Cyber Risk
Cyber Risk GmbH is a Swiss professional services firm that delivers human-centered cybersecurity, social engineering defense, and EU regulatory compliance training (NIS 2, DORA, AI Act, CER, DSA, DMA, DGA, Chips Act, Data Act) to enterprises, Boards, and high-value targets across regulated industries.
- Company typePrivate
- Founded2015
- HeadquartersHorgen, Switzerland
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Cyber Risk does
Cyber Risk GmbH is a privately held Swiss professional services firm headquartered in Horgen, Canton of Zürich, that provides cybersecurity, social engineering, and regulatory compliance training. Founded in 2015 by George Lekatis, the company delivers human-centered cybersecurity education through four core modalities: in-house instructor-led training, online live training, video-recorded training, and asynchronous distance-learning programs with certificates of completion. Its curriculum spans general awareness training, insider-threat awareness, sector-specific programs for banking, healthcare, aviation, and hospitality, executive-level briefings for Boards of Directors under NIS 2 accountability, and tailored programs for high-value targets such as senior executives and diplomats. The company also fields nine EU regulatory certification programs covering the NIS 2 Directive, AI Act, DORA, CER, DSA, DMA, Data Governance Act, European Chips Act, and Data Act, delivered via distance learning with online exams.
The business operates a hybrid GTM combining enterprise field sales for customized instructor-led engagements with a self-service channel for distance-learning programs (paid by card, QR, or PayPal). Revenue streams include one-time professional services fees (in-house and online live), licensed video content, fixed-price distance-learning programs with 60-day refund windows, and a recurring subscription tier — the Social Engineering Peace of Mind Service — that bundles quarterly knowledge updates, teleconference consulting, ongoing training, and twice-yearly OSINT assessments. Distribution is entirely direct, with no reseller or marketplace intermediaries. The company has delivered training in 36 countries and claims enterprise clients including Dell, Fujitsu, Volkswagen, Bosch, Schindler, ABB, PwC, Swiss Life, Deutsche Bank, European Investment Bank, NTT, Coop, SYGNIA, BAE Systems, Airbus, and Booz Allen Hamilton.
The underlying technology stack is minimal: there is no proprietary software platform, no SaaS product, and no mobile app. The company runs a portfolio of 35+ branded topical websites (e.g., nis-2-directive.com, healthcare-cybersecurity.ch) that function as SEO/content funnels rather than integrated product surfaces, and delivers live sessions through Zoom, Webex, and Microsoft Teams. Marketing is content-led, anchored by a monthly 68- to 139-page PDF newsletter described as an intelligence report, plus conference presence (Christina Lekati is a repeat Black Hat Trainer across Europe and Asia) and earned media in SRF and P.M. Magazine. Operational ownership is concentrated in the founder, who also leads affiliated associations (IARCP, BiiiCPA, SOXCPA) and Compliance LLC, creating a broader professional-training ecosystem around the parent entity.
Cyber Risk firmographics
Firmographics- Name
- Cyber Risk
- Legal name
- Cyber Risk GmbH
- Website
- https://cyber-risk-gmbh.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Cyber Risk GmbH is a Swiss professional services firm that delivers human-centered cybersecurity, social engineering defense, and EU regulatory compliance training (NIS 2, DORA, AI Act, CER, DSA, DMA, DGA, Chips Act, Data Act) to enterprises, Boards, and high-value targets across regulated industries.
- Ownership category
- akta.pro rank
Cyber Risk industry classification
Industry- Product category
- Cybersecurity and Compliance Training Services
- NAICS
- Computer Training (611420), Computer Training (61142), Other Computer Related Services (541519)
- SIC
- Services-Educational Services (8200)
- akta.pro primary industry
- Cybersecurity (General) (EDAOAIAB)
- akta.pro secondary industries
- Information Technology (IT) & Cybersecurity Certifications (EDAAANAA), Phishing, Social Engineering & Business Email Compromise (BEC) Training (EDABAGAB), Cybersecurity Training & Awareness Programs (BPAEANAF), Cybersecurity Learning Platforms (EDAFANAF)
Keywords
Where Cyber Risk is headquartered
LocationHeadquarters
- HQ city
- Horgen
- HQ country
- Switzerland
- HQ region
- Europe
Offices2 records
Markets served
Cyber Risk business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- In-House Instructor-Led Training: Customized training programs delivered in-person at the client's location by a Cyber Risk GmbH-approved instructor. Priced at a fixed rate plus VAT and pre-approved expenses. Payment terms: 50% billable in advance (due at least 45 days before delivery), remaining 50% due within 30 days after the last training day. Cancellation fees apply. This is the primary professional services revenue stream.
- Online Live Training: Real-time synchronous training delivered via virtual meeting platforms (Zoom, Webex, Microsoft Teams). Instructor tailors delivery method (interactive or non-interactive) to client needs. Licensed under terms consistent with the GTC.
- Video-Recorded Training: Professional pre-recorded training tailored to client needs and recorded in a professional studio. Material is licensed to the client for internal training purposes and can be hosted on the client's learning platform on-demand. Payment: 50% down payment due at least 45 days before delivery, remaining 50% within 30 days after delivery.
- Distance Learning with Certificate of Completion: Asynchronous self-study programs with official presentations sent via email, up to 3 online exams, and a Certificate of Completion upon passing. Provided at a fixed price including VAT with no additional future costs. Clients can purchase via card, QR payment, or PayPal. Full refund available up to 60 days after payment.
- Social Engineering - Peace of Mind Subscription Service: Ongoing subscription-based service offering quarterly knowledge updates, teleconference consulting sessions, tailored social engineering training, and twice-yearly OSINT assessments. Helps organizations maintain continuous social engineering defense without internal resource burden.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | In-House Instructor-Led Training — Fixed price per program plus VAT and pre-approved expenses |
| One time/ perpetual license | One time/ perpetual license | Distance Learning with Certificate of Completion — Fixed price per program, all-inclusive |
| Subscription | Annual | Social Engineering Peace of Mind Service — Subscription-based ongoing service |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels4 records
Cyber Risk product offering
Product offeringCore offering
Cyber Risk GmbH delivers human-centered cybersecurity and compliance training services to enterprises and individuals. The core offering is delivered across four formats (in-house instructor-led, online live, video-recorded, and distance learning with Certificate of Completion) and spans general cybersecurity awareness, social engineering defense, insider threat awareness, sector-specific programs for banking, healthcare, aviation, and hospitality, and nine EU regulatory certification programs (NIS 2, AI Act, DORA, CER, DSA, DMA, Data Governance Act, European Chips Act, Data Act).
Product overview
Cyber Risk GmbH offers a comprehensive portfolio of cybersecurity, compliance, and risk management training services. The core offerings include four delivery formats: In-House Instructor-Led Training Programs, Online Live Training Programs, Video-Recorded Training Programs, and Distance Learning with Certificate of Completion Programs. The training programs span general cybersecurity awareness, social engineering defense, insider threat awareness, and industry-specific training for banking, hospitality, aviation, and healthcare sectors. Specialized programs include High Value Targets Cybersecurity Training and Board of Directors briefings. The company also provides nine EU regulatory compliance certification programs (NIS 2, AI Act, DORA, CER, DSA, DMA, DGA, European Chips Act, Data Act), assessment services (Corporate OSINT Assessment, Cyber and Privacy Needs Assessment, Cyber and Privacy Risk Assessment), and a subscription-based Social Engineering Peace of Mind Service. Additional offerings include monthly cybersecurity newsletters. The portfolio is delivered primarily through instructor-led training with Christina Lekati as the lead social engineering expert and George Lekatis as the founder and General Manager.
Differentiator
Problem solved
Functional benefit
Brands
- Board Briefings: Comprehensive briefings on hybrid risk management for board members
- Peace of Mind Service
- Social Engineering and OSINT for Security Teams
- Trained Professional Programs (NIS2DTP, AIActTPro, DORATPro, CERDTPro, DiSeActTPro, DiMaActTPro, DatGovActTP, EChipsActTPro, DataActTPro)
Products and services
- In-House Instructor-Led Training Programs
Companies that use Cyber Risk
Customer profileNamed customers16 records
Segments6 records
Ideal customer profiles3 records
Cyber Risk technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability2 records
Feature8 records
Cyber Risk partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- International Association of Risk and Compliance Professionals (IARCP)coreGeorge Lekatis serves as President of the IARCP, which develops and maintains the Certified Risk and Compliance Management Professional (CRCMP) program. The IARCP offers membership programs, regular updates, specialized training, certification, ACT programs, and advocacy services to its members. The association is closely affiliated with Cyber Risk GmbH through George Lekatis's leadership.
- Basel III Compliance Professionals Association (BiiiCPA)coreGeorge Lekatis serves as President of the Basel III Compliance Professionals Association, the world's largest association of Basel III professionals dedicated to supporting compliance across the global financial sector. The association provides training, certification, and professional development services.
- Sarbanes-Oxley Compliance Professionals Association (SOXCPA)coreGeorge Lekatis serves as President of the SOXCPA, the world's largest association of Sarbanes-Oxley professionals. The association provides training, certification, and professional services to its members.
- Compliance LLCcoreGeorge Lekatis serves as General Manager of Compliance LLC, a company incorporated in Wilmington, NC, with offices in Washington, DC. Compliance LLC provides risk and compliance training in 58 countries through multiple business units including association services. Several of its business units function as associations offering specialized training, certification, and professional services to members. Represents an affiliated operating entity rather than a traditional partnership.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Cyber Risk competitors and assessment
Company assessmentBroad incumbents
- KnowBe4: Largest pure-play security awareness and simulated phishing platform; competes for the same enterprise training budget as Cyber Risk GmbH but at vastly greater scale and via an integrated SaaS platform rather than bespoke human-led training.
- SANS Institute: Premier cybersecurity training and certification provider with deep curriculum across technical and awareness domains; competes for enterprise and government training dollars with standardized, globally recognized certifications analogous to Cyber Risk GmbH's EU regulatory certificates.
- Proofpoint Security Awareness: Enterprise-grade security awareness and phishing simulation platform bundled with Proofpoint's broader threat protection suite; overlaps with Cyber Risk GmbH on social engineering defense but competes via an automated, integrated platform.
Direct peers
- Cofense: Specialist in phishing defense, simulations, and human-reported phishing intelligence; directly competes with Cyber Risk GmbH's social engineering training programs on the phishing and human-layer defense use case.
- ISACA: Global association issuing IT governance, risk, and cybersecurity certifications (CISM, CISA, CRISC); directly comparable professional certification model and overlapping audience with Cyber Risk GmbH's EU regulatory certificates.
- ISC2: Global cybersecurity professional certification body (CISSP, CCSP, etc.); comparable to Cyber Risk GmbH in monetizing independent certificates of completion and competing for the same compliance-driven training budget.
- EC-Council: Cybersecurity certification body offering CEH, CHFI, and other technical credentials; competes with Cyber Risk GmbH's distance learning certificate programs for the same professional development wallet.
Emerging players
- Phished: European-based AI-driven security awareness and phishing simulation platform; an emerging regional player with comparable target customers to Cyber Risk GmbH's European enterprise base.
- Cybrary: Online cybersecurity training platform with subscription and team offerings; an emerging player overlapping with Cyber Risk GmbH's distance learning and video-recorded training products at typically lower price points.
- Hoxhunt: Security behavior change platform combining gamified phishing simulations with personalized training; a fast-growing emerging player competing for the same enterprise security awareness spend with a more automated, scalable delivery model.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Cyber Risk social profiles
Digital presenceCyber Risk financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Risk leadership team
Management profileNumber of profiles
Profiles2 records
Cyber Risk funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Risk M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Risk
What does Cyber Risk do?
Cyber Risk GmbH delivers human-centered cybersecurity and compliance training services to enterprises and individuals. The core offering is delivered across four formats (in-house instructor-led, online live, video-recorded, and distance learning with Certificate of Completion) and spans general cybersecurity awareness, social engineering defense, insider threat awareness, sector-specific programs for banking, healthcare, aviation, and hospitality, and nine EU regulatory certification programs (NIS 2, AI Act, DORA, CER, DSA, DMA, Data Governance Act, European Chips Act, Data Act).
Is Cyber Risk a public or private company?
Cyber Risk is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber Risk founded?
Cyber Risk was founded in 2015. It employs 1 to 10 people.
Where is Cyber Risk based?
Cyber Risk is headquartered in Horgen, Switzerland, in the Europe region.
How does Cyber Risk make money?
Five revenue lines are on record. In-House Instructor-Led Training is the primary driver. The others are online Live Training, video-Recorded Training, distance Learning with Certificate of Completion and social Engineering - Peace of Mind Subscription Service.
Who are Cyber Risk's main competitors?
Broad incumbents on record are KnowBe4, SANS Institute and Proofpoint Security Awareness. Direct peers are Cofense, ISACA, ISC2 and EC-Council. Emerging players are Phished, Cybrary and Hoxhunt.
Does Cyber Risk have an API?
No public API is recorded for Cyber Risk.
What industry is Cyber Risk in?
Cyber Risk's product category is Cybersecurity and Compliance Training Services. Its primary akta.pro industry code is EDAOAIAB, Cybersecurity (General), with a secondary code of EDAAANAA, Information Technology (IT) & Cybersecurity Certifications. Its NAICS code is 611420 and its SIC code is 8200.