Founded in 2002, SEC Consult is a cybersecurity consultancy that operates at the intersection of offensive security and enterprise risk management. The firm's core work runs deep across penetration testing, red teaming, and application security assessments - covering everything from web and mobile to cloud environments, SAP systems, IoT and embedded devices, and operational technology. The threat models they deal with aren't theoretical: their client base includes government agencies, international organizations, and critical infrastructure operators across Europe, Asia, and North America.
The technical surface area is broad. Teams handle web application security, mobile security, IT infrastructure assessments, secure software development consulting, and security information management - essentially the full lifecycle from code review to incident response. SEC Defence, the company's dedicated incident response unit, provides the reactive capability when things go sideways. On the certifications side, several locations hold ISO 27001 and CREST accreditation, signals that matter when you're testing environments where the stakes are measured in real-world consequences.
SEC Consult is a subsidiary of Atos, one of the world's largest digital transformation companies, which gives it a different operational profile than a standalone pentest shop. Offices span three continents. The company emphasizes continuous learning and development, consistent with the technical depth required across its domain range - SAP security alone demands a specific skill set that doesn't overlap neatly with cloud pentesting or OT work. If you're looking for a consultancy where the technical work stays hands-on and the client base keeps the pressure real, this is the operating model.




