XM Cyber

Israel · owned by Schwarz Group (Germany) · xmcyber.com · 31 vendors

XM Cyber is a cybersecurity company specializing in Continuous Exposure Management (CEM), helping organizations identify and remediate attack paths that lead to critical assets across cloud, on-premises, OT, and hybrid environments. Founded by Israeli Intelligence veterans, the company offers a unified platform covering External Attack Surface Management, Vulnerability Risk Management, Security Controls Monitoring, and Exposed Credentials Management. XM Cyber is now part of Schwarz Group, Europe's largest retailer, operating as a core pillar of its Schwarz Digits digital sovereignty initiative.

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 4 categories; runs on 31 sub-vendors.

Insights

Last updated 2026-04-13 · revision 3

31 direct vendors, 301 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

XM Cyber exhibits high migration readiness, primarily driven by its advanced and cloud-native technology stack. The extensive use of Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, coupled with containerization (Docker, Kubernetes) and a microservices architecture, indicates a highly portable and modular system. The adoption of Infrastructure as Code tools like Terraform and Pulumi, along with robust CI/CD pipelines (GitHub Actions, Jenkins), further streamlines deployment and migration processes. Their strong regulatory compliance posture (ISO 27001, SOC 2 Type II, GDPR, CCPA, HIPAA, PCI DSS, NIS2 applicability) means they have established governance and data management practices, which, while requiring careful planning, ultimately facilitate compliant migrations. The lack of explicit, restrictive data residency requirements (beyond 'multiple regions globally') offers flexibility in choosing migration targets. The main challenges to migration readiness stem from the absence of publicly available financial stability data, which makes it difficult to assess the company's capacity to fund significant migration efforts. Additionally, the 'Vendor Lock-in Risk: Unknown' is a notable gap; however, the reported 'Total Services: 34' with vendor HQs in 7 unique countries suggests a degree of vendor diversity that could mitigate high lock-in, assuming these services are not heavily concentrated with a few critical vendors.

Compliance

6 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

XM Cyber explicitly states SOC 2 Type 2 compliance, which is appropriate for their cloud-based cybersecurity services. SOC 2 compliance demonstrates strong security controls and is critical for maintaining customer trust in their security platform. Low risk due to documented compliance and regular auditing requirements.

Evidence: https://xmcyber.com/security-compliance-and-privacy/

NIS2 (source) — Assessment Required

NIS2 applicability is uncertain. While XM Cyber operates in cybersecurity (which could fall under digital service providers), they are primarily a software vendor rather than a critical infrastructure operator. Their ownership by Schwarz Group (retail/essential services) and European operations create potential indirect exposure. Size thresholds appear to be met, but sector classification requires detailed assessment.

Evidence: https://xmcyber.com/company/

BSI C5 — Compliant

XM Cyber explicitly states BSI C5 compliance, which is a German cloud security standard. This is relevant given their European operations through Schwarz Group ownership and demonstrates commitment to high-level cloud security standards. Low risk due to documented compliance with this rigorous German security framework.

Evidence: https://xmcyber.com/security-compliance-and-privacy/

Financials

Three-year financials

Financial Resilience Score: 7/10

XM Cyber benefits from extraordinarily strong parental backing as a wholly owned subsidiary of Schwarz Group, Europe's largest retailer with annual revenues exceeding €130 billion. This ownership structure effectively eliminates near-term liquidity or funding risk, providing the company with virtually unlimited financial runway and insulating it entirely from the capital market pressures faced by independent or publicly listed cybersecurity peers. The company does not need to raise external capital, manage quarterly earnings expectations, or demonstrate short-term profitability to survive. The company's strategic positioning is further reinforced by a captive anchor customer in Schwarz Group itself — whose Lidl, Kaufland, and STACKIT cloud infrastructure represent a large, guaranteed internal deployment — alongside a growing roster of enterprise customers across EMEA, North America, and Asia-Pacific. Recognition as a Challenger in the inaugural 2025 Gartner Magic Quadrant for Exposure Assessment Platforms and consecutive Frost & Sullivan leadership awards validate its market position and support premium SaaS pricing. The recurring subscription model provides inherently predictable, high-margin revenue streams with strong net retention characteristics typical of enterprise cybersecurity platforms. However, the complete absence of public financial disclosure is a significant constraint on independent assessment. No audited revenue, EBIT, equity, or growth metrics are available for any fiscal year, making it impossible to verify profitability, cash generation, debt levels, or actual growth trajectory. Counterparties must rely entirely on qualitative signals. Additionally, the company's strategic direction is wholly controlled by a single private owner, removing independent board oversight and public market discipline. Competitive intensity from large incumbents such as Microsoft, CrowdStrike, Tenable, and Palo Alto Networks entering the CTEM/exposure management space poses a structural risk to long-term market share for pure-play vendors. Geopolitical risk stemming from Israel-based headquarters and primary R&D operations, potential product roadmap misalignment driven by Schwarz Group's internal priorities over broader commercial market needs, and the inability to benchmark performance against peers due to zero public ARR or growth disclosures further temper the overall resilience score. The score of 7 reflects very strong structural and ownership-based resilience offset by full financial opacity and meaningful competitive and geopolitical risks.

Key strengths: Wholly owned by Schwarz Group (revenues >€130 billion), providing virtually unlimited financial runway and eliminating external funding dependency, Captive anchor customer in Schwarz Group's own retail and digital infrastructure (Lidl, Kaufland, STACKIT cloud), Recurring SaaS subscription model generating predictable, high-margin enterprise revenue, Named Challenger in inaugural 2025 Gartner Magic Quadrant for Exposure Assessment Platforms, Consecutive Frost & Sullivan Leader recognition in Automated Security Validation, Multi-module platform expansion (APM, VRM, EASM, SCM, ECM, AI Security) increasing cross-sell and upsell potential, Enterprise-grade certifications: SOC 2 Type II, ISO/IEC 27001, AICPA, BSI C5, Strategic partnerships with Google Cloud, SentinelOne, and growing MSSP/channel ecosystem, Global presence across EMEA, North America, and Asia-Pacific with dedicated regional leadership, Acquisition price of ~$700 million USD implies substantial scale and investor confidence at time of exit

Risk factors: Complete absence of public financial disclosure — no audited revenue, EBIT, equity, or growth metrics available for any fiscal year, Entire strategic direction, investment levels, and exit options controlled by a single private owner with no independent board or public market discipline, Geopolitical and operational risk from Israel-based headquarters and primary R&D operations, Rapidly intensifying competition from large incumbents (Microsoft, CrowdStrike, Tenable, Qualys, Palo Alto Networks) building or acquiring CTEM/exposure management capabilities, Product roadmap risk — may be increasingly shaped by Schwarz Group's internal needs rather than the broader commercial market, No public ARR, customer count, or growth rate disclosures, making competitive benchmarking and independent performance assessment impossible, Integration risk as part of broader Schwarz Digits strategy alongside SentinelOne partnership and STACKIT cloud

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report