Skip to content

Mitigant

Potsdam-based platform that emulates real adversarial attacks against cloud and Kubernetes environments to validate security controls with evidence.

Visit Website ↗ + Add to Compare Claim This Company
50/100Incremental Innovator

Overview

Mitigant (legally Mitigant GmbH, previously operating as Resility GmbH) is a Potsdam, Germany-based cloud security vendor founded by Kennedy Torkura, Nils Karn, and Dr. Muhammad Sukmana, who met as researchers at the Hasso Plattner Institute. The company pioneered applying Security Chaos Engineering to cloud security — running automated, safe adversarial attack emulations (e.g., simulated ransomware scenarios) against AWS, Azure, GCP, and Kubernetes environments to surface exploitable misconfigurations and control gaps before real attackers do, and to produce compliance evidence against standards such as ISO 27001, BSI C5, PCI-DSS, and CIS Benchmarks.

The company has continued operating and shipping product through 2025 and into 2026: it exhibited at GISEC 2025, published a Google for Startups case study describing customers validating cloud security gaps “up to 5x faster” using Gemini-assisted tooling, and has published technical research on emerging risks such as cross-agent privilege escalation in Amazon Bedrock AgentCore (mid-2026). Its positioning has broadened from the original “Security Chaos Engineering” framing toward the industry term “Adversarial Exposure Validation,” reflecting market terminology shifts rather than a pivot away from security. Funding has come from German venture investors including High-Tech Gründerfonds (HTGF), Brandenburg Kapital, and adesso Ventures, plus support from Business Angels Berlin-Brandenburg and Telefónica’s Wayra program; exact amounts are not publicly disclosed in detail.

For CISOs, Mitigant’s core value is proactive validation — testing whether detection and response controls actually catch realistic cloud attack techniques, rather than relying on static posture scans alone. Publicly referenced use cases (e.g., Nooxit, KM.ON) and the Google for Startups partnership are modest but genuine independent signals; broader market traction (named enterprise customers at scale, analyst placements) is not well documented publicly, so this should be read as a durable, active, but still relatively early-stage niche player.

Innovation Matrix Assessment

Innovation Velocity 6/10

Early mover applying Security Chaos Engineering to cloud/Kubernetes (pre-dating much of the now-common 'Adversarial Exposure Validation' category), and has kept publishing new technical research (e.g., Bedrock AgentCore privilege-escalation findings) into 2026, showing sustained R&D activity.

Operational Value 6/10

Proactively validating whether cloud detection/response controls catch real attack techniques is operationally valuable and complements passive posture management, addressing a genuine gap CISOs face in control validation.

Market Momentum 4/10

Small seed-stage funding from regional/German investors, a handful of referenced customers (Nooxit, KM.ON), and a Google for Startups case study are the only independently traceable adoption signals found; no large funding round, major enterprise logos, or analyst-report placement was identified publicly, so momentum should be scored as early-stage.

Category Disruption 4/10

An early entrant in cloud-focused Security Chaos Engineering/Adversarial Exposure Validation, but the category itself (BAS/chaos engineering for cloud) now has multiple competitors, so it is a genuine niche contributor rather than a category-definer at this scale.

Real-World Efficacy 4/10

No independent third-party testing or named large-enterprise validation was found; the 'up to 5x faster' claim comes from a vendor/partner (Google for Startups) case study rather than an independent benchmark, so scored conservatively.

Enduring Relevance 6/10

Continuous validation of cloud/Kubernetes defenses against real attack techniques, including emerging agentic-AI attack surfaces (per its 2026 Bedrock research), is a need that should persist and likely grow over 3-5 years.

Why CISOs Should Care

Lets security teams verify, with evidence, that cloud detection and response controls actually work against realistic attack scenarios rather than assuming coverage from posture scans alone.

What Makes It Different

Grounded in the Security Chaos Engineering discipline (safe, automated adversarial emulation in live-like cloud environments) rather than static configuration scanning, with compliance-evidence generation built in.

The Matrix Verdict

50/100 — INCREMENTAL INNOVATOR

A genuine, still-active, evidence-producing niche player in cloud attack-emulation; technically credible and continuously active through 2026, but adoption evidence remains thin and regional — Incremental tier.

Editorial Note: Claims vs. Verified Findings

Could not independently verify total funding amount, employee headcount, or the scale of the Nooxit/KM.ON customer relationships beyond vendor case-study mentions. The company's category framing has shifted from 'Security Chaos Engineering' to 'Adversarial Exposure Validation' in its own marketing between 2024 and 2026, which is noted as a terminology evolution, not a verified business pivot away from security.

Sources