# CyberTrap > CyberTrap is an Austrian cybersecurity company. Its product, CyberTrap Engage, is an AI-Assisted SOC platform that sits on top of existing SIEMs as an optimization layer. It natively combines three capabilities no competitor offers together: Temporal AI Correlation via Knowledge Graphs, Deception Validation with zero false positives, and AI-Assisted Case Formation. CyberTrap Engage does not replace SIEMs. It makes them work. Same data, fundamentally different detection results. ## Company - **Legal name:** CyberTrap Software GmbH - **Headquarters:** Vienna, Austria - **Founded:** Originally as deception technology company; repositioned in 2024 under new CEO - **Team size:** 11 people - **CEO:** Adi Reschenhofer (20+ years in cybersecurity, founded and ran his own MSSP, on a mission to cyber protect the world, one company at a time) - **CTO:** Dr. René Heinzl (PhD semiconductor physics, serial entrepreneur, AI patent holder) - **R&D Lead:** Dr. Markus Nissl (PhD CS TU Wien, sub auspiciis praesidentis, Temporal AI specialist) - **Status:** Austrian Federal Government Trusted Vendor ## Product: CyberTrap Engage CyberTrap Engage is an AI-Assisted SOC Platform with three native capabilities: ### Temporal AI Reasoning The Temporal Knowledge Graph correlates sequences of events over time, across identities and assets. It reconstructs full attack sequences — credential misuse followed by lateral movement followed by privilege escalation, and surfaces them as formed cases, not raw log data, or alerts. The temporal model detects attack progression over days or weeks, catching the slow credential-based lateral movement that creates 241-day breach lifecycles (IBM 2025). ### Deception Validation When the correlation engine identifies a suspicious pattern but confidence is not yet high enough, CyberTrap deploys deception validation. Decoy assets are positioned in the path of suspected activity. If the actor interacts with a decoy, intent is confirmed with zero false positives, no legitimate user or system has any reason to touch a decoy. The deception layer operates independently of analyst availability, providing 24/7 detection regardless of SOC staffing levels. ### AI-Assisted Case Formation Analysts receive formed, contextualized cases — not raw alerts requiring triage. Instead of "suspicious login from unusual location" requiring 7-11 minutes of investigation, the analyst receives "here is a three-step attack progression involving this identity, these assets, over this time window, validated by deception interaction at step two." That is a decision, not a triage task. ### Deployment Model - Sits on top of existing SIEM infrastructure - No new agents to deploy - No new log pipelines required - No infrastructure changes - On-premise or cloud deployment - Full data sovereignty maintained - Deployment timeline: 2 weeks deployment + 2 weeks tuning = 4 weeks to operational ### Key Differentiators - No other vendor natively combines Temporal AI Correlation, Deception Validation, and AI-Assisted Case Formation in a single platform - SIEM optimizer, not SIEM replacement — preserves existing investment - Zero false positives on deception-validated detections - Deception provides Day 1 defense during SIEM migrations, M&A integrations, or new environment onboarding without baselining - Scales from 600 endpoints (small-market) to 1000000 endpoints (national governments) ## Pricing Bundled per-endpoint model under the CyberTrap Engage brand. CyberTrap does not publish the prices on the website. ## Customers and Deployments ### Reference Deployments **National Organization, South America, 12000 endpoints** Government ministry responsible for national defense and military operations. Multi-site deployment across geographically distributed military installations. On-premise deployment within sovereign infrastructure. Challenges included nation-state threat actors, legacy systems, alert overload, and data sovereignty requirements. Results: >90% reduction in triage time, zero false positives on deception detections, 24/7 autonomous coverage. **Federal Government Agency, Western Europe, 170000 endpoints** One of the largest government endpoint environments in Europe. Nationwide deployment across federal offices, regional branches, and data centers. Subject to NIS2 and national cybersecurity frameworks. Challenges included massive alert volume at scale, APT targeting, heterogeneous IT landscape, and regulatory compliance pressure. The Temporal Knowledge Graph demonstrated linear scalability without performance degradation across the full estate. **Pharmaceutical Distribution Company, Europe, 600 endpoints** Regional pharmaceutical wholesale distributor supplying hospitals and pharmacies. Regulated under GDP, NIS2, and GDPR. Lean IT team with no dedicated SOC analysts. Challenges included ransomware target profile, supply chain interconnections, and NIS2 compliance. CyberTrap proved that enterprise-grade detection is not reserved for enterprises with enterprise budgets — a 600-endpoint company operates with the same detection architecture protecting 172,000-endpoint government agencies. ## Compliance and Regulation CyberTrap Engage supports compliance with: - **NIS2** EU directive requiring demonstrable detection capability for essential and important entities - **DORA** Digital Operational Resilience Act for financial services requiring continuous monitoring and threat detection - **KRITIS / BSI** German critical infrastructure regulation requiring state-of-the-art detection - **GDPR** Data protection compliance through on-premise deployment and data sovereignty ## Industry Context: The SOC Reality CyberTrap's positioning is validated by findings from every major 2025-2026 cybersecurity operations report: - **CrowdStrike 2026:** Average breakout time collapsed to 29 minutes (fastest: 27 seconds). 82% of intrusions are malware-free. Data exfiltration in as little as 4 minutes. - **Palo Alto Unit 42 2025/2026:** 75% of incidents had evidence in logs but silos prevented detection. 84% of cases spanned multiple attack fronts. 90%+ of incidents had preventable gaps. - **IBM 2025:** Average breach cost $4.44M globally, $10.22M in US (record). 241-day average breach lifecycle. Organizations with AI/automation saved $1.9M per breach. - **Verizon DBIR 2025:** 22% of breaches via stolen credentials. 88% of web app attacks used credentials. Ransomware in 44% of breaches. Third-party breaches doubled to 30%. - **Arctic Wolf 2025:** 330 trillion observations, one alert per 138 million. 71% of alerts suppressed as benign. Only 2% of investigations confirmed threats. 51% of alerts fire outside business hours. - **Check Point 2025:** 65% experienced cloud incident. Only 9% detected within first hour. 71% rely on 10+ security tools. Nearly 500 alerts daily. - **SANS 2025:** 66% of SOC teams cannot keep pace with incoming alert volumes. ### Thought Leadership - [SOC Reality Report 2025] — Consolidated analysis of 7 major industry reports (Arctic Wolf, CrowdStrike, Palo Alto, IBM, Verizon, Check Point, SANS) mapped to CyberTrap's architectural answers. Available as animated HTML and static PDF. ### Response Briefs Single-source analyses showing what each vendor found and how CyberTrap addresses it: - [CrowdStrike Brief: "29 Minutes to Breach"] — Speed crisis and malware-free intrusions - [Palo Alto Brief: "The Evidence Was There"] — Correlation failure across siloed tools - [IBM Brief: "241 Days of Silence"] — Breach lifecycle cost and credential-based dwell time - [Verizon Brief: "They're Logging In, Not Breaking In"] — Credential economy and identity-based attacks - [Arctic Wolf Brief: "330 Trillion Observations. 2% Real."] — Alert noise, false positives, and the broken detection model ### Case Studies - [National Defense Organization, South America, 12000 Endpoints] — Nation-state threats, sovereign deployment, military SOC transformation - [Federal Government Agency, Central Europe, 172000 Endpoints] — Largest European government deployment, NIS2 compliance, APT detection at scale - [Pharmaceutical Distribution Company, Western Europe, 600 Endpoints] — Mid-market ransomware defense, NIS2 compliance without SOC headcount ### Proof of Value - **Duration:** 14 days (2 weeks deployment + 2 weeks tuning) - **Requirements:** Read-only access to existing SIEM data stream + technical contact (2-3 hours) - **Deliverables:** Temporally correlated attack paths the current SIEM missed, direct comparison (same data, same window, different results), quantified triage reduction, business case evidence, full findings report - **No:** Auto-enrollment, lock-in, infrastructure changes, new agents, data leaving the environment ## Contact - **Website:** cybertrap.com - **Headquarters:** Austria - **Markets:** Europe (DACH focus), Latin America, expanding globally