Data Security
Discover, classify and protect sensitive data against loss – with Data Classification, DLP and DSPM. The foundation for GDPR and NIS2.
Fortra Portfolio · Aqaio Value-Added Distributor DACH
The complete Fortra portfolio – clearly explained and mapped to NIS2, DORA and GDPR. As your 100% channel distributor in DACH, Aqaio delivers the arguments, demos and margins you need to win with customers. Find the right solution stack in 60 seconds.
In focus
Fortra organises its portfolio around three central protection goals. This is where most customer projects begin – and exactly where Aqaio supports you as a partner with know-how, demos and margins.
Discover, classify and protect sensitive data against loss – with Data Classification, DLP and DSPM. The foundation for GDPR and NIS2.
Protect your brand, domains and customers from phishing, fake profiles and dark web leaks – digital risk protection including active takedown.
Test your security from the attacker’s perspective – penetration testing and red-team operations with Core Impact, Cobalt Strike and Outflank.
Portfolio
Every solution addresses a specific part of the attack chain and a specific compliance topic. Grouped by area below – with the key capabilities and the value each one offers channel partners in the DACH region.

Deployment: On-premises · Best for: in-house pentest/security teams & audit-regulated organisations
Automated, multi-stage penetration testing across network, client-side and web attack vectors – validating real attack paths instead of guessing at them.
Partner USP: The licence model makes pentesting repeatable – predictable service and maintenance revenue instead of expensive one-off engagements.
Use case: A system integrator proves to a KRITIS customer ahead of the NIS2 audit that known vulnerabilities are genuinely not exploitable.

Deployment: On-premises · Best for: red teams, MSSPs & SOC providers
Platform for red team operations and adversary simulation; the industry reference for emulating command-and-control behaviour (Beacon).
Partner USP: A door-opener with MSSP/SOC customers and pentest providers – with follow-on demand for defensive solutions.
Use case: An MSSP shows a customer that their SOC detects a simulated ransomware attack only late – and then sells hardening and MDR.

Evasive red team toolkit that replicates advanced attacker techniques and deliberately bypasses defensive controls.
Partner USP: A premium add-on for mature red teams – high margin, little competition.
Use case: A specialist pentest provider tests which advanced techniques pass the customer's EDR solution undetected.
Certified red team training (Zero-Point Security) – from operator to team lead, hands-on with Cobalt Strike and practical labs.
Partner USP: Training as a high-margin add-on to the tooling business – upskills customer teams and builds long-term loyalty.
Use case: A pentest provider certifies its team to CRTO/CRTL and can take on more demanding red team engagements.

Deployment: On-prem & cloud, integrates with Microsoft 365/Office · Best for: GDPR-driven & regulated environments
Automatically and consistently classifies and labels sensitive data – the foundation of every DLP, encryption and compliance strategy.
Partner USP: The ideal entry use case for GDPR projects – opening the door to follow-up projects across the entire data security stack.
Use case: A mid-sized company automatically labels all documents containing personal data for GDPR – the basis for targeted DLP protection.

Deployment: Endpoint, network & cloud · Best for: organisations with valuable IP & personal data
Detects and prevents the loss of sensitive data at endpoints, on the network and in the cloud – including adaptive DLP for context-based sanitisation.
Partner USP: High recurring share; interlocks tightly with Data Classification and Email Security into a stack deal.
Use case: A machinery manufacturer prevents design data from leaving the company via USB, web upload or email.

Deployment: On-prem & cloud/SaaS · Licensing: per user/partner · Best for: regular data exchange with partners
Secure, encrypted and fully auditable file transfer – replacing FTP servers, scripts and shadow IT with central control and automation.
Partner USP: Fortra's flagship with strong demand; a clear compliance lever for NIS2 and DORA and a powerful door-opener topic.
Use case: An insurer replaces error-prone FTP scripts and exchanges contract data with partners in an encrypted, audit-proof way.

Data security posture management: discovers, classifies and protects sensitive data across endpoints, SaaS, cloud, databases and AI tools, and exposes risk before attackers exploit it.
Partner USP: A growth topic for cloud/SaaS-heavy customers; complements classic DLP projects.
Use case: A SaaS company discovers openly accessible customer data in a forgotten cloud bucket before an attacker does.

Deployment: Cloud gateway, complements Microsoft 365 · Best for: all organisations, especially M365 users
Protection against phishing, impersonation/BEC and malware – including outbound email DLP and encryption. Complements Microsoft 365 precisely where native filters reach their limits.
Partner USP: Over 90% of attacks start via email – an easy business case and a fast cross-sell into awareness and brand protection.
Use case: A law firm stops CEO fraud emails while preventing the accidental sending of client data.

Security awareness and phishing simulation that measurably reduce human risk and improve click behaviour.
Partner USP: A low-threshold recurring service; the perfect companion to every email security deal.
Use case: A retail company measurably lowers its phishing click rate within months – ideal as a recurring service.

Deployment: SaaS (managed) · Best for: brands with an online presence, finance & retail
Detects and removes look-alike domains, fake profiles and phishing infrastructure, and monitors the dark web for leaked credentials – with active takedown.
Partner USP: A differentiator with board-level relevance; a concrete loss-prevention case even for SMBs.
Use case: A bank has a fake login domain taken down before customers enter their credentials there.

Deployment: On-prem & cloud · Best for: KRITIS, PCI & regulated environments
File integrity monitoring and configuration compliance: detects unauthorised changes immediately and delivers a continuous, audit-ready comparison of target vs. actual state.
Partner USP: Complements SIEM/EDR rather than competing; a strong argument for NIS2/KRITIS-regulated organisations and PCI environments.
Use case: A utility detects an unauthorised change to a control file immediately – while also meeting KRITIS evidence requirements.

Deployment: On-prem & cloud · Best for: any IT organisation with patch & risk management
Detects, prioritises and helps remediate vulnerabilities on a risk basis – for a resilient security posture instead of endless scan lists.
Partner USP: A solid recurring base and a natural companion to Tripwire and penetration testing.
Use case: An IT service provider delivers its customer a prioritised findings list every month – as a predictable managed service.

Deployment: Managed service, 24/7 · Best for: customers without their own SOC
Unified threat detection and response across endpoint, network, cloud and identity – with 24/7 monitoring and automated response as a managed service.
Partner USP: Managed service revenue and an entry into long-term support contracts; ideal for customers without their own SOC.
Use case: A mid-sized company without its own SOC gets round-the-clock monitoring and immediate containment in an emergency.

Deployment: Cloud/hybrid · Best for: remote/hybrid work & VPN replacement
Identity- and context-based access per application instead of a flat VPN tunnel – limiting lateral movement if an account is compromised. As the only ZTNA solution, Fortra also protects the data inside the apps (DLP & rights management).
Partner USP: A concrete VPN replacement case; tangible security and usability gains for remote/hybrid work.
Use case: A company gives external service providers access to exactly one application – not the entire network.
Further defensive building blocks: Secure Web Gateway (real-time inspection of web traffic, blocking C2 and drive-by downloads) and CASB (a cloud access security broker for controlling cloud apps and shadow IT) – together they extend ZTNA and DLP into consistent zero-trust and cloud protection.

Deployment: native on IBM i, AIX & Linux · Best for: operators of IBM Power systems
Security, compliance and access control natively for IBM i (AS/400), AIX and Linux – hardening privileges, monitoring exit points and automating compliance.
Partner USP: A high-margin niche with little competition; IBM i customers often hold the most critical data and are underserved.
Use case: A manufacturer secures its central ERP on IBM i and documents access in an audit-proof way.
Robot – native automation for IBM i: job scheduling, monitoring, HA/DR and performance analysis.
Automate – robotic process automation for automating manual, repetitive IT and business processes.
Identity & Access Management (IAM) – management of digital identities and entitlements on a least-privilege basis.
Intermapper – network monitoring and mapping for a real-time view of the entire infrastructure.
Vityl Capacity Management – IT service monitoring with business insights to prevent outages.
Ready to win Fortra projects with protected margins?
Send a no-obligation enquiryWell-known product brands
Many well-known security products are now part of Fortra (formerly HelpSystems). If you are looking for one of these brands, this is where to find it in the current portfolio:
| Former brand | Now at Fortra |
|---|---|
| Titus & Boldon James | Data Classification – classification & labelling of sensitive data |
| Digital Guardian | Data Loss Prevention (DLP) – endpoint, network & cloud DLP |
| Clearswift | Email Security – secure email gateway with Adaptive Redaction |
| Agari | Email Security – DMARC enforcement & BEC/impersonation protection |
| PhishLabs | Brand Protection – digital risk protection & takedown |
| Terranova Security | Human Risk Management – security awareness & phishing simulation |
| Alert Logic | XDR / Managed Detection & Response – 24/7-MDR |
| Frontline (Digital Defense) | Vulnerability Management – risk-based vulnerability management |
| HelpSystems | Company name today: Fortra, LLC |
Regulation & Compliance
NIS2 has been in force since October 2024 – national implementation is underway. Thousands of companies in DACH are affected for the first time and are looking for solutions now. Partners who own the topic today win the projects – those who wait leave them to the competition.
Which Fortra solution supports which regulation? This mapping helps you tie customer needs to concrete obligations in sales conversations.
| Regulation | What it covers | Matching Fortra solutions |
|---|---|---|
| NIS2 | Risk management, reporting duties plus supply-chain and email security (Art. 21). | Email Security, Vulnerability Management, Tripwire, GoAnywhere MFT, ZTNA, XDR/MDR, Data Classification |
| DORA | Operational resilience for finance incl. secure data exchange and resilience testing (TLPT). | Core Impact, Cobalt Strike, GoAnywhere MFT, Tripwire, Vulnerability Management, ZTNA |
| GDPR | Protection of personal data and security of processing (Art. 32). | Data Classification, DLP, DSPM, Email Security, GoAnywhere MFT |
| ISO 27001 | ISMS with continuous control and evidence (Annex A controls). | Tripwire, Vulnerability Management, Data Classification, DLP, ZTNA, Powertech |
| BSI / KRITIS | Critical infrastructure and BSI IT-Grundschutz incl. attack-detection systems (§ 8a BSIG). | XDR/MDR, Tripwire, Powertech, Vulnerability Management, Email Security |
| PCI DSS | Protection of cardholder data (v4.0). | Tripwire, Vulnerability Management, GoAnywhere MFT, Data Classification, DLP |
| TISAX | Automotive & manufacturing information-security assessment (VDA ISA); often a basis for defence suppliers. | Data Classification, DLP, Tripwire, GoAnywhere MFT, Vulnerability Management |
| CMMC | US DoD supply chain: maturity certification protecting FCI/CUI per NIST SP 800-171. | Data Classification, DLP, GoAnywhere MFT, Tripwire, Vulnerability Management, ZTNA, Powertech |
| CUI / NIST 800-171 / 800-53 | Protection of Controlled Unclassified Information; US federal standards also referenced by NATO partners. | Data Classification, DLP, GoAnywhere MFT, ZTNA, Tripwire, Vulnerability Management, Powertech |
| ITAR / EAR | US export control for defence/dual-use goods: access only for authorised persons, no uncontrolled export. | Data Classification, DLP, ZTNA, GoAnywhere MFT, Email Security |
| Cyber Resilience Act (CRA) | Products with digital elements: security by design, vulnerability handling and integrity across the lifecycle. | Vulnerability Management, Tripwire, Core Impact, Cobalt Strike |
| ISG / IKT-Grundschutz (CH) | Swiss information security (ISG) & ICT baseline protection for the military, administration and suppliers. | Data Classification, DLP, GoAnywhere MFT, Tripwire, Vulnerability Management, ZTNA |
| DISA STIG | Strict configuration baselines for IT connected to military networks. | Tripwire, Vulnerability Management, Powertech |
Indicative mapping, no guarantee – the specific certification standard is decisive. For classified information (e.g. VS-NfD, NATO/EU RESTRICTED), approved products/processes of the responsible authority (e.g. BSI) apply.
Defense & Public Sector
Fortra solutions help authorities, defence companies and their suppliers protect sensitive data, meet regulatory requirements and demonstrate cyber resilience – as technical and organisational baseline measures. Rising defence budgets and tightening supply-chain requirements make this a high-margin, sticky growth area for partners.
Protect technical design and project data across the supply chain: classification, DLP against data loss, encrypted exchange (MFT) and strict access control (ZTNA).
DACH suppliers to the US DoD must demonstrate CMMC 2.0 / NIST SP 800-171. Data Classification, DLP, MFT, ZTNA, Tripwire and Vulnerability Management address core controls for protecting CUI/FCI.
Public bodies are subject to NIS2 and – as critical infrastructure – the statutory attack-detection requirement (§ 8a BSIG). Fortra delivers classification, secure data exchange, integrity monitoring and XDR/MDR.
Defence-grade resilience requires testing from an attacker's perspective. Core Impact, Cobalt Strike and Outflank (OST) enable penetration testing and adversary simulation; red-team training builds in-house expertise.
CMMC and resilience projects are long-term, consulting-intensive and sticky.
Link a concrete obligation (e.g. CUI protection, § 8a BSIG) to the right Fortra solution.
A defence customer usually needs classification + DLP + MFT + ZTNA + testing at once.
NFR/eval licences, pre-sales support and German- and English-speaking channel support.
Without warranty: the solutions listed provide technical and organisational baseline measures. CMMC, ITAR/EAR and other conformity depends on scope and implementation at the customer.
Complete Attack Chain Coverage
Fortra covers both the offensive (emulation/testing) and the defensive (protection/detection) side of the attack chain. The mapping of the 14 enterprise tactics below is a talking aid for customer conversations.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. “© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.” This representation is provided by Aqaio and does not imply any affiliation with or endorsement by MITRE.
| Tactic | Fortra solutions |
|---|---|
| Reconnaissance | Brand Protection, Email Security |
| Resource Development | Brand Protection |
| Initial Access | Email Security, Human Risk Management, Secure Web Gateway, Vulnerability Management, ZTNA, Core Impact |
| Execution | XDR/MDR, Email Security, Cobalt Strike |
| Persistence | Tripwire, XDR/MDR, Powertech, Cobalt Strike |
| Privilege Escalation | Powertech, IAM, Vulnerability Management, Core Impact |
| Defense Evasion | Tripwire, XDR/MDR, Outflank |
| Credential Access | IAM, Powertech, XDR/MDR, Cobalt Strike |
| Discovery | DSPM, Intermapper, Core Impact |
| Lateral Movement | ZTNA, XDR/MDR, Cobalt Strike |
| Collection | DLP, Data Classification, DSPM |
| Command and Control | Secure Web Gateway, CASB, XDR/MDR, Cobalt Strike |
| Exfiltration | DLP, GoAnywhere MFT, Email Security, CASB |
| Impact | Tripwire, GoAnywhere MFT, XDR/MDR, Intermapper |
Not sure which stack fits your customer?
Find your matching stackDatasheets to download
The official Fortra datasheets for our offensive security solutions and red team trainings – available instantly after a quick registration.
The official Fortra datasheets for data classification, DLP and Cloud Data Protection (CASB, SWG, ZTNA) – available instantly after a short sign-up.
Official Fortra datasheets for secure, automated file transfer – available instantly after a short sign-up.
Further Fortra datasheets across IBM i security, email security and infrastructure.
Bonus · interactive
Select your customer's requirements – the finder assembles the matching Fortra stack, links to the details above and lets you register the opportunity with Aqaio. Runs entirely locally in your browser.
Your result
Please share the results of this questionnaire in the first meeting. That way Aqaio can prepare the right demos, NFR/trial licences, pricing and NIS2/DORA use cases for your customer.
Your distributor
Partnering with Fortra through Aqaio pays off commercially and operationally: attractive, protected margins, fast project support and a portfolio with a high recurring-revenue share. Looking to become a Fortra reseller, buy Fortra licences or join the Fortra partner program? Through Aqaio as your Fortra distributor in the DACH region you get pricing, enablement and support from a single source.
Frequently asked questions
Contact
Prefer to email us directly? partner@aqaio.com