iSecNG
iSecNG is a Dortmund-based managed security services provider delivering Managed Detection & Response — Managed SIEM (Wazuh/Splunk), 24/7 SOC, EDR, Incident Response, and offensive security — exclusively to the German Mittelstand from German personnel and infrastructure.
- Company typePrivate
- Founded2023
- HeadquartersDortmund, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What iSecNG does
iSecNG GmbH is a privately held German managed security services provider (MSSP) headquartered in Dortmund, founded in 2023 by Stephan Gerhager (former CISO of E.ON, Allianz Deutschland, and CARIAD) with 11 co-founders drawn from a DAX-company security team. The company delivers a unified Managed Detection & Response (MDR) platform that bundles prevention, detection, and response services for the German Mittelstand — small-to-large SMEs typically employing 100 to 2,000+ people — as well as regulated German enterprises in insurance, finance, and critical infrastructure. Headcount stood at 20 employees as of 2026, distributed across Germany with a Berlin operating footprint.
The product portfolio spans Managed SIEM on Wazuh (open-source, priced €1,600–€5,500/month by storage tier) and Splunk (€2,700–€12,400/month by ingest volume); a 24/7 Managed SOC (€800–€12,000/month by investigation volume, delivered entirely by Level 3 analysts with no tier-1/tier-2 triage); EDR via HarfangLab Guard feat. IKARUS at €7/device/month; Incident Response at €185–€200/hour; plus Advanced Rules (SIGMA-format detection rules), Penetration Testing, Red Teaming, Threat-Led Penetration Services, Darknet/Credential Monitoring, Security Vorträge (paid speaking engagements), and Digitale Forensik (court-admissible forensics, in development). The underlying infrastructure runs on dedicated Bare Metal Kubernetes via Metalstack Cloud (operated by x-cellent Technologies) in Munich, deployed through GitOps (ArgoCD) and CI/CD pipelines, with a dedicated per-customer SIEM instance architecture and no multi-tenant data mixing.
Revenue mechanics are overwhelmingly subscription-recurring across monthly tiered SIEM, SOC, and EDR contracts, supplemented by hourly professional services (IR, SIEM Beratung) and project-based offensive security. Go-to-market is direct enterprise sales via email and Google Calendar booking, supported by content-led demand generation (technical blog, GitHub open-source contributions, r/Wazuh_de community moderation, LinkedIn), and conference speaking by CISO-level founders (Stephan Gerhager, Dominik Sigl). All services are delivered exclusively from Germany with 100% German data residency and zero foreign vendor dependencies — the central commercial differentiator in a market where Patriot Act exposure is a deal-breaker for many German enterprises. Named customers include Adesso SE, a large German insurance company, a Baden-Württemberg tool manufacturer, and an elastomer-technology manufacturer. The company is bootstrapped with no disclosed external funding.
iSecNG firmographics
Firmographics- Name
- iSecNG
- Legal name
- iSecNG GmbH
- Website
- https://isecng.de
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- iSecNG is a Dortmund-based managed security services provider delivering Managed Detection & Response — Managed SIEM (Wazuh/Splunk), 24/7 SOC, EDR, Incident Response, and offensive security — exclusively to the German Mittelstand from German personnel and infrastructure.
- Ownership category
- akta.pro rank
iSecNG industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Email Phishing & BEC Protection (HDADAKAB)
Keywords
Where iSecNG is headquartered
LocationHeadquarters
- HQ city
- Dortmund
- HQ country
- Germany
- HQ region
- Europe
Offices2 records
Markets served
iSecNG business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Managed SIEM Services: Monthly recurring subscription fees for managed Wazuh and Splunk SIEM services, priced in tiered packages based on storage capacity (hot storage GB) and log ingestion volume. Includes 30-day hot storage retention and 365-day cold storage.
- Managed SOC Services: Monthly recurring subscription for 24/7 SOC monitoring, alert investigation, and threat hunting. Tiered by investigation volume (10-250 investigations/month) with fixed SLAs.
- Advanced Rules / Managed Detection Rules: Monthly subscription for custom SIEM detection rules developed in SIGMA format, maintained and staged by iSecNG experts, priced per number of rules (10-250+).
- Incident Response: Hourly billing for incident response services (200 €/hour without SOC contract, 185 €/hour with SOC contract). Certified German experts provide containment, root cause analysis, and hardening.
- Wazuh Support: Monthly subscription for Wazuh support packages (210-1,650 €/month based on agent count), with guaranteed SLAs, Level 3 support, and developer-level Wazuh access.
- SIEM Consulting: Hourly billing (180 €/hour) for vendor-independent SIEM implementation consulting covering sizing, architecture, log source selection, and integration.
- Security Vorträge / Speaking: One-time fees for security presentations (500 €/hour for Security Vortrag) and keynotes (3,000 € flat for Key-Note), delivered by CISO-level speakers with option for live hacking demos.
- Penetration Testing & Red Teaming: Project-based professional services for offensive security assessments. Pricing based on scope, technology complexity, and duration (typically 3 days to 3 weeks).
- Darknet / Credential Monitoring: Subscription service (pricing on inquiry) in partnership with Identeco for 24/7 darknet monitoring of leaked credentials and brand mentions.
- EDR Service: Monthly per-device subscription (7 €/device/month) for HarfangLab Guard EDR, covering Windows, Linux, macOS endpoints with threat hunting and automated response.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Wazuh SIEM XXS: 1,600 €/mo, 100 GB hot storage |
| Subscription | Monthly | Splunk SIEM: 2,700–12,400 €/mo, 3–64 GB/day ingress |
| Subscription | Monthly | SOC Service: 800–12,000 €/mo, 10–250 investigations |
| Subscription | Pay-as-you-go | Incident Response: 185–200 €/hour |
| Subscription | Pay-as-you-go | SIEM Consulting: 180 €/hour |
| Subscription | Monthly | Advanced Rules: 360–6,900 €/mo, 10–250 rules |
| Subscription | Monthly | Wazuh Support: 210–1,650 €/mo, 25–1,000 agents |
| Unit Pricing | Monthly | EDR: 7 €/device/month |
| Other | Pay-as-you-go | Security Vortrag: 500 €/hour; Key-Note: 3,000 € flat |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels8 records
iSecNG product offering
Product offeringCore offering
iSecNG is a German managed security services provider that delivers Managed Detection & Response (MDR) for the German Mittelstand. Its core offerings are managed SIEM services on Wazuh and Splunk, a 24/7 SOC service, EDR via HarfangLab Guard featuring IKARUS, and incident response with digital forensics — all operated exclusively by German personnel from a Munich data center. Complementary services include penetration testing, red teaming, advanced detection rules, darknet credential monitoring, SIEM consulting, Wazuh support, and paid security speaking engagements.
Product overview
iSecNG is a German managed security services provider offering a unified MDR (Managed Detection & Response) platform combining prevention, detection, and response services. The core offering includes two Managed SIEM options (Wazuh SIEM Service and Splunk SIEM Service), a 24/7 SOC Service, EDR Service (using HarfangLab Guard), and Incident Response. Prevention services encompass Penetration Testing, Red Teaming, Advanced Rules Service, Leaked Credential Monitoring, and Security Vorträge. Detection services include SIEM Beratung and Wazuh Support. Response services comprise SOC Service, Incident Response, and Digitale Forensik. All services are delivered exclusively from Germany with German data hosting, targeting the German Mittelstand.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection & Response (MDR) Comprehensive managed security service combining prevention, detection and response capabilities (Managed SIEM, SOC, EDR, and Incident Response) into a unified offering for the German Mittelstand.
- Wazuh SIEM Service Managed SIEM on the open-source Wazuh platform hosted on dedicated bare-metal Kubernetes in Munich via Metalstack Cloud, providing real-time security analysis of logs from servers, firewalls, cloud services and endpoints, operated by L3 security experts.
- Splunk SIEM Service Managed Splunk SIEM service for real-time security anomaly detection across IT infrastructure, with flexible log ingestion via Syslog, APIs and agents, and optional Splunk Enterprise Security add-on.
- SOC Service 24/7 Managed Security Operations Center providing continuous monitoring, alert investigation and threat hunting by L3-level experts, with threat intelligence and patterns drawn from iSecNG's multi-customer footprint.
- EDR Service Endpoint Detection & Response service using HarfangLab Guard feat. IKARUS, a European EDR solution known from critical infrastructure with self-protection mechanisms that prevent agent uninstallation, covering Windows, Linux and macOS endpoints.
- Incident Response Certified incident response experts providing rapid containment, structured root cause analysis and post-incident hardening following NIST and BSI frameworks, with forensic capabilities through partner HVS-Consulting.
- Penetration Testing Professional penetration testing combining manual and automated methods to identify vulnerabilities in infrastructure and applications, performed by SANS and Offensive Security certified experts.
- Red Teaming Realistic attacker simulation using only publicly available OSINT information to test organizational resilience, conducted by small teams of experienced experts without prior credentials.
- Advanced Rules Service Custom detection rules developed in SIGMA format and converted for the customer's SIEM, providing tailored threat detection with low false positives based on current attacker group behavior.
- Leaked Credential Monitoring 24/7 Darknet monitoring for compromised credentials, brand mentions and intellectual property, provided through partnership with Identeco and integrated with Managed SIEM or SOC services where applicable.
- Security Vorträge (Paid Speaking)
Quantifiable outcome
- Dedicated SIEM instances per customer — no multi-tenant data mixing
- +3 more outcomes
Companies that use iSecNG
Customer profileNamed customers4 records
Segments2 records
Ideal customer profiles2 records
iSecNG technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability2 records
Feature6 records
iSecNG partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- WazuhcoreiSecNG is a Wazuh Platinum Partner — the highest tier of the Wazuh partner program. The partnership provides direct access to the Wazuh product development team, early access to features, and exclusive support resources. Dominik Sigl serves as the official Wazuh Ambassador for the DACH region and co-moderates the r/Wazuh_de German Reddit community.
- x-cellent Technologiescorex-cellent Technologies operates the Metalstack Cloud infrastructure on which iSecNG's managed SIEM services run. The infrastructure is located in a Munich data center and provides Bare Metal Kubernetes as a Service with automated hardware scaling, enabling iSecNG to offer dedicated, isolated SIEM instances per customer.
- Metalstack CloudcoreMetalstack Cloud provides the Kubernetes-based infrastructure for iSecNG's managed SIEM platform. iSecNG's ArgoCD integration guide for Metalstack clusters is included in Metalstack's official documentation. The infrastructure enables GitOps-driven CI/CD for SIEM operations.
- HVS-ConsultingminorForensic partner for court-admissible digital forensics. A retainer with HVS-Consulting is included in iSecNG's Managed SOC service for severe security incidents requiring forensic analysis. Represents a supplementary resource rather than a primary service component.
- Allianz für Cyber-Sicherheit (Alliance for Cyber Security)minoriSecNG is a member of the Allianz für Cyber-Sicherheit, a German public-private partnership initiative coordinated by the BSI (Federal Office for Information Security) to strengthen cyber security in Germany. Displayed as a member badge on the iSecNG website.
Scale indicators6 records
Recent moves7 records
Expansion highlights6 records
iSecNG competitors and assessment
Company assessmentMarket position
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
iSecNG social profiles
Digital presenceiSecNG compliance and trust
Trust signalCompliance3 records
iSecNG financial estimates
Financial estimateRevenue estimate
Valuation estimate
iSecNG leadership team
Management profileNumber of profiles
Profiles5 records
iSecNG funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
iSecNG M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about iSecNG
What does iSecNG do?
iSecNG is a German managed security services provider that delivers Managed Detection & Response (MDR) for the German Mittelstand. Its core offerings are managed SIEM services on Wazuh and Splunk, a 24/7 SOC service, EDR via HarfangLab Guard featuring IKARUS, and incident response with digital forensics — all operated exclusively by German personnel from a Munich data center. Complementary services include penetration testing, red teaming, advanced detection rules, darknet credential monitoring, SIEM consulting, Wazuh support, and paid security speaking engagements.
Is iSecNG a public or private company?
iSecNG is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was iSecNG founded?
iSecNG was founded in 2023. It employs 1 to 10 people.
Where is iSecNG based?
iSecNG is headquartered in Dortmund, Germany, in the Europe region.
How does iSecNG make money?
Ten revenue lines are on record. Managed SIEM Services are the primary driver. The others are managed SOC Services, advanced Rules / Managed Detection Rules, incident Response, wazuh Support, SIEM Consulting, security Vorträge / Speaking, penetration Testing & Red Teaming, darknet / Credential Monitoring and EDR Service.
Does iSecNG have an API?
No public API is recorded for iSecNG.
What industry is iSecNG in?
iSecNG's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is HDADAKAB, Email Phishing & BEC Protection. Its NAICS code is 54151 and its SIC code is 7370.