SecurityStudio
SecurityStudio is a Minnesota-based SaaS company offering cybersecurity risk management software—S2Org, S2Vendor, S2Team, S2Partner, S2PCI—and the proprietary S2Score 300-850 scoring methodology, serving public sector, education, critical infrastructure, commercial, and managed service provider clients.
- Company typePrivate
- Founded2017
- HeadquartersMinnetonka, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What SecurityStudio does
SecurityStudio is a SaaS cybersecurity risk management company founded in 2017 and headquartered in Edina, Minnesota. It sells a six-product platform—S2Org for organizational risk assessments, S2Vendor for third-party vendor risk management, S2Team for measuring employee security knowledge gaps, S2Partner as an MSP client dashboard, S2PCI for PCI DSS compliance support in Levels 2-4, and the proprietary S2Score, a 300-850 cyber risk scoring methodology modeled on a consumer credit score. The platform is targeted at state and local government, commercial enterprises, K-12, higher education, critical infrastructure operators, and managed service providers; software pricing is quote-based and not publicly disclosed. The firm also operates the SecurityStudio Academy, which sells the multi-tier Certified Virtual Chief Information Security Officer (CvCISO) program, the Certified SecurityStudio Risk Assessor (CSSRA) course, and a TeejLab-co-developed API security course at publicly listed prices ranging from $800 to $6,000.
The business operates a hybrid go-to-market that combines product-led growth—free demo access through the website and self-service risk evaluation—with a channel-partner ecosystem spanning Managed Service Providers, Managed Cloud Service Providers, and Area Education Agencies. Revenue is generated primarily through recurring software subscriptions, Academy course and certification revenue, and partner portal access. The company is founder-led by Evan Francen (CEO) and Kevin Orth (CTO), has completed only one disclosed capital raise (a $300,000 exempt securities offering in June 2021), and has no public revenue disclosure, no M&A history, and no institutional investor footprint beyond that initial round. Named customers include Land O'Lakes, Loffler, Central Unit School District, PCA Technology Group, Noftek, and MnCCC.
SecurityStudio firmographics
Firmographics- Name
- SecurityStudio
- Legal name
- SecurityStudio Inc.
- Website
- https://securitystudio.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SecurityStudio is a Minnesota-based SaaS company offering cybersecurity risk management software—S2Org, S2Vendor, S2Team, S2Partner, S2PCI—and the proprietary S2Score 300-850 scoring methodology, serving public sector, education, critical infrastructure, commercial, and managed service provider clients.
- Ownership category
- akta.pro rank
SecurityStudio industry classification
Industry- Product category
- Cybersecurity risk management software
- NAICS
- Software Publishers (5132), Custom Computer Programming Services (541511)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Security Awareness, Training & Compliance Attestation (HDADAIAJ)
- akta.pro secondary industries
- Compliance, Risk & Audit Management (SOC 2/ISO/PCI) (HDABANAK), Cybersecurity (General) (EDAOAIAB)
Keywords
Where SecurityStudio is headquartered
LocationHeadquarters
- HQ city
- Minnetonka
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
SecurityStudio business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Software Platform Subscription: Annual subscription access to SecurityStudio's risk management platform including S2Org, S2Vendor, S2Team, S2Partner, S2PCI, and S2Score tools. Pricing is likely tiered based on organization size or assessment volume.
- Training and Certification Programs: Revenue from SecurityStudio Academy courses including CvCISO certification program, CSSRA certification, and individual courses. Programs include Foundations, Level 3 specializations (Budgeting, Communications, Complex Environments), and subscription-based access to materials.
- Partner Portal Access: Partners (MSPs, MCSPs, AEAs) likely pay for access to manage multiple client accounts through the partner portal.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | CvCISO Complete Program Bundle - Full certification pathway |
| Subscription | Annual | CvCISO Level 3 Course Bundle - Advanced specialization |
| One time/ perpetual license | Pay-as-you-go | Individual Level 3 Courses |
| Subscription | Annual | CSSRA Certification Course |
| Subscription | Pay-as-you-go | TeejLab API Security Course |
| Subscription | Multi-year contract | CvCISO Foundations Course |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels9 records
SecurityStudio product offering
Product offeringCore offering
SecurityStudio sells a cloud-based cybersecurity risk management platform that lets organizations quantify their security posture using the proprietary S2Score (300-850 scale) and run risk assessments across operations, vendors, employees, partners, and PCI DSS compliance. The company also monetizes SecurityStudio Academy, which delivers the multi-level CvCISO certification program, the CSSRA risk assessor credential, and specialized courses such as API security.
Product overview
SecurityStudio is a cybersecurity risk management software company offering a platform-based product portfolio. The core offering consists of six software products: S2Org (organizational risk assessment), S2Vendor (third-party vendor risk management), S2Team (employee security knowledge assessment), S2Partner (MSP client management dashboard), S2PCI (PCI DSS compliance tool for Levels 2-4), and S2Score (cyber risk scoring methodology, 300-850 range). Additionally, the company offers SecurityStudio Academy, which provides the CvCISO (Certified Virtual Chief Information Security Officer) training and certification program with multiple courses including Foundations, Level 3 bundles (Budgeting, Communications, Complex Environments), CSSRA certification, and API Security training in partnership with TeejLab. The platform enables decision-makers in public sector, business leaders, and managed service providers to identify threats and make risk-informed decisions.
Differentiator
Problem solved
Functional benefit
Brands
- S2Score: Cyber risk scoring methodology ranging from 300-850, similar to a credit score, for objectively measuring cyber risk.
- S2Org
- S2Vendor
- S2Team
- S2Partner
- S2PCI
- CvCISO Academy
- CvCISO CommUnity
Products and services
- S2Org Organizational information security risk assessment tool that establishes a quantifiable baseline for security posture and prioritizes remediation. Used by thousands of public and private organizations.
- S2Vendor Third-party vendor risk management tool that simplifies, automates, and standardizes vendor security assessments.
- S2Team Aggregates employee information security knowledge gaps across an organization to inform and direct employee security training.
- S2Partner Dashboard for managed service providers to manage client modules and users, enabling delivery of assessments across multiple client accounts.
- S2PCI PCI compliance software that identifies correct Self-Assessment Questionnaire (SAQ) forms and streamlines PCI DSS compliance documentation for Levels 2-4 organizations.
- S2Score Proprietary cyber risk scoring methodology ranging from 300-850, similar to a credit score, enabling organizations to objectively measure and track cyber risk over time.
- CvCISO Program Certified Virtual Chief Information Security Officer (CvCISO) training and certification program with four designation levels, designed to establish industry standards for vCISO quality.
- CSSRA (Certified SecurityStudio Risk Assessor) Hands-on certification course (10 modules, 24 hours) that teaches a repeatable, scalable standard for conducting objective, defensible risk assessments using the S2Org platform.
- CvCISO Foundations Course Introductory cohort course (10 weeks, 60 classroom hours plus practical assignments) covering the fundamentals of the vCISO role; upon passing, graduates attain CvCISO Level 1 or Level 2 certification.
- CvCISO Complete Program Course Bundle Complete CvCISO certification pathway bundling the Foundations Course plus all Level 3 courses (Budgeting, Communications, Complex Environments) with 2-year access to materials, mentorship, and community.
- CvCISO Level 3 Course Bundle Bundle covering CvCISO-B (Budgeting), CvCISO-C (Communications), and CvCISO-E (Complex Environments) advanced specialization courses with 12 months of access.
- Information Security Budget Justification Course (CvCISO-B) Advanced course teaching cybersecurity leaders to build, defend, and communicate effective security budgets aligned to business objectives.
- Information Security Communications Course (CvCISO-C) Advanced course strengthening communication skills for cybersecurity leaders to convey complex security concepts to executives, boards, and non-technical stakeholders.
- Information Security in Complex Environments Course (CvCISO-E) Advanced course giving information security leaders a structured methodology to secure complex environments such as state-level or global enterprises.
- TeejLab API Security and Governance Foundations Course Self-paced 12-hour course developed in partnership with TeejLab providing hands-on experience with API discovery, security frameworks, legal considerations, and API governance practices; awards a certificate and 12 CPE credits.
Quantifiable outcome
- Organizations can establish a quantifiable baseline for their security posture to enable tracking over time
- +1 more outcomes
Companies that use SecurityStudio
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles6 records
SecurityStudio technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
SecurityStudio partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- TeejLabcoreTeejLab collaborated with SecurityStudio Academy to develop the API Security and Governance Foundations Course. This self-paced 12-hour course provides hands-on experience with the TeejLab API Discovery platform and covers API evolution, security frameworks, legal considerations, and governance practices. Upon completion, participants earn a certificate and 12 CPE credits.
- PCI Security Standards CouncilcoreSecurityStudio aligns S2PCI product with PCI DSS standards. The company recommends the PCI Security Standards Council's PCI Awareness Training for individuals wanting to enhance their understanding of PCI compliance.
Scale indicators1 record
Recent moves5 records
Expansion highlights4 records
SecurityStudio competitors and assessment
Company assessmentBroad incumbents
- RSA Archer: RSA Archer is an established enterprise GRC platform offering broad risk, compliance, and incident management capabilities. It is a broader incumbent in the same GRC category where SecurityStudio operates, though focused on larger enterprises.
- ServiceNow GRC: ServiceNow's integrated GRC module is part of a broader enterprise workflow platform addressing risk, compliance, and audit management. It is a broad incumbent in the same GRC category where SecurityStudio competes, particularly for enterprise customers.
- OneTrust: OneTrust is a large trust intelligence platform covering privacy, security, GRC, and ethics programs. It competes with SecurityStudio in vendor risk and compliance attestation, though as a much broader platform with overlapping modules.
Direct peers
- Drata: Drata is a compliance automation and security posture management platform that streamlines SOC 2, ISO 27001, HIPAA, and PCI DSS audits. It competes head-to-head with SecurityStudio's assessment-based GRC approach, particularly in the SMB and startup segments.
- Hyperproof: Hyperproof is a SaaS compliance and risk management platform for SOC 2, ISO 27001, FedRAMP, and other frameworks. It directly competes with SecurityStudio's assessment-driven compliance approach for mid-market and regulated customers.
- Secureframe: Secureframe provides automated compliance management for SOC 2, ISO 27001, HIPAA, PCI, and other frameworks with continuous monitoring. It overlaps directly with SecurityStudio's S2Org, S2Vendor, and S2PCI offerings for SMB and mid-market customers.
- Cynomi: Cynomi is a vCISO enablement platform designed for MSPs to deliver cybersecurity services to SMB clients. It overlaps with SecurityStudio's S2Partner and CvCISO Academy positioning as an MSP-focused cybersecurity/risk platform.
- Vanta: Vanta is a leading compliance automation platform offering SOC 2, ISO 27001, HIPAA, and continuous monitoring for organizations. It directly competes with SecurityStudio in the automated security/compliance assessment category, including trust reports and vendor risk management.
- LogicGate: LogicGate offers a no-code GRC platform for risk, compliance, and security program management. It is comparable to SecurityStudio's risk assessment and compliance tracking functionality, especially for organizations seeking customizable risk workflows.
- AuditBoard: AuditBoard is a cloud-based GRC platform for audit, risk, and compliance management used by enterprises. It overlaps with SecurityStudio's organizational risk assessment and compliance documentation workflows, particularly in mid-market and enterprise segments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
SecurityStudio social profiles
Digital presenceSecurityStudio financial estimates
Financial estimateRevenue estimate
Valuation estimate
SecurityStudio leadership team
Management profileNumber of profiles
Profiles2 records
SecurityStudio funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SecurityStudio M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SecurityStudio
What does SecurityStudio do?
SecurityStudio sells a cloud-based cybersecurity risk management platform that lets organizations quantify their security posture using the proprietary S2Score (300-850 scale) and run risk assessments across operations, vendors, employees, partners, and PCI DSS compliance. The company also monetizes SecurityStudio Academy, which delivers the multi-level CvCISO certification program, the CSSRA risk assessor credential, and specialized courses such as API security.
Is SecurityStudio a public or private company?
SecurityStudio is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SecurityStudio founded?
SecurityStudio was founded in 2017. It employs 11 to 50 people.
Where is SecurityStudio based?
SecurityStudio is headquartered in Minnetonka, United States, in the North America region.
How does SecurityStudio make money?
Three revenue lines are on record. Software Platform Subscription is the primary driver. The others are training and Certification Programs and partner Portal Access.
Who are SecurityStudio's main competitors?
Broad incumbents on record are RSA Archer, ServiceNow GRC and OneTrust. Direct peers are Drata, Hyperproof, Secureframe, Cynomi, Vanta, LogicGate and AuditBoard.
Does SecurityStudio have an API?
No public API is recorded for SecurityStudio.
What industry is SecurityStudio in?
SecurityStudio's product category is Cybersecurity risk management software. Its primary akta.pro industry code is HDADAIAJ, Security Awareness, Training & Compliance Attestation, with a secondary code of HDABANAK, Compliance, Risk & Audit Management (SOC 2/ISO/PCI). Its NAICS code is 5132 and its SIC code is 7371.