Developer docs
API playgroundTry for free, no card

Search company profiles

Deutsche Cyber Sicherheitsorganisation - DCSO

Full company profile

uuid000rsre

Namestring
Deutsche Cyber Sicherheitsorganisation - DCSO
Legal namestring
DCSO Deutsche Cyber-Sicherheitsorganisation GmbH
Websiteurl
dcso.de
Company typeenum
Private
Founded yearint
2015
Descriptiontext

DCSO Deutsche Cyber-Sicherheitsorganisation GmbH is a Berlin-based managed security service provider (MSSP) founded in 2015 by Allianz SE, BASF SE, Bayer AG, and Volkswagen AG to counter organised cybercrime and state-controlled industrial espionage targeting German industry. It operates as a not-for-profit, reinvesting all proceeds into mission rather than distributing to shareholders, and is governed as an independent GmbH with the four founders as community anchors. Headquartered at EUREF-Campus 22 in Berlin with a 24/7/365 Managed SOC, DCSO serves enterprise, KRITIS, public administration, and mid-market clients primarily across the DACH region (Germany, Austria, Switzerland). The company employs approximately 110 staff from 21 nationalities and holds ISO 27001, TISAX, BSI C5, and BSI-qualified APT response credentials.

DCSO's technology stack is built around proprietary components developed and operated entirely in Germany: the Threat Intelligence Engine (TIE) delivering IoC feeds via API, a managed Embedded SIEM (eSIEM) deployed on-premises for data sovereignty, high-performance network sensors (30-100 GBit/s) correlating endpoint, network, cloud, and Active Directory telemetry, and OCSF-compliant data pipelines (via the secunet/Tenzir consortium) that preprocess telemetry at the network edge. The product portfolio is organised into three domains — Defend (MDR, eSIEM, Threat Intelligence, Incident Response, Internet Exposure Monitoring), Improve (Security Consulting, Assessment, Technology evaluation across 90+ tested products), and Connect (a vendor-neutral community with 100 meetings and 168 threat intel reports). BSI-listed incident response and vendor-neutral product assessment are notable technical differentiators in the DACH market.

The business model combines recurring managed services (24/7 SOC, MDR, Threat Intelligence, IEM, incident response retainer) sold on annual or multi-year subscription contracts with bespoke professional services for NIS2/DORA/BSI C5/IT-Grundschutz compliance, security consulting, and maturity assessments, all delivered via direct enterprise field sales with quote-based pricing. There is no self-serve or PLG motion; sales are conducted through account executives, the community membership onboarding flow, and an incident-response hotline. Distribution is exclusively DACH, with recent strategic moves aimed at scaling capacity (Deutsche Telekom T Cloud Public, 2026) and broadening product surface into KRITIS, public administration, and the Mittelstand.

Short descriptiontext

DCSO is a Berlin-based managed security service provider (MSSP) founded in 2015 by Allianz, BASF, Bayer, and Volkswagen, delivering 24/7 SOC, MDR, threat intelligence, and compliance services to enterprises, KRITIS operators, and public-sector entities across the DACH region.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersBerlin, Germany
HQ citystring
Berlin
HQ countrystring
Germany
HQ regionstring
Europe
Markets served

Serves global market

Offices2 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
managed security services, threat intelligence, incident response, security consulting, cyber defense
Industry3 codes
1Managed Security Services (MSSP) & 24/7 SOC Operations
CodeBPAKAHAAPrimaryYes
2Security Operations Center (SOC) as a Service
CodeBPAEADABPrimaryNo
3Endpoint Security Managed Services (EDR/XDR)
CodeBPAEADAHPrimaryNo
NAICS code3 codes
  • Security Systems Services (except Locksmiths)561621
  • Computer Systems Design and Related Services54151
  • Computer Facilities Management Services541513
SIC code1 code
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Managed Security Services
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model4 records
1Managed Security Services (MSS)
TypeManaged Services
Description

Recurring managed SOC, MDR, Threat Intelligence, Incident Response, and monitoring services sold as subscription contracts. Revenue is primarily recurring in nature with contracts typically structured on annual or multi-year terms. Services include 24/7/365 monitoring, embedded SIEM, and managed detection and response capabilities.

dcso.de
2Professional Security Consulting
TypeProfessional Services
Description

Bespoke security consulting engagements covering strategic information security, IT security architecture, identity and access management, NIS2 compliance, and cyber security incident management. Sold as professional services engagements, typically project-based or retainer.

dcso.de
3NIS2 Compliance Services
TypeProfessional Services
Description

Modular consulting packages including starter workshops, gap analyses, roadmap development, and compliance maintenance for NIS2 Directive requirements. Sold as consulting engagements, potentially retainer-based for ongoing compliance maintenance.

dcso.de
4Security Assessment Services
TypeProfessional Services
Description

Objective maturity assessments of organisations and their supply chains using comprehensive test catalogues including common compliance standards. Supports investment decisions and budget prioritisation.

dcso.de
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Pricing details4 tiers
1MDR Complete — Full MDR service covering endpoint and network data correlation, cloud security, AD security, and 24/7/365 SOC monitoring.
ModelSubscriptionBilling cadenceAnnual
Notes

Pricing is quote-based and not publicly disclosed. Customised to customer environment and requirements.

dcso.de
2NIS2 Starter Workshop — One-day on-site workshop covering NIS2 directive basics, scoping, gap analysis, and quick check.
ModelOtherBilling cadenceMulti-year contract
Notes

Quote-based. Includes scoping analysis and short report with actionable recommendations.

dcso.de
3NIS2 Compliance — Full consulting, implementation, and operational managed services for NIS2 compliance.
ModelSubscriptionBilling cadenceMulti-year contract
Notes

Quote-based; modular building blocks allow customers to select services based on protection needs.

dcso.de
4Security Assessment — Objective maturity measurement using comprehensive test catalogues and benchmarks.
ModelOtherBilling cadenceMulti-year contract
Notes

Quote-based project engagement; results support investment decisions and budget prioritisation.

dcso.de
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

DCSO operates as a Managed Security Service Provider (MSSP) delivering 24/7/365 managed detection and response, threat intelligence, incident response, internet exposure monitoring, security consulting, and security assessment services to enterprises and critical infrastructure operators in the DACH region. Services are built on proprietary technology including an embedded SIEM (eSIEM), high-performance network sensors, and a Threat Intelligence Engine, all operated from a Berlin-based SOC under full European data sovereignty.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • 36 member insurers (representing over 63% of the German insurance market by premiums) participated in a single pooled audit, reducing individual audit burdens while providing reliable compliance assurance for AWS adoption.
+2 more records
Product overview1 text field

DCSO operates as a Managed Security Service Provider (MSSP) offering a modular, integrated portfolio of cybersecurity services built around a community model. The core offerings span three domains: Defend (Managed Detection & Response, Threat Intelligence, Internet Exposure Monitoring, Incident Response), Improve (Security Consulting, Security Assessment, Security Technology), and Connect (DCSO Community). Central to the MDR service is the proprietary Managed eSIEM (embedded SIEM), developed and operated entirely in Germany. The Threat Intelligence service is powered by the Threat Intelligence Engine (TIE) with a modern API for custom IoC feeds. These services are enriched with DCSO's own sensors and community-sourced findings, and delivered via a 24/7 Managed SOC in Berlin. The portfolio also includes NIS2 compliance consulting and external attack surface management under the IEM umbrella.

Product and service10 records
1Managed Detection & Response (MDR)
CategoryManaged Security Services
Description

24/7/365 managed SOC service providing endpoint and network detection and response, cloud security and Active Directory correlation, and actionable remediation guidance, with a proprietary embedded SIEM (eSIEM) developed and operated entirely in Germany. Targeted at organisations from Mittelstand to KRITIS operators and public administration.

2Threat Intelligence
CategoryManaged Security Services
Description

Tactical, operational and strategic threat intelligence including IoC feeds via a modern API (Threat Intelligence Engine / TIE), Ad-hoc Reports, Weekly TI Reports, and Strategic Reports covering attacker groups, attack methods and malware families. Delivered by analysts enriched with community and CERT insights.

3Incident Response
CategoryManaged Security Services
Description

BSI-qualified APT response service covering emergency response, compromise assessments and readiness assessments across the full security incident lifecycle, with close integration of IR, threat intelligence and threat detection.

4Internet Exposure Monitoring (IEM)
CategoryManaged Security Services
Description

External attack surface monitoring service that proactively identifies exposed assets, protects brand and reputation, and prioritises high-risk areas. Includes Information Leakage Monitoring and Identity Leakage Monitoring / Account Takeover Prevention modules.

5Security Consulting
CategoryProfessional Services
Description

Professional consulting across strategic information security, IT security architecture, identity & access management, NIS2 compliance, cyber security incident management, crisis management training, and board-level advisory.

6Security Assessment
CategoryProfessional Services
Description

Objective, vendor-neutral assessment of an organisation's security maturity level and that of its suppliers using a comprehensive test catalogue covering common compliance standards. Creates transparency to support investment decisions and budget prioritisation.

7Security Technology Evaluation
CategoryProfessional Services
Description

Vendor-neutral product testing and evaluation service, assessing functional and non-functional product features with individually weighted results. Provides consulting on suitable product solutions based on DCSO's portfolio of 90+ tested products.

8DCSO Community
CategoryCommunity / Managed Security Services
Description

Secure, vendor-neutral community platform connecting DCSO member companies, government agencies and research institutions, providing peer exchange, regular expert discussions, actionable recommendations, manufacturer-independent product overviews, and exclusive security situation updates.

9NIS2 Compliance Services
CategoryProfessional Services
Description

Modular consulting packages including starter workshops, gap analyses, roadmap development, and ongoing compliance maintenance for organisations affected by the EU NIS2 Directive.

10Sovereign MDR with OCSF Data Pipelines
CategoryManaged Security Services
Description

MDR offering leveraging OCSF (Open Cybersecurity Schema Framework) data pipelines at the network edge for intelligent data processing, filtering, structuring, normalising and prioritising of security data before controlled transfer to DCSO's centralised SOC analysis. Enables sovereign MDR with European data control.

Scale indicator6 records

Each record includes

Type, Value, Description, Source

Partnership7 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-01
Description

DCSO, secunet, and Tenzir formed a strategic consortium to address organisations with high cyber risk, including critical infrastructure operators, government agencies, and production facilities. The consortium provides a joint offering based on secunet edge — a secure local anchor for early warning, detection, and defence in distributed infrastructure. secunet edge serves as a trusted security anchor providing local execution environment for DCSO's sensor technology and managed SOC.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2026-06-01
Description

Tenzir provides the intelligent data pipeline at the network edge within the secunet edge-based joint offering. Its security data pipelines filter, structure, normalise, and prioritise security data before controlled transfer to DCSO's central SOC for analysis. Tenzir's OCSF-compliant data pipelines enable sovereign MDR with data processing at the point of origin.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2026-05-04
Description

DCSO and Deutsche Telekom formed a strategic partnership integrating DCSO's cybersecurity services into Deutsche Telekom's T Cloud Public. The partnership was formalised at Digital X Berlin on 4 May 2026, providing DCSO with a sovereign, high-security cloud infrastructure 'made in Germany' for delivering cybersecurity services. The T Cloud Public offers highest security standards, European data residency, and resilient scalable infrastructure.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2026-03-17
Description

DCSO conducted the second GDV (German Insurance Association) community audit for AWS, assessing AWS security controls against BSI C5, DORA, BaFin requirements, and EIOPA guidelines. 36 member insurers participated, representing over 63% of the German insurance market by premiums. The pooled audit reduced individual audit burdens while providing reliable assurance to accelerate AWS adoption.

Strategic tierCoreTypeImplementation/ SI/ Consulting PartnerAnnounced on2024-07-16
Description

DCSO and ]init[ AG initiated a strategic partnership and joint service offering for IT security in public administration. The offering combines ]init['s digitalisation expertise with DCSO's cybersecurity capabilities, providing a holistic approach addressing both technical and organisational security aspects for public sector organisations. The modular offering supports organisations in achieving IT-Grundschutz compliance.

Strategic tierMinorTypeGTM or Marketing Partner
Description

DCSO became a member of BVMW, the German Mittelstand association, to strengthen cybersecurity for mid-sized businesses. This membership supports DCSO's outreach to the Mittelstand segment and aligns with its mission to protect the broader German economy.

Strategic tierMinorTypeGTM or Marketing Partner
Description

DCSO is a partner of the Allianz für Cyber-Sicherheit (ACS), Germany's central platform for cybersecurity information and collaboration, under the patronage of the German Federal Ministry of the Interior.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

Global digital services group's cybersecurity arm delivering managed SOC, MDR, and sovereign cloud services across Europe. Competes with DCSO at the higher end of enterprise and government security outsourcing, including NIS2/DORA-related programs.

TypeBroad incumbent
Description

European IT services group with a dedicated cybersecurity practice covering SOC, identity, compliance, and incident response. Competes with DCSO for large enterprise and public-sector cybersecurity engagements in Germany and continental Europe.

TypeBroad incumbent
Description

Global cybersecurity platform leader with the Falcon MDR/SIEM/IR portfolio and a growing DACH presence. Sets the competitive ceiling DCSO is benchmarked against on endpoint, cloud, and managed detection capabilities for enterprise buyers.

TypeDirect peer
Description

Global MDR provider delivering 24/7 managed detection and response through a SOC-as-a-service model. Direct competitor to DCSO's MDR Complete for mid-market and enterprise customers seeking outsourced SOC capabilities outside the German sovereign stack.

TypeDirect peer
Description

European-headquartered MSSP/MDR provider (subsidiary of Orange) operating managed SOCs across multiple countries. Closest large European analog to DCSO's managed SOC, threat intelligence, and incident response stack, and a credible alternative for pan-European enterprise buyers evaluating DCSO.

TypeDirect peer
Description

Global pure-play MDR and managed security services provider with Taegis XDR. Direct competitor for enterprise and mid-market customers evaluating outsourced SOC, detection, and incident response services outside of a sovereign stack.

TypeBroad incumbent
Description

Global cybersecurity platform with Unit 42 providing MDR, incident response, and threat intelligence. Competes with DCSO in enterprise and KRITIS accounts where buyers weigh integrated platform breadth against DCSO's sovereign, community-led model.

TypeBroad incumbent
Description

IT services and cybersecurity arm of Deutsche Telekom, operating managed security services and sovereign cloud infrastructure across Germany and Europe. Now also DCSO's infrastructure partner via T Cloud Public; competes broadly in enterprise managed security while complementing DCSO at the infrastructure layer.

TypeEmerging player
Description

European security data pipeline vendor behind DCSO's OCSF-based sovereign MDR architecture. Niche but highly relevant peer/partner — comparable in mission (open, sovereign security data infrastructure) and adjacent in offering (data pipeline vs. full managed SOC).

TypeDirect peer
Description

German listed cybersecurity provider specializing in high-security IT, SINA, and IT-Grundschutz-aligned offerings for government and KRITIS. Closest domestic peer to DCSO and now a consortium partner via secunet edge; competes for the same BSI-qualified, sovereignty-sensitive enterprise and public-sector engagements.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers1 record

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

AI capability8 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles10 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance5 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Deutsche Cyber Sicherheitsorganisation - DCSO

Managed Security Servicesdcso.de

DCSO is a Berlin-based managed security service provider (MSSP) founded in 2015 by Allianz, BASF, Bayer, and Volkswagen, delivering 24/7 SOC, MDR, threat intelligence, and compliance services to enterprises, KRITIS operators, and public-sector entities across the DACH region.

What Deutsche Cyber Sicherheitsorganisation - DCSO does

DCSO Deutsche Cyber-Sicherheitsorganisation GmbH is a Berlin-based managed security service provider (MSSP) founded in 2015 by Allianz SE, BASF SE, Bayer AG, and Volkswagen AG to counter organised cybercrime and state-controlled industrial espionage targeting German industry. It operates as a not-for-profit, reinvesting all proceeds into mission rather than distributing to shareholders, and is governed as an independent GmbH with the four founders as community anchors. Headquartered at EUREF-Campus 22 in Berlin with a 24/7/365 Managed SOC, DCSO serves enterprise, KRITIS, public administration, and mid-market clients primarily across the DACH region (Germany, Austria, Switzerland). The company employs approximately 110 staff from 21 nationalities and holds ISO 27001, TISAX, BSI C5, and BSI-qualified APT response credentials.

DCSO's technology stack is built around proprietary components developed and operated entirely in Germany: the Threat Intelligence Engine (TIE) delivering IoC feeds via API, a managed Embedded SIEM (eSIEM) deployed on-premises for data sovereignty, high-performance network sensors (30-100 GBit/s) correlating endpoint, network, cloud, and Active Directory telemetry, and OCSF-compliant data pipelines (via the secunet/Tenzir consortium) that preprocess telemetry at the network edge. The product portfolio is organised into three domains — Defend (MDR, eSIEM, Threat Intelligence, Incident Response, Internet Exposure Monitoring), Improve (Security Consulting, Assessment, Technology evaluation across 90+ tested products), and Connect (a vendor-neutral community with 100 meetings and 168 threat intel reports). BSI-listed incident response and vendor-neutral product assessment are notable technical differentiators in the DACH market.

The business model combines recurring managed services (24/7 SOC, MDR, Threat Intelligence, IEM, incident response retainer) sold on annual or multi-year subscription contracts with bespoke professional services for NIS2/DORA/BSI C5/IT-Grundschutz compliance, security consulting, and maturity assessments, all delivered via direct enterprise field sales with quote-based pricing. There is no self-serve or PLG motion; sales are conducted through account executives, the community membership onboarding flow, and an incident-response hotline. Distribution is exclusively DACH, with recent strategic moves aimed at scaling capacity (Deutsche Telekom T Cloud Public, 2026) and broadening product surface into KRITIS, public administration, and the Mittelstand.

Deutsche Cyber Sicherheitsorganisation - DCSO firmographics

Firmographics
Name
Deutsche Cyber Sicherheitsorganisation - DCSO
Legal name
DCSO Deutsche Cyber-Sicherheitsorganisation GmbH
Website
https://dcso.de
Company type
Private
Founded year
2015
Operating status
Operating
Headcount range
11–50 employees
Short description
DCSO is a Berlin-based managed security service provider (MSSP) founded in 2015 by Allianz, BASF, Bayer, and Volkswagen, delivering 24/7 SOC, MDR, threat intelligence, and compliance services to enterprises, KRITIS operators, and public-sector entities across the DACH region.
Ownership category
akta.pro rank

Deutsche Cyber Sicherheitsorganisation - DCSO industry classification

Industry
Product category
Managed Security Services
NAICS
Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151), Computer Facilities Management Services (541513)
SIC
Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Managed Security Services (MSSP) & 24/7 SOC Operations (BPAKAHAA)
akta.pro secondary industries
Security Operations Center (SOC) as a Service (BPAEADAB), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)

Keywords

  • Managed security services
  • Threat intelligence
  • Incident response
  • Security consulting
  • Cyber defense

Where Deutsche Cyber Sicherheitsorganisation - DCSO is headquartered

Location

Headquarters

HQ city
Berlin
HQ country
Germany
HQ region
Europe

Offices2 records

Markets served

Deutsche Cyber Sicherheitsorganisation - DCSO business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales

Revenue model

  1. Managed Security Services (MSS): Recurring managed SOC, MDR, Threat Intelligence, Incident Response, and monitoring services sold as subscription contracts. Revenue is primarily recurring in nature with contracts typically structured on annual or multi-year terms. Services include 24/7/365 monitoring, embedded SIEM, and managed detection and response capabilities.
  2. Professional Security Consulting: Bespoke security consulting engagements covering strategic information security, IT security architecture, identity and access management, NIS2 compliance, and cyber security incident management. Sold as professional services engagements, typically project-based or retainer.
  3. NIS2 Compliance Services: Modular consulting packages including starter workshops, gap analyses, roadmap development, and compliance maintenance for NIS2 Directive requirements. Sold as consulting engagements, potentially retainer-based for ongoing compliance maintenance.
  4. Security Assessment Services: Objective maturity assessments of organisations and their supply chains using comprehensive test catalogues including common compliance standards. Supports investment decisions and budget prioritisation.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualMDR Complete — Full MDR service covering endpoint and network data correlation, cloud security, AD security, and 24/7/365 SOC monitoring.
OtherMulti-year contractNIS2 Starter Workshop — One-day on-site workshop covering NIS2 directive basics, scoping, gap analysis, and quick check.
SubscriptionMulti-year contractNIS2 Compliance — Full consulting, implementation, and operational managed services for NIS2 compliance.
OtherMulti-year contractSecurity Assessment — Objective maturity measurement using comprehensive test catalogues and benchmarks.

Go-to-market motion3 records

Distribution channels3 records

Marketing channels7 records

Deutsche Cyber Sicherheitsorganisation - DCSO product offering

Product offering

Core offering

DCSO operates as a Managed Security Service Provider (MSSP) delivering 24/7/365 managed detection and response, threat intelligence, incident response, internet exposure monitoring, security consulting, and security assessment services to enterprises and critical infrastructure operators in the DACH region. Services are built on proprietary technology including an embedded SIEM (eSIEM), high-performance network sensors, and a Threat Intelligence Engine, all operated from a Berlin-based SOC under full European data sovereignty.

Product overview

DCSO operates as a Managed Security Service Provider (MSSP) offering a modular, integrated portfolio of cybersecurity services built around a community model. The core offerings span three domains: Defend (Managed Detection & Response, Threat Intelligence, Internet Exposure Monitoring, Incident Response), Improve (Security Consulting, Security Assessment, Security Technology), and Connect (DCSO Community). Central to the MDR service is the proprietary Managed eSIEM (embedded SIEM), developed and operated entirely in Germany. The Threat Intelligence service is powered by the Threat Intelligence Engine (TIE) with a modern API for custom IoC feeds. These services are enriched with DCSO's own sensors and community-sourced findings, and delivered via a 24/7 Managed SOC in Berlin. The portfolio also includes NIS2 compliance consulting and external attack surface management under the IEM umbrella.

Differentiator

Problem solved

Functional benefit

Products and services

  • Managed Detection & Response (MDR) 24/7/365 managed SOC service providing endpoint and network detection and response, cloud security and Active Directory correlation, and actionable remediation guidance, with a proprietary embedded SIEM (eSIEM) developed and operated entirely in Germany. Targeted at organisations from Mittelstand to KRITIS operators and public administration.
  • Threat Intelligence Tactical, operational and strategic threat intelligence including IoC feeds via a modern API (Threat Intelligence Engine / TIE), Ad-hoc Reports, Weekly TI Reports, and Strategic Reports covering attacker groups, attack methods and malware families. Delivered by analysts enriched with community and CERT insights.
  • Incident Response BSI-qualified APT response service covering emergency response, compromise assessments and readiness assessments across the full security incident lifecycle, with close integration of IR, threat intelligence and threat detection.
  • Internet Exposure Monitoring (IEM) External attack surface monitoring service that proactively identifies exposed assets, protects brand and reputation, and prioritises high-risk areas. Includes Information Leakage Monitoring and Identity Leakage Monitoring / Account Takeover Prevention modules.
  • Security Consulting Professional consulting across strategic information security, IT security architecture, identity & access management, NIS2 compliance, cyber security incident management, crisis management training, and board-level advisory.
  • Security Assessment Objective, vendor-neutral assessment of an organisation's security maturity level and that of its suppliers using a comprehensive test catalogue covering common compliance standards. Creates transparency to support investment decisions and budget prioritisation.
  • Security Technology Evaluation Vendor-neutral product testing and evaluation service, assessing functional and non-functional product features with individually weighted results. Provides consulting on suitable product solutions based on DCSO's portfolio of 90+ tested products.
  • DCSO Community Secure, vendor-neutral community platform connecting DCSO member companies, government agencies and research institutions, providing peer exchange, regular expert discussions, actionable recommendations, manufacturer-independent product overviews, and exclusive security situation updates.
  • NIS2 Compliance Services Modular consulting packages including starter workshops, gap analyses, roadmap development, and ongoing compliance maintenance for organisations affected by the EU NIS2 Directive.
  • Sovereign MDR with OCSF Data Pipelines MDR offering leveraging OCSF (Open Cybersecurity Schema Framework) data pipelines at the network edge for intelligent data processing, filtering, structuring, normalising and prioritising of security data before controlled transfer to DCSO's centralised SOC analysis. Enables sovereign MDR with European data control.

Quantifiable outcome

  • 36 member insurers (representing over 63% of the German insurance market by premiums) participated in a single pooled audit, reducing individual audit burdens while providing reliable compliance assurance for AWS adoption.
  • +2 more outcomes

Companies that use Deutsche Cyber Sicherheitsorganisation - DCSO

Customer profile

Named customers1 record

Segments4 records

Ideal customer profiles4 records

Deutsche Cyber Sicherheitsorganisation - DCSO technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

AI capability8 records

Feature6 records

Deutsche Cyber Sicherheitsorganisation - DCSO partnerships and signals

Strategic signal

Partnerships

Seven partnerships are on record, tiered core and minor.

  • secunet AGcoreStrategic or Co-development Partner · 1 June 2026DCSO, secunet, and Tenzir formed a strategic consortium to address organisations with high cyber risk, including critical infrastructure operators, government agencies, and production facilities. The consortium provides a joint offering based on secunet edge — a secure local anchor for early warning, detection, and defence in distributed infrastructure. secunet edge serves as a trusted security anchor providing local execution environment for DCSO's sensor technology and managed SOC.
  • Tenzir GmbHcoreTechnology or Integration · 1 June 2026Tenzir provides the intelligent data pipeline at the network edge within the secunet edge-based joint offering. Its security data pipelines filter, structure, normalise, and prioritise security data before controlled transfer to DCSO's central SOC for analysis. Tenzir's OCSF-compliant data pipelines enable sovereign MDR with data processing at the point of origin.
  • Deutsche TelekomcoreTechnology or Integration · 4 May 2026DCSO and Deutsche Telekom formed a strategic partnership integrating DCSO's cybersecurity services into Deutsche Telekom's T Cloud Public. The partnership was formalised at Digital X Berlin on 4 May 2026, providing DCSO with a sovereign, high-security cloud infrastructure 'made in Germany' for delivering cybersecurity services. The T Cloud Public offers highest security standards, European data residency, and resilient scalable infrastructure.
  • Amazon Web Services (AWS)coreTechnology or Integration · 17 March 2026DCSO conducted the second GDV (German Insurance Association) community audit for AWS, assessing AWS security controls against BSI C5, DORA, BaFin requirements, and EIOPA guidelines. 36 member insurers participated, representing over 63% of the German insurance market by premiums. The pooled audit reduced individual audit burdens while providing reliable assurance to accelerate AWS adoption.
  • ]init[ AG für digitale KommunikationcoreImplementation/ SI/ Consulting Partner · 16 July 2024DCSO and ]init[ AG initiated a strategic partnership and joint service offering for IT security in public administration. The offering combines ]init['s digitalisation expertise with DCSO's cybersecurity capabilities, providing a holistic approach addressing both technical and organisational security aspects for public sector organisations. The modular offering supports organisations in achieving IT-Grundschutz compliance.
  • Bundesverband mittelständische Wirtschaft (BVMW)minorGTM or Marketing PartnerDCSO became a member of BVMW, the German Mittelstand association, to strengthen cybersecurity for mid-sized businesses. This membership supports DCSO's outreach to the Mittelstand segment and aligns with its mission to protect the broader German economy.
  • Allianz für Cyber-Sicherheit (ACS)minorGTM or Marketing PartnerDCSO is a partner of the Allianz für Cyber-Sicherheit (ACS), Germany's central platform for cybersecurity information and collaboration, under the patronage of the German Federal Ministry of the Interior.

Scale indicators6 records

Recent moves6 records

Expansion highlights6 records

Deutsche Cyber Sicherheitsorganisation - DCSO competitors and assessment

Company assessment

Broad incumbents

  • Atos Cybersecurity (Eviden): Global digital services group's cybersecurity arm delivering managed SOC, MDR, and sovereign cloud services across Europe. Competes with DCSO at the higher end of enterprise and government security outsourcing, including NIS2/DORA-related programs.
  • Sopra Steria Cybersecurity: European IT services group with a dedicated cybersecurity practice covering SOC, identity, compliance, and incident response. Competes with DCSO for large enterprise and public-sector cybersecurity engagements in Germany and continental Europe.
  • CrowdStrike: Global cybersecurity platform leader with the Falcon MDR/SIEM/IR portfolio and a growing DACH presence. Sets the competitive ceiling DCSO is benchmarked against on endpoint, cloud, and managed detection capabilities for enterprise buyers.
  • Palo Alto Networks (Unit 42): Global cybersecurity platform with Unit 42 providing MDR, incident response, and threat intelligence. Competes with DCSO in enterprise and KRITIS accounts where buyers weigh integrated platform breadth against DCSO's sovereign, community-led model.
  • T-Systems (Deutsche Telekom): IT services and cybersecurity arm of Deutsche Telekom, operating managed security services and sovereign cloud infrastructure across Germany and Europe. Now also DCSO's infrastructure partner via T Cloud Public; competes broadly in enterprise managed security while complementing DCSO at the infrastructure layer.

Direct peers

  • Arctic Wolf: Global MDR provider delivering 24/7 managed detection and response through a SOC-as-a-service model. Direct competitor to DCSO's MDR Complete for mid-market and enterprise customers seeking outsourced SOC capabilities outside the German sovereign stack.
  • Orange Cyberdefense: European-headquartered MSSP/MDR provider (subsidiary of Orange) operating managed SOCs across multiple countries. Closest large European analog to DCSO's managed SOC, threat intelligence, and incident response stack, and a credible alternative for pan-European enterprise buyers evaluating DCSO.
  • Secureworks: Global pure-play MDR and managed security services provider with Taegis XDR. Direct competitor for enterprise and mid-market customers evaluating outsourced SOC, detection, and incident response services outside of a sovereign stack.
  • secunet AG: German listed cybersecurity provider specializing in high-security IT, SINA, and IT-Grundschutz-aligned offerings for government and KRITIS. Closest domestic peer to DCSO and now a consortium partner via secunet edge; competes for the same BSI-qualified, sovereignty-sensitive enterprise and public-sector engagements.

Emerging players

  • Tenzir: European security data pipeline vendor behind DCSO's OCSF-based sovereign MDR architecture. Niche but highly relevant peer/partner — comparable in mission (open, sovereign security data infrastructure) and adjacent in offering (data pipeline vs. full managed SOC).

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights6 records

Customer concentration

Deutsche Cyber Sicherheitsorganisation - DCSO social profiles

Digital presence

Deutsche Cyber Sicherheitsorganisation - DCSO compliance and trust

Trust signal

Compliance5 records

Deutsche Cyber Sicherheitsorganisation - DCSO financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Deutsche Cyber Sicherheitsorganisation - DCSO leadership team

Management profile

Number of profiles

Profiles10 records

Deutsche Cyber Sicherheitsorganisation - DCSO funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Deutsche Cyber Sicherheitsorganisation - DCSO M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Deutsche Cyber Sicherheitsorganisation - DCSO

What does Deutsche Cyber Sicherheitsorganisation - DCSO do?

DCSO operates as a Managed Security Service Provider (MSSP) delivering 24/7/365 managed detection and response, threat intelligence, incident response, internet exposure monitoring, security consulting, and security assessment services to enterprises and critical infrastructure operators in the DACH region. Services are built on proprietary technology including an embedded SIEM (eSIEM), high-performance network sensors, and a Threat Intelligence Engine, all operated from a Berlin-based SOC under full European data sovereignty.

Is Deutsche Cyber Sicherheitsorganisation - DCSO a public or private company?

Deutsche Cyber Sicherheitsorganisation - DCSO is a private company. It is classified as corporate owned and is currently operating.

When was Deutsche Cyber Sicherheitsorganisation - DCSO founded?

Deutsche Cyber Sicherheitsorganisation - DCSO was founded in 2015. It employs 11 to 50 people.

Where is Deutsche Cyber Sicherheitsorganisation - DCSO based?

Deutsche Cyber Sicherheitsorganisation - DCSO is headquartered in Berlin, Germany, in the Europe region.

How does Deutsche Cyber Sicherheitsorganisation - DCSO make money?

Four revenue lines are on record. Managed Security Services (MSS) is the primary driver. The others are professional Security Consulting, NIS2 Compliance Services and security Assessment Services.

Who are Deutsche Cyber Sicherheitsorganisation - DCSO's main competitors?

Broad incumbents on record are Atos Cybersecurity (Eviden), Sopra Steria Cybersecurity, CrowdStrike, Palo Alto Networks (Unit 42) and T-Systems (Deutsche Telekom). Direct peers are Arctic Wolf, Orange Cyberdefense, Secureworks and secunet AG. Tenzir is listed as an emerging player.

Does Deutsche Cyber Sicherheitsorganisation - DCSO have an API?

Yes. DCSO's Threat Intelligence Engine (TIE) provides a modern API that aggregates, normalises, and contextualises indicators of compromise (IoC) from curated sources and makes these indicators available via a modern API. The API allows users to create custom tailored IoC feeds for integration with web proxies, SIEMs, network analysis systems, or analyst workflows. No additional technical specifics (protocol, auth method, sandbox, versioning, rate limits) are stated in the available source material.

What industry is Deutsche Cyber Sicherheitsorganisation - DCSO in?

Deutsche Cyber Sicherheitsorganisation - DCSO's product category is Managed Security Services. Its primary akta.pro industry code is BPAKAHAA, Managed Security Services (MSSP) & 24/7 SOC Operations, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 561621 and its SIC code is 7370.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals