Skip to content
Exploit Labs
2016 - 2026

A Decade of Offensive Security.

Ten years. One job: proving how far an attacker gets.

No side business, no distraction - since 2016 exclusively adversary simulation for regulated institutions and critical-infrastructure operators across DACH, the Nordics, and MENA.

A Decade in the Making
  1. 2016

    Exploit Labs founded in Germany - threat-intelligence-driven offensive security from day one.

  2. 2017

    First team member receives dedicated red team training in the USA.

  3. 2019

    Enterprise Red Teaming practice established. Cobalt Strike shop - further differentiation between penetration testing and red teaming.

  4. 2021

    Joined the ENISA Workgroup on Threat Landscapes.

  5. 2022

    Appointed Official OffSec Learning & Channel Partner. Forming an alliance with SecureIT and deepening our activities in Iceland. Opening of Exploit Labs LLC in Dubai, with further activities in Austria and Switzerland.

  6. 2023

    ISO 27001 on the basis of IT-Grundschutz (BSI), certificate BSI-IGZ-0539-2023. Member of the FIRST Special Interest Group for Red Teaming. A team member qualifies as a SANS trainer for the first time - a milestone in how we develop our people.

  7. 2024

    First official TIBER and DORA TLPT engagements. Training partnership with Manufaktur IT Training. Further deepening physical penetration testing skills.

  8. 2025 / 2026

    OffSec Channel & Learning Partner (DACH, MENA, GCC). Full-scope cyber-physical red team engagements across the EU. Successfully won further government tenders around penetration testing and source code review. Furthering our capabilities around Automated / AI-driven penetration testing and pentest-as-a-service.

By the Numbers
10
Years of offensive security
200+
Enterprises & institutions across DACH, Nordics & MENA
3
Continents · Frankfurt · Dubai · Reykjavík
25+
Combined years of pentest & red team experience
BSI
ISO 27001 on the basis of IT-Grundschutz, certificate BSI-IGZ-0539-2023
OffSec
OffSec Official Channel & Learning Partner
BSI seal: ISO 27001 on the basis of IT-Grundschutz, certificate BSI-IGZ-0539-2023

ISO 27001 on the basis of IT-Grundschutz (BSI), certificate BSI-IGZ-0539-2023 Member of the FIRST Special Interest Group for Red Teaming

What Sets Us Apart

Focus over portfolio sprawl. Reach over regional comfort.

One craft. No side hustle.
Only penetration testing, red teaming and the training that feeds them.

No incident response. No IT admin work. No "we do that too". We concentrate on one job - adversary simulation - and get better at it, instead of drifting into generic "consultants" who "also" pentest on the side.

International exposure
Iceland, Europe, UAE - hidden champions, RegTech, GovTech, critical infrastructure. And everything in between

From Reykjavík to Frankfurt to Dubai: our clients operate internationally. Banks, insurers, government bodies, manufacturing, logistics, defense, healthcare, energy - there is barely a vertical or horizontal we haven't been dropped into. It doesn't get boring.

From daily life - stylized

Snapshots from our locations and trainings. All faces are deliberately anonymized - what matters is the working mode, not the individual.

OSCP training room, stylized
Dubai boardroom, stylized
Frankfurt terrace, stylized
Client briefing, stylized
Dusk over the Rhine-Main region
Office dog
Global Footprint

Global Footprint. Local Sovereignty. Zero Operational Silos.

Offensive security cannot be executed from a generic remote desk when your assets span critical infrastructure in the North Atlantic, industrial IoT in the DACH region, and frontier AI ecosystems in the Middle East.

Exploit Labs (XPLT) operates across three distinct, highly specialized operational hubs designed to give enterprise clients both deep regional compliance and international threat intelligence:

DACH
Engineering & Regulatory Hub

Built around the stringent compliance mandates of Central Europe. We serve German Hidden Champions and international industrial groups navigating DORA, NIS2, KRITIS, and TIBER-EU requirements. This is where our core methodology for deep-code audits, PTaaS, and threat-led red teaming is refined.

Iceland
Critical Infrastructure & Physical OffSec Hub

Specialized in sovereign resilience, subsea connectivity, and extreme physical-logical security engagements. Serving Iceland’s vital energy and financial sectors, our team executes physical breach simulations and facility security validation under conditions where geographic isolation demands absolute uptime.

UAE
Frontier Tech & Sovereign Security Sister Company

Headquartered locally to support the GCC’s rapid adoption of next-generation infrastructure. We provide local headcount and on-demand technical depth for Web3/blockchain security, AI-native system penetration testing, and hyper-growth enterprise ecosystems.

By deploying dedicated local talent backed by our international offensive research unit, XPLT delivers the exact requirement enterprise procurement demands: Global adversary emulation with sovereign, on-ground accountability.

Team Values & Process

How we work. What we measure. What we improve.

Exploit Labs is built on four operating principles that govern every engagement, every report, and every hiring decision. They are not decoration - they define how we work.

KPI #1
Quality is the only metric that matters.

We do not optimize for speed or volume. Every finding is reproducible, every report is reviewed, every engagement is defensible. When forced to choose between fast and right, we choose right.

Dual role
Operator and instructor. Same person.

Everyone here both pentests and trains. Only what you can teach, you truly understand. Those who want to can stand in front of customers as OffSec-certified instructors and teach their favorite courses. That keeps our knowledge fresh and our clients current.

Tooling
Cloud-first, AI-assisted, human-decided.

We operate in a cloud-first environment with pentest report engines and AI-assisted tools - but only where they create real value. We do not follow the hype blindly. A human remains accountable for every critical outcome.

Continuous improvement
We improve our process before we scale our revenue.

Everyone on the team is invited to push the technical process forward: What can we do better? How will we pentest differently in two years compared to today? We engage in ENISA, FIRST, OWASP and other formats to deliberately look beyond the horizon.

These four principles are the backbone of our culture. They decide who we hire, which tools we adopt, and how we close an engagement. If this fits you, apply or reach out.

Leadership
CEO / Founder
Johannes Schönborn
Advisory Board Member
Ron Yeatman
CFO
Maja Schönborn
The People Behind the Decade

Everyone who has helped build Exploit Labs.

Exploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricatureExploit Labs team member caricature

Honorable mentions. To everyone who has walked this road with us over the past ten years - including those whose portrait we couldn't track down or who never sat for one: thank you. You are just as much a part of this story. And to all of our partners and clients who trusted us and walked this way with us - thank you for a decade of Exploit Labs.

Pentest Penthouse

160 m² for events, workshops and team gatherings.

Our Frankfurt penthouse is the base for client workshops, debriefings and everything that keeps a team together. Not a coworking desk - a place with character.

Pentest Penthouse loft with long table and a view of the Frankfurt skyline
The loft: one table that seats the whole team plus guests - debriefings, reviews, cooking together.
Workshop room with laptops and a large screen for hands-on training
Workshop setup for up to 12 participants: hands-on labs, GOAD sessions and internal technical deep dives.
Penthouse rooftop terrace at dusk with lounge furniture
The rooftop terrace: where team gatherings end and the best ideas for the next attack path start.
Work at XPLT

Questions about the team.

What makes us as a team and how we work.

How does the team work?

Remote first. We do not just work from home offices; we provide a real remote workspace. Travel is usually 10-25%. We also have a 160 sqm pentest penthouse for events, team gatherings and to chill.

What does the technical setup look like?

Cloud-first environment, pentest report engines and AI-enabled tools where they create value and make pentest work easier, without following the hype.

What does the dual role mean?

Pentest/red team plus training. Only what you can teach, you truly understand. Those who want to can become an OffSec-certified instructor for their favorite courses.

Where do we work?

We travel between our hotspots Frankfurt, Dubai and Reykjavík. It is not going to get boring.

Who do we hire?

All-around pentesters. No single swim lane operators like "I only do web apps". We are looking for curious minds.

How does the team engage externally?

We are active in ENISA, FIRST, OWASP and other formats, and deliberately look beyond the horizon.

How do we improve?

Everyone is invited to push the technical process forward: What can we do better? How will we pentest differently in two years compared to today?

What is the most important KPI?

Our single most valued KPI is quality.

Does this sound like you?

Apply right here - your application lands confidentially with frontoffice@xplt.com.

Application · Work at XPLT
Locations
HQ · Exploit Labs GmbH
Frankfurt
Exploit Labs LLC
Dubai
Exploit Iceland
Reykjavík