SECUINFRA GmbH
Germany · owned by Independent (Germany) · www.secuinfra.com · 18 vendors
SECUINFRA is a German cybersecurity company specializing in the detection, analysis, and defense against cyber attacks. The company operates a Cyber Defense Center (CDC) based in Germany and offers services including Security Information and Event Management (SIEM), threat intelligence, and managed detection and response. Their tagline is 'Cyber Defense - Made in Germany.'
Resilience scores
- Digital Sovereignty: 22
- Digital Resilience: 5
- Financial Resilience: 7
Technology vendors
- Gartner — Technology — United States
- Google LLC — Technology — United States
- SwissSign Group AG — Cybersecurity — Switzerland
- and 15 more
Insights
Last updated 2026-08-13 · revision 12
18 direct vendors, 240 subvendors
Direct vendors by controlling owner country (sample)
- Switzerland: 1
- Austria: 1
- United States: 11
Subvendors by controlling owner country (sample)
- Romania: 1
- United States: 164
- Poland: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SECUINFRA GmbH demonstrates medium migration readiness. A key strength is their deep expertise in modern cloud security platforms, as evidenced by their 'MDR Microsoft Cloud' service and internal use of Microsoft Azure, Microsoft Sentinel, and Microsoft Defender. This indicates a strong capability to adopt and manage cloud-native solutions. Their internal tech stack also includes cloud-based services like Microsoft 365, Personio, and Cloudflare. However, their readiness is tempered by several factors. The regulatory environment, particularly strict GDPR data residency requirements and potential NIS2 applicability, presents significant compliance hurdles for any large-scale migration, especially concerning data transfer and processing locations. While there is vendor geographic diversity (6 countries for HQs), their reliance on specific major platforms like Microsoft and Elastic for core services could introduce some platform-specific lock-in, potentially complicating migration to alternative ecosystems. The internal use of WordPress for their website, while common, represents a less cloud-native component. The lack of financial data also prevents an assessment of their capacity to fund a substantial migration effort. Overall, their technical expertise in cloud security is a strong enabler, but regulatory complexities and potential platform lock-in pose challenges.
Compliance
8 in-scope frameworks identified; showing 3.
HinSchG — Partially Compliant
Germany's Whistleblower Protection Act (HinSchG), which transposed the EU Whistleblower Directive (2019/1937) into German law (in force since July 2023), requires companies with 50+ employees to establish internal reporting channels for whistleblowers. SECUINFRA has publicly deployed a whistleblower portal (https://secuinfra.hinweis.me/), which directly demonstrates compliance with the core HinSchG requirement to establish an internal reporting channel. Risk is Low because the primary obligation (establishing a reporting channel) is demonstrably met. The status is 'Partially Compliant' rather than 'Compliant' because the full procedural requirements (designated responsible person, acknowledgement within 7 days, feedback within 3 months, confidentiality protections, non-retaliation policies) cannot be verified from public sources alone.
Evidence: https://secuinfra.hinweis.me/, https://www.secuinfra.com/de/imprint/, https://www.gesetze-im-internet.de/hinschg/
BDSG — Assessment Required
The BDSG is Germany's national data protection law that supplements and implements GDPR at the national level. It is automatically applicable to all companies established in Germany that process personal data — which SECUINFRA unambiguously does. The BDSG contains specific provisions beyond GDPR, including: stricter rules on employee data processing (§26 BDSG), specific requirements for data protection officers (§38 BDSG — mandatory if 20+ persons regularly process personal data using automated means), and additional rules for sensitive data categories. Given SECUINFRA's size (two offices, 24/7 operations since 2010) and the nature of its work (processing employee data and client security data), it almost certainly meets the §38 BDSG threshold for mandatory DPO appointment. Risk is Medium because SECUINFRA's ISO 27001 certification and privacy policy indicate awareness of data protection obligations, but no public evidence of a formally appointed and registered DPO was found.
Evidence: https://www.secuinfra.com/de/privacy-policy/, https://secuinfra.hinweis.me/, https://www.gesetze-im-internet.de/bdsg_2018/, https://www.bfdi.bund.de/DE/Home/home_node.html
EU Cybersecurity Act — Assessment Required
The EU Cybersecurity Act (Regulation (EU) 2019/881) established ENISA's permanent mandate and created the EU cybersecurity certification framework. While the CSA itself does not impose direct obligations on all companies, it is highly relevant to SECUINFRA as a cybersecurity service provider because: (1) EU cybersecurity certification schemes (e.g., EUCS — EU Cloud Scheme, EUCC — Common Criteria scheme) may apply to SECUINFRA's cloud-based MDR services; (2) the forthcoming EU Cyber Resilience Act (CRA) will impose security requirements on products with digital elements; (3) SECUINFRA's clients in regulated sectors may require CSA-certified products/services. Risk is Medium because the CSA certification schemes are still being developed and rolled out, and mandatory certification requirements for MSSPs are not yet fully established. However, SECUINFRA should monitor ENISA scheme developments closely.
Evidence: https://www.enisa.europa.eu/topics/cybersecurity-policy/certification, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019R0881, https://www.secuinfra.com/de/managed-detection-and-response/microsoft/, https://www.allianz-fuer-cybersicherheit.de/Webs/ACS/DE/Home/home_node.html
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
SECUINFRA GmbH shows strong qualitative resilience signals despite limited public financial disclosure. As a privately held, owner-managed German GmbH founded in 2010, it has demonstrated 15+ years of continuous operation in a structurally growing niche (Cyber Defense / MDR / SOC services). The business model is anchored in recurring-revenue Managed Detection & Response and Incident Response retainers, which provide higher revenue visibility than pure project consulting. The company is ISO 27001 and ISO 9001 certified and holds BSI recognition as a qualified APT-Response service provider, reinforcing customer trust and pricing power. Owner-managed German Mittelstand firms of this size class typically maintain conservative balance sheets, finance growth from retained earnings, and carry modest external debt. Headcount has approximately doubled from ~40 in the late 2010s to 80+ today, indicating sustained organic growth without evidence of dilutive capital raises or M&A. Structural tailwinds from NIS2, DORA, and KRITIS-Dachgesetz regulation support continued demand. However, resilience is capped by limited financial transparency (no publicly filed P&L under the small-GmbH exemption of §§ 267, 325 HGB), key-person concentration on founder-CEO Ramon Weil, geographic concentration in Germany, and dependency on partner technology vendors (Microsoft, Elastic, Splunk, IBM, Palo Alto, etc.). Scale is modest relative to large MSSP competitors such as T-Systems, Deutsche Telekom Security, Accenture, Sophos and Arctic Wolf, which could pressure margins over time.
Key strengths: 15+ year track record since 2010 with founder still CEO, Recurring-revenue MDR and IR retainer business model, ISO 27001 and ISO 9001 certified organization-wide, BSI-listed Qualified APT-Response service provider, Structural regulatory tailwinds (NIS2, DORA, KRITIS), Five-time consecutive kununu Top Company (2022-2026) supporting talent retention, Owner-managed with typically conservative German Mittelstand balance sheet, Headcount roughly doubled in ~5 years indicating strong organic growth
Risk factors: Limited financial transparency - no public P&L as small GmbH, Key-person concentration on founder-CEO Ramon Weil (sole managing director), Talent-market dependency in tight cybersecurity labor market, Vendor/technology dependency on Microsoft, Elastic, Splunk, IBM, Palo Alto and others, Geographic concentration in Germany with limited natural diversification, Scale disadvantage vs. large MSSPs (T-Systems, Deutsche Telekom Security, Accenture, Sophos, Arctic Wolf)
Revenue by geography
- Germany: 95%
- Rest of DACH / International: 5%
Workforce by country
- Germany: 80
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.