Europe is tightening resilience requirements for critical infrastructure, creating new opportunities for a security industry long defined by manpower and guarding hours. International groups such as Securitas, G4S and Prosegur benefit from scale, technology and cross-border client relationships. Germany, however, also has an unusually strong group of large domestic providers. KÖTTER in particular illustrates that relevance in the European security market does not necessarily require a continent-wide branch network. As security mandates become more complex, capital strength, technology, certification and the ability to integrate services are likely to determine who can compete successfully in the critical infrastructure sector.
European security policy is changing an industry that is still frequently associated with factory gates, guarding services and mobile patrols. With the EU Directive on the Resilience of Critical Entities, or CER Directive, the European Union has considerably broadened the concept of protecting essential services. Critical entities must identify relevant risks and implement technical, organisational and security measures designed to prevent incidents, withstand disruption and limit its consequences. The directive explicitly addresses areas including physical protection, perimeter monitoring, detection systems, access control, crisis management, business continuity and the security and qualification of personnel.
This means that activities once purchased as individual security services are increasingly becoming components of a broader resilience strategy. The European Commission now explicitly regards attacks on critical infrastructure and hybrid threats as elements of Europe’s internal security challenge. Its ProtectEU strategy, presented in 2025, consequently calls for closer cooperation between public authorities, businesses and other actors involved in protecting European society and the economy.
Germany has transposed the CER requirements into national law through its Critical Infrastructure Umbrella Act, the KRITIS-Dachgesetz. The legislation was issued on 11 March 2026 and entered into force on 17 March. It establishes cross-sector minimum requirements for the physical resilience of critical facilities and complements regulation focused more heavily on information and cyber security. Details concerning implementation and the precise scope of some requirements are continuing to develop through the associated regulatory framework.
For private security companies, the significance extends well beyond additional guarding hours. As operators are required to analyse risks more systematically, prepare resilience measures and link physical and digital protection, demand is shifting towards combinations of services that were traditionally procured separately: consultancy, security technology, control rooms, guarding, access management, video analytics, cyber security, crisis organisation and business continuity.
That is also the economic importance of the new European framework. It is not simply increasing demand for security. It is changing the kind of security provider capable of meeting that demand.
Europe Has Security Giants – but Not a Single Security Market
At first sight, the changing environment appears to favour multinational providers. Europe has several very large security companies, yet the industry as a whole remains highly fragmented. The Confederation of European Security Services, CoESS, represents a market comprising around 45,000 private security companies, some two million security officers and annual turnover exceeding EUR 40 billion.
Yet Europe does not possess a fully integrated market for private security services. Such services are explicitly excluded from the scope of the EU Services Directive. Licensing systems, qualification requirements, labour-market structures and the distinction between private and sovereign security functions therefore remain significantly more national than in many other service industries.
This creates a central contradiction in the European market: risks are becoming more European and regulatory expectations are converging, while the delivery of security remains strongly rooted in national markets.
For global providers, this is both an advantage and a constraint. Technologies, control-room concepts, risk analytics and operating experience can be transferred across markets. The actual delivery of security services, however, still depends heavily on national labour markets, legal requirements and customer structures.
Few companies illustrate this better than Securitas. The Swedish group generated global sales of SEK 155.1 billion in 2025 and operates in 44 markets. Securitas Europe alone recorded sales of SEK 67.4 billion and employed around 111,000 people. Technology is becoming increasingly important within that business: Technology and Solutions accounted for 34 per cent of European segment sales in 2025.
Germany occupies a particularly important place within the group. It accounted for 20 per cent of Securitas Europe’s sales, making it the company’s largest individual European market, ahead of France at 13 per cent and Sweden at 12 per cent.
This helps explain why the German debate over the future of private security cannot be separated entirely from Securitas’ wider European strategy. In his interview with Tagesspiegel, Securitas Germany CEO Ralf Brümmer describes an information-driven approach to security (Intelligence-led Security) that combines physical events, technological systems, external risk information and human analysis in a common situational picture. The objective is not simply to respond faster to incidents, but to identify relevant risks before they develop into concrete security events.
Securitas is far from alone in pursuing this direction. G4S has been part of US-based Allied Universal since 2021. The combined organisation says it employs more than 760,000 people across over 100 countries and territories, with Allied Universal reporting global revenues of approximately USD 23 billion. G4S itself employs more than 46,500 people in Europe and offers not only guarding but also technology, remote monitoring, risk services and consultancy across numerous markets.
Spain’s Prosegur provides another indication of the scale involved. The group generated record revenues of EUR 4.93 billion in 2025, with more than EUR 2 billion coming from Europe. Its Prosegur Security division alone reported global revenues of EUR 2.604 billion.
These groups possess an advantage likely to become more valuable in critical infrastructure protection: they can spread investment in platforms, control rooms, analytics and specialist expertise across large customer portfolios and multiple countries. International industrial groups, in turn, can use them to standardise elements of their security architecture across different sites.
Scale, however, is not sufficient on its own. Private security remains a business shaped by local labour markets, wage structures, customer proximity, licensing requirements and dependable operational delivery. This leaves substantial space for strong national providers.
Germany Has More Than One Major Security Provider
Germany is a particularly good example. The German Security Industry Association, BDSW, forecast sector revenues of approximately EUR 14.75 billion for 2025. At the end of that year, close to 291,000 people were employed in the statistical category covering guarding and security services and detective activities.
Market concentration remains limited. According to the latest Lünendonk ranking, Germany’s 25 largest security service providers generated combined security revenues of EUR 5.63 billion in 2025, representing roughly 40 per cent of the relevant market excluding cash-in-transit services. Even the largest providers therefore operate in a market that remains considerably more fragmented than many technology or business-service sectors.
Securitas Germany leads the ranking with revenues of EUR 1.239 billion. The companies behind it, however, represent a different corporate landscape. Essen-based KÖTTER generated EUR 659 million in security revenues in 2025. Kieler Wach- und Sicherheitsgesellschaft, including Sicherheit Nord, followed with estimated revenues of EUR 558 million, while Niedersächsische Wach- und Schliessgesellschaft together with VSU was estimated at EUR 410 million. WISAG recorded EUR 310.4 million in security revenues, Pond Security EUR 292.2 million, Klüh EUR 221.8 million and Piepenbrock EUR 212.6 million.
The structure matters. Germany is not a market consisting simply of global groups at one end and thousands of small regional guards at the other. Between them sits a substantial layer of large domestic security and facility-service companies with significant workforces, control-room infrastructure, technology capabilities and long-standing relationships with industry and the public sector.
For international providers, this makes Germany attractive – but far from easy.
KÖTTER: A German Countermodel to the Multinational Group
Among these domestic providers, KÖTTER occupies a particularly interesting position. That is not merely because it ranks second behind Securitas in the German market, but because its development represents a different route towards integrated security.
The KÖTTER Group generated total revenues of EUR 770 million in 2025, an increase of 6.6 per cent, and employed 16,400 people. According to Lünendonk, revenues in its security division increased by 8.6 per cent to EUR 659 million. That means KÖTTER Security grew considerably faster in 2025 than market leader Securitas Germany, where revenues increased by 2.4 per cent.
KÖTTER remains family-owned and primarily focused on Germany. The group states that it operates more than 100 branches in over 60 German cities. This domestic concentration fundamentally distinguishes it from Securitas, G4S or Prosegur.
The company does not appear to be compensating for the absence of a comparable international footprint by pursuing rapid geographic expansion. Instead, it has been broadening its value chain within its home market.
The acquisition of the WAKO Group in 2024 strengthened KÖTTER’s position particularly in northern Germany, with WAKO being fully integrated into KÖTTER’s structures at the beginning of 2026. Also in 2026, the group acquired STuK Sicherheitstechnik, expanding its capabilities in electronic security and fire protection systems.
Strategically, its expansion into cyber security may prove even more significant. Since May 2026, IT security specialist G.I.P., in which KÖTTER holds a majority stake, has operated as KÖTTER Cyber Security. The group can therefore increasingly combine manpower-based security, electronic security systems, control-room services, consulting and cyber security within one broader offering.
Its development in critical infrastructure security suggests that this is more than a branding exercise. In 2025, KÖTTER obtained certification under all published parts of the European EN 17483 series governing private security services for critical infrastructure protection. CoESS described KÖTTER as the first German provider, and one of only a small number of European security companies, to have achieved certification across the full published series, including specific requirements covering aviation and maritime and port security.
The significance of this standard may increase as the European critical infrastructure market develops. EN 17483 provides a certifiable quality framework for private security providers protecting critical infrastructure. In a market where national licensing and operating conditions continue to vary, such European standards can create a common language of quality across borders.
KÖTTER also has a notable direct connection to European industry policy. Friedrich P. Kötter currently serves as First Vice-President of CoESS and chairs its Airport Security Committee. The CoESS leadership also includes representatives of Securitas Europe, G4S Europe and Prosegur Europe.
This puts the German family-owned company in an unusual position: operationally concentrated on its domestic market, but closely connected to European standardisation and industry policy.
For the German market, that combination may prove valuable. A multinational industrial company may favour Securitas or G4S because of the possibility of aligning security structures across several countries. A German critical infrastructure operator may instead value a provider deeply embedded in national regulation and labour structures while still meeting European standards.
These are different competitive advantages, and revenue rankings capture only part of them.
European Harmonisation May Widen the Gap Between Providers
The CER Directive is designed to improve the resilience of critical entities across Europe. It does not, however, create a homogeneous security services market. Indeed, more uniform expectations for operators may make differences between providers more visible.
As long as a contract consists predominantly of manpower-based guarding, a relatively broad range of security companies can compete. Once clients demand risk analysis, certified processes, electronic security technology, control-room capabilities, cyber security, crisis management and standards that can be recognised across jurisdictions, barriers to entry become considerably higher.
International groups benefit from scalability. Securitas can spread technology investments across a European operation employing 111,000 people and generating more than SEK 67 billion in annual sales. G4S operates within the resources of a global organisation employing hundreds of thousands of people. Prosegur similarly combines substantial European activities with businesses outside the region.
For KÖTTER and other large national groups, the opportunity lies elsewhere: in deeper vertical integration and detailed knowledge of their domestic markets. Proprietary control rooms, electronic security, cyber services, fire and emergency capabilities can prevent such companies from becoming little more than manpower suppliers to technology-led third parties.
The strategy is not inexpensive. As security providers become technology, data and cyber-security companies as well as employers of guards, their cost structures change. Software, redundant monitoring centres, specialist staff, certifications and continuous training require capital that cannot be monetised as directly as additional guarding hours.
This may increase consolidation pressure. Lünendonk expects Germany’s security services market to grow by between 6.7 and 7.6 per cent annually through 2030 and explicitly identifies critical infrastructure regulation as one of the drivers. Yet six of Germany’s 25 largest providers recorded declining revenues in 2025.
Growth, therefore, will not necessarily be distributed evenly. Providers with capital, technology and certified processes are more likely to benefit from complex contracts. Smaller businesses may increasingly concentrate on regional or specialist niches, work as partners within broader delivery structures, or become acquisition targets.
KÖTTER has already demonstrated through the integration of WAKO and the acquisition of STuK that a family-owned group can itself participate actively in market consolidation. It would nevertheless be premature to interpret this as the beginning of an inevitable transformation into a pan-European group. Its strategy to date points more strongly towards increasing the depth of its German capabilities than towards geographical expansion at any price.
Between European Ambition and National Reality
Europe’s emerging critical infrastructure security market is therefore not developing like a conventional single market. Europe is increasingly harmonising what critical operators are expected to achieve, but much less who delivers those services and under which national conditions.
This favours security companies able to operate on both levels: European standards and national implementation.
Securitas has an obvious advantage through its scale and presence across the markets of Securitas Europe. Germany is not a peripheral operation within the group, but its largest European national market. Developments in Germany therefore matter to the group’s broader European business.
KÖTTER represents a different model. It does not possess a comparable international footprint, but its scale in Germany is sufficient to support significant investment in technology and specialist capabilities. Its role within CoESS and its early comprehensive EN 17483 certification show that European relevance does not necessarily depend on operating subsidiaries across the continent.
Other major German players – including KWS/Sicherheit Nord, Niedersächsische Wach- und Schliessgesellschaft, WISAG, Pond, Klüh and Piepenbrock – occupy positions between these two models, combining regional strength, specialist capabilities and, in several cases, broader facility-service portfolios. In Lünendonk’s market study, competitors identified Securitas and KÖTTER by a clear margin as the two companies perceived to play the most important roles in Germany’s security services market.
For operators, however, rankings may gradually matter less than the ability to perform. As critical infrastructure regulation becomes more demanding, the relevant questions change: Can the provider understand the client’s risks? Can it integrate technology? Can it provide qualified personnel, maintain reliable control-room operations and interpret events sufficiently well to support decisions during a crisis?
This development also contains a contradiction. Europe wants critical infrastructure to become more resilient and less vulnerable to dependency. Yet as operators outsource increasingly complex security processes to integrated providers, they may themselves become more dependent on those providers. Global groups offer scale and standardisation, but proprietary platforms can increase customer lock-in. National providers offer local proximity and regulatory familiarity, but must invest heavily to develop comparable technological capabilities. In both cases, operators must increasingly consider not only price and service quality, but also data ownership, interoperability, supplier resilience and the practical consequences of changing provider.
There is a second tension. The demand for earlier detection inevitably produces more monitoring, more data and greater reliance on algorithmic analysis. A richer situational picture can improve security, but it also creates additional sensitive information that must itself be protected. As private security becomes more data-driven, the cyber security and operational resilience of the service provider become part of the client’s own security architecture.
Brümmer’s emphasis on human judgement is significant in this context. Technology and AI can identify anomalies, process large volumes of information and prioritise warnings, but the interpretation of context, intent and proportionate response remains, in his view, a human responsibility. The long-term competitive advantage of security companies may therefore lie less in any individual technology than in their ability to combine information, operational experience and qualified judgement.
The sector is consequently moving away from an isolated guarding model towards something closer to integrated resilience management. Securitas describes part of this transition as (Intelligence-led Security). Its significance extends beyond one company’s terminology: it reflects an attempt to transform a traditionally labour-intensive industry into one that is more heavily based on information, technology and specialist knowledge.
For private security providers, the European resilience agenda opens substantial commercial opportunities. It also raises the requirements for investment, expertise, certification and trust. Whether this ultimately favours a small number of international platforms or produces a more differentiated ecosystem of multinational groups, strong national providers and specialist companies remains open.
What is becoming clearer is the structure of the competition. Europe will need providers capable of financing innovation and scaling solutions across borders, but also companies sufficiently embedded in individual markets to translate European resilience requirements into reliable local operations. Securitas and KÖTTER represent two different versions of that proposition.
The European security industry may therefore become more international and more national at the same time. Technology, standards and risk intelligence can increasingly cross borders; manpower, regulation and operational accountability remain local. For the protection of critical infrastructure, the strongest providers may ultimately be those capable of managing precisely that tension – without creating new dependencies while attempting to reduce existing ones.
[CN]




