Cocon
GMO Cybersecurity by Ierae, a Tokyo-based subsidiary of GMO Internet Group (parent: Cocon, founded 2013), provides expert-led vulnerability assessment, penetration testing, SOC services, and ASM tooling to enterprise customers across financial services, technology, government, and other regulated sectors in Japan.
- Company typePrivate
- Founded2013
- HeadquartersTokyo, Japan
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Cocon does
GMO Cybersecurity by Ierae, Inc. (operating under parent company Cocon, founded 2013) is a Tokyo-based cybersecurity services firm specializing in vulnerability assessment, penetration testing, and managed security operations. The company serves enterprise customers across financial services, technology, government, healthcare, manufacturing, automotive, entertainment, and legal verticals, providing expert-led security testing conducted by what the company describes as Japan's largest in-house team of white hat hackers (200+ personnel). Notable client logos include Mizuho Securities, Mitsubishi UFJ Investment, multiple regional banks (Hokkaido, Yokohama, Hokuriku, Tsukuba, Tokushima Daishi), KDDI, NEC, CyberAgent, freee, Preferred Networks, Sharp, TOPPAN, Sysmex, Terumo, The Pokemon Company, and Saitama Prefectural Police. International clients include Golomt Bank (Mongolia) and Ulaanbaatar City (Mongolia).
The company's technology stack combines proprietary tooling with human expert assessment. Core offerings include the GMOサイバー攻撃ネットde診断 ASM (Attack Surface Management) platform for automated external asset discovery and vulnerability detection, a SOC (Security Operation Center) for continuous threat monitoring and incident response, WAF management services (WAFエイド) that reduce false positives, and specialized diagnostic services covering web applications, mobile apps (iOS/Android), cloud environments, network infrastructure, IoT devices, LLM/AI systems, and space/satellite infrastructure. The team has contributed 269 CVE disclosures and holds the world championship title at DEF CON Cloud Village CTF for three consecutive years (2023–2025). Red team exercises, threat modeling, digital forensics, and product security incident response (PSIRAAS) round out the offensive and defensive service portfolio.
The business operates on a hybrid revenue model combining project-based professional services (one-time vulnerability assessments, penetration tests, red team exercises, incident response, and digital forensics) with recurring subscription revenue (SOC monitoring, ASM tool licensing, and multi-year enterprise contracts). GTM is primarily direct enterprise sales with custom quote-based pricing and multi-year contract structures, supplemented by a partner/reseller channel and self-serve ASM tools for internal team use. As a subsidiary of GMO Internet Group, the company benefits from group-level distribution, brand association, and operational resources, while maintaining its position as Japan's No.1 vendor in the domestic vulnerability diagnosis and penetration testing market per ITR research (2025 forecast).
Cocon firmographics
Firmographics- Name
- Cocon
- Legal name
- GMOサイバーセキュリティ byイエラエ株式会社
- Website
- https://cocon-corporation.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- GMO Cybersecurity by Ierae, a Tokyo-based subsidiary of GMO Internet Group (parent: Cocon, founded 2013), provides expert-led vulnerability assessment, penetration testing, SOC services, and ASM tooling to enterprise customers across financial services, technology, government, and other regulated sectors in Japan.
- Ownership category
- akta.pro rank
Cocon industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Computer Facilities Management Services (541513)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where Cocon is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices1 record
Markets served
Cocon business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Vulnerability Assessment & Penetration Testing Services: One-time and project-based security assessment services including web application, mobile app, cloud, network, IoT, and specialized penetration testing. Revenue generated through professional services engagements with enterprise clients.
- SOC and Security Operations Services: Recurring SOC (Security Operation Center) services providing ongoing monitoring, defense, and alert response. Subscription-based service for continuous security operations.
- ASM Tool Subscription: Automated Attack Surface Management tool subscription for enterprises to manage vulnerability assessment internally on a regular basis.
- Security Training and Certification: Ierae Academy provides security training courses and certification preparation including offensive security (OSCP) and incident response training.
- Incident Response & Digital Forensics: Forensic investigation and incident response services when security incidents occur, including cause identification and recurrence prevention.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Enterprise custom quoting |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Cocon product offering
Product offeringCore offering
Cocon, through its GMO Cybersecurity by Ierae subsidiary, provides enterprise cybersecurity services and software including vulnerability diagnosis, penetration testing, Attack Surface Management (ASM) tooling, managed Security Operation Center (SOC) services, WAF management, incident response and digital forensics, and specialized AI/LLM security assessments. The company leverages over 200 white hat hackers and a proprietary ASM platform to deliver recurring and project-based engagements to enterprise, financial, government and technology customers, primarily in Japan.
Product overview
GMOサイバーセキュリティ byイエラエ offers a comprehensive cybersecurity portfolio centered on vulnerability assessment/penetration testing services and managed security operations. The core offerings include the GMOサイバー攻撃ネットde診断 ASM tool for attack surface management and vulnerability detection, SOC (Security Operation Center) services for threat monitoring and incident response, WAF management through WAFエイド, and a full suite of specialized diagnostic services covering web applications, mobile apps, cloud, networks, IoT devices, AI/LLM systems, and physical security. The company also provides incident response, digital forensics, security consulting, and professional training through its イエラエアカデミー platform. These products work together to provide end-to-end security coverage from proactive vulnerability identification through continuous monitoring to incident response.
Differentiator
Problem solved
Functional benefit
Brands
- イエラエアカデミー (Ierae Academy): Security training and certification preparation services including offensive security certification courses and incident response training.
Products and services
- GMO サイバー攻撃ネットde診断 (Attack Surface Management Tool) Proprietary Attack Surface Management (ASM) tool that visualizes externally exposed assets and enables company-wide vulnerability management; designed for enterprise security teams to internalize regular vulnerability assessments.
- SOC (Security Operation Center) Service Managed Security Operation Center service providing automated and advanced cyber attack defense, alert detection, and incident response support for enterprise customers.
- WAF Aid (Managed WAF Service) Managed Web Application Firewall service that reduces false positives, improves defense accuracy, and reduces operational burden for in-house security teams.
- Vulnerability Assessment & Penetration Testing Comprehensive vulnerability diagnosis and penetration testing services performed by in-house white hat hackers, covering web applications, smartphone applications (iOS/Android), cloud environments, network/platform infrastructure, IoT, and AI/LLM systems. Includes red team exercises.
- Security Incident Response Support Incident response support services including initial response, root cause analysis, and recurrence prevention recommendations, plus digital forensics and product security incident response (PSIRAAS).
- Security Consulting Security consulting services in which expert consultants accompany and support client teams in addressing diverse security challenges, including specialized support for space and satellite cybersecurity.
- Ierae Academy (Security Training & Certification) Professional security training and certification preparation services including offensive security (OSCP) courses and incident response training, delivered by instructors active in the field.
Quantifiable outcome
- 16,000+ vulnerability diagnosis cases completed
- +2 more outcomes
Companies that use Cocon
Customer profileNamed customers51 records
Segments4 records
Ideal customer profiles4 records
Cocon technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Cocon partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and flagship.
- National Cyber Security Center (NCO), Cabinet Secretariat of JapancoreParticipated as a related event organizer in the National Cybersecurity Month 2026, led by the National Cyber Security Center under the Cabinet Secretariat. GMO Cybersecurity contributed experts as speakers at the flagship security conference.
- Interpol and European CouncilflagshipGMO Cybersecurity by Ierae provided cybersecurity crime investigation training exercises for the 2nd consecutive year at an event jointly organized by Interpol and the European Council. The company conducted cyber crime investigation exercises with participation from 160 investigators from 50 countries.
- GMO Internet GroupcoreCore group company within GMO Internet Group, utilizing group resources and brand recognition. Part of one of Japan's largest internet service groups providing infrastructure and business services.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Cocon competitors and assessment
Company assessmentDirect peers
- LAC Co., Ltd. Japanese cybersecurity firm offering vulnerability assessment, penetration testing, and SOC services to enterprises and government, directly competing with GMO Cybersecurity in the domestic market for the same set of regulated and enterprise customers.
- NRI Secure Technologies: Major Japanese security consulting and managed security services provider offering vulnerability diagnostics, SOC, and incident response to financial institutions and large enterprises, a direct competitor in Japan's pen testing and managed security market.
- Rapid7: Global provider of vulnerability management, penetration testing services, and managed detection and response, directly comparable to GMO Cybersecurity's assessment, ASM, and SOC offerings on a product/services basis.
- NCC Group: Global cybersecurity services firm specializing in vulnerability assessment, penetration testing, and incident response for enterprises, with strong government and critical infrastructure client overlap comparable to GMO Cybersecurity's regulated customer base.
- SecureWorks: Managed security services provider offering MDR, vulnerability management, and incident response, directly comparable to GMO Cybersecurity's SOC and assessment portfolio with similar GTM toward enterprise and regulated customers.
- bishopfox: US-based offensive security firm specializing in penetration testing, red teaming, and vulnerability research with a talent-led brand similar to GMO Cybersecurity's white-hacker positioning.
Broad incumbents
- NTT Security (Japan): Arm of NTT Group delivering a broad cybersecurity services portfolio including vulnerability assessment, SOC, and consulting across Japan, overlapping with GMO Cybersecurity's enterprise and government offerings but as part of a much larger telecom conglomerate portfolio.
- Trend Micro (Japan): Global Japanese-headquartered cybersecurity vendor with a services arm covering vulnerability assessment, threat research, and incident response; overlaps with GMO Cybersecurity but at much broader scale and across a wider product portfolio.
- Mandiant (Google Cloud): Incident response, threat intelligence, and security assessment firm now part of Google Cloud; comparable to GMO Cybersecurity's incident response, digital forensics, and AI/LLM-adjacent security consulting offerings at much larger global scale.
Regional players
- Internet Initiative Japan (IIJ) - Security Business: Japanese IT and network services provider with a substantial managed security services business including vulnerability assessment and SOC, competing with GMO Cybersecurity primarily in the Japan domestic market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Cocon social profiles
Digital presenceCocon financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cocon leadership team
Management profileNumber of profiles
Profiles3 records
Cocon funding detail
Funding detailFunding overview
Funding rounds6 records
Investors17 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cocon M&A and investment
M&A and investmentM&A7 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cocon
What does Cocon do?
Cocon, through its GMO Cybersecurity by Ierae subsidiary, provides enterprise cybersecurity services and software including vulnerability diagnosis, penetration testing, Attack Surface Management (ASM) tooling, managed Security Operation Center (SOC) services, WAF management, incident response and digital forensics, and specialized AI/LLM security assessments. The company leverages over 200 white hat hackers and a proprietary ASM platform to deliver recurring and project-based engagements to enterprise, financial, government and technology customers, primarily in Japan.
Is Cocon a public or private company?
Cocon is a private company. It is classified as venture growth investor backed and is currently operating.
When was Cocon founded?
Cocon was founded in 2013. It employs 51 to 100 people.
Where is Cocon based?
Cocon is headquartered in Tokyo, Japan, in the Asia region.
How does Cocon make money?
Five revenue lines are on record. Vulnerability Assessment & Penetration Testing Services are the primary driver. The others are SOC and Security Operations Services, ASM Tool Subscription, security Training and Certification and incident Response & Digital Forensics.
Who are Cocon's main competitors?
Direct peers on record are LAC Co., Ltd., NRI Secure Technologies, Rapid7, NCC Group, SecureWorks and bishopfox. Broad incumbents are NTT Security (Japan), Trend Micro (Japan) and Mandiant (Google Cloud). Internet Initiative Japan (IIJ) - Security Business is listed as a regional player.
Does Cocon have an API?
No public API is recorded for Cocon.
What industry is Cocon in?
Cocon's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services. Its NAICS code is 54151 and its SIC code is 8700.