IPHMx
Germany · www.iphmx.com · 2 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 2
- Financial Resilience: 8
Technology vendors
- Akamai Technologies, Inc. — Technology — United States
- IdenTrust, Inc. — Cybersecurity — United States
Services catalogue
1 service in catalogue across 1 category; runs on 2 sub-vendors.
- Email Security
Insights
Last updated 2026-05-15 · revision 2
2 direct vendors, 58 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
Subvendors by controlling owner country (sample)
- Australia: 2
- Canada: 2
- China: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The company's migration readiness is assessed as low, primarily due to a severe lack of critical information and potential vendor lock-in risks. The most significant challenge is the complete absence of data regarding the 'Internal Tech Stack' and 'Key Technologies'. Without understanding the current architecture (e.g., monolithic vs. microservices, legacy vs. cloud-native, containerization), it is impossible to accurately gauge the complexity and effort required for migration. Additionally, while 'Vendor Lock-in Risk' is unknown, the concentration of all identified vendors (for 2 services) in a single country (United States) suggests a potential for high vendor lock-in, which could complicate and increase the cost of migrating away from these services. The guideline 'Few vendors (1-3) indicates high lock-in risk' supports this concern if the 2 services are from 1 or 2 vendors. Furthermore, there is no information on the 'Regulatory Environment' or 'Financial Stability' (revenue concentration, growth history), both of which are crucial for understanding compliance requirements and the financial capacity to fund a migration. The 'Data Residency Requirements' are 'Not specified', which could either indicate flexibility or an unaddressed risk. The cumulative effect of these significant data gaps and the potential for vendor lock-in places the company in a low state of migration readiness.
Compliance
5 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 applicability depends on company size and industry sector. Without knowing IPHMx's specific industry and size, risk is medium. If the company operates in essential or important entity sectors (energy, transport, banking, health, digital infrastructure, manufacturing, etc.) and meets size thresholds (50+ employees or €10M+ turnover), NIS2 would apply with high penalties for non-compliance.
SOC 2 (source) — Assessment Required
SOC2 applicability depends on whether IPHMx provides cloud services or technology services to other organizations. Without knowing their business model, risk is medium. If they are a service provider, SOC2 compliance would be important for customer trust and contract requirements, though not legally mandated.
GDPR (source) — Assessment Required
GDPR applies to all companies headquartered in the EU/EEA that process personal data. As IPHMx is located in Germany, GDPR is mandatory applicable. High risk due to severe penalties (up to 4% of annual global turnover or €20M), strict compliance requirements, and active enforcement by German data protection authorities. Non-compliance can result in significant fines, legal action, and reputational damage.
Financials
Three-year financials
- 2024: revenue USD 53.8B, EBIT USD 12.7B, equity USD 45.0B
- 2023: revenue USD 57.0B, EBIT USD 16.7B, equity USD 44.1B
- 2022: revenue USD 51.6B, EBIT USD 13.9B, equity USD 39.8B
Financial Resilience Score: 8/10
iphmx.com is not an independent company but rather the technical domain (IronPort Hosted Mail eXchange) used by Cisco Systems, Inc. for its cloud-based email security service. As such, financial resilience must be assessed at the Cisco parent level, where the company demonstrates strong financial health with consolidated revenue of approximately $53.8B in FY2024 and operating income of ~$12.7B. Cisco generates very strong operating cash flow (consistently >$13B annually) and maintains a large, diversified enterprise customer base across networking, security, collaboration, and observability segments. The shift to subscription/SaaS model, which includes the IPHMX cloud email service, improves recurring revenue quality and visibility. However, FY2024 saw a ~6% revenue decline due to inventory digestion and softer enterprise spending, and the $28B Splunk acquisition (closed March 2024) increased debt load and integration risk. Within the cloud email security market specifically, Cisco IronPort/Secure Email faces intense competition from Proofpoint, Microsoft Defender for Office 365, Mimecast, and Abnormal Security, and has been losing share in some segments.
Key strengths: Very large installed base of enterprise customers using Cisco Secure Email/IronPort, Strong cash flow generation (>$13B operating cash flow annually at Cisco parent), Shift to subscription/SaaS model improves recurring revenue quality, Diversified across networking, security, collaboration, observability, Security segment grew from <$2B at IronPort acquisition (2007) to ~$4B today
Risk factors: Highly competitive cloud email security market (Proofpoint, Microsoft Defender, Mimecast, Abnormal Security), Cisco IronPort/Secure Email has been losing market share in some segments, FY2024 revenue declined ~6% YoY due to inventory digestion and softer enterprise spending, Splunk acquisition ($28B) increased debt and integration risk, iphmx.com has no standalone financials, employee counts, or segment disclosures
Revenue by geography
- Americas: 52%
- EMEA: 28%
- APJC: 20%
Revenue by product/service
- Networking: 58%
- Services: 25%
- Collaboration: 8%
- Security (incl. Secure Email/IronPort): 7%
- Observability: 3%
Workforce by country
- Total Global (Cisco): 84900
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.