Securitum
Securitum is a Kraków-based penetration testing firm employing 52 people, including 35+ certified pentesters, that delivers web, mobile, infrastructure, cloud, and red team security testing to 300+ enterprise clients across Europe, with specialized DORA and NIS2 compliance services.
- Company typePrivate
- Founded2009
- HeadquartersKraków, Poland
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Securitum does
Securitum is a Poland-based penetration testing services company founded in 2009 and headquartered in Kraków, operating through the legal entity Securitum Audyty Sp. z o.o. The company employs 52 people, including more than 35 certified penetration testers holding credentials such as OSCP, OSWE, CISSP, ECPTX, and EWPTX, positioning itself as one of the largest penetration testing firms in Central and Eastern Europe. Securitum delivers a comprehensive portfolio of security testing services spanning web and mobile application testing, infrastructure testing, cloud security assessments, red teaming, SSDLC implementation, social engineering, configuration analysis, OSINT, source code review, and desktop/console application testing. Sub-products include CyberScan Pro (external network scanning in four tiers), Periodic External Network Scanning (recurring audits), DORA Analysis with Threat-Led Penetration Testing for financial institutions, and UKSC/NIS2 Zero Audit gap analysis for critical infrastructure operators.
The company's service delivery model combines manual expert analysis with industry-standard automated tools (Nessus Professional, Burp Suite Pro, sslscan, Kali Linux distribution) and includes manual verification of automated scan results to filter false positives. Operational scale indicators include approximately 750 security tests performed yearly for 300+ clients, with cumulative figures of 2,776 penetration tests and 10,000+ vulnerabilities detected over the past three years. Named enterprise customers span financial services (BNP Paribas, Alior Bank, Nationale Nederlanden, BOŚ Bank, Aegon), technology (Proton AG, Alphabet, Cast AI, X-KOM), retail/e-commerce (Ocado Technology UK, Baselinker, Answear, Superpharm), automotive (Volkswagen), and healthcare (Medicover, apoQlar GmbH), with documented multi-year engagements (e.g., Proton AG 2022-2025).
Securitum generates revenue primarily through project-based professional services engagements priced after scope interviews, with periodic external scanning offered on a recurring basis. Distribution is sales-led via direct phone and email outreach, with a dedicated Project Manager assigned to each engagement and a brand ambassador referral program supplementing direct sales. Marketing relies on thought leadership: the company owns and operates the Sekurak Hacking Party conference (24 editions since 2019, with the 2024 MEGA edition attracting approximately 1,200 attendees), publishes the Pentest Chronicles technical blog, and publicly releases penetration testing reports demonstrating technical credibility to prospects and recruits.
Securitum firmographics
Firmographics- Name
- Securitum
- Legal name
- Securitum Audyty Sp. z o.o.
- Website
- https://securitum.com
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Securitum is a Kraków-based penetration testing firm employing 52 people, including 35+ certified pentesters, that delivers web, mobile, infrastructure, cloud, and red team security testing to 300+ enterprise clients across Europe, with specialized DORA and NIS2 compliance services.
- Ownership category
- akta.pro rank
Securitum industry classification
Industry- Product category
- Cybersecurity Penetration Testing Services
- NAICS
- Security Systems Services (56162)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where Securitum is headquartered
LocationHeadquarters
- HQ city
- Kraków
- HQ country
- Poland
- HQ region
- Europe
Offices1 record
Markets served
Securitum business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Professional Penetration Testing Services: Core revenue stream from penetration testing services including web application, mobile, infrastructure, cloud security, red teaming, SSDLC implementation, configuration analysis, OSINT, desktop/console applications, and source code review. Services are project-based and quoted according to scope.
- Periodic Security Audits: Recurring security audit services including external network scanning performed on regular basis for optimal results and ongoing security monitoring.
- Compliance Audit Services: DORA analysis and UKSC/NIS2 zero audit services for financial institutions and organizations subject to cybersecurity regulations. Implementation phase services are priced separately after audit completion.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | UKSC Zero Audit starting price for gap analysis |
| Other | Pay-as-you-go | CyberScan Pro 4-tier pricing structure |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
Securitum product offering
Product offeringCore offering
Securitum provides professional penetration testing services covering web applications, mobile applications, infrastructure, cloud environments, source code, desktop/console applications, social engineering, OSINT, configuration analysis, SSDLC implementation, and red teaming. The company also delivers specialized compliance audits including DORA Threat-Led Penetration Testing for financial institutions and NIS2/UKSC gap analysis, alongside recurring external network scanning via its CyberScan Pro service.
Product overview
Securitum is a penetration testing services company offering a portfolio of specialized security testing services. The core offerings include web application, mobile application, infrastructure, cloud security, social engineering, red teaming, configuration analysis, OSINT, source code review, and desktop/console application testing. The portfolio includes specialized sub-products such as CyberScan Pro (external network scanning with four pricing tiers), Periodic External Network Scanning (recurring security audits), DORA Analysis (financial sector compliance with TLPT testing), and UKSC/NIS2 Zero Audit (regulatory gap analysis). Services are delivered by certified penetration testers using industry-standard tools and methodologies.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Application Penetration Testing Security testing service that evaluates web application security by simulating attacks using automated and manual techniques to identify exploitable vulnerabilities, intended for organizations seeking to assess their web-facing systems.
- Mobile Application Penetration Testing Testing service combining manual and automated techniques to assess mobile application security controls, identify vulnerabilities, and determine the potential impact of attacks on iOS and Android applications.
- Infrastructure Penetration Testing Network infrastructure security testing that simulates attacks to identify exploitable vulnerabilities in servers, network devices, and applications for enterprise IT environments.
- Cloud Security & Cloud Assessment Risk analysis and security assessment for cloud-based systems, evaluating vulnerabilities and ensuring adequate protection of data stored on remote cloud servers.
- Social Engineering Testing service that evaluates organizational vulnerability to human-based attacks including phishing, vishing, and other manipulation techniques targeting personnel.
- SSDLC Implementation Secure Software Development Life Cycle implementation service that integrates security measures at each stage of the software development process for development teams.
- Configuration Analysis Security audit service that reviews system and application configurations to identify misconfigurations and security weaknesses across the IT estate.
- OSINT Open Source Intelligence gathering service that collects and analyzes publicly available information to identify potential security risks and external attack surfaces.
- Desktop & Console Applications Testing Security testing service for desktop and console applications including interface analysis, protocol testing, and custom network protocol assessment.
- Source Code Review White-box security assessment that analyzes source code to identify vulnerabilities, security weaknesses, and compliance issues for development teams.
- Red Teaming Comprehensive attack simulation service conducted by ethical hackers that tests organizational security through reconnaissance, exploitation, and post-exploitation phases.
- CyberScan Pro External network scanning service providing vulnerability scanning, dark web analysis, certificate transparency database domain discovery, and social media security checks, offered in four tiers (Basic, Standard, Advanced, Expert).
- Periodic External Network Scanning Recurring security audit service for external infrastructure that detects vulnerabilities and misconfigurations through regular scanning using professional tools like Nessus, Burp Suite Pro, and sslscan.
- DORA Analysis Digital Operational Resilience Act (DORA) compliance audit for financial institutions, including Threat-Led Penetration Testing (TLPT) with dedicated Threat Intelligence Provider (TIP) team and Red Team phases for full-scope multi-layered attack simulation.
- UKSC/NIS2 Zero Audit Gap analysis and compliance assessment service for the Act on National Cybersecurity System implementing the NIS2 Directive, including documentation review, staff interviews, gap analysis report, and implementation roadmap development.
Quantifiable outcome
- 2,776 penetration tests completed in last 3 years
- +2 more outcomes
Companies that use Securitum
Customer profileNamed customers20 records
Segments3 records
Ideal customer profiles1 record
Securitum technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Securitum partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Brand Ambassador PartnersminorPartnership program for individuals or companies that refer new customers to Securitum's penetration testing services. Ambassadors earn commission (or company discount if referring their own employer) for introductions without any sales work required.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Securitum competitors and assessment
Company assessmentOthers
- OffSec (Offensive Security): Cybersecurity training and consulting firm (creators of OSCP) that runs professional penetration testing services and trains many of the same certified practitioners in Securitum's talent pool; adjacent ecosystem participant.
Broad incumbents
- Orange Cyberdefense: Large European MSSP and security consultancy with extensive penetration testing, threat intelligence and red team capabilities as part of broader managed services; competes on regulated-sector and cross-border enterprise contracts.
- NCC Group: Global cybersecurity consulting firm with a very large dedicated penetration testing practice serving financial and enterprise clients across Europe; comparable for regulated-sector pentest and TLPT work, but operates as a broader portfolio incumbent rather than a specialist.
- WithSecure (formerly F-Secure): European cybersecurity vendor offering consulting and penetration testing alongside endpoint and managed detection products; comparable for enterprise compliance-driven pentest engagements in the EU market.
Direct peers
- Bishop Fox: Specialist US-based offensive security and penetration testing firm delivering web, mobile, network and red team services to enterprise and financial clients; highly comparable boutique positioning and methodology to Securitum.
- Pen Test Partners: UK-based penetration testing specialist serving financial services, retail, and tech with a multi-tester team; closest European boutique comparable in service mix and target verticals to Securitum.
- NetSPI: Pure-play penetration testing and attack surface management firm using combined automated tooling and human-led testing; competes directly with Securitum for enterprise pentest mandates in Europe and globally.
- Secarma: UK cybersecurity consultancy with core penetration testing, red teaming and managed security testing offerings; comparable boutique specialist competing for European enterprise and financial pentest deals.
- Coalfire: US-headquartered cybersecurity advisory and penetration testing firm with strong financial-services and compliance focus, including DORA-adjacent resilience assessments; competing peer in regulated sector pentesting.
Emerging players
- Holm Security: Sweden-based vulnerability management and automated penetration testing platform provider that overlaps with Securitum's CyberScan Pro and external scanning offerings; partial overlap in vulnerability assessment use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Securitum social profiles
Digital presenceSecuritum financial estimates
Financial estimateRevenue estimate
Valuation estimate
Securitum leadership team
Management profileNumber of profiles
Profiles8 records
Securitum funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Securitum M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Securitum
What does Securitum do?
Securitum provides professional penetration testing services covering web applications, mobile applications, infrastructure, cloud environments, source code, desktop/console applications, social engineering, OSINT, configuration analysis, SSDLC implementation, and red teaming. The company also delivers specialized compliance audits including DORA Threat-Led Penetration Testing for financial institutions and NIS2/UKSC gap analysis, alongside recurring external network scanning via its CyberScan Pro service.
Is Securitum a public or private company?
Securitum is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Securitum founded?
Securitum was founded in 2009. It employs 51 to 100 people.
Where is Securitum based?
Securitum is headquartered in Kraków, Poland, in the Europe region.
How does Securitum make money?
Three revenue lines are on record. Professional Penetration Testing Services are the primary driver. The others are periodic Security Audits and compliance Audit Services.
Who are Securitum's main competitors?
OffSec (Offensive Security) is listed as an others. Broad incumbents are Orange Cyberdefense, NCC Group and WithSecure (formerly F-Secure). Direct peers are Bishop Fox, Pen Test Partners, NetSPI, Secarma and Coalfire. Holm Security is listed as an emerging player.
Does Securitum have an API?
No public API is recorded for Securitum.
What industry is Securitum in?
Securitum's product category is Cybersecurity Penetration Testing Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 56162 and its SIC code is 8734.