NEON Information Security is a Munich-based cybersecurity company founded in 2023 that built VASE (Verification through Attacks in a Security Environment) to close a persistent gap in enterprise security: proving that deployed controls actually detect and respond to real attack behavior, not merely that they are present or correctly configured. VASE continuously validates operational security effectiveness through automated attacker simulations, producing repeatable evidence that security controls work as intended across changing infrastructure and evolving techniques. This approach supports growing regulatory expectations that favor ongoing proof over point-in-time attestations, aligning with requirements such as NIS2 and DORA.
Positioned in the Continuous Security Validation / Security Control Validation / CTEM-adjacent market, VASE goes beyond vulnerability management and security posture management by executing realistic attack scenarios rather than only identifying weaknesses. The platform uses an agent-based, distributed testing architecture deployed throughout customer environments and runs multi-stage, end-to-end attack chains. It includes a library of more than 2,000 configurable test cases aligned to the MITRE ATT&CK framework, enabling regular, automated repetition similar in intent to Breach and Attack Simulation but oriented toward systematic control verification.
VASE supports on-premises, cloud, and hybrid environments, and validates not only whether attacks succeed but whether security controls and SIEM systems detect, correlate, and respond appropriately. Licensing is based on the number of deployed agents and available test cases, with customer-managed deployment and an optional SaaS model. NEON is self-funded via consulting revenue supplemented by EU R&D funding, is early in commercial market entry with limited reference customers, and is initially focused on Germany and regulated sectors such as government, municipalities, financial services, and critical infrastructure, supported by partners including Elastic, ACS, and KIT.
See All Locations
See All Locations