/ICS security services — a benchmark competitor for enterprise and critical-infrastructure customers Spotit targets.
- Accenture Security: Global system integrator with a large managed security services practice serving enterprise clients across Europe — competing for large Belgium and EU managed security and compliance mandates.
Emerging players
- Claroty: OT/ICS cybersecurity specialist providing asset discovery, vulnerability management, and secure remote access for industrial environments — an emerging OT-focused competitor and partner-ecosystem reference point for Spotit's OT practice.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
spotit social profiles
Digital presencespotit compliance and trust
Trust signalCompliance1 record
spotit financial estimates
Financial estimateRevenue estimate
Valuation estimate
spotit leadership team
Management profileNumber of profiles
Profiles3 records
spotit funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
spotit M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about spotit
What does spotit do?
Spotit is Belgium's largest independent managed security services provider (MSSP), delivering cybersecurity and networking services organized around the NIST framework: Identify (assessments, pentesting, governance), Prevent & Protect (managed NOC/SOC, NaaS, OT segmentation), Detect & Respond (24/7 SOC, CSIRT, OT threat monitoring), and Recover (CISO, DPO, ISO as a Service). The portfolio covers both IT and OT/ICS environments with a 100+ strong team, 24/7 SOC/NOC operations, and deep NIS2, GDPR, ISO 27001, and DORA compliance expertise.
Is spotit a public or private company?
spotit is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was spotit founded?
spotit was founded in 2014. It employs 101 to 250 people.
Where is spotit based?
spotit is headquartered in Merelbeke, Belgium, in the Europe region.
How does spotit make money?
Five revenue lines are on record. Managed Security Services (SOC & NOC) is the primary driver. The others are security Assessments & Penetration Testing, network as a Service (NaaS), governance Services (CISO, DPO, ISO) and OT Security & Networking Optimization.
Who are spotit's main competitors?
Direct peers on record are NVISO, Toreon and Orange Cyberdefense. Regional players are Proximus (security services) and Realdolmen (Geva Group). Broad incumbents are Secureworks, Sopra Steria Cybersecurity, IBM Security / IBM Managed Security Services and Accenture Security. Claroty is listed as an emerging player.
Does spotit have an API?
No public API is recorded for spotit.
What industry is spotit in?
spotit's product category is Managed Security Services. Its primary akta.pro industry code is BPAKAHAA, Managed Security Services (MSSP) & 24/7 SOC Operations, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 5415 and its SIC code is 7370.