Developer docs
API playgroundTry for free, no card

Search company profiles

SySS

Full company profile

uuid000s8ah

Namestring
SySS
Legal namestring
SySS GmbH
Websiteurl
syss.de
Company typeenum
Private
Founded yearint
2005
Descriptiontext

SySS GmbH is a privately held German IT security consultancy headquartered in Tübingen that has provided offensive-security and incident-response services since 1998. Its core commercial offering centers on manual, consultant-led penetration testing across web applications, APIs, mobile apps, internal and external networks (LAN/WLAN/IP), operational technology (OT) environments, embedded systems, cloud infrastructure, and custom software, supplemented by red teaming, purple teaming, targeted client-side and phishing simulation (TARGET/TECH, TARGET/PHISH), digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Delivery rests on in-house methodologies organised into discrete test modules rather than a proprietary automated platform, with the firm publicly publishing Security Advisories (SYSS-YYYY-XXX) documenting vulnerabilities discovered during engagements.

SySS operates a sales-led, consultative go-to-market motion via direct client contact (phone, email [email protected], and a dedicated incident hotline +49 7071 407856-99), with physical branch offices in Frankfurt am Main and Munich in addition to its Tübingen headquarters, and a wholly-owned Austrian subsidiary, SySS Cyber Security GmbH, based in Vienna. Pricing is quote-based per engagement scope, complexity, and duration, with multi-year contracts referenced in the disclosed billing model; no standard price list or productized subscription tier is public. Revenue therefore flows from professional-services engagements rather than licensed software, and the firm does not expose SDKs, APIs, or application products.

The company targets regulated, security-sensitive organizations in the DACH region, with named verticals including financial services, industrial/manufacturing (OT), healthcare, and government/public sector, alongside general enterprise clients. It is founder/management-owned with no disclosed institutional investors, funding rounds, or M&A activity; managing directors are Sebastian Schreiber (founder) and Sebastian Nerz (co-managing director, late-2025/2026 appointment). Marketing is content-led via the Pentest Blog, Tech Blog, Pentest TV YouTube channel, Pentest Library whitepapers, a newsletter, and an active event calendar (DWX, Hack workshops), positioning SySS as a thought-leadership-led services brand rather than a product vendor.

Short descriptiontext

SySS is a German, Tübingen-based IT security consultancy offering manual penetration testing, red teaming, digital forensics, threat intelligence, and security training to regulated enterprises across the DACH region.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersTübingen, Germany
HQ citystring
Tübingen
HQ countrystring
Germany
HQ regionstring
Europe
Markets served

Serves global market

Offices4 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
penetration testing services, cybersecurity consulting, red team assessments, digital forensics services, security awareness training
Industry4 codes
1Vulnerability Management & Penetration Testing Services
CodeBPAEADADPrimaryYes
2Penetration Testing & Red Teaming
CodeBPAKADAEPrimaryNo
3Vulnerability Assessment & Scanning
CodeHDADAHAAPrimaryNo
4Application Security Testing (SAST/DAST/IAST/SCA)
CodeHDADACACPrimaryNo
NAICS code1 code
  • Computer Systems Design and Related Services54151
Product category
Penetration Testing & Cybersecurity Consulting
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model3 records
1Professional Penetration Testing Services
TypeProfessional Services
Description

SySS generates revenue through professional security testing services including penetration tests, red teaming exercises, and security assessments. These are typically project-based engagements with scope defined per client requirements.

2Security Consulting
TypeProfessional Services
Description

Technical consulting services for IT security projects, security architecture review, and incident response support. These services are billed as consulting engagements.

3Training and Education
TypeProfessional Services
Marketing channels10 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels2 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Pricing details1 tier
1Custom Professional Services Engagement
ModelOtherBilling cadenceMulti-year contract
Notes

Penetration testing and security consulting services are priced based on project scope, complexity, and duration. Specific pricing requires direct inquiry via sales contact.

GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

SySS is an IT security consultancy that performs manual penetration testing, ethical hacking, and security assessments against enterprise IT environments. Their core business is delivering project-based security testing engagements (web, API, mobile, network, cloud, OT) augmented by red teaming, digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Customers contract directly with SySS consultants for tailored engagements rather than licensing a software product.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Identification of security vulnerabilities before exploitation by attackers
+2 more records
Product overview1 text field

SySS GmbH is a German cybersecurity company offering a comprehensive portfolio of penetration testing and security assessment services. The core offering is the Penetrationstest (Pentest), a structured simulated attack on IT systems to identify security vulnerabilities. This core service is supplemented by specialized test modules including Webapp-Pentest, WEBSERVICE/API-Pentest, Mobile-App-Pentest, Netzwerk-Penetrationstest, OT-Pentest, WLAN-Pentest, and IP-Pentest for different target environments. Complementary services include Red Teaming (realistic APT-style attacks), Digitale Forensik (digital forensics and incident response), Threat Intelligence, Live-Hacking demonstrations, and Schulung (security training). The TARGET modules provide specialized assessments for phishing simulation (TARGET/PHISH) and client security testing (TARGET/TECH), while Purple Teaming combines offensive and defensive security evaluation. SySS also publishes Security Advisories documenting discovered vulnerabilities. The company operates primarily in the DACH region (Germany, Austria, Switzerland) with headquarters in Tübingen and branch offices in Frankfurt, Munich, and Vienna (SySS Cyber Security GmbH).

Product and service8 records
1Penetrationstest (Pentest)
CategorySecurity Testing Services
Description

Core service in which IT Security Consultants simulate cyberattacks on IT systems, web applications, networks, and infrastructure to identify security vulnerabilities before malicious hackers can exploit them. Sold to enterprise and organizational clients as a tailored, project-based engagement.

2Technisches Consulting
CategorySecurity Consulting Services
Description

Neutral and independent IT security consulting providing expert guidance on security strategy, architecture, policies, and risk assessment for organizations that need to address incidents, post-pentest findings, new requirements, or outsourced security work.

3Digitale Forensik und Incident Response
CategoryIncident Response Services
Description

Support for organizations during and after acute IT security incidents, including securing and analyzing court-admissible digital evidence and reconstructing attack patterns. Includes a dedicated 24/7 incident hotline (+49 7071 407856-99).

4Red Teaming
CategoryAdversary Simulation Services
Description

Realistic simulated attacks from an external perspective without prior internal knowledge, using APT techniques to test an organization's processes, technical controls, and employee awareness against targeted threats.

5Threat Intelligence
CategoryThreat Intelligence Services
Description

Collection, analysis, and contextualization of information about potential cyber risks to help organizations defend against digital threats targeting their environment.

6Live-Hacking
CategorySecurity Awareness Services
Description

Live in-person demonstrations where SySS specialists show, in real time, how attackers gain access to third-party data, used to raise security awareness among employees and decision-makers.

7Schulung (Security Training)
CategorySecurity Training Services
Description

Training programs for security officers and IT-responsible staff covering current IT security topics, methodologies, and hands-on hacking experience, including dedicated workshops such as Hack1/Hack2, Hack10 (network security), and Hack12 (Entra ID / Azure).

8Purple Teaming
CategoryAdversary Simulation Services
Description

Coordinated attack-and-defense exercises combining Red Team and Blue Team activities to improve detection capabilities, monitoring systems, and incident response processes for organizations with existing defensive teams.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Market position
Competitive moat4 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile5 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature9 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries1 record

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

SySS

Penetration Testing & Cybersecurity Consultingsyss.de

SySS is a German, Tübingen-based IT security consultancy offering manual penetration testing, red teaming, digital forensics, threat intelligence, and security training to regulated enterprises across the DACH region.

What SySS does

SySS GmbH is a privately held German IT security consultancy headquartered in Tübingen that has provided offensive-security and incident-response services since 1998. Its core commercial offering centers on manual, consultant-led penetration testing across web applications, APIs, mobile apps, internal and external networks (LAN/WLAN/IP), operational technology (OT) environments, embedded systems, cloud infrastructure, and custom software, supplemented by red teaming, purple teaming, targeted client-side and phishing simulation (TARGET/TECH, TARGET/PHISH), digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Delivery rests on in-house methodologies organised into discrete test modules rather than a proprietary automated platform, with the firm publicly publishing Security Advisories (SYSS-YYYY-XXX) documenting vulnerabilities discovered during engagements.

SySS operates a sales-led, consultative go-to-market motion via direct client contact (phone, email [email protected], and a dedicated incident hotline +49 7071 407856-99), with physical branch offices in Frankfurt am Main and Munich in addition to its Tübingen headquarters, and a wholly-owned Austrian subsidiary, SySS Cyber Security GmbH, based in Vienna. Pricing is quote-based per engagement scope, complexity, and duration, with multi-year contracts referenced in the disclosed billing model; no standard price list or productized subscription tier is public. Revenue therefore flows from professional-services engagements rather than licensed software, and the firm does not expose SDKs, APIs, or application products.

The company targets regulated, security-sensitive organizations in the DACH region, with named verticals including financial services, industrial/manufacturing (OT), healthcare, and government/public sector, alongside general enterprise clients. It is founder/management-owned with no disclosed institutional investors, funding rounds, or M&A activity; managing directors are Sebastian Schreiber (founder) and Sebastian Nerz (co-managing director, late-2025/2026 appointment). Marketing is content-led via the Pentest Blog, Tech Blog, Pentest TV YouTube channel, Pentest Library whitepapers, a newsletter, and an active event calendar (DWX, Hack workshops), positioning SySS as a thought-leadership-led services brand rather than a product vendor.

SySS firmographics

Firmographics
Name
SySS
Legal name
SySS GmbH
Website
https://syss.de
Company type
Private
Founded year
2005
Operating status
Operating
Headcount range
51–100 employees
Short description
SySS is a German, Tübingen-based IT security consultancy offering manual penetration testing, red teaming, digital forensics, threat intelligence, and security training to regulated enterprises across the DACH region.
Ownership category
akta.pro rank

SySS industry classification

Industry
Product category
Penetration Testing & Cybersecurity Consulting
NAICS
Computer Systems Design and Related Services (54151)
akta.pro primary industry
Vulnerability Management & Penetration Testing Services (BPAEADAD)
akta.pro secondary industries
Penetration Testing & Red Teaming (BPAKADAE), Vulnerability Assessment & Scanning (HDADAHAA), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)

Keywords

  • Penetration testing services
  • Cybersecurity consulting
  • Red team assessments
  • Digital forensics services
  • Security awareness training

Where SySS is headquartered

Location

Headquarters

HQ city
Tübingen
HQ country
Germany
HQ region
Europe

Offices4 records

Markets served

SySS business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations, Others

Revenue model

  1. Professional Penetration Testing Services: SySS generates revenue through professional security testing services including penetration tests, red teaming exercises, and security assessments. These are typically project-based engagements with scope defined per client requirements.
  2. Security Consulting: Technical consulting services for IT security projects, security architecture review, and incident response support. These services are billed as consulting engagements.
  3. Training and Education:

Pricing tiers

ModelBillingPrice
OtherMulti-year contractCustom Professional Services Engagement

Go-to-market motion1 record

Distribution channels2 records

Marketing channels10 records

SySS product offering

Product offering

Core offering

SySS is an IT security consultancy that performs manual penetration testing, ethical hacking, and security assessments against enterprise IT environments. Their core business is delivering project-based security testing engagements (web, API, mobile, network, cloud, OT) augmented by red teaming, digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Customers contract directly with SySS consultants for tailored engagements rather than licensing a software product.

Product overview

SySS GmbH is a German cybersecurity company offering a comprehensive portfolio of penetration testing and security assessment services. The core offering is the Penetrationstest (Pentest), a structured simulated attack on IT systems to identify security vulnerabilities. This core service is supplemented by specialized test modules including Webapp-Pentest, WEBSERVICE/API-Pentest, Mobile-App-Pentest, Netzwerk-Penetrationstest, OT-Pentest, WLAN-Pentest, and IP-Pentest for different target environments. Complementary services include Red Teaming (realistic APT-style attacks), Digitale Forensik (digital forensics and incident response), Threat Intelligence, Live-Hacking demonstrations, and Schulung (security training). The TARGET modules provide specialized assessments for phishing simulation (TARGET/PHISH) and client security testing (TARGET/TECH), while Purple Teaming combines offensive and defensive security evaluation. SySS also publishes Security Advisories documenting discovered vulnerabilities. The company operates primarily in the DACH region (Germany, Austria, Switzerland) with headquarters in Tübingen and branch offices in Frankfurt, Munich, and Vienna (SySS Cyber Security GmbH).

Differentiator

Problem solved

Functional benefit

Products and services

  • Penetrationstest (Pentest) Core service in which IT Security Consultants simulate cyberattacks on IT systems, web applications, networks, and infrastructure to identify security vulnerabilities before malicious hackers can exploit them. Sold to enterprise and organizational clients as a tailored, project-based engagement.
  • Technisches Consulting Neutral and independent IT security consulting providing expert guidance on security strategy, architecture, policies, and risk assessment for organizations that need to address incidents, post-pentest findings, new requirements, or outsourced security work.
  • Digitale Forensik und Incident Response Support for organizations during and after acute IT security incidents, including securing and analyzing court-admissible digital evidence and reconstructing attack patterns. Includes a dedicated 24/7 incident hotline (+49 7071 407856-99).
  • Red Teaming Realistic simulated attacks from an external perspective without prior internal knowledge, using APT techniques to test an organization's processes, technical controls, and employee awareness against targeted threats.
  • Threat Intelligence Collection, analysis, and contextualization of information about potential cyber risks to help organizations defend against digital threats targeting their environment.
  • Live-Hacking Live in-person demonstrations where SySS specialists show, in real time, how attackers gain access to third-party data, used to raise security awareness among employees and decision-makers.
  • Schulung (Security Training) Training programs for security officers and IT-responsible staff covering current IT security topics, methodologies, and hands-on hacking experience, including dedicated workshops such as Hack1/Hack2, Hack10 (network security), and Hack12 (Entra ID / Azure).
  • Purple Teaming Coordinated attack-and-defense exercises combining Red Team and Blue Team activities to improve detection capabilities, monitoring systems, and incident response processes for organizations with existing defensive teams.

Quantifiable outcome

  • Identification of security vulnerabilities before exploitation by attackers
  • +2 more outcomes

Companies that use SySS

Customer profile

Segments5 records

Ideal customer profiles5 records

SySS technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature9 records

SySS partnerships and signals

Strategic signal

Scale indicators3 records

Recent moves7 records

Expansion highlights5 records

SySS competitors and assessment

Company assessment

Market position

Competitive moat4 records

Key risks6 records

Key highlights7 records

Customer concentration

SySS social profiles

Digital presence

SySS financial estimates

Financial estimate

Revenue estimate

Valuation estimate

SySS leadership team

Management profile

Number of profiles

Profiles2 records

SySS subsidiaries and ownership

Company hierarchy

Subsidiaries1 record

SySS funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

SySS M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about SySS

What does SySS do?

SySS is an IT security consultancy that performs manual penetration testing, ethical hacking, and security assessments against enterprise IT environments. Their core business is delivering project-based security testing engagements (web, API, mobile, network, cloud, OT) augmented by red teaming, digital forensics and incident response, threat intelligence, live-hacking demonstrations, and security training. Customers contract directly with SySS consultants for tailored engagements rather than licensing a software product.

Is SySS a public or private company?

SySS is a private company. It is classified as founder individual operated bootstrapped and is currently operating.

When was SySS founded?

SySS was founded in 2005. It employs 51 to 100 people.

Where is SySS based?

SySS is headquartered in Tübingen, Germany, in the Europe region.

How does SySS make money?

Three revenue lines are on record. Professional Penetration Testing Services are the primary driver. The others are security Consulting and training and Education.

Does SySS have an API?

No public API is recorded for SySS.

What industry is SySS in?

SySS's product category is Penetration Testing & Cybersecurity Consulting. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 54151.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals