Summary
- SEPPmail has acquired Aarhus-based CyberPilot for an undisclosed price.
- CyberPilot employs around 50 people and serves more than 1,000 European organisations.
- The deal links email-security consolidation with growing procurement interest in European ownership, service delivery and data sovereignty.
Swiss email-security provider SEPPmail has acquired Danish security-awareness company CyberPilot, adding phishing simulation and training to a portfolio previously concentrated on technical email controls.
The transaction was signed and completed on 10 August, with the companies disclosing it publicly on 13 August. The purchase price has not been released.
CyberPilot, founded in Aarhus in 2016, employs around 50 people and says more than 1,000 organisations across Europe use its awareness and phishing-simulation services. Existing contracts, support arrangements and points of contact are expected to continue, while the company will operate as an independent unit inside the SEPPmail group.
SEPPmail’s existing portfolio covers email encryption, digital signatures, secure file transfer and filtering. CyberPilot extends the group into employee-focused controls intended to measure and reduce susceptibility to phishing and other forms of social engineering.
The companies plan to make CyberPilot’s products available through SEPPmail’s German-speaking channel from late 2026 after localisation, packaging and support work. CyberPilot’s existing management will also join the wider group’s management board.
SEPPmail has made European origin a central part of the acquisition strategy. Marcus Zeidler, its chief executive, said: “For many of our customers, data sovereignty has long since become a supply chain requirement.”
That procurement theme has become more visible as European organisations assess not just the capabilities of security products but the legal, operational and ownership structures behind them. Security platforms can process message content, telemetry, identity information and administrative data, making hosting locations and access arrangements relevant to buyers in regulated sectors.
European ownership alone does not settle those questions. A supplier can be headquartered in Europe while relying on non-European cloud services, subcontractors or support functions, so sovereignty claims still need to be examined against the architecture and contractual model actually being procured.
The commercial logic of the acquisition is more conventional. Awareness training sits close to email security because phishing remains one of the principal ways attackers obtain credentials or persuade employees to authorise fraudulent activity. Bringing the products under one group gives SEPPmail an additional control category while giving CyberPilot a channel into German-speaking markets.
Consolidation can reduce the number of suppliers an organisation manages, but it can also create broader dependency on one platform group. Email encryption, malware filtering, phishing simulation and employee training address different risks, and combining them commercially does not make their technical effectiveness interchangeable.
The acquisition is therefore part product expansion and part European market consolidation. It also illustrates how sovereignty is moving from a policy discussion into the language of cybersecurity procurement, particularly where services process sensitive corporate information.
SEPPmail says CyberPilot is one component in a wider plan to build a European email-security platform and expects additional disciplines to be added over time. A central administration console is already identified as the next step.
For the companies involved, the immediate work will be integration without disrupting existing customers. For the wider market, the deal adds another example of specialist European security providers assembling broader portfolios as customers seek fewer contracts, more integrated administration and clearer answers about where security data is handled.




