An increasing number of systems, data flows and processes are located outside traditional, centralised security perimeters. At the same time, many organisations are under considerable pressure due to tight budgets and a lack of staff. Furthermore, AI and automation have made attacks on distributed, often inadequately protected infrastructures more economically attractive to attackers. Operators of critical infrastructure and public sector organisations must also meet strict regulatory and operational requirements, such as ensuring the operation of decentralised systems, reliably documenting incidents and restoring operational capability.
“The resilience of critical organisations is crucial to the stability of our society. Attacks on utility providers, healthcare facilities, public authorities or other decentralised infrastructure can significantly disrupt the functioning of public life,” says Marc-Julian Siewert, CEO of secunet. “This is precisely where our partnership with DCSO and Tenzir comes in: we are creating an integrated solution that provides guidance on the threat landscape, makes attacks visible more quickly and strengthens the ability of particularly vulnerable organisations to respond.”
“Effective cyber defence across the board is now a collective endeavour. DCSO brings to this consortium what no product can replace: operational clout, threat intelligence from a unique community, and a bridge to government security agencies. Together, we are the first provider to deliver this complete stack from a German source,” comments Dr Andreas Rohr, Managing Director of DCSO Deutsche Cyber-Sicherheitsorganisation GmbH, on the partnership.
“Security data must be processed where it is generated and transferred from there securely and in a controlled manner to the analysis stage. This is precisely what our pipelines enable: they make secunet edge the intelligent data layer at the network edge and connect it securely to DCSO’s SOC expertise,” explains Johan Hesse, Chief Operating Officer, Tenzir GmbH.
A systematic approach to resilient and sovereign cyber defence
The joint offering from the three partners addresses this challenge with an integrated systems approach. It combines three complementary layers: secunet edge, as an edge gateway platform, creates a secure and physically controllable execution environment for distributed infrastructures directly on-site. The DCSO’s sensor technology and security services, as well as Tenzir’s data pipelines, run on this platform without requiring extensive local IT expertise. secunet edge also serves as a trusted on-site security anchor in the event of an attack.
Tenzir’s security data pipeline forms the intelligent data layer at the network edge. It filters, structures, normalises and prioritises security data before it is forwarded in a controlled manner to downstream analytics and SOC systems. Particularly in modern security architectures with large volumes of telemetry data, this pre-processing is crucial for relieving the load on central analysis platforms, reducing costs and making relevant signals available more quickly.
The processed data is then transmitted securely and in compliance with data protection regulations from the distributed sensors to the DCSO’s central analytics backend. There, a Managed Security Operations Centre (SOC) handles detection, analysis and incident response around the clock, based on continuous threat intelligence. Immediate measures can be centrally controlled and take effect directly on site. This reduces response times from hours or days to a matter of minutes and significantly limits the spread of an attack. System integrators, managed service providers and operators of large-scale infrastructures benefit from this in particular.
Comprehensive situation overview for distributed infrastructures
This collaborative approach, utilising distributed secunet edge installations, lays the foundation for tactical security situation assessments. Particularly in environments comprising numerous smaller facilities—such as doctors’ surgeries, branch networks, remote industrial sites or decentralised supply facilities—this approach provides a comprehensive analysis of the situation across the entire area, rather than relying solely on large centralised facilities.
Looking ahead, this approach supports the technical requirements for cross-domain situational awareness concepts. For example, in the context of the ‘Cyberdome’ digital shield being developed for Germany by the Federal Office for Information Security: distributed security data is collected in a structured manner, processed at the network edge, minimised where necessary, and incorporated into comprehensive situational awareness overviews – in a pseudonymised or anonymised form, where legally or organisationally required.
Availability
The joint solution based on secunet edge is already undergoing field trials and is available immediately for further evaluation. Interested organisations can contact any of the three partners to arrange a joint needs analysis and a structured start to the pilot phase.
![[Translate to English:] [Translate to English:]](/fileadmin/user_upload/03_Presse/Pressemitteilungen/Pressemitteilungen_DE/Pressemitteilungen_2026_DE/secunet_edge_Keyvisual_Koop.png)
