Cirosec
cirosec GmbH is a Heilbronn-based German IT security consultancy (founded 2002) that delivers penetration testing, red teaming, incident response, security consulting, and training to enterprise clients across the DACH region.
- Company typePrivate
- Founded2002
- HeadquartersHeilbronn, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cirosec does
Cirosec GmbH is a Heilbronn, Germany-based IT security consulting firm founded in 2002, operating privately with founder/management ownership (CEO and Founder Stefan Strobel, plus co-founders Steffen Gundel, Daniela Strobel, Marco Lorenz, and Stefan Middendorf). The firm specializes in offensive and defensive security services for enterprise clients across the DACH region, delivered by a boutique team of 11-50 employees. Its service portfolio covers IT security consulting and ISMS implementation, penetration testing, red team assessments (including DORA-compliant threat-led penetration testing), incident response and forensics (with 24/7 availability for contract customers), vendor-neutral security product selection and implementation, and a broad training catalog spanning the Hacking Extreme offensive series, cloud security (Azure, AWS, Office 365), ISO 27001 Lead Implementer/Auditor, and NIS-2 executive training.
The business model is pure professional services: project-based engagements (pentests, red team, IR) priced on inquiry, plus cohort-based training courses capped at 15 participants. Go-to-market is direct sales-led, with no self-serve, marketplace, or channel partner distribution; demand is supported by an active technical blog, security advisories and CVE publications, a German-language podcast, newsletter, and DACH event presence. The firm holds ISO 27001:2022 certification, is a member of the BSI Alliance for Cyber Security, and operates a formal 90+30 day responsible disclosure policy. Notable technical assets include a proprietary cirosec PGP Signer CA infrastructure for secure email and an active research output that has produced CVEs against Trend Micro Apex One, HP Hotkey Support, AVG Internet Security, Overwolf, baramundi Management Agent, Checkpoint Harmony, Webroot, Bitdefender, VMware Workstation, and RealVNC. Customers are enterprise organizations in Germany, Austria, and Switzerland requiring compliance with NIS-2, DORA, and ISO 27001, with no named logos disclosed.
Cirosec firmographics
Firmographics- Name
- Cirosec
- Legal name
- cirosec GmbH
- Website
- https://cirosec.de
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- cirosec GmbH is a Heilbronn-based German IT security consultancy (founded 2002) that delivers penetration testing, red teaming, incident response, security consulting, and training to enterprise clients across the DACH region.
- Ownership category
- akta.pro rank
Cirosec industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Other Scientific and Technical Consulting Services (541690), Professional, Scientific, and Technical Services (54), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
- akta.pro secondary industries
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Governance, Risk & Compliance (GRC) & Security Management (EDAOAIAG), Executive/Board Security Advisory & Risk Briefings (BPAKADAK)
Keywords
Where Cirosec is headquartered
LocationHeadquarters
- HQ city
- Heilbronn
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Cirosec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Professional Services - IT Security Consulting: Bespoke consulting engagements including IT security advisement, concepts, reviews, analyses, ISMS implementation, and product selection/implementation. Revenue generated through project-based professional services engagements.
- Security Assessments: Penetration testing, red teaming assessments, and threat-oriented penetration testing according to DORA (TLPT). Revenue from security testing engagements.
- Security Training Programs: Security awareness and technical training programs (e.g., Malware/Ransomware, Windows Security, Azure/AWS Cloud Security, ISO 27001, NIS-2, Incident Handling, Hacking Extreme courses). Training fees charged per participant with cancellation policies documented in AGB.
- Incident Response: Emergency incident response services with 24/7 availability for contract customers. Support during cyber attacks with specialized expertise.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | Training courses with varying duration and content complexity |
| One time/ perpetual license | Pay-as-you-go | Hacking Extreme Buffer Overflows training |
| Other | Multi-year contract | Custom consulting and security assessment engagements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels7 records
Cirosec product offering
Product offeringCore offering
Cirosec is a specialized IT security consulting firm that delivers bespoke professional services in the German-speaking region (DACH), including IT security advisory, concepts, reviews, analyses and ISMS implementation, penetration testing, red team / threat-led penetration testing under DORA, 24/7 incident response and forensics, and a catalog of security training and awareness programs. The company combines offensive and defensive security services with active vulnerability research and published CVE advisories.
Product overview
Cirosec is a German cybersecurity consulting and services company offering a comprehensive portfolio of professional security services rather than a software product platform. The core offerings include IT security consulting, penetration testing, red team assessments, incident response and forensics, security management and compliance, and security training programs. Their services are delivered by highly experienced consultants with over 25 years of expertise in the field. The company also operates a technical blog and vulnerability research program that publishes advisories and zero-day discoveries, demonstrating their active research contributions to the security community. Cirosec's training offerings span advanced offensive security courses (Hacking Extreme series), cloud security training (Azure, AWS, Office 365), compliance training (ISO 27001, NIS-2), and specialized courses in malware analysis and buffer overflows.
Differentiator
Problem solved
Functional benefit
Products and services
- IT Security Consulting
- Penetration Testing
- Red Team Assessments
- Incident Response and Forensics
- Security Management and Compliance
- Selection and Implementation of Security Products and Solutions
- Security Training and Awareness Programs
Quantifiable outcome
- ISO 27001:2022 certification for processes and measures in IT and information security
Companies that use Cirosec
Customer profileNamed customers1 record
Segments1 record
Ideal customer profiles1 record
Cirosec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Cirosec partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered minor.
- Radiant SecurityminorJoint hosting of technical webinar on May 21, 2026 addressing structural coverage gaps in Security Operations Centers. Cirosec co-hosts with Radiant Security to discuss how the riskiest SOC alerts (WAF, DLP, OT/IoT, dark web intelligence, supply chain signals) go uninvestigated and how AI SOC platforms can help. Cirosec positioned as the German cybersecurity expert partner.
- SOS-Kinderdorf (SOS Children's Villages)minorCorporate social responsibility partnership. Cirosec displays SOS Children's Village badge on website as part of their CSR/community engagement activities.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
Cirosec competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Global incident response and threat intelligence leader with strong DACH presence. Competes directly with cirosec's incident response and red team services at the large enterprise tier, with much larger bench and global reach.
- Trustwave (Singtel): Global cybersecurity firm offering managed security services, penetration testing, and incident response. Competes with cirosec for enterprise DACH mandates but operates at significantly larger scale with broader portfolio.
Direct peers
- OneConsult AG: Swiss cybersecurity consultancy offering penetration testing, red teaming, incident response, and security audits. Comparable boutique services firm operating in the German-speaking market.
- HvS-Consulting AG: German security consultancy focused on penetration testing, ISMS, and ISO 27001 advisory in the DACH region. Comparable in compliance and offensive security service mix.
- SEC Consult (part of Eviden/Atos): Austrian-headquartered cybersecurity consultancy with deep DACH penetration testing, red team, and managed detection services. Comparable offensive security focus, larger scale, and similar enterprise customer base in the region.
- Compass Security AG: Swiss security consulting firm providing penetration testing, red teaming, incident response, and security training. Comparable mid-sized DACH offensive security specialist.
- SySS GmbH: German penetration testing specialist based in Tübingen, focused on IT security testing, red teaming, and security research. Highly comparable as a boutique DACH pentest firm with strong research reputation.
- ERNW (Enno Rey Netzwerke): Heidelberg-based independent security consulting firm offering penetration testing, red teaming, incident response, and security research in DACH. Closely comparable in service mix, research-driven positioning, and boutique scale.
- RedTeam Pentesting GmbH: German penetration testing firm specializing in offensive security assessments and security research. Direct competitor in DACH pentest market with similar research-driven profile and CVE publication track record.
Emerging players
- ModZero: Swiss-based security research and consulting firm focused on vulnerability research, penetration testing, and security advisories. Comparable research-driven boutique DACH firm with similar offensive security orientation.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Cirosec social profiles
Digital presenceCirosec compliance and trust
Trust signalCompliance1 record
Cirosec financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cirosec leadership team
Management profileNumber of profiles
Profiles6 records
Cirosec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cirosec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cirosec
What does Cirosec do?
Cirosec is a specialized IT security consulting firm that delivers bespoke professional services in the German-speaking region (DACH), including IT security advisory, concepts, reviews, analyses and ISMS implementation, penetration testing, red team / threat-led penetration testing under DORA, 24/7 incident response and forensics, and a catalog of security training and awareness programs. The company combines offensive and defensive security services with active vulnerability research and published CVE advisories.
Is Cirosec a public or private company?
Cirosec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cirosec founded?
Cirosec was founded in 2002. It employs 11 to 50 people.
Where is Cirosec based?
Cirosec is headquartered in Heilbronn, Germany, in the Europe region.
How does Cirosec make money?
Four revenue lines are on record. Professional Services - IT Security Consulting is the primary driver. The others are security Assessments, security Training Programs and incident Response.
Who are Cirosec's main competitors?
Broad incumbents on record are Mandiant (Google Cloud) and Trustwave (Singtel). Direct peers are OneConsult AG, HvS-Consulting AG, SEC Consult (part of Eviden/Atos), Compass Security AG, SySS GmbH, ERNW (Enno Rey Netzwerke) and RedTeam Pentesting GmbH. ModZero is listed as an emerging player.
Does Cirosec have an API?
No public API is recorded for Cirosec.
What industry is Cirosec in?
Cirosec's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory, with a secondary code of BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC). Its NAICS code is 541690 and its SIC code is 7370.