Mandiant
Mandiant provides incident response, threat intelligence, managed detection, and cybersecurity consulting to enterprise and government clients, operating as a Google Cloud subsidiary after Alphabet's $5.4B acquisition in 2022. Its portfolio spans IR retainers, managed defense, red team and cloud assessments, the ThreatSpace cyber range, and the M-Trends annual report, integrated with Google SecOps and Gemini.
- Company typePrivate
- Founded2004
- HeadquartersAlexandria, United States
- Headcount5,001–10,000
- GTM typeB2B
- OfferingServices
What Mandiant does
Mandiant is a cybersecurity consulting and threat intelligence firm founded in 2004 by Kevin Mandia and headquartered in Alexandria, Virginia. The company provides incident response services, proactive security assessments, managed detection and response, and threat intelligence to enterprise and government clients across financial services, healthcare, education, government, technology, and professional services verticals. Its core product portfolio includes Mandiant Consulting (incident response, red team, cloud architecture assessments, compromise assessments, cyber defense assessments), Mandiant Retainer (flexible pre-negotiated access to IR experts with 2-hour response SLAs), Mandiant Managed Defense (24x7 threat detection), Mandiant Academy (cybersecurity training via ThreatSpace cyber range), and the annual M-Trends threat intelligence report. Mandiant was acquired by FireEye in 2013 for approximately $1 billion and subsequently acquired by Google (Alphabet) in 2022 for $5.4 billion at a 57% premium, becoming a wholly-owned subsidiary of Google Cloud. It now operates as part of Google's security portfolio alongside Google SecOps, Google Threat Intelligence Group, and Wiz (acquired separately for $32 billion in March 2026), with channel partnerships spanning Accenture, Deloitte, PwC, Netenrich, TENEX.AI, Auto-ISAC, and a network of law firms, insurance providers, and ransomware negotiators. The business model combines subscription-like recurring retainers, professional services engagements, managed services, and training revenue, with enterprise pricing largely quote-based and a recent expansion into AI-native platforms (Google AI Threat Defense, launched May 2026) that integrate Mandiant's frontline intelligence with Gemini models.
Mandiant firmographics
Firmographics- Name
- Mandiant
- Legal name
- Mandiant, Inc.
- Website
- https://mandiant.com
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 5,001–10,000 employees
- Short description
- Mandiant provides incident response, threat intelligence, managed detection, and cybersecurity consulting to enterprise and government clients, operating as a Google Cloud subsidiary after Alphabet's $5.4B acquisition in 2022. Its portfolio spans IR retainers, managed defense, red team and cloud assessments, the ThreatSpace cyber range, and the M-Trends annual report, integrated with Google SecOps and Gemini.
- Ownership category
- akta.pro rank
Mandiant industry classification
Industry- Product category
- Cybersecurity Consulting & Incident Response Services
- NAICS
- Computer Systems Design and Related Services (54151), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Managed Detection & Response (MDR) & SOC Services (HDADAGAG), Threat Intelligence Services (BPAEADAC)
Keywords
Where Mandiant is headquartered
LocationHeadquarters
- HQ city
- Alexandria
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Mandiant business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Incident Response Retainers: Flexible incident response retainer providing immediate access to cybersecurity experts with pre-negotiated terms and 2-hour response times, with proactive services to strengthen defenses before incidents occur.
- Strategic Consulting Services: Comprehensive cybersecurity consulting including incident response, crisis management, threat hunting, security testing, cloud security assessments, and cyber defense center development.
- Threat Intelligence Services: Custom cyber risk research and analysis, embedded frontline intelligence experts, dedicated expert integration, and cyber threat intelligence capability development and training.
- Mandiant Academy Training: Cybersecurity training courses ranging from 6 to 24 hours, covering topics such as static and dynamic analysis, cyber intelligence foundations, election security, insider threat analysis, and hands-on exercises in ThreatSpace cyber range.
- Managed Defense: 24x7 threat detection and elimination services through Mandiant Managed Defense.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | Mandiant Academy Training Courses |
| One time/ perpetual license | Pay-as-you-go | Cyber Defense Summit 2026 Conference |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
Mandiant product offering
Product offeringCore offering
Mandiant provides frontline cybersecurity consulting, incident response, and threat intelligence services to enterprise and government organizations. Core offerings include the Mandiant Retainer (pre-negotiated expert access with 2-hour response times), Mandiant Managed Defense (24x7 threat detection and elimination), technical assurance (red team, cloud architecture, compromise, and cyber defense assessments), strategic readiness, and the Mandiant Academy training program built on the ThreatSpace cyber range. Services are powered by proprietary threat intelligence drawn from over 500,000 hours of annual incident response work and integrated with Google Cloud's security portfolio.
Product overview
Mandiant, now part of Google Cloud, offers a comprehensive cybersecurity portfolio centered on Mandiant Consulting and Mandiant Managed Defense. The core offering includes incident response services, threat intelligence, and strategic consulting augmented by the Mandiant Retainer for flexible access to experts. Supporting products include Mandiant Academy with ThreatSpace cyber range for hands-on training, the annual M-Trends threat intelligence report, and specialized assessments (Red Team, Cloud Architecture, Compromise, Cyber Defense). The portfolio integrates with Google SecOps platform for operational transformation and includes open-source tools like AuraInspector for Salesforce security. The company also hosts the annual Cyber Defense Summit conference for practitioner education and community building.
Differentiator
Problem solved
Functional benefit
Brands
- Mandiant Academy: Cybersecurity training division offering courses on incident response, threat intelligence, and security analysis with certification programs.
- ThreatSpace
- M-Trends
Products and services
- Mandiant Consulting World-renowned cybersecurity consulting services combining deep understanding of global attacker behavior with over two decades of frontline experience, providing comprehensive incident response, preparedness, technical response, and crisis management for enterprise and government clients.
- Mandiant Retainer Flexible incident response retainer providing enterprise customers immediate access to Mandiant cybersecurity experts with pre-negotiated terms, 2-hour response times, and proactive services to strengthen defenses before incidents occur.
- Mandiant Managed Defense 24x7 managed threat detection and response service that finds and eliminates threats with confidence, combining Mandiant frontline expertise with continuous monitoring for enterprise security operations.
- Incident Response Services Technical incident response services including preparedness planning, on-demand technical response, and crisis management to help organizations tackle security breaches confidently.
- Red Team Assessments Red team assessments that emulate real attacker behavior using the latest tactics, techniques, and procedures (TTPs) from the frontlines, revealing complex attack paths that conventional assessments often miss.
- Cloud Architecture Assessment Cloud architecture assessment that identifies and mitigates commonly exploited misconfigurations across AWS, Azure, and Google Cloud environments, reducing attack surface and improving threat detection.
- Compromise Assessment Service to discover if an organization has been breached and proactively hunt for hidden attackers by combining extensive incident response experience with real-time threat intelligence.
- Cyber Defense Assessment Assessment providing a clear understanding of defensive capabilities with a prioritized roadmap to build stronger, more resilient security programs prepared for any challenge.
- Strategic Readiness Proactive security capability enhancement service helping organizations advance their approach to cyber risk management for complex challenges including M&A due diligence, supply chain attacks, and insider threats.
- Cyber Risk Management Service to pinpoint the cyber risks most relevant to an organization, translate findings for executive leadership, and empower smarter security investments through tabletop exercises.
- Crisis Communications Strategic crisis communications services providing readiness to respond effectively to modern multifaceted attacks, safeguarding stakeholders and mitigating reputational risk.
- Mandiant Academy Reality-based cybersecurity training courses taught by frontline incident response and threat intelligence experts, including on-demand courses, instructor-led classes, certification programs, and ThreatSpace cyber range exercises.
- ThreatSpace Cyber Range Immersive, hands-on cyber range for practicing real-world threats in a realistic virtual environment, preparing security teams for AI-assisted incident response.
- Cybersecurity Transformation Services Consulting engagement to transform core security processes and technologies, up-leveling threat detection, containment, and remediation capabilities while optimizing security operations for a more mature and resilient defense.
- Google AI Threat Defense Autonomous AI-powered security platform integrating Mandiant threat intelligence with Wiz, CodeMender, and Gemini to continuously discover, prioritize, and remediate software vulnerabilities at machine speed.
Quantifiable outcome
- Organizations save $1.9 million per breach when using extensive security AI and automation.
- +2 more outcomes
Companies that use Mandiant
Customer profileNamed customers7 records
Segments6 records
Ideal customer profiles2 records
Mandiant technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature4 records
Mandiant partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and supporting.
- Auto-ISACcoreGoogle Cloud joined the Automotive Information Sharing and Analysis Center (Auto-ISAC) as an Innovator Partner to strengthen cybersecurity across the automotive sector. The partnership involves contributing security experts, threat intelligence from Mandiant, and resources to protect vehicles, factories, and supply chains against evolving cyber threats. This aligns with Google's previously announced commitment to invest at least $10 billion over five years to advance cybersecurity across critical infrastructure sectors.
- Law Firms NetworksupportingMandiant collaborates with a global network of leading law firms to help clients mitigate risk and minimize liability from cyberattacks. The integrated ecosystem improves threat visibility, accelerates incident response, and prepares organizations for crisis situations before they occur.
- Insurance Providers and BrokerssupportingMandiant partners with insurance providers and brokers to provide cyber risk management services. The collaboration helps organizations access cyber insurance while strengthening their security posture through Mandiant expertise.
- Ransomware NegotiatorssupportingMandiant works with specialized ransomware negotiation firms as part of its cyber risk partner ecosystem. The network provides comprehensive support for organizations facing ransomware attacks, from technical response to negotiation assistance.
- Google Threat Intelligence GroupcoreMandiant operates as part of Google Cloud's security portfolio, integrated with the Google Threat Intelligence Group. This integration combines Mandiant's frontline incident response expertise with Google's scale and AI capabilities to provide comprehensive AI-powered security solutions.
- AccenturecoreAccenture is an ecosystem partner using the Google AI Threat Defense platform which integrates Mandiant threat intelligence. Accenture is already using the platform and contributing to customer implementations.
- DeloittecoreDeloitte is an ecosystem partner for Google AI Threat Defense platform which integrates Mandiant threat intelligence. Deloitte contributes to customer implementations using the combined platform capabilities.
- PwCcorePwC is an ecosystem partner for Google AI Threat Defense platform, utilizing Mandiant threat intelligence. PwC has an expanded alliance with Google Cloud and is leveraging AI-native controls for customer deployments.
- NetenrichsupportingNetenrich is a launch partner for Google AI Threat Defense platform, utilizing Mandiant threat intelligence capabilities as part of the platform ecosystem.
- TENEX.AIsupportingTENEX.AI is a launch partner for Google AI Threat Defense platform, integrating Mandiant threat intelligence into their security operations offerings.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Mandiant competitors and assessment
Company assessmentDirect peers
- CrowdStrike: CrowdStrike is a leading endpoint detection and response (EDR) provider with a growing MDR, incident response, and threat intelligence practice (Falcon OverWatch, Falcon Intelligence). CrowdStrike acquired Mandiant's Threat Intelligence Unit in 2025, making it both a direct competitor and a buyer of Mandiant's adjacent capability.
- Palo Alto Networks (Unit 42): Palo Alto Networks' Unit 42 is a direct competitor in incident response, threat intelligence, and managed detection services, combining consulting expertise with Palo Alto's broader security platform — closely comparable to Mandiant's consulting-plus-platform model.
- IBM X-Force: IBM X-Force offers incident response, threat intelligence, and managed security services backed by one of the largest security research teams globally. It competes head-to-head with Mandiant for Fortune 500 IR retainers and consulting engagements.
- Secureworks: Secureworks is a pure-play MDR and managed security services provider with strong incident response heritage. Its Taegis platform and IR services position it as a direct competitor to Mandiant Managed Defense and Mandiant Consulting.
- Kroll Cyber Risk: Kroll's Cyber Risk practice provides incident response, digital forensics, breach notification, and threat intelligence — directly competing with Mandiant Consulting across enterprise and mid-market breach response engagements.
- NCC Group: NCC Group is a global cybersecurity consulting and managed services firm with strong incident response, threat intelligence, and red team capabilities — competing with Mandiant particularly in EMEA and across regulated industries.
- Optiv: Optiv is a security solutions integrator and MSSP providing advisory, managed security, and incident response services. It competes with Mandiant on consulting-led enterprise security engagements, particularly in mid-market and large enterprise segments.
Emerging players
- Rapid7: Rapid7 combines security analytics (InsightIDR), vulnerability management, and managed detection and response services. While more platform-led than Mandiant, its MDR and incident response offerings overlap meaningfully with Mandiant Managed Defense.
- Bishop Fox: Bishop Fox specializes in offensive security, red teaming, and attack surface management — directly overlapping with Mandiant's Red Team Assessments, Technical Assurance, and Compromise Assessment offerings.
Broad incumbents
- Booz Allen Hamilton Cyber: Booz Allen Hamilton operates a large federal and commercial cybersecurity consulting practice with deep incident response and threat intelligence capabilities, frequently competing with Mandiant in government and Fortune 500 engagements.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Mandiant social profiles
Digital presenceMandiant compliance and trust
Trust signalCompliance4 records
Mandiant financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mandiant leadership team
Management profileNumber of profiles
Profiles9 records
Mandiant subsidiaries and ownership
Company hierarchySubsidiaries1 record
Mandiant funding detail
Funding detailFunding overview
Funding rounds2 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mandiant M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mandiant
What does Mandiant do?
Mandiant provides frontline cybersecurity consulting, incident response, and threat intelligence services to enterprise and government organizations. Core offerings include the Mandiant Retainer (pre-negotiated expert access with 2-hour response times), Mandiant Managed Defense (24x7 threat detection and elimination), technical assurance (red team, cloud architecture, compromise, and cyber defense assessments), strategic readiness, and the Mandiant Academy training program built on the ThreatSpace cyber range. Services are powered by proprietary threat intelligence drawn from over 500,000 hours of annual incident response work and integrated with Google Cloud's security portfolio.
Is Mandiant a public or private company?
Mandiant is a private company. It is classified as corporate owned and is currently operating.
When was Mandiant founded?
Mandiant was founded in 2004. It employs 5,001 to 10,000 people.
Where is Mandiant based?
Mandiant is headquartered in Alexandria, United States, in the North America region.
How does Mandiant make money?
Five revenue lines are on record. Incident Response Retainers are the primary driver. The others are strategic Consulting Services, threat Intelligence Services, mandiant Academy Training and managed Defense.
Who are Mandiant's main competitors?
Direct peers on record are CrowdStrike, Palo Alto Networks (Unit 42), IBM X-Force, Secureworks, Kroll Cyber Risk, NCC Group and Optiv. Emerging players are Rapid7 and Bishop Fox. Booz Allen Hamilton Cyber is listed as a broad incumbent.
Does Mandiant have an API?
No public API is recorded for Mandiant.
What industry is Mandiant in?
Mandiant's product category is Cybersecurity Consulting & Incident Response Services. Its primary akta.pro industry code is BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 54151 and its SIC code is 7370.