News

ATHENE UP26@it-sa finalists: An interview with RedCastle

30/08/2026

RedCastle is one of the five finalists for the ATHENE UP26@it-sa Award

As IT forensic experts, they were always called in only when it was already too late. Felix Wanner and Stefan Köhler were no longer willing to put up with this, so they founded Red Castle to provide effective protection for small and medium-sized enterprises through a managed SOC service. In this interview, the Red Castle founders talk about how they started the business, the most costly mistake in the company’s history – and why they almost didn’t apply for the ATHENE Startup Award UP26@it-sa. 

Your start-up in one sentence? 

RedCastle operates an AI-powered Security Operations Centre for small and medium-sized enterprises – with its own analysts, its own forensic team and operations based in Germany. 
#MittelstandsSOC #ManagedSOC #SecurityFürDenMittelstand 

When did you first realise with absolute certainty: ‘This is exactly what’s missing from the market’? 

Felix Wanner: I’ve been hacking for over 20 years; for the last 18 years, I’ve been on the other side as an IT forensic expert and IT consultant. The difference between the two roles is the timing: as a hacker, I arrive before the damage is done; as a forensic expert, I arrive afterwards. And by then, it’s almost always too late.

Over the years, the picture has remained remarkably consistent, from small and medium-sized enterprises right through to large corporations: tools are in place, often purchased at great expense, but they are incorrectly configured and lack the processes to support them. The vulnerability scanner identifies the open vulnerability, the EDR detects the suspicious process, and external monitoring spots the exposed service. Yet none of these systems communicates with the others, and ultimately none of them is analysed. An attacker moves across all these layers, whilst the defences operate in silos. 

We were absolutely certain of this after two IT forensics cases at RedCastle, which are typical of small and medium-sized enterprises. One client was running an expensive EDR solution, but audit logging had been completely disabled. In another case, the SIEM had reported several thousand alerts, but nobody had analysed them, and a ransomware incident followed. The problem is rarely a lack of technology. The problem is that nobody is managing it. 

That is exactly why we founded RedCastle: instead of ‘false security’, there is ONE platform that brings everything together, and a team that runs it. Every day. 

How big is your team, who’s in it, and how did you all meet?

Stefan Köhler: There are 14 of us: as a board member, I oversee sales and commercial operations; Felix Wanner is responsible for technology, SOC operations and platform development; and Jasmin Wanner heads up marketing. In addition, we have SOC analysts, IT security and IT forensics, incident response, IT operations, project management and accounts. 

We came together over 20 years ago: Felix and I have been friends since 2003, Jasmin is his wife, and the rest of the team also joined us mainly through personal recommendations and long-standing collaborations. 

Two things set us apart: we are a registered co-operative owned by the founders – no venture capital, no investors; decisions are made by the three of us. And in the technical team, everyone holds a relevant degree or recognised certification, including three Master’s degrees in IT security and IT forensics. 

Felix and I complement each other best in terms of our personalities: he drives things forward, thinks in terms of action plans and demands a lot from the team and himself. I’m the calmer one, who sees things through to the end and keeps track of the commitments we’ve made to our clients. Without him, we’d be slower; without me, we’d be more chaotic.

Whose life (or working day) do you make noticeably easier? 

Felix Wanner: Medium-sized companies with between 50 and 1,000 employees, whose IT department consists of two to five people, none of whom specialise exclusively in security. This also includes operators in the NIS2 and KRITIS sectors who are subject to compliance requirements but are unable to provide the necessary evidence internally. 

The working day of the person responsible for IT security within the company becomes noticeably easier. In SMEs, this is often the IT manager who also holds this role, whilst for regulated operators it is the ISB or CISO. Our platform has processed well over 50 million alerts, of which around 18,000 – or 0.03 per cent – have reached an analyst. Otherwise, someone internally would have had to review the rest – or, more realistically, nobody would have. Instead of a constant stream of alerts, the IT manager receives a phone call when the situation is serious, complete with an assessment and specific recommendations for action.

Where do you think you’ll be in a year’s time, if everything goes well? 

Stefan Köhler: We are currently working towards ISO 27001 certification, which is firmly on the agenda for next year. In the short term, we are moving our own XDR agent out of beta and into full operation, and expanding the sales channels that we have barely tapped into so far. Within a year, we aim to have a three-figure number of customers.

Why are you so convinced that you, of all people, will be successful? 

Felix Wanner: We don’t sell tools; we provide the service. We carry out forensic analysis and incident response with our own team. So we constantly see how attacks actually unfold, and this experience feeds directly into our detection rules. To this end, AI models and data run on our own servers in Germany, rather than in a US cloud. For our target audience, this is not a minor consideration, but often a prerequisite for working with us. It also makes financial sense: a SOC subscription costs less than employing your own security specialist.

What have been the biggest successes and challenges so far? 

Stefan Köhler: Our greatest success is that the platform has been up and running since February 2026, following several years of development. Since then, we’ve already on-boarded clients – all through word of mouth and without any advertising. The fact that regulated, reputable clients trust us and commission us is by no means a given for a young company. 

The low point was a major incident response contract which we handled not directly, but via an intermediary service provider. We have still not been paid for it to this day. The mistake was costly, but it led to a rule that still applies today: we will only accept direct commissions, with our own contract and our own invoice, no matter how attractive a project via a third party may seem.

Why did you enter the ATHENE Startup Award UP26@it-sa? 

Felix Wanner: To be honest, we almost missed it. We were so busy expanding the SOC and the platform that the application would have slipped our minds had an employee not pointed out the extended deadline to us. In our day-to-day operations, our team is constantly spotting ways to make the platform even better, and I’m happy to put those ideas into practice. Talking about the results to the outside world often comes last for us.

That’s precisely why submitting the application was the right decision. it-sa is the stage where our target audience is present in person and where a panel of experts critically assesses our product.

 

show all news