IPHMx

Germany · www.iphmx.com · 2 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 2 sub-vendors.

Insights

Last updated 2026-05-15 · revision 2

2 direct vendors, 58 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company's migration readiness is assessed as low, primarily due to a severe lack of critical information and potential vendor lock-in risks. The most significant challenge is the complete absence of data regarding the 'Internal Tech Stack' and 'Key Technologies'. Without understanding the current architecture (e.g., monolithic vs. microservices, legacy vs. cloud-native, containerization), it is impossible to accurately gauge the complexity and effort required for migration. Additionally, while 'Vendor Lock-in Risk' is unknown, the concentration of all identified vendors (for 2 services) in a single country (United States) suggests a potential for high vendor lock-in, which could complicate and increase the cost of migrating away from these services. The guideline 'Few vendors (1-3) indicates high lock-in risk' supports this concern if the 2 services are from 1 or 2 vendors. Furthermore, there is no information on the 'Regulatory Environment' or 'Financial Stability' (revenue concentration, growth history), both of which are crucial for understanding compliance requirements and the financial capacity to fund a migration. The 'Data Residency Requirements' are 'Not specified', which could either indicate flexibility or an unaddressed risk. The cumulative effect of these significant data gaps and the potential for vendor lock-in places the company in a low state of migration readiness.

Compliance

5 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applicability depends on company size and industry sector. Without knowing IPHMx's specific industry and size, risk is medium. If the company operates in essential or important entity sectors (energy, transport, banking, health, digital infrastructure, manufacturing, etc.) and meets size thresholds (50+ employees or €10M+ turnover), NIS2 would apply with high penalties for non-compliance.

SOC 2 (source) — Assessment Required

SOC2 applicability depends on whether IPHMx provides cloud services or technology services to other organizations. Without knowing their business model, risk is medium. If they are a service provider, SOC2 compliance would be important for customer trust and contract requirements, though not legally mandated.

GDPR (source) — Assessment Required

GDPR applies to all companies headquartered in the EU/EEA that process personal data. As IPHMx is located in Germany, GDPR is mandatory applicable. High risk due to severe penalties (up to 4% of annual global turnover or €20M), strict compliance requirements, and active enforcement by German data protection authorities. Non-compliance can result in significant fines, legal action, and reputational damage.

Financials

Three-year financials

Financial Resilience Score: 8/10

iphmx.com is not an independent company but rather the technical domain (IronPort Hosted Mail eXchange) used by Cisco Systems, Inc. for its cloud-based email security service. As such, financial resilience must be assessed at the Cisco parent level, where the company demonstrates strong financial health with consolidated revenue of approximately $53.8B in FY2024 and operating income of ~$12.7B. Cisco generates very strong operating cash flow (consistently >$13B annually) and maintains a large, diversified enterprise customer base across networking, security, collaboration, and observability segments. The shift to subscription/SaaS model, which includes the IPHMX cloud email service, improves recurring revenue quality and visibility. However, FY2024 saw a ~6% revenue decline due to inventory digestion and softer enterprise spending, and the $28B Splunk acquisition (closed March 2024) increased debt load and integration risk. Within the cloud email security market specifically, Cisco IronPort/Secure Email faces intense competition from Proofpoint, Microsoft Defender for Office 365, Mimecast, and Abnormal Security, and has been losing share in some segments.

Key strengths: Very large installed base of enterprise customers using Cisco Secure Email/IronPort, Strong cash flow generation (>$13B operating cash flow annually at Cisco parent), Shift to subscription/SaaS model improves recurring revenue quality, Diversified across networking, security, collaboration, observability, Security segment grew from <$2B at IronPort acquisition (2007) to ~$4B today

Risk factors: Highly competitive cloud email security market (Proofpoint, Microsoft Defender, Mimecast, Abnormal Security), Cisco IronPort/Secure Email has been losing market share in some segments, FY2024 revenue declined ~6% YoY due to inventory digestion and softer enterprise spending, Splunk acquisition ($28B) increased debt and integration risk, iphmx.com has no standalone financials, employee counts, or segment disclosures

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report