Buyer fit
Good fit when
- ✓German SMEs and regulated EU buyers that need on-premises or sovereign cloud delivery for NIS2 and BSI alignment
- ✓Customers that already own SIEM and EDR and want a co-managed SOC layer rather than a rip-and-replace platform
- ✓Microsoft-stack mid-market buyers in DACH that want a German MDR with deep Sentinel and Defender practice
Watch out when
- ×Non-European multinationals needing 24/7 follow-the-sun coverage from regional SOCs
- ×Buyers who require a published response SLA and breach warranty backed by financial commitments
- ×Teams that rely heavily on G2 or large public review pools to vet vendors
Coverage
5 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom quote, varies by chosen tier.
How pricing works+−
Sold direct.
Not published
Cost caveats
- –On-Premises tier requires the customer to keep running their own SIEM hardware and licensing
- –Co-Managed tier means the customer's team still executes part of the response
- –No published SLA, response timing depends on the underlying SIEM and EDR you bring
What costs extra (3)+−
- –SOC consulting and CDRC build-out
- –SIEM use case engineering
- –Incident response retainer
Team and access
Certifications
Reputation
SECUINFRA has a Gartner Peer Insights vendor profile in the MDR category but limited English-language community coverage on G2 and PeerSpot. Most public sentiment comes from German-language IT press and the firm's own publishing. Buyers shopping outside Germany should expect to lean on direct references.
What customers praise
- ✓Sovereign delivery options appeal to German SMEs and regulated EU buyers wary of US cloud providers
- ✓Three-tier model (full-service, co-managed, on-premises) gives buyers a real choice on data residency
- ✓Placed 4th in Germany's Best Employers 2025 by Great Place to Work, suggests lower analyst churn than typical for a German MSSP
Common complaints
- ×Limited public review base outside German-language sources
- ×No published SLA or detection metrics to benchmark against pure-play competitors
- ×Footprint is concentrated in Germany, multinationals will need to confirm timezone and language coverage
Almost no English-language Reddit discussion. r/cybersecurity_de and German LinkedIn carry more chatter than the global subs.
Questions to ask
- 1.
Which of the three tiers fits us best, full-service, Co-Managed or On-Premises, and how does pricing differ between them?
- 2.
If we go On-Premises, what hardware, SIEM licensing and storage costs are we still on the hook for?
- 3.
How does response work at 3am if our team is unreachable, and which actions are autonomous versus customer-approved?
- 4.
What detection content stays with us if we leave, and what is built specifically inside our SIEM versus your platform?
- 5.
Do you have customer references in our regulated sector, ideally NIS2 or BSI-aligned, that we can speak with?
- 6.
How do you handle multilingual reporting if we have non-German operating units?
- 7.
What does the analyst rotation look like, and how is night shift covered from German Cyber Defense Centers?
Evidence
Sources reviewed
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
