SySS
SySS is a German, Tübingen-based IT security consultancy offering manual penetration testing, red teaming, digital forensics, threat intelligence, and security training to regulated enterprises across the DACH region.
- Company typePrivate
- Founded2005
- HeadquartersTübingen, Germany
- Headcount51–100
- GTM typeB2B
- OfferingServices
What SySS does
SySS GmbH is a privately held German IT security consultancy headquartered in Tübingen that has provided offensive-security and incident-response services since 1998. Its core commercial offering centers on manual, consultant-led penetration testing across web applications, APIs, mobile apps, internal and external networks (LAN/WLAN/IP), operational technology (OT) environments, embedded systems, cloud infrastructure, and custom software, supplemented by red teaming, purple teaming, targeted client-side and phishing simulation (TARGET/TECH, TARGET/PHISH), digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Delivery rests on in-house methodologies organised into discrete test modules rather than a proprietary automated platform, with the firm publicly publishing Security Advisories (SYSS-YYYY-XXX) documenting vulnerabilities discovered during engagements.
SySS operates a sales-led, consultative go-to-market motion via direct client contact (phone, email [email protected], and a dedicated incident hotline +49 7071 407856-99), with physical branch offices in Frankfurt am Main and Munich in addition to its Tübingen headquarters, and a wholly-owned Austrian subsidiary, SySS Cyber Security GmbH, based in Vienna. Pricing is quote-based per engagement scope, complexity, and duration, with multi-year contracts referenced in the disclosed billing model; no standard price list or productized subscription tier is public. Revenue therefore flows from professional-services engagements rather than licensed software, and the firm does not expose SDKs, APIs, or application products.
The company targets regulated, security-sensitive organizations in the DACH region, with named verticals including financial services, industrial/manufacturing (OT), healthcare, and government/public sector, alongside general enterprise clients. It is founder/management-owned with no disclosed institutional investors, funding rounds, or M&A activity; managing directors are Sebastian Schreiber (founder) and Sebastian Nerz (co-managing director, late-2025/2026 appointment). Marketing is content-led via the Pentest Blog, Tech Blog, Pentest TV YouTube channel, Pentest Library whitepapers, a newsletter, and an active event calendar (DWX, Hack workshops), positioning SySS as a thought-leadership-led services brand rather than a product vendor.
SySS firmographics
Firmographics- Name
- SySS
- Legal name
- SySS GmbH
- Website
- https://syss.de
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- SySS is a German, Tübingen-based IT security consultancy offering manual penetration testing, red teaming, digital forensics, threat intelligence, and security training to regulated enterprises across the DACH region.
- Ownership category
- akta.pro rank
SySS industry classification
Industry- Product category
- Penetration Testing & Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKADAE), Vulnerability Assessment & Scanning (HDADAHAA), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where SySS is headquartered
LocationHeadquarters
- HQ city
- Tübingen
- HQ country
- Germany
- HQ region
- Europe
Offices4 records
Markets served
SySS business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Professional Penetration Testing Services: SySS generates revenue through professional security testing services including penetration tests, red teaming exercises, and security assessments. These are typically project-based engagements with scope defined per client requirements.
- Security Consulting: Technical consulting services for IT security projects, security architecture review, and incident response support. These services are billed as consulting engagements.
- Training and Education:
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom Professional Services Engagement |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels10 records
SySS product offering
Product offeringCore offering
SySS is an IT security consultancy that performs manual penetration testing, ethical hacking, and security assessments against enterprise IT environments. Their core business is delivering project-based security testing engagements (web, API, mobile, network, cloud, OT) augmented by red teaming, digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Customers contract directly with SySS consultants for tailored engagements rather than licensing a software product.
Product overview
SySS GmbH is a German cybersecurity company offering a comprehensive portfolio of penetration testing and security assessment services. The core offering is the Penetrationstest (Pentest), a structured simulated attack on IT systems to identify security vulnerabilities. This core service is supplemented by specialized test modules including Webapp-Pentest, WEBSERVICE/API-Pentest, Mobile-App-Pentest, Netzwerk-Penetrationstest, OT-Pentest, WLAN-Pentest, and IP-Pentest for different target environments. Complementary services include Red Teaming (realistic APT-style attacks), Digitale Forensik (digital forensics and incident response), Threat Intelligence, Live-Hacking demonstrations, and Schulung (security training). The TARGET modules provide specialized assessments for phishing simulation (TARGET/PHISH) and client security testing (TARGET/TECH), while Purple Teaming combines offensive and defensive security evaluation. SySS also publishes Security Advisories documenting discovered vulnerabilities. The company operates primarily in the DACH region (Germany, Austria, Switzerland) with headquarters in Tübingen and branch offices in Frankfurt, Munich, and Vienna (SySS Cyber Security GmbH).
Differentiator
Problem solved
Functional benefit
Products and services
- Penetrationstest (Pentest) Core service in which IT Security Consultants simulate cyberattacks on IT systems, web applications, networks, and infrastructure to identify security vulnerabilities before malicious hackers can exploit them. Sold to enterprise and organizational clients as a tailored, project-based engagement.
- Technisches Consulting Neutral and independent IT security consulting providing expert guidance on security strategy, architecture, policies, and risk assessment for organizations that need to address incidents, post-pentest findings, new requirements, or outsourced security work.
- Digitale Forensik und Incident Response Support for organizations during and after acute IT security incidents, including securing and analyzing court-admissible digital evidence and reconstructing attack patterns. Includes a dedicated 24/7 incident hotline (+49 7071 407856-99).
- Red Teaming Realistic simulated attacks from an external perspective without prior internal knowledge, using APT techniques to test an organization's processes, technical controls, and employee awareness against targeted threats.
- Threat Intelligence Collection, analysis, and contextualization of information about potential cyber risks to help organizations defend against digital threats targeting their environment.
- Live-Hacking Live in-person demonstrations where SySS specialists show, in real time, how attackers gain access to third-party data, used to raise security awareness among employees and decision-makers.
- Schulung (Security Training) Training programs for security officers and IT-responsible staff covering current IT security topics, methodologies, and hands-on hacking experience, including dedicated workshops such as Hack1/Hack2, Hack10 (network security), and Hack12 (Entra ID / Azure).
- Purple Teaming Coordinated attack-and-defense exercises combining Red Team and Blue Team activities to improve detection capabilities, monitoring systems, and incident response processes for organizations with existing defensive teams.
Quantifiable outcome
- Identification of security vulnerabilities before exploitation by attackers
- +2 more outcomes
Companies that use SySS
Customer profileSegments5 records
Ideal customer profiles5 records
SySS technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature9 records
SySS partnerships and signals
Strategic signalScale indicators3 records
Recent moves7 records
Expansion highlights5 records
SySS competitors and assessment
Company assessmentMarket position
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
SySS social profiles
Digital presenceSySS financial estimates
Financial estimateRevenue estimate
Valuation estimate
SySS leadership team
Management profileNumber of profiles
Profiles2 records
SySS subsidiaries and ownership
Company hierarchySubsidiaries1 record
SySS funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SySS M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SySS
What does SySS do?
SySS is an IT security consultancy that performs manual penetration testing, ethical hacking, and security assessments against enterprise IT environments. Their core business is delivering project-based security testing engagements (web, API, mobile, network, cloud, OT) augmented by red teaming, digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Customers contract directly with SySS consultants for tailored engagements rather than licensing a software product.
Is SySS a public or private company?
SySS is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SySS founded?
SySS was founded in 2005. It employs 51 to 100 people.
Where is SySS based?
SySS is headquartered in Tübingen, Germany, in the Europe region.
How does SySS make money?
Three revenue lines are on record. Professional Penetration Testing Services are the primary driver. The others are security Consulting and training and Education.
Does SySS have an API?
No public API is recorded for SySS.
What industry is SySS in?
SySS's product category is Penetration Testing & Cybersecurity Consulting. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 54151.