secAdair
secAdair is a Cologne-based cybersecurity and DevSecOps consulting boutique serving regulated German and DACH enterprises needing pragmatic ISMS/DSMS implementation and compliance with NIS2, DORA, BAIT, VAIT, and KRITIS, delivered via project-based engagements by a small team of certified specialists.
- Company typePrivate
- Founded2017
- HeadquartersCologne, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What secAdair does
secAdair GmbH is a Cologne-based cybersecurity consulting firm founded in 2017 that operates as a private, bootstrapped professional services boutique (1–10 employees). The company delivers three core service lines: (1) Cybersecurity/cyber resilience consulting focused on prevention and avoidance of attacks through pragmatic information security management; (2) DevSecOps services including secure coding, security code reviews, and secure deployment for agile teams; and (3) Compliance advisory implementing EU/German regulatory requirements (NIS2, DORA, BAIT, VAIT, KRITIS, GDPR) via ISMS and DSMS frameworks. Revenue is generated through project-based consulting engagements and retainer arrangements sold directly to enterprise clients, with no published pricing and no intermediaries.
The firm's go-to-market is built on direct enterprise engagement combined with thought-leadership content, most notably the monthly "Stand der Technik" podcast co-produced with commercial law firm HEUKING, which covers current IT-security and data-protection topics and serves as a top-of-funnel relationship channel. secAdair's customer base is horizontal, targeting regulated enterprises that must comply with EU cybersecurity directives, agile software organizations seeking DevSecOps integration, and any organization seeking pragmatic cyber resilience. The team holds OSCP, CISSP, and PECB ISO27001 Implementer/Auditor certifications, and the company operates a 24/7 cyber-incident emergency hotline (+49 221 5694 7927) out of its headquarters at Wolfsstraße 16, 50667 Köln. Ownership is concentrated in co-founders and Managing Directors Daniel Wasser and Jürgen Funke, with no disclosed external investors or parent company.
secAdair firmographics
Firmographics- Name
- secAdair
- Legal name
- secAdair GmbH
- Website
- https://secadair.de
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- secAdair is a Cologne-based cybersecurity and DevSecOps consulting boutique serving regulated German and DACH enterprises needing pragmatic ISMS/DSMS implementation and compliance with NIS2, DORA, BAIT, VAIT, and KRITIS, delivered via project-based engagements by a small team of certified specialists.
- Ownership category
- akta.pro rank
secAdair industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Governance, Risk & Compliance (GRC) & Security Management (EDAOAIAG)
Keywords
Where secAdair is headquartered
LocationHeadquarters
- HQ city
- Cologne
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
secAdair business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consulting Services: Professional consulting services for cybersecurity, including risk assessments, security audits, penetration testing, and incident response. Revenue is generated through project-based engagements and retainer arrangements with enterprise clients requiring ongoing security expertise.
- Compliance Advisory: Regulatory compliance consulting for NIS2, DORA, BAIT, VAIT, KRITIS, and data protection requirements. Implementation of ISMS and DSMS frameworks for clients.
- DevSecOps Services: Secure coding, security code reviews, and secure deployment services for agile development teams, helping organizations integrate security into their software development lifecycle.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
secAdair product offering
Product offeringCore offering
secAdair is a Cologne-based cybersecurity consulting firm that delivers pragmatic information security management, DevSecOps, and regulatory compliance services for German and EU-regulated enterprises. Its three core offerings are Cybersecurity (cyber resilience solution concepts to protect critical systems), DevSecOps (secure coding, security code reviews, and secure deployment for agile teams), and Compliance (pragmatic implementation of NIS2, BAIT, VAIT, DORA, DSGVO/GDPR, and ISMS/DSMS frameworks). The firm also operates a 24/7 cyber-incident emergency hotline and co-produces the 'Stand der Technik' podcast with HEUKING law firm.
Product overview
secAdair is an IT security consulting company offering three core services: Cybersecurity (notPwnd! through cyber resilience), DevSecOps (Secure Coding, Security Codereviews, and Secure Deployment), and Compliance (NIS2, BAIT, VAIT, DORA, DSGVO implementation). The company also produces the 'Stand der Technik' podcast on data protection and IT security in partnership with HEUKING law firm. All services are delivered by certified professionals (OSCP, CISSP, PECB ISO27001) with expertise spanning technical cybersecurity, DevSecOps, network, pentest, and regulatory compliance.
Differentiator
Problem solved
Functional benefit
Products and services
- Cybersicherheit (Cybersecurity)
Quantifiable outcome
- Pragmatic, value-adding implementation of regulatory requirements
Companies that use secAdair
Customer profileSegments3 records
Ideal customer profiles3 records
secAdair technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
secAdair partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- HEUKING (Law Firm)coreStrategic partnership with commercial law firm HEUKING for joint podcast production. The monthly 'Stand der Technik' podcast is co-hosted by HEUKING lawyers Dr. Lutz Keppeler and Manuel Poncza along with secAdair co-founder Daniel Wasser. The podcast covers current IT security and data protection topics including NIS2, DORA, CRA, and GDPR, positioning both firms as thought leaders in the German cybersecurity and data protection space.
Scale indicators1 record
secAdair competitors and assessment
Company assessmentBroad incumbents
- WithSecure (formerly F-Secure Cyber Security Consulting): WithSecure runs an established European cybersecurity consulting practice covering offensive security, incident response, and compliance advisory. A broader incumbent with overlapping service lines and European regulated-enterprise customers.
- msg systems AG: msg is a large German IT/services group with a substantial cybersecurity and compliance practice serving regulated industries (finance, insurance, healthcare). Broader incumbent competing for the same NIS2/BAIT/VAIT enterprise budgets that secAdair targets.
- Orange Cyberdefense Germany: Orange Cyberdefense is a major European MSSP/consultancy with a German presence offering managed SOC, pentesting, and compliance advisory. Broad incumbent competing for the same enterprise CISOs and regulated-entity RFPs.
- TÜV SÜD (cybersecurity services): TÜV SÜD operates a sizable cybersecurity and information security certification/audit business serving regulated German enterprises. A broad incumbent competing for ISMS/ISO27001 and KRITIS-related compliance work.
Direct peers
- SySS GmbH: SySS is a Tübingen-based German cybersecurity consultancy offering penetration testing, secure software review, and incident response. It is a direct competitor in the same DACH pentesting/DevSecOps niche that secAdair targets.
- Cure53: Berlin-based Cure53 is a boutique German security consultancy focused on penetration testing, code review, and security research. Comparable as a small, highly technical boutique serving similar enterprise clients.
- Security Research Labs (SRLabs): Berlin-based SRLabs provides security consulting, penetration testing, and cryptography advisory to enterprises and governments. Direct competitor in the boutique German cybersecurity consulting space with overlapping technical and advisory offerings.
- usd AG: usd AG is a German security consulting firm specializing in ISMS/ISO 27001 implementation, penetration testing, and compliance auditing — a direct peer across both secAdair's compliance and DevSecOps service lines.
Regional players
- Hornetsecurity: Hannover-based Hornetsecurity is a German cybersecurity vendor with adjacent managed services around email security, backup, and compliance; while more product-led, it competes for the same German SMB/mid-market compliance budgets.
Emerging players
- SoSafe (awareness/security culture): Cologne-based SoSafe is an emerging German cybersecurity scale-up focused on security awareness and phishing simulation. It shares the DACH cybersecurity ecosystem and overlapping buyer audience (CISOs, compliance leads) even though its product is adjacent rather than directly competing.
Market position
Strengths5 records
Weaknesses5 records
Key risks6 records
Key highlights5 records
Customer concentration
secAdair social profiles
Digital presencesecAdair compliance and trust
Trust signalCompliance3 records
secAdair financial estimates
Financial estimateRevenue estimate
Valuation estimate
secAdair leadership team
Management profileNumber of profiles
Profiles2 records
secAdair funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
secAdair M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about secAdair
What does secAdair do?
secAdair is a Cologne-based cybersecurity consulting firm that delivers pragmatic information security management, DevSecOps, and regulatory compliance services for German and EU-regulated enterprises. Its three core offerings are Cybersecurity (cyber resilience solution concepts to protect critical systems), DevSecOps (secure coding, security code reviews, and secure deployment for agile teams), and Compliance (pragmatic implementation of NIS2, BAIT, VAIT, DORA, DSGVO/GDPR, and ISMS/DSMS frameworks). The firm also operates a 24/7 cyber-incident emergency hotline and co-produces the 'Stand der Technik' podcast with HEUKING law firm.
Is secAdair a public or private company?
secAdair is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was secAdair founded?
secAdair was founded in 2017. It employs 1 to 10 people.
Where is secAdair based?
secAdair is headquartered in Cologne, Germany, in the Europe region.
How does secAdair make money?
Three revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are compliance Advisory and devSecOps Services.
Who are secAdair's main competitors?
Broad incumbents on record are WithSecure (formerly F-Secure Cyber Security Consulting), msg systems AG, Orange Cyberdefense Germany and TÜV SÜD (cybersecurity services). Direct peers are SySS GmbH, Cure53, Security Research Labs (SRLabs) and usd AG. Hornetsecurity is listed as a regional player. SoSafe (awareness/security culture) is listed as an emerging player.
Does secAdair have an API?
No public API is recorded for secAdair.
What industry is secAdair in?
secAdair's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory. Its NAICS code is 54151.