AWARE7
German boutique offering penetration testing, security awareness training, and BSI/BMBF/EU-funded security research from Gelsenkirchen.
Visit Website ↗ + Add to CompareOverview
AWARE7 is a boutique cybersecurity firm based in Gelsenkirchen, Germany, founded in 2018 by Dr.-Ing. Matteo Große-Kampmann and Chris Wojzechowski. The ISO 27001-certified company focuses on three areas: offensive security testing (penetration testing and vulnerability assessment), information security management consulting (building ISO 27001-aligned ISMS programs), and security awareness — including live hacking demonstrations delivered to corporate and public audiences across the German-speaking market.
What sets AWARE7 apart from a typical regional pentest shop is its research pedigree: roughly a fifth of company revenue comes from publicly funded research projects for Germany’s Federal Office for Information Security (BSI), the Federal Ministry of Education and Research (BMBF), and EU research programs. That work has produced published CVEs and conference presentations, giving the firm a technical credibility trail that goes beyond marketing claims. The company also built RiskRex, an internal digital risk assessment tool used to surface technical and human weaknesses during engagements.
AWARE7 operates as a regional specialist rather than a global platform vendor. It is a sensible fit for mid-market German and EU organizations that want hands-on penetration testing and awareness programming from a locally grounded team with a genuine research track record, but it does not compete at enterprise platform scale with the larger international MSSPs and pentest firms.
Innovation Matrix Assessment
Actively maintains a research pipeline (BSI/BMBF/EU-funded projects) alongside commercial services, a steady but boutique-scale pace of capability development rather than rapid product iteration.
ISO 27001-certified delivery across pentesting, ISMS consulting, and awareness training, with reported output of dozens of penetration tests and 300+ live hacking sessions annually, though at boutique regional scale.
Steady regional growth and continued public research funding since 2018, but no disclosed VC funding or major expansion events to indicate accelerating trajectory.
A conventional boutique pentest-and-awareness model; its internal RiskRex tool is a useful delivery aid rather than a category-redefining product.
Publishing real CVEs and running government-funded (BSI/BMBF/EU) research projects provides independent, verifiable evidence of technical capability beyond vendor marketing.
Penetration testing and security awareness remain core, recurring needs for mid-market organizations, particularly in the regulated German/EU market this firm targets.
Why CISOs Should Care
Offers hands-on penetration testing and awareness programs backed by a genuine government-funded research track record, useful for EU-based organizations wanting a locally grounded testing partner.
What Makes It Different
Unlike most boutique pentest shops, a meaningful share of AWARE7's work is publicly funded security research for German and EU authorities, producing published CVEs rather than purely commercial deliverables.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A credible, evidence-backed boutique European testing and awareness firm; strong on technical legitimacy for its size, but a regional specialist rather than an enterprise-scale platform play.
Editorial Note: Claims vs. Verified Findings
The company's self-reported figures (20% of revenue from public research, 300+ live hacking shows per year, office size) are vendor-sourced and unverified; ISO 27001 certification and published CVE credits are independently verifiable.
Sources
Alternatives to AWARE7
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…