HvS-Consulting
HvS-Consulting GmbH is a German cyber security consulting firm offering ISMS/BCMS/awareness consulting, penetration testing, red teaming, and 24/7 incident response for over 500 customers from startups to DAX40 corporations across the DACH region.
- Company typePrivate
- Founded2004
- HeadquartersGarching, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What HvS-Consulting does
HvS-Consulting GmbH is a privately held German cyber security consulting firm headquartered in Garching bei München, founded in 2004. The firm delivers professional services across three pillars — technologies, processes, and people — anchored in regulatory and framework expertise (ISO 27001, NIS-2, TISAX/VDA ISA, KRITIS, EASA Part-IS, DVO 2019/1583) and supported by a team of 60+ IT security specialists with two decades of experience serving customers from startups to DAX40 corporations, totaling more than 500 clients. Its service lines include ISMS/BCMS/Awareness consulting, external Information Security Officer placement, security assessments (penetration tests, red teaming, blue team training, OSINT, social engineering, cloud security assessments, vulnerability scans, security audits), and incident response — anchored by a 24/7 IR retainer, threat hunting, M365 IR, and the HvS Threat Insights intelligence product.
The company's product surface is modest but operationally relevant: the IS-FOX Security Awareness Platform (e-learning, videos, phishing simulations, SCORM delivery) sold as a standalone brand at is-fox.com; the NIS-2 Self-Assessment Tool (freemium, German/English) used as a lead-generation and compliance-maturity asset; an internal Public Key Infrastructure (HvS Root-CA I / Issue-CA I) issuing certificates since 2013; and open-source NFS security tooling (nfs_analyze, fuse_nfs) published on the firm's GitHub. Research outputs include the Lazarus Report (2020) and Emissary Panda/APT27 Report (2021), which signal the firm's offensive-research credentials.
Commercially, HvS operates a direct, sales-led model with a 24/7 hotline for incident response and a content/event-driven demand-generation layer (German/English blog, on-demand webinars via Microsoft Teams, NIS-2 Self-Assessment tool as a free funnel asset, LinkedIn and Google paid acquisition, Cleverreach email, ProvenExpert reviews). Professional services engagements (ISMS, assessments, awareness campaigns) are custom-quoted and project-based, while recurring revenue derives from the 24/7 Incident Response Retainer and the IS-FOX awareness platform. The firm operates exclusively in the DACH region, holds its own ISO 27001:2022 certification by TÜV NORD CERT and a TISAX label (assessment May 3, 2026), and routes all customer data through German and European Microsoft cloud infrastructure — reinforcing its "Cyber Security made in Germany" positioning.
HvS-Consulting firmographics
Firmographics- Name
- HvS-Consulting
- Legal name
- HvS-Consulting GmbH
- Website
- https://hvs-consulting.de
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- HvS-Consulting GmbH is a German cyber security consulting firm offering ISMS/BCMS/awareness consulting, penetration testing, red teaming, and 24/7 incident response for over 500 customers from startups to DAX40 corporations across the DACH region.
- Ownership category
- akta.pro rank
HvS-Consulting industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Management Consulting Services (54161), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Risk, Compliance & Internal Controls Consulting (BPAHACAJ), Phishing, Social Engineering & Business Email Compromise (BEC) Training (EDABAGAB), Managed Detection & Response (MDR) & SOC Services (HDADAGAG), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where HvS-Consulting is headquartered
LocationHeadquarters
- HQ city
- Garching
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
HvS-Consulting business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- Professional Cybersecurity Consulting Services: One-time and project-based consulting engagements for ISMS establishment (ISO 27001, NIS-2, TISAX, KRITIS), business continuity management, external ISO services, risk management, and security policy development. These engagements are billed on a quote/project basis.
- Security Assessments: Discretely scoped assessments including penetration tests, red teaming, social engineering, security audits, cloud security assessments, vulnerability scans, and security stresstests. Billed per engagement.
- Incident Response Retainer and Services: 24/7 Incident Response Retainer providing always-on emergency response capability. Also per-incident incident response, threat hunting, CDC coaching, and M365 incident response services. Retainer suggests recurring revenue; per-incident services are one-time engagements.
- Security Awareness (IS-FOX): E-learning, video-based training, and phishing simulation tools delivered via the IS-FOX platform. Likely subscription-based per-seat or platform access model, as the platform supports user management and SCORM course delivery.
- Awareness Kampagnen: Security awareness campaign services combining technology, content, and process elements to sensitize and qualify employees and IT staff.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Professional consulting services (ISMS, BCMS, Awareness) — custom quote |
| Other | Multi-year contract | Security assessments (penetration tests, red teaming, audits) — custom quote |
| Subscription | Annual | 24/7 Incident Response Retainer — custom quote |
| Freemium | Pay-as-you-go | NIS-2 Self-Assessment Tool — free |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels10 records
HvS-Consulting product offering
Product offeringCore offering
HvS-Consulting is a German cybersecurity consulting firm that delivers ISMS consulting (ISO 27001, NIS-2, TISAX, KRITIS, EASA Part-IS), security assessments (penetration testing, red teaming, social engineering, cloud security audits, vulnerability scans), 24/7 incident response and threat hunting, business continuity management consulting, and security awareness training through its proprietary IS-FOX platform. It also provides threat intelligence via HvS Threat Insights, a free NIS-2 Self-Assessment Tool, and operates an internal PKI issuing certificates to employees and customers.
Product overview
HvS-Consulting is a cyber security consulting firm offering a portfolio of services centered around its IS-FOX Security Awareness Platform (e-learning, videos, phishing simulations) and consulting services including ISMS implementation (ISO 27001, NIS-2, TISAX, KRITIS), security assessments (penetration testing, red teaming, vulnerability scans), incident response (24/7 retainer, M365 IR, threat hunting), BCMS consulting, and threat intelligence (HvS Threat Insights). The company also operates an internal PKI for employee and customer certificates.
Differentiator
Problem solved
Functional benefit
Brands
- IS-FOX: Security awareness product line for e-learning, videos, phishing simulations and training tools
- HvS Threat Insights
- HvS PKI
Products and services
- IS-FOX Security Awareness Platform Proprietary security awareness product line providing e-learning modules, training videos, phishing simulations, and SCORM-based training tools for sensitizing and qualifying employees and IT staff. Bundled under the IS-FOX brand and sold as a standalone product via is-fox.com.
- ISMS Consulting Services
- Security Assessments
- 24/7 Incident Response Retainer
- Incident Response Services
- BCMS Consulting
- HvS Threat Insights
- Public Key Infrastructure (HvS PKI)
Quantifiable outcome
- 500+ customers served from startups to large enterprises
- +1 more outcomes
Companies that use HvS-Consulting
Customer profileNamed customers1 record
Ideal customer profiles2 records
HvS-Consulting technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
HvS-Consulting partnerships and signals
Strategic signalScale indicators6 records
Recent moves5 records
Expansion highlights5 records
HvS-Consulting competitors and assessment
Company assessmentDirect peers
- Secunet Security Networks AG: German publicly listed cybersecurity firm offering security consulting, managed security, and crypto/PKI solutions. Comparable as a DACH-rooted cybersecurity services and consulting provider with overlapping ISMS, compliance, and security assessment offerings, though significantly larger and broader in scope.
- InfoGuard AG: Swiss-German speaking cybersecurity firm offering penetration testing, security audits, ISMS consulting, and managed security services. Closely comparable to HvS's full-stack consulting, assessment, and IR portfolio targeting DACH-region enterprises.
- Sygnia: Global cybersecurity consulting and incident response firm (acquired by Team8) focused on adversary simulation, IR, and cyber defense center build-outs. Comparable to HvS in service mix — red teaming, threat hunting, IR retainer — with similar consulting-led delivery model.
- usd AG: German security consulting firm specializing in penetration testing, ISO 27001/TISAX/PCI-DSS consulting, and incident response. Directly comparable in service mix, regional focus, and target customer segment, serving DACH mid-market and enterprise.
- Red Team Pentesting GmbH: German offensive security boutique specializing in penetration testing, red teaming, and security audits. Directly comparable to HvS's assessment and adversary simulation practices, with similar DACH enterprise customer base and research-driven positioning.
- NVISO: European cybersecurity services firm specializing in security assessments, red teaming, incident response, and security consulting. Directly comparable to HvS's offensive security, IR retainer, and advisory offerings, with similar mid-market to enterprise client mix.
- admeritia GmbH: German independent cybersecurity consultancy focusing on penetration testing, ISMS/ISO 27001, and incident response. Closely comparable specialist German security consulting peer with similar size, regional DACH focus, and service-line overlap with HvS.
Broad incumbents
- Trustwave: Global cybersecurity firm offering managed detection and response, penetration testing, and compliance consulting. Comparable in IR retainer, assessment, and GRC service lines but operates as a much larger global MSSP rather than HvS's regional consulting boutique.
- T-Systems (Deutsche Telekom Security): Large German IT services and security subsidiary of Deutsche Telekom, offering managed security, SOC, and compliance services at scale. Comparable in security services breadth but competes as a much broader incumbent with portfolio offerings rather than HvS's boutique specialist model.
- KPMG Cyber Security Services: Big Four consulting firm with a substantial German cybersecurity practice covering ISMS, compliance, IR, and security strategy. Comparable on GRC and assessment work but competes as a generalist incumbent with broader enterprise reach than HvS's specialist positioning.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
HvS-Consulting social profiles
Digital presenceHvS-Consulting compliance and trust
Trust signalCompliance2 records
HvS-Consulting financial estimates
Financial estimateRevenue estimate
Valuation estimate
HvS-Consulting leadership team
Management profileNumber of profiles
Profiles8 records
HvS-Consulting funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
HvS-Consulting M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about HvS-Consulting
What does HvS-Consulting do?
HvS-Consulting is a German cybersecurity consulting firm that delivers ISMS consulting (ISO 27001, NIS-2, TISAX, KRITIS, EASA Part-IS), security assessments (penetration testing, red teaming, social engineering, cloud security audits, vulnerability scans), 24/7 incident response and threat hunting, business continuity management consulting, and security awareness training through its proprietary IS-FOX platform. It also provides threat intelligence via HvS Threat Insights, a free NIS-2 Self-Assessment Tool, and operates an internal PKI issuing certificates to employees and customers.
Is HvS-Consulting a public or private company?
HvS-Consulting is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was HvS-Consulting founded?
HvS-Consulting was founded in 2004. It employs 11 to 50 people.
Where is HvS-Consulting based?
HvS-Consulting is headquartered in Garching, Germany, in the Europe region.
How does HvS-Consulting make money?
Five revenue lines are on record. Professional Cybersecurity Consulting Services are the primary driver. The others are security Assessments, incident Response Retainer and Services, security Awareness (IS-FOX) and awareness Kampagnen.
Who are HvS-Consulting's main competitors?
Direct peers on record are Secunet Security Networks AG, InfoGuard AG, Sygnia, usd AG, Red Team Pentesting GmbH, NVISO and admeritia GmbH. Broad incumbents are Trustwave, T-Systems (Deutsche Telekom Security) and KPMG Cyber Security Services.
Does HvS-Consulting have an API?
No public API is recorded for HvS-Consulting.
What industry is HvS-Consulting in?
HvS-Consulting's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC), with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 54161 and its SIC code is 8742.