
German penetration testing and IT security assessment services firm.
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
SySS GmbH is an IT security company founded in 1998 by Sebastian Schreiber and headquartered in Tübingen, Germany. The company specializes in penetration testing and security assessments, operating as a vendor-independent service provider across the DACH region (Germany, Austria, Switzerland). In 2018, SySS expanded by founding an Austrian subsidiary, SySS Cyber Security GmbH, based in Vienna. The company's core services include penetration testing, red teaming, and physical security assessments. Physical assessments involve testing the physical security of company sites by attempting to gain unauthorized access to premises and achieve client-defined objectives such as accessing server rooms or retrieving sensitive assets. SySS also conducts research and development activities and maintains an R&D team that publishes findings through a pentest blog, technical articles, and security advisories. SySS operates on a vendor-independent basis, meaning its assessments and recommendations are not tied to any specific product or manufacturer. After each engagement, clients receive written and electronic documentation that undergoes a two-step quality assurance process for technical and linguistic accuracy. The reports provide technical recommendations but do not include product-specific suggestions. The company serves a broad range of clients including small and medium-sized businesses, large corporations, public utilities, hospitals, financial institutions, and government entities. Its client base includes organizations such as Deutsche Bahn, Deutsche Lufthansa, Mercedes-Benz Group, SAP SE, Vodafone, and over 50 hospitals. SySS holds ISO 27001 certification and TISAX accreditation. The company employs approximately 170 staff and has formulated published ethical principles for penetration testers. It also follows a responsible disclosure policy for newly discovered vulnerabilities.