Possehl Secure GmbH
Possehl Secure GmbH is a Cologne-based cybersecurity services provider founded in 2007, part of the Possehl Group's Possehl Digital unit since 2023, delivering identity governance, 24/7 SOC, and managed security services to German mid-sized businesses and critical infrastructure operators.
- Company typePrivate
- Founded2007
- HeadquartersKöln, Germany
- Headcount—
- GTM typeB2B
- OfferingServices
What Possehl Secure GmbH does
Possehl Secure GmbH is a Cologne-based cybersecurity services provider founded in 2007 that targets German mid-sized businesses (SMEs) and, to a lesser extent, critical infrastructure operators. Since 2023 the firm has operated as a wholly-owned subsidiary within the Possehl Group's Possehl Digital digitalization unit, under Managing Directors Michael Gentzen and Michael Sieben, both founding members. The company employs more than 35 senior cybersecurity experts and runs a vendor-neutral advisory, implementation, and managed-services model covering identity governance, privileged access management, zero trust architecture, 24/7 Security Operations Center monitoring, vulnerability management, and regulatory readiness for NIS2, DORA, and the Cyber Resilience Act.
The core product surface is the Security Factory framework, which segments services across IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER, and GOVERN phases, with MIGA (Identity Governance & Administration) as the flagship repeatable offering. MIGA is a customized SailPoint IdentityIQ deployment packaged with a container architecture, preconfigured processes, and an attached managed-service tier for ongoing operation. Delivery relies on a multi-vendor technology stack anchored by strategic partnerships with SailPoint, CyberArk, Microsoft, Elastic, Zscaler, Evidian/Atos, and runZero, supported by more than 25 distributor and integration partners.
Commercially, Possehl Secure sells exclusively via direct enterprise sales and industry events (notably it-sa Expo&Congress and its own Cybersecurity Impulse Day), with all engagements priced via individualized quote-based proposals using hourly, daily flat-rate, or monthly recurring billing. The revenue mix combines one-off Security Consulting and Professional Services projects with recurring Managed Services contracts, including 24/7 SOC and Managed IAM. Geographic scope is currently limited to Germany.
Possehl Secure GmbH firmographics
Firmographics- Name
- Possehl Secure GmbH
- Legal name
- Possehl Secure GmbH
- Website
- https://possehl-secure.de
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Short description
- Possehl Secure GmbH is a Cologne-based cybersecurity services provider founded in 2007, part of the Possehl Group's Possehl Digital unit since 2023, delivering identity governance, 24/7 SOC, and managed security services to German mid-sized businesses and critical infrastructure operators.
- Ownership category
- akta.pro rank
Possehl Secure GmbH industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (5415), Security Systems Services (56162)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Identity & Access Security Services (IAM, PAM, Zero Trust) (BPAKAHAI)
- akta.pro secondary industries
- Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF), Privileged Access Management (PAM) (HDADAAAC), Key Management, Encryption & Secrets Management (KMS/HSM/Vault) (HDABAHAG)
Keywords
Where Possehl Secure GmbH is headquartered
LocationHeadquarters
- HQ city
- Köln
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Possehl Secure GmbH business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Security Consulting: Initial advice on existing infrastructure, status quo assessments, risk identification and evaluation, provider selection support, and certification assistance.
- Professional Services: Implementation of tools and processes including planning, configuration, integration, technical realization, documentation, and employee training. Supporting customers through all phases from analysis to goal definition to concrete implementation.
- Managed Services: Continuous support in operating security infrastructure including ongoing operations, effectiveness reviews, weakness identification, targeted countermeasures, release/version management, 1st and 2nd level support, and focused IT outtasking.
- Time-based Billing: Hourly billing for time spent, or daily flat rates. Invoicing after completion and acceptance for performance-related work, otherwise monthly in arrears.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Monthly | Time-based professional services |
Go-to-market motion3 records
Distribution channels2 records
Marketing channels6 records
Possehl Secure GmbH product offering
Product offeringCore offering
Possehl Secure GmbH delivers vendor-neutral cybersecurity services for German mid-sized businesses, spanning Security Consulting, Professional Service (implementation), and Managed Service (ongoing operations). Its portfolio covers Security Factory assessments (IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER/GOVERN), a 24/7 Security Operations Center (SOC), the MIGA Identity Governance & Administration solution built on SailPoint IdentityIQ, Privileged Access Management, Enterprise Access Management, Zero Trust Protection, vulnerability and endpoint management, and regulatory readiness assessments for NIS2, CRA, and DORA.
Product overview
Possehl Secure GmbH offers a comprehensive cybersecurity portfolio focused on German mid-sized businesses. The core offering includes the Security Factory framework for initial assessments and consulting, with MIGA (Identity Governance & Administration) as a key managed service built on SailPoint IdentityIQ. Their services span IDENTIFY (penetration testing, vulnerability scanning, OT visibility, Active Directory assessments, compromise assessments, risk analyses), PROTECT (identity management, PAM, EAM, Zero Trust, Microsoft 365 Security, Email Security), DETECT & RESPOND (SOC with 24/7 monitoring, EDR, vulnerability management, NOC), RECOVER, and GOVERN (NIS2/CRA/DORA readiness, CISO-as-a-Service). The company provides services across Security Consulting, Professional Service (implementation), and Managed Service (ongoing operations) delivery models.
Differentiator
Problem solved
Functional benefit
Brands
- MIGA: Identity Governance & Administration solution for SMEs, built on SailPoint IdentityIQ platform
- Security Factory
Products and services
- MIGA Identity Governance & Administration Customized identity governance and administration solution developed for mid-sized companies, based on SailPoint IdentityIQ platform, with preconfigured processes, role-based access, automated provisioning/deprovisioning, and recertification workflows.
- Security Operations Center (SOC) 24/7 Security Operations Center providing early detection of security incidents, faster risk assessment, and effective response, monitoring preventive, detective, and reactive security technologies.
- Security Factory Holistic 360° cybersecurity assessment and consulting framework covering risk identification, critical resource analysis, vulnerabilities, and security mechanisms against threats across IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER, and GOVERN phases.
- Managed Identity & Access Management Managed service for the operation and further development of IAM solutions, including operation of the entire IAM solution, extensions and customizations, release management, and application management.
- Privileged Access Management (PAM) Security approach for managing and securing privileged accounts to minimize unauthorized access, including password management and session management with recording and auditing capabilities.
- Enterprise Access Management (EAM) Identity and access control solution for collaborative environments using Evidian's Enterprise Access Management suite, enabling single sign-on (SSO), multi-factor authentication (MFA), and centralized access control with Active Directory integration.
- Zero Trust Protection Zero Trust Network Access (ZTNA) architecture based on 'never trust, always verify' principle, with context-based access controls, real-time monitoring, and microsegmentation.
- Vulnerability Management Continuous identification and assessment of security vulnerabilities across IT environments, with visibility, prioritization based on real-world threats, and concrete remediation recommendations.
- Endpoint Detection & Response Detection and response capabilities for endpoint security, monitoring and analyzing preventive, detective, and reactive technologies to ensure IT security.
- OT Visibility Scan 4-week structured assessment providing transparency into IT, OT, and unknown assets using runZero, identifying critical communication paths, segmentation risks, and basis for OT security and network segmentation decisions.
- Vulnerability Scan Security scanning service identifying vulnerabilities across the entire IT environment, enriched with up-to-date threat intelligence, known attack vectors, and actual exploitability for clear prioritization.
- Active Directory Security Assessment Security assessment of Active Directory environments using PingCastle analysis and expert evaluation, identifying hidden vulnerabilities and providing prioritized recommendations for action.
- Network Operation Center (NOC) 24/7 Network Operations Center for monitoring and managing network infrastructure alongside SOC services.
- Readiness Assessment | NIS2, CRA, DORA Compliance readiness assessment for regulatory requirements including NIS2, Cyber Resilience Act (CRA), and Digital Operational Resilience Act (DORA), helping organizations meet increasing regulatory requirements.
- CISO-as-a-Service Virtual Chief Information Security Officer service providing expert cybersecurity leadership and guidance for organizations without internal CISO resources.
- Penetration Testing Security testing services to identify vulnerabilities and security gaps through offensive security assessments.
- Compromise Assessment Assessment service to identify potential compromise or breach indicators in organization systems and networks.
- Microsoft 365 Security Security services specifically focused on Microsoft 365 environment protection and hardening.
- Email Security Specialized email security services protecting against phishing, malware, and other email-borne threats.
Quantifiable outcome
- Fast implementation of MIGA within short timeframe through preconfigured processes and container architecture
- +2 more outcomes
Companies that use Possehl Secure GmbH
Customer profileSegments2 records
Ideal customer profiles2 records
Possehl Secure GmbH technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration12 records
AI capability4 records
Feature3 records
Possehl Secure GmbH partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and minor.
- SailPointcoreSailPoint IdentityIQ platform is the foundation for MIGA (Identity Governance & Administration) solution. Possehl Secure has over 15 years of experience implementing SailPoint solutions for mid-sized companies, providing optimized and standardized deployment via container architecture.
- CyberArkcorePrivileged Access Management (PAM) technology partner for securing and managing privileged accounts with auditable access controls.
- MicrosoftcoreTechnology partner for Microsoft 365 Security, Azure integration, Defender for Endpoint, and Azure Sentinel SIEM capabilities used in SOC operations.
- ElasticcoreTechnology partner for Elastic Defend and Elastic SIEM solutions used in Security Operations Center for detecting, analyzing, and mitigating cyberattacks.
- ZscalercoreZero Trust Network Access (ZTNA) technology partner providing technical foundation for Zero Trust architecture implementations.
- Evidian (Atos Group)coreEnterprise Access Management solution partner. Evidian EAM provides modular identity and access management suite enabling single sign-on (SSO), multi-factor authentication (MFA), and centralized access control management.
- runZerocoreOT Visibility Scan technology partner. runZero platform enables agentless discovery of assets in complex, heterogeneous IT and OT environments for comprehensive infrastructure transparency.
- TD-SynnexminorTechnology distributor for accessing state-of-the-art technologies and products.
- WestconminorTechnology distributor for security solutions.
- InfinigateminorCybersecurity-focused technology distributor.
Scale indicators7 records
Recent moves7 records
Expansion highlights5 records
Possehl Secure GmbH competitors and assessment
Company assessmentBroad incumbents
- CANCOM SE: DACH-focused IT services and managed services provider with a dedicated cybersecurity business unit. Directly comparable to Possehl Secure in targeting German mid-market customers with managed security services.
- Bechtle AG: One of the largest IT services companies in the DACH region with a growing cybersecurity portfolio including managed SOC and consulting. Comparable in DACH mid-market reach and broad IT services bundling.
- Computacenter AG & Co. KG: Large UK/German-headquartered IT services provider with significant cybersecurity services practice including SOC, advisory, and managed services. Competes with Possehl Secure for mid-market and enterprise security engagements in Germany.
- secunet Security Networks AG: Public German cybersecurity firm with deep roots in critical infrastructure and public-sector security. Comparable as a German cybersecurity services provider with significant regulated-customer exposure, though broader and larger than Possehl Secure.
- TÜV Rheinland iT-Sec GmbH: Subsidiary of TÜV Rheinland offering cybersecurity consulting, testing, and managed services for German enterprises. Overlaps with Possehl Secure in assessment, SOC, and compliance readiness work for DACH mid-market.
- Atos (Evidian): Parent of Evidian (one of Possehl Secure's core technology partners). Atos delivers IAM, SOC, and managed security services globally and competes for the same enterprise and mid-market identity governance opportunities.
- Avanade: Global IT services firm jointly owned by Accenture and Microsoft with deep identity, security, and managed services practices. Competes for Microsoft-centric security engagements including SOC and identity governance in Europe.
- Syss (Deloitte): German cybersecurity firm Syss was acquired by Deloitte and now forms part of its cyber practice. A leading German penetration testing and security services firm now competing at scale with Possehl Secure.
Direct peers
- Softline Solutions GmbH: German IAM/IAG specialist and long-standing SailPoint delivery partner focused on mid-sized enterprises. Directly comparable in offering (SailPoint implementation), customer segment (DACH SMEs), and partner-driven go-to-market.
Emerging players
- Orange Cyberdefense: European-headquartered MSSP with a strong DACH presence offering SOC, threat intelligence, and managed security services. Comparable to Possehl Secure as a European cybersecurity services specialist serving enterprise and mid-market.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Possehl Secure GmbH social profiles
Digital presencePossehl Secure GmbH financial estimates
Financial estimateRevenue estimate
Valuation estimate
Possehl Secure GmbH leadership team
Management profileNumber of profiles
Profiles5 records
Possehl Secure GmbH funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Possehl Secure GmbH M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Possehl Secure GmbH
What does Possehl Secure GmbH do?
Possehl Secure GmbH delivers vendor-neutral cybersecurity services for German mid-sized businesses, spanning Security Consulting, Professional Service (implementation), and Managed Service (ongoing operations). Its portfolio covers Security Factory assessments (IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER/GOVERN), a 24/7 Security Operations Center (SOC), the MIGA Identity Governance & Administration solution built on SailPoint IdentityIQ, Privileged Access Management, Enterprise Access Management, Zero Trust Protection, vulnerability and endpoint management, and regulatory readiness assessments for NIS2, CRA, and DORA.
Is Possehl Secure GmbH a public or private company?
Possehl Secure GmbH is a private company. It is classified as corporate owned and is currently operating.
When was Possehl Secure GmbH founded?
Possehl Secure GmbH was founded in 2007.
Where is Possehl Secure GmbH based?
Possehl Secure GmbH is headquartered in Köln, Germany, in the Europe region.
How does Possehl Secure GmbH make money?
Four revenue lines are on record. Security Consulting is the primary driver. The others are professional Services, managed Services and time-based Billing.
Who are Possehl Secure GmbH's main competitors?
Broad incumbents on record are CANCOM SE, Bechtle AG, Computacenter AG & Co. KG, secunet Security Networks AG, TÜV Rheinland iT-Sec GmbH, Atos (Evidian), Avanade and Syss (Deloitte). Softline Solutions GmbH is listed as a direct peer. Orange Cyberdefense is listed as an emerging player.
Does Possehl Secure GmbH have an API?
No public API is recorded for Possehl Secure GmbH.
What industry is Possehl Secure GmbH in?
Possehl Secure GmbH's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAI, Identity & Access Security Services (IAM, PAM, Zero Trust), with a secondary code of BPAKADAF, Security Architecture & Engineering Advisory (Zero Trust, IAM, Network). Its NAICS code is 561621 and its SIC code is 7381.