Ein Gespräch mit Michael Sörgel, Gründer und CEO der Somitec

The digital threat landscape is growing rapidly, yet many companies still underestimate their own vulnerability. This is exactly where Somitec comes in: the system house, founded in 2003, has developed in recent years into a Managed Service Provider that supports primarily medium-sized companies with holistic, individual and practical IT solutions. The focus is not only on technology, but also on trust – and the claim to sustainably strengthen the IT security of its customers.
In an interview with Michael Sörgel, founder and CEO of Somitec, we examine why basic security measures such as backups or multi-factor authentication are often neglected, what responsibility managers bear in defending against cyberattacks and how a smaller, personal company can make a difference in times of growing digital risks.
Sörgel, who is himself a father, compliance manager, data protection officer and certified auditor, not only brings expertise but also a clear attitude: “We sell trust, not technical solutions.” With this philosophy, he aims to raise awareness among companies, improve processes and sharpen awareness – not least to prevent attackers from getting even richer.
Look forward to an exciting discussion about IT security as a matter close to the heart, the courage to take new paths and why “business karma” plays a decisive role in digitalization.
Silicon Valley Europe: Mr. Sörgel, you founded Somitec back in 2003 and have since developed it from a classic system house into a Managed Service Provider. What was the decisive moment for you to take this path?
Michael Sörgel: The path began 12 years ago; one of my motivations was to offer my customers flexible and high-quality services without the initial investment that is difficult for many SMEs to manage.
With our Managed Services, even small companies can afford IT services at an enterprise level.
Silicon Valley Europe: Many companies underestimate basic security measures such as backups or multi-factor authentication. In your experience, why are these basics often neglected?
Michael Sörgel: I still don’t fully understand it. Certainly, it’s not a financial issue—many basic measures cost almost nothing. I even give away my experience and tips, to a certain extent, to advance the topic.
Ignorance, carelessness, and complacency.
Ignorance, because it isn’t communicated clearly and simply enough—even by IT service providers. I can’t exclude myself from that either. But for years, we’ve been striving to focus on the topic, and now it’s reached our customers we support.
Carelessness: “We’re not interesting to cyber attackers,” “We’re perfectly well protected,” or my favorite: “We’re ISO certified…”
Complacency: Advice is ignored, or there’s no “lesson learned” after an incident. Unfortunately, this applies to all entrepreneurs, IT departments, and IT service providers. I don’t mean this to sound preachy, but sometimes I have to shake my head when I see how IT security is handled.
This is both frustrating and motivating because I see the demand that still exists, and giving up has never been an option for me.
Silicon Valley Europe: You emphasize that Somitec doesn’t sell pure technical solutions but trust. What does that mean concretely in your daily work with customers?
Michael Sörgel: Concretely, this means more communication, patience, and once again communication to find a path together with the customer. The easy route would be to sell Product 1, 2, and 3, issue an invoice—and done.
Products are important and correct, but without implementing and providing them with expertise in a balanced way, they only unfold part of their potential.
Silicon Valley Europe: In IT security, you often talk about “Business Karma.” Could you explain what you mean by that and what role this idea plays in the corporate environment?
Michael Sörgel: Business Karma, the categorical imperative – I wish for, and frankly, I even demand, a collaborative approach on equal footing, with respect and trust. That’s what I offer my customers, and that’s what I expect from them. Of course, I and we are service providers and “serve,” but on a good level.
Silicon Valley Europe: Your customers are predominantly medium-sized companies from the region. What specific challenges do these companies face in the area of IT security – and how do they differ from large corporations?
Michael Sörgel: In my early professional years, I worked as a freelancer at a large company, which was undoubtedly great and educational. But it also showed me how specialized individual departments are. A medium-sized company needs internal employees and external service providers who see the bigger picture, recognize dependencies and opportunities, and communicate them to management.
The major challenge in IT security for medium-sized companies is that they are much more frequently targeted by attacks than one might think, yet they cannot cover everything with their own resources. Issues like GDPR, NIS2, AI Act also pose challenges for medium-sized companies, as there is typically no dedicated department or staff available to continuously address them.
Silicon Valley Europe: In addition to technical implementation, you also offer consulting and coaching to increase companies’ security maturity levels. What typical vulnerabilities do you repeatedly encounter in this process?
Michael Sörgel: I generally proceed by taking an external look at the company. If I notice any negligence, I address the companies directly, and in most cases, I find a similar picture internally. A simple example: the company has no or insufficient entries for DMARC and SPF – this gives me more information than necessary and makes it easier for attackers to carry out successful phishing attacks.
Internally, I almost always find unchanged default configurations, for example in the Active Directory, no or inadequate network segmentation, no truly reliable backup strategy, shadow IT, and the management team sees itself as being outside the IT security policy.
Silicon Valley Europe: You yourself have had an unusual career path – from motorcycle mechanic to IT specialist, and on to founder and CEO. How does this versatility shape your work and your approach to challenges today?
Michael Sörgel: I can only recommend it! My parents ran a small craft business, which taught me at an early age the responsibility and effort required of entrepreneurs, as well as the need to constantly work toward your own goals and desires. It wasn’t always easy or fun, but it was incredibly valuable. Early on, I helped my dad in the carpentry workshop and later, during my apprenticeship as a motorcycle mechanic, I learned to improvise, repair, and not just grab a new part from the warehouse.
I always found it very satisfying when I could complete my tasks well and “bite” into finding a solution.
Silicon Valley Europe: Many managing directors, as you say, have little awareness of their own vulnerability. What would you say is the most important message for these CEOs?
Michael Sörgel: My message is: Dear managing directors, you are the captain and anchor of your company – so be the ship’s boy in your team, with all the rights and duties that entails.
With us, it's regulated this way: legally, I am on equal footing with the trainees. While I can view and edit other data, my user account is restricted in exactly the same way as everyone else's.
Silicon Valley Europe: IT security is close to your heart. What personally drives you to always go the “extra mile” for your customers?
Michael Sörgel: It's personal. When I was 12, my dad told me: “Michael, go for it – but then you have to stick with it.”
I'm curious, I want to understand things, and I'm interested in topics that have nothing to do with the IT world.
And one more saying that has stayed with me, from my late grandmother: “Take what isn't yours and leave everyone else what is theirs.”
Silicon Valley Europe: Then we very much hope that your commitment bears fruit and that more and more SMEs take an interest in IT security. Thank you for your contribution and your dedication.
Michael Sörgel: As I said earlier, I enjoy doing more than just what's necessary, and a good result fills me with joy.