KastGroup is a Swiss family-owned company (founded 2014) that builds customized IT security operations for organizations ranging from small businesses to enterprises. Headquartered in Wallisellen, near Zürich, it has carved out a niche across healthcare and general industry - running a 24/7 Security Operations Center certified to ISO/IEC 27001:2022, alongside a Risk Operations Center designed for continuous vulnerability management. The threat model here is broad-spectrum: monitoring, detection, and active defense baked into managed services rather than left to point products.
The team's offensive capabilities include penetration testing, red teaming, and continuous vulnerability scanning through their own tools - swisspentest for ongoing scan cycles and riscape for integrated risk management. They also operate a Medical Native SOC tailored specifically to healthcare providers, where regulatory pressure and legacy medical devices create a distinct attack surface. PolicyClue, a cybersecurity awareness browser extension, rounds out the human-layer defense.
On the defensive operations side, the work spans network infrastructure hardening, phishing awareness training, and policy-driven risk management. The culture signals lean toward long-term, ownership-driven thinking - family-owned, not venture-scaled. If you're interested in building and defending real environments rather than selling tools into a vacuum, the domains here are concrete: SOC engineering, red team tradecraft, medical device security, and vulnerability management at operational tempo.






