L. Possehl & Co. mbH isn't your typical cybersecurity shop. It's a 178-year-old German investment group - Lübeck-headquartered, sole shareholder a non-profit foundation - that owns and operates more than 200 companies across ten autonomous divisions. Annual revenues land around €8.4 billion, with roughly 13,500 employees spread across 30+ countries. The portfolio spans machinery and plant engineering, construction, precious metal processing, electronics, and digital solutions.
That breadth is the threat surface. Each subsidiary operates independently, which means each carries its own attack vector: OT environments in manufacturing plants, IT systems in construction firms, data pipelines in digital solutions units. The "Best Owner" model gives leadership teams autonomy, but security posture and digitalization initiatives flow through a shared network. For anyone working in InfoSec here, the challenge isn't defending one perimeter - it's coordinating governance and incident response across a sprawling, heterogeneous ecosystem where a compromise in one division can ripple across others.
The ownership structure matters. The Possehl Foundation's mandate emphasizes long-term independence and sustainable business decisions, not quarterly extraction. That translates to a culture where security investments can be framed as legacy protection rather than cost centers. Founders selling into the group expect their companies to be kept whole; maintaining that trust means keeping the infrastructure intact and the threat models current.






