Skip to content

LocateRisk

LocateRisk is a German external attack surface management and vendor risk management platform that combines automated asset discovery with continuous vulnerability monitoring for the DACH market.

Visit Website ↗ + Add to Compare
57/100Incremental Innovator

Overview

LocateRisk grew out of a 2018 hackathon hosted by Sparkassen Versicherung, a large German insurer, and has since built a combined external attack surface management (EASM) and vendor risk management (VRM) platform aimed at the DACH region (Germany, Austria, Switzerland). The product automatically discovers an organization’s internet-facing digital assets without requiring any installation, checks them against nine vulnerability categories, and continuously re-scans for changes, producing prioritized remediation guidance rather than a raw vulnerability list.

The company’s customer base spans small and mid-sized businesses up through KRITIS operators (Germany’s designation for critical infrastructure entities) and ministries, and by the company’s own account it serves over 1,000 organizations in the DACH region — a customer count that, if accurate, would represent meaningful market penetration in a regionally focused category. LocateRisk won the ATHENE Startup Award for “Best Cybersecurity Startup 2024 DACH” at it-sa, Europe’s largest IT security trade show, and placed second in WirtschaftsWoche’s Best of Technology Award 2024 — both independently judged industry recognitions rather than self-reported claims.

For CISOs and risk managers at German-speaking-market organizations, particularly those subject to KRITIS obligations or managing vendor risk across a supply chain, LocateRisk offers a regionally focused, no-install alternative to larger international EASM/VRM platforms, with the it-sa award serving as one of the more concrete independent validations in this batch of profiles.

Innovation Matrix Assessment

Innovation Velocity 6/10

Growing from a 2018 hackathon project to a platform covering nine vulnerability categories with continuous monitoring and over 1,000 reported customers by 2024 indicates sustained, real product development over six years.

Operational Value 6/10

A reported customer base spanning SMEs to KRITIS operators and government ministries, combined with two independent 2024 industry awards, suggests a functioning, credible operation for a company of its size.

Market Momentum 6/10

Winning the independently judged 'Best Cybersecurity Startup 2024 DACH' award at it-sa and placing in WirtschaftsWoche's Best of Technology Award 2024 are concrete, third-party-validated momentum signals within the same year.

Category Disruption 5/10

Combining EASM with vendor risk management in a no-install, continuously updating platform is a sensible product bundle, but EASM and VRM are both established categories with larger international competitors; the disruption here is more regional-market-fit than technical novelty.

Real-World Efficacy 5/10

No independent, named third-party benchmark of detection accuracy was found; the customer-count and award recognitions are independently corroborated, but efficacy of the underlying scanning technology itself rests on the company's own description.

Enduring Relevance 6/10

KRITIS obligations and general EU cyber-resilience regulation are driving real demand for external attack surface and vendor risk visibility among exactly the mid-sized and public-sector DACH organizations LocateRisk targets.

Why CISOs Should Care

CISOs at German-speaking-market organizations, especially those with KRITIS obligations, get a no-install EASM and vendor risk platform built specifically around DACH regulatory needs, backed by independent 2024 industry recognition.

What Makes It Different

LocateRisk's DACH-region focus and combined EASM-plus-VRM bundle differentiate it from larger, more US/UK-centric EASM vendors that treat European regulatory context as a secondary consideration.

The Matrix Verdict

57/100 — INCREMENTAL INNOVATOR

A regionally strong, independently recognized EASM/VRM vendor well matched to DACH-market compliance needs; its main open question is how its detection technology stacks up against larger EASM platforms outside its home region.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: the specific '1,000+ customers' figure and detection-accuracy claims across the nine vulnerability categories. Independently verifiable: the it-sa 'Best Cybersecurity Startup 2024 DACH' award and the WirtschaftsWoche Best of Technology Award 2024 placement, both third-party-judged recognitions.

Sources