XMCO operates a security services firm rooted in penetration testing, vulnerability management, and forensic response. The technical stack spans offensive tools (Cobalt Strike, PowerShell, C/C++, Go) alongside cloud platforms (Azure, AWS) and established security frameworks (OWASP, PCI DSS) — a pattern typical of firms balancing hands-on red-team work with audit and compliance delivery. Active projects span red-team simulation, penetration testing campaigns, and internal tool development, while pain points cluster around scaling service delivery (pentest expansion, red-team scaling, audit portfolio diversification) and internal structure (HR function maturity in a high-growth environment).
XMCO is an independent French security services firm founded in 2002, headquartered in Paris. The firm operates across penetration testing, security audits, gap analysis, PCI DSS certification support, vulnerability intelligence (through CERT-XMCO), threat intelligence, and digital forensics. The company holds CERT and PCI QSA credentials. Current workforce is 51–200 employees, concentrated in security-focused roles, with minimal hiring velocity and current open positions concentrated in France. Operating model combines compliance-driven audit work (PCI DSS, CERT frameworks) with offensive security services (red-team simulation, penetration testing).
XMCO holds CERT and PCI QSA (Qualified Security Assessor) certifications, qualifying them to conduct PCI DSS assessments and vulnerability management activities.
XMCO's tech stack includes Cobalt Strike, C/C++, PowerShell, Python, Go, and OWASP frameworks—standard offensive security tooling for red-team campaigns and penetration testing.
Other companies in the same industry, closest in size