ELCA Security
ELCA Security is a Swiss cybersecurity firm and wholly-owned subsidiary of ELCA Group, providing 24/7 managed security services, SME and IAM products, and advisory consulting to Swiss enterprises, governmental organizations, and SMEs, anchored by its Geneva-based Senthorus SOC.
- Company typePrivate
- Founded2021
- HeadquartersLausanne, Switzerland
- Headcount251–500
- GTM typeB2B
- OfferingServices
What ELCA Security does
ELCA Security is a Swiss cybersecurity company headquartered in Pully, Switzerland, operating as a 100% wholly-owned subsidiary of ELCA Group — a 55+ year-old Swiss IT services firm with 2,300+ professionals. Founded in 2021, the company provides managed security services, advisory consulting, offensive and defensive security, and cybersecurity products to Swiss enterprises, governmental organizations, SMEs, and municipalities, with Swiss data sovereignty as a core structural differentiator. Operations are anchored by Senthorus, a Next-Generation Security Operations Center (SOC) operating 24/7 from Geneva, which delivers Managed Detection and Response (MDR) for Microsoft Sentinel, Microsoft XDR, Splunk Cloud/Enterprise, and endpoint EDRs (Microsoft Defender, SentinelOne, CrowdStrike, Carbon Black), powered by Bluevoyant's technology backbone.
The platform integrates 900+ custom alerts, 300+ custom data connectors, 600+ proprietary detection rules, AI-enabled Risk Based Alerting, and a proprietary Next Generation Content engine for rapid detection content updates. Complementary product lines include Praethorus (a per-asset priced SME cybersecurity product at CHF 9.99/month or CHF 99/year, with an optional CHF 499 onboarding package and CHF 9/minute emergency response), TrustID (Swiss MFA, SSO, identity federation, and e-signature with an EPR-compliant HealthID variant for healthcare), and a comprehensive advisory practice covering ISMS, ISO27k, FADP/nFADP/GDPR compliance, post-quantum cryptography readiness, penetration testing, and CSIRT incident response with a 30-minute activation SLA.
Revenue is generated through five primary streams: subscription-based MDR/SOC services (annual contracts, quote-based), per-asset Praethorus licensing, TrustID subscriptions (with white-label options), advisory and professional services, and offensive security engagements. Distribution is hybrid — direct enterprise field sales for Senthorus and advisory, self-service/PLG for Praethorus within Switzerland, plus an event-driven and partner-led GTM motion that includes the ELCASecurity Insights conferences in Zurich and Lausanne, and partnerships with Microsoft, Bluevoyant, Splunk, the Vaud Chamber of Commerce and Industry (CVCI), the European Broadcasting Union, and Switzerland's National Cyber Security Center.
ELCA Security firmographics
Firmographics- Name
- ELCA Security
- Legal name
- ELCA Security SA (ELCA Security AG) (ELCA Security Ltd)
- Website
- https://elcasecurity.ch
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- ELCA Security is a Swiss cybersecurity firm and wholly-owned subsidiary of ELCA Group, providing 24/7 managed security services, SME and IAM products, and advisory consulting to Swiss enterprises, governmental organizations, and SMEs, anchored by its Geneva-based Senthorus SOC.
- Ownership category
- akta.pro rank
ELCA Security industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
Keywords
Where ELCA Security is headquartered
LocationHeadquarters
- HQ city
- Lausanne
- HQ country
- Switzerland
- HQ region
- Europe
Offices3 records
Markets served
ELCA Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services (Senthorus MDR): 24/7 Swiss-based SOC monitoring, detection, investigation and response services. Includes MDR for Endpoint, MDR for Microsoft XDR/Sentinel, and MDR for Splunk Cloud/Enterprise. Subscription-based with custom alerting, threat hunting, and incident response.
- Advisory and Consulting Services: Security consulting covering ISMS implementation, ISO27k standards, data protection compliance (FADP, nFADP, GDPR), crisis management, and security architecture. Includes staff augmentation.
- Offensive Security Services: Penetration testing services including web application, mobile application, Active Directory, network infrastructure, hardware/IoT, red team, purple team, and IT/OT assessments. Also includes CSIRT incident response services.
- Praethorus Cybersecurity Solution: SME-focused cybersecurity product with per-asset licensing model. Includes endpoint protection agent, security assessment, chatbot support, and 24/7 incident response. Scalable license per customer needs.
- TrustID Identity Solutions: Digital identity solutions including MFA, SSO, identity federation, and e-signature services. Offered as mobile app-based authentication with white-labeling options for partners.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Praethorus Monthly License |
| Subscription | Annual | Praethorus Annual License |
| Unit Pricing | Pay-as-you-go | Praethorus Emergency Response |
| Subscription | Annual | Senthorus MDR Services |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels7 records
ELCA Security product offering
Product offeringCore offering
ELCA Security is a Swiss cybersecurity company that delivers managed detection and response (MDR) services through its Senthorus Security Operations Center, advisory and consulting services covering ISMS, ISO27k, FADP/nFADP and GDPR compliance, offensive and defensive security services such as penetration testing and incident response, and dedicated products including Praethorus (SME cybersecurity) and TrustID (digital identity, MFA, SSO, e-signature). The company serves Swiss SMEs, municipalities, associations, and large enterprises with Swiss data sovereignty.
Product overview
ELCA Security operates as a unified cybersecurity portfolio offering managed security services, SME-focused products, and enterprise advisory services. The core Senthorus MDR/SOC platform integrates with Microsoft (Sentinel, Defender Suite) and Splunk SIEMs, supported by Bluevoyant technology. Praethorus provides a dedicated SME cybersecurity product with endpoint protection, risk assessment, and chatbot support. TrustID offers Swiss digital identity services with MFA, SSO, and e-Signature capabilities. Advisory services cover penetration testing, incident response, GRC, and post-quantum cryptography assessments. The company is headquartered in Geneva/Pully, Switzerland with a 100% ELCA-owned subsidiary structure.
Differentiator
Problem solved
Functional benefit
Brands
- Senthorus: Swiss Next-Generation Security Operations Center (SOC) offering Managed Detection and Response (MDR) services
- Praethorus
- TrustID
Products and services
- Senthorus - Swiss Next-Generation SOC Swiss-based Next-Generation Security Operations Center offering 24/7 Managed Detection and Response (MDR) services including threat monitoring, detection, investigation, hunting, and response across endpoints, cloud, and hybrid environments.
- Praethorus Cybersecurity solution designed for Swiss SMEs, associations, and municipalities. Features deployable protection agent for 24/7 endpoint monitoring, online risk self-assessment tool, integrated cybersecurity chatbot, and 24/7 incident response support.
- TrustID Swiss digital identity (eID) solution providing Multi-Factor Authentication (MFA), identity federation, Single Sign-On (SSO), and e-Signature capabilities. Includes HealthID variant compliant with Electronic Patient Record (EPR) requirements.
- MDR for Endpoint Managed Detection and Response service for endpoint protection leveraging Microsoft Defender, SentinelOne, Crowdstrike, and Carbon Black EDRs with 24x7 monitoring, automated remediation, threat hunting, and incident investigation.
- MDR for Microsoft XDR Extended Detection and Response service activating 24x7 monitoring across the full Microsoft Defender Suite including Endpoint, Office 365, Identity, and Cloud Apps with MITRE ATT&ACK Framework mapping.
- MDR for Microsoft Sentinel Managed Detection and Response for Microsoft Sentinel SIEM combining the SIEM tool with an elite 24x7 security operations team, providing 900+ custom alerts and 300+ custom data connectors with express onboarding and log optimization.
- MDR for Splunk Cloud Managed Detection and Response for Splunk Cloud platform leveraging 600+ proprietary rules, AI capabilities, and Risk Based Alerting, including CIS-based security maturity workshop.
- MDR for Splunk Enterprise Managed Detection and Response for Splunk Enterprise correlating and analyzing network, user, endpoint, and security logs in real time with 600+ proprietary rules and AI-powered threat intelligence.
- Penetration Testing Services Comprehensive penetration testing services including web application, mobile application, Active Directory, network infrastructure, workstation, hardware/IoT, red team, purple team, IT/OT, Wi-Fi, API, and VPN security assessments using OWASP and PTES frameworks.
- Incident Response (CSIRT) 24/7 Computer Security Incident Response Team providing rapid response with 30-minute activation SLA and 4-hour maximum onsite SLA, including digital forensics, crisis communication support, legal aspects handling, and NIST standards adherence.
- Advisory and Consulting Services Comprehensive consulting covering Strategy, Human Factor (security awareness), Access Management, Data Protection, Application Security, Cloud & Storage, and Operations, including Security Architecture, Zero Trust, and ISMS implementation.
- Governance, Risk and Compliance (GRC) GRC services including Strategy Definition, Security Measures & Compliance, Security Dashboard, Vendor Management, Secure SDLC, Secure Project Management, CISO as a Service, and Threat Modeling.
- Post-Quantum Cryptography Assessment Vendor-neutral PQC assessment service helping organizations prepare for quantum computing threats, including cryptographic discovery, algorithm analysis, and migration planning aligned with NIST deprecation timelines.
- Vulnerability Management Full Cycle Vulnerability Management service using Microsoft Azure Security Centre and Qualys for cloud environments, Greenbone Security Manager for on-premises, providing continuous assessment and remediation workflow.
Quantifiable outcome
- SOC coverage increased from 24% to 100% for tpg customer
- +5 more outcomes
Companies that use ELCA Security
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles3 records
ELCA Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability9 records
Feature5 records
ELCA Security partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered flagship, core and major.
- European Broadcasting Union (EBU)flagshipPartnership with EBU and SRG SSR to protect Eurovision Song Contest 2025 in Basel, securing an event with 170 million viewers during challenging geopolitical climate.
- BluevoyantcoreSenthorus platform is powered by Bluevoyant's cutting-edge technology. Bluevoyant converges internal and external cybersecurity capabilities into a unified platform. The company has received multiple Microsoft Security awards including Partner of the Year in 2022 and 2023, and MSSP of the Year in 2023.
- ELCA GroupcoreELCA is a prominent Swiss IT company with 55+ years of experience in end-to-end cybersecurity and digital transformation. ELCA Security is a 100% owned subsidiary of ELCA, providing state-of-the-art security solutions. ELCA Group has 2,300+ professionals.
- MicrosoftcoreIntegration with Microsoft security suite including Sentinel SIEM, Defender for Endpoint, Defender for Identity, Microsoft 365 Defender, Defender for Cloud Apps, and Defender for OT. ELCASecurity partnered with Microsoft to secure Eurovision Song Contest 2025.
- SplunkmajorMDR services for Splunk Cloud and Splunk Enterprise platforms with 600+ proprietary detection rules, AI capabilities, and Risk Based Alerting integration.
- Switzerland's National Cyber Security Center (NCSC)majorCollaboration with Switzerland's National Cyber Security Center as part of the Eurovision Song Contest 2025 security operation.
- Vaud Chamber of Commerce and Industry (CVCI)majorPartnership to inform, raise awareness, and support CVCI members with accessible and concrete cybersecurity solutions tailored for Vaud-based companies.
- TrustIDcoreProprietary identity solution providing MFA, SSO, identity federation, and e-signature services. Can be white-labeled for partner organizations.
Scale indicators12 records
Recent moves8 records
Expansion highlights5 records
ELCA Security competitors and assessment
Company assessmentDirect peers
- Arctic Wolf: MDR/security operations vendor serving mid-market and SME customers with concierge-style SOC delivery and subscription pricing. Closely comparable on SME/mid-market positioning that parallels ELCA Security's Praethorus and Senthorus offerings.
- Kudelski Security: Swiss-headquartered cybersecurity division of the Kudelski Group offering MDR/SOC, advisory, GRC and managed security services to enterprise and public-sector clients across Europe. Closely comparable on geography, target customer profile, and full-stack cybersecurity portfolio.
- Bluevoyant: Global MSSP that supplies the underlying technology platform powering Senthorus. Direct MSSP/MDR competitor with similar Microsoft Sentinel, Defender, and Splunk MDR offerings, awarded Microsoft Security MSSP of the Year 2023.
- Orange Cyberdefense: European cybersecurity arm of Orange operating 24/7 SOCs across multiple geographies, providing MDR, threat intelligence and consulting to enterprise and government customers. Closely comparable on managed SOC scale and European regulated-customer focus.
- ReliaQuest: US-headquartered MDR provider offering 24/7 SOC-as-a-service integrated with Microsoft Sentinel, Defender and Splunk, targeting enterprises with hybrid environments. Comparable MDR technology stack and enterprise customer profile.
- eSentire: Pure-play MDR provider with global SOC operations serving mid-market and enterprise customers. Comparable on subscription-based managed detection and response model and multi-vendor EDR/SIEM integration approach.
- Expel: MDR provider with transparent pricing and cloud-native SOC platform integrating with Microsoft, Splunk and CrowdStrike stacks. Comparable MDR-only business model and technology ecosystem overlap with Senthorus.
Broad incumbents
- CrowdStrike: Leading EDR/XDR platform vendor that has expanded into MDR/Falcon Complete services and partner-delivered MDR. Comparable as a security technology incumbent that competes with ELCA Security's MDR-for-Endpoint module and broader SOC integrations.
- Eviden (Atos): European IT services and cybersecurity business (part of Atos group) providing managed SOC, GRC and consulting to large enterprises and governments across Europe. Comparable enterprise/government cybersecurity services portfolio and European scale.
Regional players
- Swisscom: Switzerland's incumbent telecommunications provider with a substantial cybersecurity services business (managed security, SOC, consulting) serving Swiss enterprise and public-sector customers. Comparable Swiss market focus but broader telecom-owned portfolio.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
ELCA Security social profiles
Digital presenceELCA Security compliance and trust
Trust signalCompliance3 records
ELCA Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
ELCA Security leadership team
Management profileNumber of profiles
Profiles8 records
ELCA Security subsidiaries and ownership
Company hierarchySubsidiaries1 record
ELCA Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ELCA Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ELCA Security
What does ELCA Security do?
ELCA Security is a Swiss cybersecurity company that delivers managed detection and response (MDR) services through its Senthorus Security Operations Center, advisory and consulting services covering ISMS, ISO27k, FADP/nFADP and GDPR compliance, offensive and defensive security services such as penetration testing and incident response, and dedicated products including Praethorus (SME cybersecurity) and TrustID (digital identity, MFA, SSO, e-signature). The company serves Swiss SMEs, municipalities, associations, and large enterprises with Swiss data sovereignty.
Is ELCA Security a public or private company?
ELCA Security is a private company. It is classified as corporate owned and is currently operating.
When was ELCA Security founded?
ELCA Security was founded in 2021. It employs 251 to 500 people.
Where is ELCA Security based?
ELCA Security is headquartered in Lausanne, Switzerland, in the Europe region.
How does ELCA Security make money?
Five revenue lines are on record. Managed Security Services (Senthorus MDR) is the primary driver. The others are advisory and Consulting Services, offensive Security Services, praethorus Cybersecurity Solution and trustID Identity Solutions.
Who are ELCA Security's main competitors?
Direct peers on record are Arctic Wolf, Kudelski Security, Bluevoyant, Orange Cyberdefense, ReliaQuest, eSentire and Expel. Broad incumbents are CrowdStrike and Eviden (Atos). Swisscom is listed as a regional player.
Does ELCA Security have an API?
No public API is recorded for ELCA Security.
What industry is ELCA Security in?
ELCA Security's product category is Cybersecurity Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC). Its NAICS code is 561621 and its SIC code is 7370.