Send email Copy Email Address
2026-10-01
Patricia Müller

Putting Cyber Defense to the Test

RedMimicry simulates realistic cyberattacks to find out whether security systems, processes and teams can detect and respond to an attack in practice. The new team at the CISPA startup incubator now receives funding through StartUpSecure.

For Stefan Steinberg, COO of RedMimicry, and CEO Alexander Rausch, the idea for the startup grew out of many years of working in cyber defense. They repeatedly saw companies fall victim to cyberattacks even though they appeared well protected on paper.

The problem, Steinberg explains, was often not a lack of security tools, but the way those tools and processes worked together when an attack actually happened. RedMimicry was founded around a simple change of perspective: instead of only looking for vulnerabilities, companies should be able to test whether their cyber defense can actually detect and respond to a realistic attack.

„With RedMimicry, companies can practice and test this very interaction in a practical setting,“ says Steinberg.

Testing the defense against realistic attacks

RedMimicry recreates the behavior of real Threat Actors through multi-stage attack chains. The aim is not simply to combine individual techniques, but to reproduce an attack in a way that generates the kind of security response a real incident would trigger.

That matters because modern cyber defense systems are complex and increasingly AI-supported. An attack has to pass through numerous filters before a security team can see how its defenses actually react. RedMimicry can therefore be used to test, for example, whether forensic investigations work in practice or whether lateral movement is detected.

The platform covers a broad range of applications, from validating individual rules in SIEM systems to customized Red Teaming. Threat Signals, Playbooks and Advanced Practices allow companies to move from testing individual detections toward assessing their wider cyber defense.

For Steinberg, the key is the interaction between systems, processes and people. A real cyberattack does not test just one security tool. It tests whether the entire defense works together.

 

„In Germany, there are an incredible number of opportunities for startups to successfully carry out research-based projects. Unfortunately, the path to success is often fraught with pitfalls. CISPA was there to guide us as an experienced pilot.“

Stefan Steinberg
Founder and COO of RedMimicry

The next step for RedMimicry is to make these tests even more useful. As part of a (through the Federal Ministry of Research, Technology and Space) StartUpSecure-funded development project, the team is working on a Machine-Learning-based pipeline that connects simulated attack steps with the Security Telemetry they generate.

The goal is to show which stages of an attack were visible to systems such as EDR, NDR or SIEM, where a Detection was triggered and where visibility may have been missing. RedMimicry goes one step further than a gap analysis: the results are also intended to provide concrete recommendations on how existing systems can be hardened and improved. This enables companies to make the most effective use of the security systems they already have and to address specific areas where the tests reveal gaps in their defense.

RedMimicry is also pursuing a vendor-neutral approach. Its technology is designed to work with unnormalized, vendor-specific Telemetry and uses Large Language Models and semantic similarities to correlate security data without relying on fixed schemas. For Steinberg, this can reduce the time and effort required to integrate different security systems, particularly in heterogeneous environments.

Making cyber defense measurable

For RedMimicry, detecting an attack is only part of the story. The team also wants to provide clear evidence of what happened.

This makes it possible to repeat an attack after a security measure or fix has been introduced and check whether the change actually improved the defense. In this way, testing becomes a continuous process: simulate an attack, analyze the response, improve the defense and test it again.

From research to application with CISPA

CISPA now supports RedMimicry throughout this journey, both with technical and administrative expertise. Steinberg describes CISPA as an experienced guide through the challenges of turning a research-related project into a startup.

Looking ahead, RedMimicry wants to strengthen three areas of cyber defense: detection, process quality and confidence in taking action. For Steinberg, the underlying principle is clear: “ You can't patch your way to security.”

Instead, organizations need to know how their defenses behave when an attack actually happens and they need a way to test and improve that response repeatedly.

 

Further information: https://redmimicry.com/