
Proofpoint has acquired Hornetsecurity for 1.8 billion US dollars, placing a formerly German email security vendor under US ownership. This guide explains what the deal changes for existing customers, why digital sovereignty matters for DACH businesses in 2026, what to watch when switching providers, and how Conbool is positioned as a German alternative.
Die neuesten Beiträge aus unserem Blog.

Mit der Übernahme von Hornetsecurity durch Proofpoint gerät ein bisher deutscher E-Mail-Security-Anbieter unter US-Eigentümerschaft. Dieser Beitrag ordnet den Eigentümerwechsel ein, erklärt die…

Die DSGVO stellt Anforderungen an den Verantwortlichen, nicht an ein Programm. Was Thunderbird im Unternehmen abdeckt, wo die Lücken liegen und was ergänzt werden muss.
On 9 December 2025, Proofpoint announced that it had acquired Hornetsecurity in a deal valued at around 1.8 billion US dollars. For years, Hornetsecurity was marketed as a German email security vendor, founded in Hanover and serving thousands of businesses across the DACH region and beyond. With this acquisition, a formerly German provider now sits under the ownership of a US company. For many European customers, that single fact reframes a familiar question: not whether the product still works, but who ultimately controls it and the data flowing through it.
This article looks at what the ownership change concretely means, why digital sovereignty has become a board level topic in 2026, what you should watch when evaluating a provider switch, and how Conbool is positioned as a German alternative. The goal here is context, not a sales pitch. If you want a direct feature by feature view, the Conbool versus Hornetsecurity comparison lays that out separately.
TL;DR: Proofpoint acquired Hornetsecurity in December 2025 for roughly 1.8 billion US dollars, placing a formerly German email security vendor under US corporate ownership. In the short term, contracts and data centres stay put. Over the medium term, the open questions are governance, roadmap control, and exposure to US law such as the CLOUD Act. For organisations that treat digital sovereignty as a requirement, the deal is a good moment to review whether a European owned alternative fits better. A provider switch is mostly a migration project: feature matching, MX cutover, and DNS adjustments, best planned around the existing contract renewal.
A change of ownership is easy to underestimate because the product keeps running. The login page looks the same, the contract is still valid, and the data centre has not moved. The substance sits one level deeper, in who governs the company.
Hornetsecurity is now part of the Proofpoint group. That means the product roadmap, pricing strategy, and long term direction are set within a US owned corporate structure. Acquisitions frequently lead to portfolio consolidation, where overlapping products are merged, repositioned, or sunset over time. None of that is guaranteed, but the decision authority now lies with a new owner whose priorities may differ from those a customer signed up for.
The most consequential point for European customers is jurisdiction. The US CLOUD Act can compel a US company to disclose data it controls, regardless of where that data is physically stored. The relevant question is therefore not only where the data centre stands, but who owns and operates the company holding the keys. A US parent introduces a chain of control that can reach across borders, which is exactly the exposure that European sovereignty rules were designed to limit.
For existing customers, the practical uncertainty is timing. Service terms, data processing agreements, and renewal dates were negotiated with a German vendor. After the acquisition, the same paperwork is governed by a different corporate group. This is not a reason to panic, but it is a reason to read the contract again and to confirm that the terms still match the compliance posture your organisation needs.
Digital sovereignty used to be a topic for specialists. In 2026 it is a recurring item in board meetings, procurement checklists, and audit reports across the DACH region. Several forces push in the same direction.
GDPR remains the baseline. It requires that personal data be processed lawfully and that international transfers stand on a solid legal footing. On top of that, the NIS2 directive raises the bar for many organisations by mandating concrete technical and organisational measures for communication security, with management liability attached. Public bodies, law firms, healthcare providers, and operators of critical infrastructure face additional sector specific requirements that often favour suppliers under European control.
The common thread is control. When a vendor is owned and operated inside the European Union, processes data in the EU, and is not subject to extraterritorial access by a third country, the answer to an auditor is simple and clean. When ownership sits outside the EU, the same answer requires legal caveats, transfer mechanisms, and ongoing justification. For email, which carries the most sensitive communication most organisations produce, that difference is hard to ignore.
If the acquisition prompts you to evaluate alternatives, treat the switch as a project rather than a single decision. Four areas deserve attention.
Start by mapping what you actually use, not the full feature catalogue. Most organisations rely on a core set: phishing protection, spam filtering, malware and attachment scanning, email encryption, and central disclaimer management. Compare the candidate against that real list. The Conbool versus Proofpoint comparison is a useful reference point if Proofpoint is now effectively the parent you would be buying from.
The technical heart of a switch is the MX record. Your MX points incoming mail at the gateway, so changing providers means re-pointing it and updating the surrounding authentication records: SPF, DKIM, and DMARC. A clean cutover runs the new gateway in an observation mode first, then enforces policies once reports are stable. With a modern cloud gateway, the base configuration is typically done in under an hour, with tuning spread over the first one to two weeks.
The most common avoidable cost is contract overlap. If you switch mid term, you may pay two vendors at once. Map the renewal date of your existing Hornetsecurity contract and plan the migration so the new service goes live as the old one ends.
The table below frames the decision the acquisition introduces.
| Criterion | US owned provider after acquisition | European owned alternative |
|---|---|---|
| Ownership and control | US corporate group | EU based company |
| Data jurisdiction | Potentially exposed to US CLOUD Act | Governed by EU law |
| Roadmap direction | Set within the acquiring group | Set by the European vendor |
| Sovereignty answer to auditors | Requires transfer mechanisms and caveats | Direct and clean |
| Core protection features | Mature and broad | Comparable for typical needs |
Let us be straight about this. Hornetsecurity is a capable product, and Proofpoint is a serious vendor. The point of this article is not to talk a competitor down. The acquisition simply changes one specific variable, ownership and jurisdiction, and that variable matters a great deal to organisations for which sovereignty is a hard requirement.
Conbool is a German email security vendor. The platform is developed in Karlsruhe, and data is processed within the European Union, under European law, without a US parent in the chain of control. On the functional side, Conbool covers the same core ground that most teams use a vendor like Hornetsecurity for:
The honest framing is this: if your decision comes down to raw feature count, several vendors will satisfy you. If your decision is shaped by who owns the company, where data is governed, and what answer you can give an auditor or a customer asking about sovereignty, a European owned provider has a structural advantage that no feature comparison erases. That is the lens the Proofpoint acquisition brings into focus.
If you want to see where your own domain stands today, the free email security check gives you a quick baseline before any migration conversation.
Yes. Proofpoint announced the acquisition of Hornetsecurity on 9 December 2025 in a deal valued at around 1.8 billion US dollars. Hornetsecurity, founded in Hanover and long marketed as a German email security vendor, now sits under the ownership of Proofpoint, a US company. The acquisition does not change the brand name overnight, but it does change who ultimately controls the company, its roadmap, and the corporate group that governs how customer data is handled.
In the short term, contracts, service endpoints, and data centre locations usually stay the same, so day to day operation continues. Over the medium term the relevant questions are ownership and governance rather than where a single data centre stands. A US parent company brings the product roadmap, pricing strategy, and group level data processing under US corporate control, which can expose data to laws such as the US CLOUD Act. Existing customers should review their contract term, renewal dates, and data processing agreement, then decide whether the new ownership structure still matches their sovereignty requirements.
Digital sovereignty has moved from a nice to have to a board level topic across the DACH region. Regulations such as GDPR and NIS2, together with sector specific requirements for public bodies, law firms, and critical infrastructure, push organisations to keep control over where data lives and which jurisdiction governs it. A provider that is owned and operated in the European Union, processes data in the EU, and is not subject to extraterritorial US access offers a cleaner answer to auditors, customers, and regulators than a US owned vendor, even when the technical features look comparable.
The licence fee is only part of the picture. The real cost of a switch sits in the migration: matching features, reconfiguring policies, changing the MX record, adjusting SPF, DKIM, and DMARC, and running a parallel observation phase before enforcement. With a modern cloud gateway the technical setup is typically completed in under an hour, and the observation and tuning phase runs over the first one to two weeks. The main project risk is contract overlap, so plan the switch around the renewal date of the existing contract to avoid paying twice.
Yes. Conbool is a German email security vendor that develops its platform in Karlsruhe and processes data within the European Union. It covers the same core ground as Hornetsecurity, including phishing and malware protection, spam filtering, email encryption, large file transfer, and disclaimer management, while keeping ownership and data under European control. The honest framing is that Hornetsecurity remains a capable product. The decision point introduced by the Proofpoint acquisition is governance and sovereignty, not raw feature count, and that is where a European owned provider has a structural advantage.
The Proofpoint acquisition of Hornetsecurity does not break anything overnight. Services keep running, contracts stay valid, and the product is as capable as it was before. What the deal changes is the answer to one question that matters more every year: who owns the company, and which jurisdiction governs the data that flows through it. For organisations that treat digital sovereignty as a requirement rather than a preference, that is reason enough to review the landscape.
If you want to understand your options, start with the free email security check to see where your domain stands, then read the Conbool versus Hornetsecurity comparison for a direct, feature level view. The right time to plan a switch is well before your current contract renews.
Further reading: