NetSPI
NetSPI is a Minneapolis-based cybersecurity firm that delivers human-led, AI-accelerated Penetration Testing as a Service (PTaaS), Attack Surface Management, and security assessments to Fortune 500 enterprises, top U.S. banks, and major technology firms globally.
- Company typePrivate
- Founded2001
- HeadquartersMinneapolis, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingServices
What NetSPI does
NetSPI is a Minneapolis-based, privately held cybersecurity firm founded in 2001 that pioneered the Penetration Testing as a Service (PTaaS) delivery model. The company combines 350+ in-house penetration testers with purpose-built AI to deliver continuous and point-in-time security testing across applications (web, API, mobile, thick client), networks (external, internal, wireless, mainframe z/OS, host-based), cloud (AWS, Azure, GCP), hardware and embedded systems (IoT, automotive, medical devices, ATMs, OT), and AI/ML systems. Supporting modules include Attack Surface Visibility (External Asset Discovery, Dark Web Monitoring, Domain Monitoring, Cloud Configuration Reviews), Security Assessments (Red Team Operations, Social Engineering, Detective Controls Testing, Secure Code Review, Threat Modeling, Cybersecurity Maturity Assessment), and agentic MCP integrations that allow customer AI agents to act on NetSPI engagement and vulnerability data. NetSPI Labs drives R&D through open-source tools (MicroBurst, PowerUpSQL, PowerHuntShares) and bleeding-edge research.
The company serves Fortune 500 enterprises, the top 10 U.S. banks, and MAMAA tech giants (Meta, Apple, Microsoft, Amazon, Alphabet), with named customers including Microsoft, Chubb, Medtronic, Global Atlantic Financial Group, Broadridge, Veradigm, Gong, Hudl, and Trimble. Its go-to-market blends enterprise field sales (dedicated client delivery management, white-glove account support), inside sales (Schedule a Test, Request a Demo CTAs), and channel partnerships (AWS ISV Accelerate Program, broader partner program). Revenue is generated through subscription-based PTaaS programs, recurring Attack Surface Management bundles, and professional services engagements, with pricing ranging from approximately $15,000 for focused assessments to $500,000+ for enterprise transformation programs. NetSPI is backed by KKR and Ten Eleven Ventures following a $90M round in May 2021 and a $410M round in October 2022 led by KKR with Sunstone Partners, and has made three acquisitions (Silent Break Security, nVisium, Hubble) to expand capability and talent. The company maintains offices in Minneapolis (HQ), Portland (engineering/R&D), and Pune, India.
NetSPI firmographics
Firmographics- Name
- NetSPI
- Legal name
- NetSPI LLC
- Website
- https://netspi.com
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- NetSPI is a Minneapolis-based cybersecurity firm that delivers human-led, AI-accelerated Penetration Testing as a Service (PTaaS), Attack Surface Management, and security assessments to Fortune 500 enterprises, top U.S. banks, and major technology firms globally.
- Ownership category
- akta.pro rank
NetSPI industry classification
Industry- Product category
- Penetration Testing Services
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415), Security Systems Services (56162)
- SIC
- Services-Testing Laboratories (8734), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
- akta.pro secondary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where NetSPI is headquartered
LocationHeadquarters
- HQ city
- Minneapolis
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
NetSPI business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Penetration Testing as a Service (PTaaS): Subscription-based pentesting services with continuous and point-in-time testing options across applications, networks, cloud, AI/ML, mainframes, and hardware. Includes program management, findings tracking, remediation testing, and trend analysis through a centralized platform. Revenue generated through recurring engagement programs with enterprise customers.
- Attack Surface Management: Ongoing attack surface visibility and monitoring services bundled with pentesting engagements, providing external asset discovery, dark web monitoring, and domain monitoring capabilities.
- Security Assessments: Advisory services including Red Team Operations, Social Engineering, Detective Controls Testing, Threat Modeling, Cybersecurity Maturity Assessment, and Secure Code Review delivered as professional services engagements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise Penetration Testing Programs |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels9 records
NetSPI product offering
Product offeringCore offering
NetSPI provides Penetration Testing as a Service (PTaaS) combining 350+ in-house human security experts with purpose-built AI to deliver continuous and point-in-time security testing across applications, networks, cloud, AI/ML, mainframe, and hardware environments. The company also offers Attack Surface Management (external asset discovery, dark web monitoring, domain monitoring) and Security Assessments (red teaming, social engineering, detective controls testing, secure code review, threat modeling, maturity assessments) for enterprise security programs.
Product overview
NetSPI is a proactive cybersecurity platform provider offering Penetration Testing as a Service (PTaaS) as its core offering, combining 350+ elite human penetration testers with purpose-built AI. The platform delivers continuous and point-in-time testing across multiple attack surfaces including applications (web, API, mobile, thick client), networks (external, internal, wireless, mainframe), cloud (AWS, Azure, GCP), hardware/embedded systems, and AI/ML systems. Supporting the PTaaS platform are Attack Surface Visibility modules providing 360-degree visibility through External Asset Discovery, Dark Web Monitoring, and Domain Monitoring. The product portfolio also includes Security Assessments such as Red Team Operations, Detective Controls Testing, Secure Code Review, Threat Modeling, Cybersecurity Maturity Assessment, and Social Engineering services. NetSPI Labs drives innovation through open-source tools and research.
Differentiator
Problem solved
Functional benefit
Brands
- NetSPI Labs: Research and development division focused on bleeding edge cybersecurity innovation and open-source tools
Products and services
- NetSPI PTaaS Platform
Quantifiable outcome
- Eliminates false positives at scale through human-led, AI-accelerated approach
- +2 more outcomes
Companies that use NetSPI
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles4 records
NetSPI technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability7 records
Feature8 records
NetSPI partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and strategic.
- MicrosoftcoreDeep integration partnership with Microsoft including Entra ID Conditional Access policy testing, Azure security research (discovered vulnerability in Microsoft Entra via Nested App Authentication), Microsoft Defender integration, Azure cloud security testing, and collaboration on Quick Share data security.
- AWScoreAWS ISV Accelerate Program partner providing cloud security configuration reviews for AWS environments including S3 bucket misconfigurations, EC2 metadata exploitation, and automated weekly security scans.
- AzurecoreAzure cloud security integration with automated weekly configuration scans, Entra ID (Azure AD) integration, Azure Sentinel SIEM integration, and Azure Batch Service security testing capabilities.
- Google Cloud Platform (GCP)coreGCP cloud penetration testing services including GKE security, Cloud Functions testing, Firebase development security, and IAM policy validation for Google Cloud environments.
- CrowdStrikecorePlatform integration with CrowdStrike Falcon for endpoint security monitoring, attack simulation validation, and unified security visibility across CrowdStrike-protected environments.
- OktacoreIntegration with Okta identity provider for IAM security validation, authentication testing, and single sign-on security assessment capabilities.
- ServiceNowcoreServiceNow ticketing system integration enabling seamless workflow automation for pentest findings, remediation tracking, and security workflow management.
- JiracoreJira ticketing integration for vulnerability findings management, remediation tracking, and agile security workflow integration.
- ChubbstrategicStrategic partnership bringing attack surface management capabilities to Chubb policyholders. NetSPI provides proactive security solutions integrated into cyber insurance offerings.
Scale indicators8 records
Recent moves8 records
Expansion highlights8 records
NetSPI competitors and assessment
Company assessmentDirect peers
- Synack: Synack is one of the closest direct competitors to NetSPI in the PTaaS market. Both combine elite human security researchers with a platform to deliver on-demand, continuous penetration testing to enterprise customers, targeting similar Fortune 500 buyer personas.
- Cobalt: Cobalt operates a PTaaS platform that connects customers to a curated community of pentesters for on-demand security testing. Like NetSPI, it serves enterprise customers seeking scalable, platform-driven penetration testing with continuous engagement models.
- Bishop Fox: Bishop Fox is a long-standing offensive security services firm competing directly with NetSPI in pentesting, red teaming, and attack surface management. Both serve Fortune 500 enterprises with similar human-led testing services.
Broad incumbents
- Rapid7: Rapid7 is a public cybersecurity platform offering vulnerability management, ASM, and managed detection services that overlap with NetSPI's PTaaS and ASM offerings. As a broader platform vendor, Rapid7 competes with NetSPI for security budget allocation at enterprise customers.
- Tenable: Tenable is a leading vulnerability management and attack surface management platform. While primarily a software vendor, Tenable's continuous assessment capabilities overlap with NetSPI's ASM and continuous pentesting offerings for enterprise buyers.
- CrowdStrike: CrowdStrike is a dominant endpoint security platform that has expanded into ASM (Falcon Surface) and adjacent security testing capabilities. As a large incumbent with bundled offerings, it represents competitive pressure for NetSPI in enterprise security budgets.
- Palo Alto Networks: Palo Alto Networks offers Cortex ASM and broader security platform capabilities that overlap with NetSPI's attack surface management and continuous testing offerings. As a platform incumbent, it competes for consolidated security spending.
Emerging players
- HackerOne: HackerOne is a leading bug bounty and crowdsourced security testing platform. While its model differs (crowdsourced vs. in-house testers), it competes with NetSPI for vulnerability discovery and continuous security testing budgets at enterprise customers.
- Bugcrowd: Bugcrowd operates a crowdsourced cybersecurity platform offering pentesting, bug bounty, and attack surface management. It overlaps with NetSPI in the PTaaS space but uses a crowdsourced researcher model rather than employed pentesters.
Others
- nVisium: nVisium was acquired by NetSPI in January 2023, so it is now part of NetSPI rather than a competitor. It was previously a comparable application security and pentesting firm focused on enterprise customers with similar service offerings.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
NetSPI social profiles
Digital presenceNetSPI compliance and trust
Trust signalCompliance11 records
NetSPI financial estimates
Financial estimateRevenue estimate
Valuation estimate
NetSPI leadership team
Management profileNumber of profiles
Profiles10 records
NetSPI funding detail
Funding detailFunding overview
Funding rounds3 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NetSPI M&A and investment
M&A and investmentM&A4 records
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NetSPI
What does NetSPI do?
NetSPI provides Penetration Testing as a Service (PTaaS) combining 350+ in-house human security experts with purpose-built AI to deliver continuous and point-in-time security testing across applications, networks, cloud, AI/ML, mainframe, and hardware environments. The company also offers Attack Surface Management (external asset discovery, dark web monitoring, domain monitoring) and Security Assessments (red teaming, social engineering, detective controls testing, secure code review, threat modeling, maturity assessments) for enterprise security programs.
Is NetSPI a public or private company?
NetSPI is a private company. It is classified as private equity controlled and is currently operating.
When was NetSPI founded?
NetSPI was founded in 2001. It employs 501 to 1,000 people.
Where is NetSPI based?
NetSPI is headquartered in Minneapolis, United States, in the North America region.
How does NetSPI make money?
Three revenue lines are on record. Penetration Testing as a Service (PTaaS) is the primary driver. The others are attack Surface Management and security Assessments.
Who are NetSPI's main competitors?
Direct peers on record are Synack, Cobalt and Bishop Fox. Broad incumbents are Rapid7, Tenable, CrowdStrike and Palo Alto Networks. Emerging players are HackerOne and Bugcrowd. nVisium is listed as an others.
Does NetSPI have an API?
Yes. NetSPI offers an Open API that enables integrations across the security ecosystem, including asset management, identity providers, vulnerability scanning, and ticketing platforms. The platform provides integration capabilities and API that ensure security insights are immediately actionable within customers' current tech stack and workflows.
What industry is NetSPI in?
NetSPI's product category is Penetration Testing Services. Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54151 and its SIC code is 8734.