RiskSense
RiskSense provides a risk-based vulnerability management and application security orchestration platform using proprietary human-interactive machine learning, serving enterprise security teams with prioritization, threat intelligence, and penetration testing; acquired by Ivanti in August 2021.
- Company typePrivate
- Founded2015
- HeadquartersSunnyvale, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What RiskSense does
RiskSense, founded in 2015 by a group of cybersecurity experts (including co-founder and CEO Srinivas Mukkamala and co-founder Mark Fidel), provides risk-based vulnerability management (RBVM) and application security orchestration and correlation (ASOC) through a proprietary human-interactive machine learning platform. The platform enriches infrastructure-to-application security findings with near-real-time vulnerability threat intelligence (the Vulnerability Knowledge Base) and delivers adversarial, risk-based prioritization of vulnerabilities, end-to-end exposure tracking, and remediation validation. It supports multi-source data ingestion via flat file, XML, or web service API and is offered across multiple regional platform instances (US, EU, India) with SAML/SSO access.
The company's revenue model combines recurring platform subscriptions (RBVM, ASOC) with managed services (Vulnerability Management as a Service) and professional services (penetration testing for hosts, networks, and web applications). Pricing is quote-based on multi-year enterprise contracts. Go-to-market is sales-led, with direct enterprise field sales supplemented by self-serve platform access and a data integration/connector channel. The platform is underpinned by a documented patent portfolio, a deep bench of security researchers, and a Fellowship Program with New Mexico Tech, UC Riverside, and Carnegie Mellon University.
RiskSense was acquired by Ivanti on August 2, 2021, and now operates as part of Ivanti's security product portfolio, branded as Ivanti Neurons for RBVM, ASOC, and the Vulnerability Knowledge Base. Following the acquisition, the company has 101-250 employees and is reported as headquartered in Sunnyvale, California, with active data residency in the United States, the European Union, and India, and localized marketing presence in English (Global, Australia, UK), German, Spanish, French, Italian, Chinese, and Japanese.
RiskSense firmographics
Firmographics- Name
- RiskSense
- Legal name
- RiskSense
- Website
- https://risksense.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Acquired
- Headcount range
- 101–250 employees
- Short description
- RiskSense provides a risk-based vulnerability management and application security orchestration platform using proprietary human-interactive machine learning, serving enterprise security teams with prioritization, threat intelligence, and penetration testing; acquired by Ivanti in August 2021.
- Ownership category
- akta.pro rank
RiskSense industry classification
Industry- Product category
- Vulnerability Management and Risk Prioritization Software
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industries
- Vulnerability Assessment & Scanning (HDADAHAA), Threat Intelligence Services (BPAEADAC), Vulnerability Management & Penetration Testing Services (BPAEADAD), Risk Scoring, Fraud & Anomaly Detection (HDAAAHAD)
Keywords
Where RiskSense is headquartered
LocationHeadquarters
- HQ city
- Sunnyvale
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
RiskSense business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- RiskSense Platform Subscriptions (RBVM, ASOC): Recurring subscription-based access to the RiskSense platform for risk-based vulnerability management and application security orchestration and correlation, with multiple regional platform instances (Platform 1, 2, 4, EU, IN) accessed via login.
- Vulnerability Management as a Service (VMaaS): Managed-service delivery of RBVM including vulnerability scanning and prioritization as an outsourced offering.
- Penetration Testing Services: Professional services revenue from industry-leading penetration testing engagements for hosts/networks and web applications.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based enterprise pricing for RBVM/ASOC platform, VMaaS, and penetration testing |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
RiskSense product offering
Product offeringCore offering
RiskSense provides a risk-based vulnerability management and attack surface orchestration platform that uses human-interactive machine learning to correlate vulnerability data with threat intelligence, asset context, and exploit availability so security teams can prioritize and remediate the issues most likely to be weaponized. It complements the platform with managed vulnerability management services, penetration testing, and broad data integrations into enterprise security and IT tooling.
Product overview
RiskSense is a single risk-based vulnerability management platform (now marketed by Ivanti as Ivanti Neurons for RBVM/ASOC) that pairs a core human-interactive machine learning–powered engine with several offerings: the RBVM and ASOC core products drive prioritization, while the Vulnerability Threat Intelligence (Ivanti Neurons for Vulnerability Knowledge Base) feeds near-real-time vulnerability data, and VMaaS, Penetration Testing, and Data Integrations/Connectors extend the platform into managed services, offensive testing, and ingestion from external sources via flat file, XML, or web service API.
Differentiator
Problem solved
Functional benefit
Brands
- Ivanti Neurons for RBVM: Risk-based vulnerability management product offering under the Ivanti Neurons platform
- Ivanti Neurons for ASOC
Products and services
- RiskSense RBVM Platform Risk-based vulnerability management software that uses human-interactive machine learning to prioritize vulnerabilities based on threat intelligence, exploit availability, and asset business context. Sold to enterprise security teams for vulnerability prioritization and remediation orchestration.
- RiskSense Attack Surface & Orchestration Center (ASOC) Attack surface discovery and orchestration solution that maps the full external and internal attack surface and orchestrates remediation workflows across security and IT teams. Targeted at enterprise vulnerability management and security operations buyers.
- Vulnerability Threat Intelligence Curated vulnerability and exploit threat intelligence feed that enriches scanner output with real-world exploit data to inform prioritization decisions. Used by enterprise security teams consuming the RiskSense platform.
- Vulnerability Management as a Service (VMaaS) Managed vulnerability management service delivered by RiskSense experts who operate the platform on behalf of customers, handling scanning, prioritization, and remediation guidance. Sold to organizations that lack in-house vulnerability management capacity.
- Penetration Testing Services Offensive security testing engagements that identify exploitable weaknesses in customer environments and feed results back into the RiskSense prioritization model. Sold to enterprise security teams seeking validated exploit evidence.
- RiskSense Data Integrations Pre-built integrations that ingest vulnerability, asset, EDR, CMDB, and cloud security data into the RiskSense platform to support unified risk prioritization. Sold as part of platform deployments to enterprise customers.
Quantifiable outcome
- End-to-end comprehensive oversight of vulnerability exposure tracking and remediation validation across infrastructure and applications.
Companies that use RiskSense
Customer profileSegments3 records
Ideal customer profiles1 record
RiskSense technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature5 records
RiskSense partnerships and signals
Strategic signalScale indicators4 records
Recent moves6 records
Expansion highlights6 records
RiskSense competitors and assessment
Company assessmentDirect peers
- Skybox Security: Skybox Security provides vulnerability management and threat-centric vulnerability prioritization across hybrid environments. Competes with RiskSense on enterprise risk-based prioritization and exposure analysis.
- Rapid7: Rapid7 InsightVM and InsightConnect provide risk-based vulnerability management and security orchestration for enterprise security teams. Direct overlap with RiskSense's RBVM and ASOC product positioning.
- Kenna Security (now Cisco Vulnerability Management): Kenna Security is a pioneering risk-based vulnerability management platform using ML-driven exploit and prioritization scoring, acquired by Cisco. One of the closest pure-play comparables to RiskSense's approach.
- Qualys: Qualys VMDR delivers vulnerability management, detection, and response with risk-based prioritization as a cloud-native platform. Competes head-to-head with RiskSense on enterprise vulnerability prioritization and threat intelligence.
- Tenable: Tenable is the leading commercial vulnerability management and RBVM platform (Nessus, Tenable One), offering risk-based prioritization across infrastructure and cloud. It is the most direct competitor to RiskSense's core RBVM/ASOC offering.
- Expanse (now Palo Alto Networks): Expanse pioneered external attack surface management with risk-based prioritization, acquired by Palo Alto Networks. Its capabilities are adjacent and increasingly overlapping with RiskSense's vulnerability exposure tracking.
Broad incumbents
- Microsoft (Defender Vulnerability Management): Microsoft Defender Vulnerability Management provides natively bundled risk-based vulnerability management within the Microsoft security ecosystem, creating powerful displacement risk for standalone RBVM platforms like RiskSense.
- Palo Alto Networks (Cortex / VM-Series): Palo Alto Networks bundles vulnerability and attack surface capabilities (including the Expanse acquisition) into its Cortex XSIAM and Prisma platforms, competing broadly with RiskSense within enterprise security operations portfolios.
Regional players
- WithSecure (formerly F-Secure): WithSecure offers vulnerability management, managed detection, and penetration testing services, with a strong presence in Europe. Comparable in its combination of platform, managed services, and offensive testing offerings.
Emerging players
- Brinqa: Brinqa offers a risk-based vulnerability management and cybersecurity asset management platform that prioritizes threats using business context. A more focused, emerging competitor with significant product overlap.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
RiskSense social profiles
Digital presenceRiskSense financial estimates
Financial estimateRevenue estimate
Valuation estimate
RiskSense leadership team
Management profileNumber of profiles
Profiles3 records
RiskSense funding detail
Funding detailFunding overview
Funding rounds3 records
Investors9 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RiskSense M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RiskSense
What does RiskSense do?
RiskSense provides a risk-based vulnerability management and attack surface orchestration platform that uses human-interactive machine learning to correlate vulnerability data with threat intelligence, asset context, and exploit availability so security teams can prioritize and remediate the issues most likely to be weaponized. It complements the platform with managed vulnerability management services, penetration testing, and broad data integrations into enterprise security and IT tooling.
Is RiskSense a public or private company?
RiskSense is a private company. It is classified as corporate owned and is currently acquired.
When was RiskSense founded?
RiskSense was founded in 2015. It employs 101 to 250 people.
Where is RiskSense based?
RiskSense is headquartered in Sunnyvale, United States, in the North America region.
How does RiskSense make money?
Three revenue lines are on record. RiskSense Platform Subscriptions (RBVM, ASOC) is the primary driver. The others are vulnerability Management as a Service (VMaaS) and penetration Testing Services.
Who are RiskSense's main competitors?
Direct peers on record are Skybox Security, Rapid7, Kenna Security (now Cisco Vulnerability Management), Qualys, Tenable and Expanse (now Palo Alto Networks). Broad incumbents are Microsoft (Defender Vulnerability Management) and Palo Alto Networks (Cortex / VM-Series). WithSecure (formerly F-Secure) is listed as a regional player. Brinqa is listed as an emerging player.
Does RiskSense have an API?
Yes. Data integrations and connectors enable Ivanti Neurons for RBVM and ASOC to ingest data from a variety of sources via web service API, as well as flat file and XML formats. No public developer documentation, sandbox, rate limits, or auth methods are described.
What industry is RiskSense in?
RiskSense's product category is Vulnerability Management and Risk Prioritization Software. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of HDADAHAA, Vulnerability Assessment & Scanning.