F-IT Security and Audit
F-IT Security and Audit GmbH is a German boutique consultancy specializing in IT security, IT audit, and regulatory compliance (BAIT, VAIT, KAIT, DORA) for large enterprises and system-critical banks in the DACH financial sector.
- Company typePrivate
- Founded2015
- HeadquartersPansfelde, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What F-IT Security and Audit does
F-IT Security and Audit GmbH is a privately held, Erkrath-based IT consulting firm (GmbH registered at AG Wuppertal, HRB 35242) specializing in information security, IT audit/revision, and regulatory compliance for the German regulated financial sector. Its service portfolio covers Information Security (security architecture, 24/7 SOC support, SIEM, vulnerability management, privileged access management), IT Audit support for 2nd and 3rd lines of defense, Regulatory Compliance advisory for BAIT, VAIT, KAIT, and DORA, IT sourcing advisory (out- and insourcing in the BaFin-regulated sector), training/workshops (offered since 1992), and technology and process support including Mainframe (zSecure) and ServiceNow. The firm's differentiators are deep regulatory domain knowledge, a codified "Audit Defense" methodology for managing multiple concurrent audit requests, and a senior leadership profile anchored by Managing Director Christoph Franke (CISA-accredited since 2005).
The business operates as a boutique professional services firm: revenue is generated through project-based consulting and retainer-style engagements with no online contracting, pricing is bespoke (quotes issued on request alongside AGB), and go-to-market is enterprise field sales driven by direct outreach, professional networks (LinkedIn, Xing), referrals, and thought leadership. The technology stack leverages third-party tools rather than proprietary platforms — ServiceNow for workflow, Qualys and Nessus for vulnerability management, SIEM platforms for SOC operations, and zSecure for mainframe privileged access — positioning F-IT as an implementation and operations partner rather than a software vendor. The team consists of 1-10 experienced professionals, and the firm explicitly targets large enterprises and clients with high IT-compliance requirements, primarily banks, financial service providers, asset management firms, insurance companies, and the IT service providers serving them in the DACH region. Reference customers include MHB and Finanz Informatik Technologie Service, both system-critical banking IT environments.
F-IT Security and Audit firmographics
Firmographics- Name
- F-IT Security and Audit
- Legal name
- F-IT Security and Audit GmbH
- Website
- https://f-it.biz
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- F-IT Security and Audit GmbH is a German boutique consultancy specializing in IT security, IT audit, and regulatory compliance (BAIT, VAIT, KAIT, DORA) for large enterprises and system-critical banks in the DACH financial sector.
- Ownership category
- akta.pro rank
F-IT Security and Audit industry classification
Industry- Product category
- IT Security and Audit Consulting
- NAICS
- Management, Scientific, and Technical Consulting Services (5416), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
Keywords
Where F-IT Security and Audit is headquartered
LocationHeadquarters
- HQ city
- Pansfelde
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
F-IT Security and Audit business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Professional Services: The company generates revenue through consulting and professional services engagements. Services include IT security architecture, IT audit support, regulatory compliance implementation, SOC support, training, and workshops. Engagements are likely project-based or retainer arrangements for ongoing support.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
F-IT Security and Audit product offering
Product offeringCore offering
F-IT Security and Audit GmbH is a German consulting firm specializing in IT security, IT audit/revision, and regulatory compliance services for the BaFin-regulated financial sector. The company delivers security architecture design, SOC operations support (including 24/7 SOC establishment), vulnerability management, privileged access management, and IT audit examination support (2nd/3rd line of defense). Additional offerings include regulatory compliance advisory (BAIT, VAIT, KAIT, DORA), IT out/insourcing advisory, training and workshops, and technology/process support leveraging Mainframe, ServiceNow, Qualys, Nessus, and zSecure.
Product overview
F-IT Security and Audit GmbH is a consulting services firm specializing in IT security, IT audit/revision, and information security. The company offers a portfolio of interconnected services including Information Security (covering SOC operations, SIEM, incident management), IT Audit (with CISA-accredited expertise), Regulatory Compliance (BAIT, VAIT, KAIT, DORA), Sourcing advisory, Training/Workshops, and Technology & Process support. Their services are primarily targeted at large enterprises and clients with high IT compliance requirements, particularly in the regulated financial sector. They support tool-based processes using platforms such as ServiceNow, Qualys, Nessus, and zSecure.
Differentiator
Problem solved
Functional benefit
Products and services
- Information Security (Informationssicherheit)
Quantifiable outcome
- Successfully established and currently operating a 24/7 SOC for a client where the company played key role as Senior Security Architect and provides ongoing support as Security Incident Manager or L2-Analyst
- +1 more outcomes
Companies that use F-IT Security and Audit
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles2 records
F-IT Security and Audit technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
F-IT Security and Audit partnerships and signals
Strategic signalScale indicators5 records
Recent moves6 records
Expansion highlights5 records
F-IT Security and Audit competitors and assessment
Company assessmentDirect peers
- SRC Security Research & Consulting GmbH: SRC is a German security consultancy offering penetration testing, ISO 27001/GRC advisory, and IT security audit support for regulated organizations — directly comparable to F-IT's information security and IT audit portfolio.
- msg: msg is a large German IT consulting and software firm with a strong regulated-industry (banking/insurance) practice covering IT security, audit, governance and regulatory compliance — directly overlapping with F-IT's BAIT/VAIT/DORA and ServiceNow-based GRC work, but at significantly larger scale.
- usd AG: usd AG is a German security consulting firm specializing in PCI DSS, ISO 27001, compliance audits and security testing — a comparable boutique competitor focused on regulated compliance and audit services.
- HiSolutions AG: HiSolutions is a German security and risk management consultancy specializing in information security, GRC and IT audit for regulated enterprises — a closely comparable boutique competitor in the same German-speaking market.
Broad incumbents
- secunet Security Networks AG: secunet is a larger, publicly listed German IT security provider serving government, critical infrastructure and regulated industries with consulting, products and managed security services — overlapping with F-IT's regulated-sector security work but at substantially greater scale and breadth.
- KPMG Germany: KPMG Germany's IT Advisory and Financial Risk practices deliver regulatory compliance, IT audit, cybersecurity and DORA implementation services — overlapping directly with F-IT's core service lines for German banks and insurers.
- T-Systems International: T-Systems (Deutsche Telekom subsidiary) delivers large-scale IT security, SOC and regulatory compliance services to European banks and insurers — overlapping with F-IT's SOC and DORA work, but serving enterprise-scale clients with bundled managed-service offerings.
- TÜV Rheinland i-sec GmbH: TÜV Rheinland's information security division provides IT/cybersecurity audits, ISO certifications, and compliance advisory across regulated industries — directly comparable to F-IT's audit and BAIT/ISO 27001 work, with much broader geographic and service reach.
- PwC Germany: PwC's Financial Services Risk & Regulation practice in Germany covers BAIT, VAIT, KAIT, DORA and IT audit — a broad incumbent that competes with F-IT for the same BaFin-regulated advisory engagements, especially at scale.
- Deloitte (Germany): Deloitte's Risk & Regulatory practice serves German banks and insurers on BAIT/DORA compliance, IT audit, cyber risk and governance — a Big Four incumbent competing for the same regulatory and audit mandates as F-IT, particularly for mid-to-large institutions.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
F-IT Security and Audit social profiles
Digital presenceF-IT Security and Audit compliance and trust
Trust signalCompliance8 records
F-IT Security and Audit financial estimates
Financial estimateRevenue estimate
Valuation estimate
F-IT Security and Audit leadership team
Management profileNumber of profiles
Profiles1 record
F-IT Security and Audit funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
F-IT Security and Audit M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about F-IT Security and Audit
What does F-IT Security and Audit do?
F-IT Security and Audit GmbH is a German consulting firm specializing in IT security, IT audit/revision, and regulatory compliance services for the BaFin-regulated financial sector. The company delivers security architecture design, SOC operations support (including 24/7 SOC establishment), vulnerability management, privileged access management, and IT audit examination support (2nd/3rd line of defense). Additional offerings include regulatory compliance advisory (BAIT, VAIT, KAIT, DORA), IT out/insourcing advisory, training and workshops, and technology/process support leveraging Mainframe, ServiceNow, Qualys, Nessus, and zSecure.
Is F-IT Security and Audit a public or private company?
F-IT Security and Audit is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was F-IT Security and Audit founded?
F-IT Security and Audit was founded in 2015. It employs 1 to 10 people.
Where is F-IT Security and Audit based?
F-IT Security and Audit is headquartered in Pansfelde, Germany, in the Europe region.
How does F-IT Security and Audit make money?
One revenue line is on record: professional Services.
Who are F-IT Security and Audit's main competitors?
Direct peers on record are SRC Security Research & Consulting GmbH, msg, usd AG and HiSolutions AG. Broad incumbents are secunet Security Networks AG, KPMG Germany, T-Systems International, TÜV Rheinland i-sec GmbH, PwC Germany and Deloitte (Germany).
Does F-IT Security and Audit have an API?
No public API is recorded for F-IT Security and Audit.
What industry is F-IT Security and Audit in?
F-IT Security and Audit's product category is IT Security and Audit Consulting. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory. Its NAICS code is 5416 and its SIC code is 8700.