Ujima
ujima is a Frankfurt-based managed cybersecurity services provider delivering 24x7 SOC, SIEM, EDR, IR, pentesting, MFA, and security consulting to German mid-market companies and KRITIS-regulated operators across healthcare, financial services, construction, and automotive sectors.
- Company typePrivate
- Founded2013
- HeadquartersFrankfurt, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Ujima does
ujima GmbH is a Frankfurt am Main-based managed security services provider (MSSP) founded in 2013 by Stefan Görres to deliver integrated cybersecurity exclusively to German mid-market and regulated enterprises. The firm bundles six managed service lines — EDR as a Service, SOC as a Service, SIEM as a Service, IR as a Service, Pentesting as a Service, and Multifaktor Authentifizierung — plus a strategic Cyber Security Beratung (consulting) practice, all anchored on a 24x7x365 Security Operations Center staffed by 30+ German-speaking specialists. Operations span 70+ customers and 135,000+ monitored endpoints across healthcare (Sana Klinikum Offenbach; Krankenhausverbund Nordrhein-Westfalen), construction (Bauunternehmen Hessen, 7,000+ employees), financial services (a 2,000-employee bank, a 1,500-employee insurer), and automotive supply (an 800-employee supplier), with explicit positioning around German mandatory frameworks — KRITIS, NIS2, IT-SIG 2.0, and DORA — and DIN EN ISO/IEC 27001 certification achieved in 2024.
The technology stack is multi-vendor and integration-heavy rather than proprietary: ujima operates SOC workflows over 100+ integrated security tools sourced through core-tier partnerships with SentinelOne (EDR), Fortinet (network), Tenable (vulnerability management), Exabeam (SIEM/UEBA), Claroty (OT/IoT, including healthcare), LogPoint (SIEM), Horizon3.ai (autonomous pentesting), Semperis (Active Directory/identity), Microsoft (Azure, Sentinel, Teams, Bookings), and minor partners including OPSWAT, Cloudflare, Brevo, and the Allianz für Cybersicherheit initiative. The model is "Cyber Security aus einer Hand" — single-vendor managed delivery of detection, response, and assurance across heterogeneous tool estates — delivered with a Probebetrieb (pilot) entry point and quote-based enterprise engagement on annual or multi-year subscription contracts.
Revenue mechanics blend three streams: recurring managed security subscriptions (SOC/SIEM/EDR/IR/Pentesting), project-based cyber security consulting and strategy work, and pass-through resale of partner software licenses and tools. Go-to-market is sales-led and direct: enterprise field sales for larger Mittelstand and KRITIS accounts, inside sales for inbound inquiries, with demand generation through German-language SEO, a technical blog, webinars, a gated Pentesting Strategy 2026 whitepaper (€197 list value), Google Ads, LinkedIn retargeting, and Brevo-powered email nurturing. Ownership remains concentrated with founder Stefan Görres; the company is privately held, discloses no venture or private-equity backing, and operates from a single Frankfurt headquarters at Kennedyallee 93.
Ujima firmographics
Firmographics- Name
- Ujima
- Legal name
- ujima GmbH
- Website
- https://ujima.de
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ujima is a Frankfurt-based managed cybersecurity services provider delivering 24x7 SOC, SIEM, EDR, IR, pentesting, MFA, and security consulting to German mid-market companies and KRITIS-regulated operators across healthcare, financial services, construction, and automotive sectors.
- Ownership category
- akta.pro rank
Ujima industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Facilities Management Services (541513), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Cybersecurity Support Operations (SOC Triage, Incident Intake) (BPAAACAF)
- akta.pro secondary industries
- Managed OT Security Services (MSSP/MDR for ICS/OT) (HDADAJAN), Network Security Services (Firewall/VPN/ZTNA/SASE Integration) (BPAEAEAG)
Keywords
Where Ujima is headquartered
LocationHeadquarters
- HQ city
- Frankfurt
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Ujima business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services: Recurring managed security services including SOC, EDR, SIEM, IR and Pentesting delivered as subscription-based services with continuous monitoring and support
- Cyber Security Consulting: Advisory and strategy services for cyber security, helping clients develop and implement security concepts and compliance requirements
- Licenses and Tools: Resale of cybersecurity software licenses and tools from technology partners including SentinelOne, Fortinet, Tenable, and others
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise Security Services |
| Hybrid | Multi-year contract | Trial / Pilot Program |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels7 records
Ujima product offering
Product offeringCore offering
Ujima provides managed cybersecurity services to German Mittelstand and critical infrastructure operators under a 'Cyber Security as a Service' model, delivering a 24x7x365 Security Operations Center plus integrated EDR, SIEM, Incident Response, penetration testing, multi-factor authentication, and strategic consulting. The company bundles third-party security technologies (SentinelOne, Fortinet, Tenable, Exabeam, Claroty, etc.) with its German-speaking specialist team to deliver continuous monitoring and compliance support for KRITIS, NIS2, IT-SIG 2.0, and DORA requirements.
Product overview
Ujima offers a unified portfolio of managed cybersecurity services under a 'Cyber Security as a Service' model, providing German Mittelstand companies with comprehensive protection through six core service offerings: EDR as a Service (endpoint detection and response), SOC as a Service (24x7 security operations center monitoring), SIEM as a Service (security information and event management), IR as a Service (incident response), Pentesting as a Service (penetration testing), and Multifaktor Authentifizierung (multi-factor authentication). These services are complemented by strategic cybersecurity consulting. The company emphasizes a holistic approach where real security results from an ongoing process rather than a single product, combining human expertise with technology for continuous protection.
Differentiator
Problem solved
Functional benefit
Products and services
- EDR as a Service Endpoint Detection and Response service that reliably identifies unusual and potentially dangerous activities across all endpoints of the client organization.
- SOC as a Service Security Operations Center service operating 24x7x365 that forms a central unit for monitoring, detection, investigation, and response to security incidents for client organizations.
- SIEM as a Service Security Information and Event Management service that collects and aggregates data from various sources across the corporate network, enabling detailed monitoring, detection, reporting, and alerting.
- IR as a Service Incident Response service that develops comprehensive incident response strategies with an experienced IR team available 24x7x365 during active incidents.
- Pentesting as a Service Penetration testing service that simulates cyber attacks on computer systems, networks, and web applications to identify vulnerabilities before real attackers can exploit them.
- Multifaktor Authentifizierung Multi-Factor Authentication service based on the principle of combining multiple different types of authentication methods rather than relying on a single factor, for enhanced security.
- Cyber Security Beratung Strategic cybersecurity consulting service that analyzes security posture and advises on further measures to make companies digitally secure, including development and implementation of security concepts and compliance requirements.
Quantifiable outcome
- Implementation timeline of 'few weeks' for SOC/SIEM deployment
- +2 more outcomes
Companies that use Ujima
Customer profileNamed customers6 records
Segments5 records
Ideal customer profiles4 records
Ujima technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Ujima partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and minor.
- SentinelOnecoreTechnology partnership for endpoint detection and response (EDR) solutions. SentinelOne provides core EDR technology integrated into ujima's managed security services offering.
- FortinetcoreTechnology partner for network security solutions including firewalls and security infrastructure.
- TenablecoreTechnology partner for vulnerability management and exposure analytics solutions.
- ExabeamcoreTechnology partner for security information and event management (SIEM) and user entity behavior analytics (UEBA).
- ClarotycoreTechnology partner for industrial and healthcare cybersecurity, including OT/IoT security solutions.
- LogPointcoreTechnology partner for SIEM and security automation solutions.
- Horizon3.aicoreTechnology partner for autonomous penetration testing and attack surface management.
- SemperiscoreTechnology partner for Active Directory and hybrid identity cybersecurity solutions.
- MicrosoftcoreTechnology platform partner using Microsoft services including Azure, Microsoft 365, Teams, Bookings, and Sentinel for security operations. EU-US Data Privacy Framework compliant.
- Allianz für CybersicherheitminorPartnership with German cybersecurity alliance initiative for information sharing and collaborative security efforts.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
Ujima competitors and assessment
Company assessmentDirect peers
- Arctic Wolf Networks: US-headquartered managed detection and response / SOC-as-a-service provider delivering 24x7 monitoring, EDR, SIEM, and IR. Directly comparable service portfolio and recurring-revenue MSSP model to ujima, though at vastly larger scale and with venture backing.
- ReliaQuest: Provider of managed detection and response built on GreyMatter, integrating SIEM, EDR, and cloud telemetry with a 24x7 SOC. Closely aligned with ujima's bundled managed security approach.
- eSentire: Pure-play MDR/MSSP offering 24x7 SOC, EDR, network traffic analysis, and incident response to mid-market and enterprise customers. Same target segment positioning and recurring managed-service economics as ujima.
- Expel: Transparent MDR provider combining a 24x7 SOC with managed EDR, SIEM, cloud, and identity threat detection. Closely comparable managed detection and response business model for mid-market and enterprise customers.
Broad incumbents
- Sophos: Global cybersecurity vendor with a broad portfolio spanning endpoint, network, email, and managed detection and response (Sophos MDR). Overlaps with ujima's EDR, network security, and managed SOC capabilities but as part of a much larger product suite.
- Orange Cyberdefense: European MSSP and consultancy within the Orange Group, operating 24x7 SOCs across multiple countries. Comparable managed security services portfolio with stronger geographic reach and resources than ujima.
Regional players
- T-Systems (Deutsche Telekom): Germany-headquartered incumbent IT and security services arm of Deutsche Telekom, offering managed SOC, SIEM, and security operations to German enterprise and public-sector customers. Comparable target market and service breadth but at vastly larger scale and as part of a telco portfolio.
- Controlware: German IT systems integrator and managed services provider with a cybersecurity portfolio spanning SOC, network security, and vulnerability management. Directly comparable regional MSSP competing for similar German Mittelstand and enterprise customers.
- SySS: Germany-based cybersecurity specialist focused on penetration testing, incident response, and red teaming. Comparable to ujima's pentesting and IR practices, and a regional alternative for German customers evaluating specialised security services.
Emerging players
- Hornetsecurity: German-headquartered cloud security provider spanning email security, backup, and managed security services. Adjacent competitor in the German Mittelstand security market with overlap in managed services positioning.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Ujima social profiles
Digital presenceUjima compliance and trust
Trust signalCompliance1 record
Ujima financial estimates
Financial estimateRevenue estimate
Valuation estimate
Ujima leadership team
Management profileNumber of profiles
Profiles1 record
Ujima funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Ujima M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Ujima
What does Ujima do?
Ujima provides managed cybersecurity services to German Mittelstand and critical infrastructure operators under a 'Cyber Security as a Service' model, delivering a 24x7x365 Security Operations Center plus integrated EDR, SIEM, Incident Response, penetration testing, multi-factor authentication, and strategic consulting. The company bundles third-party security technologies (SentinelOne, Fortinet, Tenable, Exabeam, Claroty, etc.) with its German-speaking specialist team to deliver continuous monitoring and compliance support for KRITIS, NIS2, IT-SIG 2.0, and DORA requirements.
Is Ujima a public or private company?
Ujima is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Ujima founded?
Ujima was founded in 2013. It employs 11 to 50 people.
Where is Ujima based?
Ujima is headquartered in Frankfurt, Germany, in the Europe region.
How does Ujima make money?
Three revenue lines are on record. Managed Security Services are the primary driver. The others are cyber Security Consulting and licenses and Tools.
Who are Ujima's main competitors?
Direct peers on record are Arctic Wolf Networks, ReliaQuest, eSentire and Expel. Broad incumbents are Sophos and Orange Cyberdefense. Regional players are T-Systems (Deutsche Telekom), Controlware and SySS. Hornetsecurity is listed as an emerging player.
Does Ujima have an API?
No public API is recorded for Ujima.
What industry is Ujima in?
Ujima's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is BPAAACAF, Cybersecurity Support Operations (SOC Triage, Incident Intake), with a secondary code of HDADAJAN, Managed OT Security Services (MSSP/MDR for ICS/OT). Its NAICS code is 541513 and its SIC code is 7373.