RISCPoint
RISCPoint is a Cleveland-based cybersecurity and compliance consulting firm serving U.S. government agencies, defense contractors, healthcare organizations, and SaaS companies with FedRAMP, CMMC, SOC 2, HITRUST, and HIPAA advisory services, supported by an AI-powered RADAR Security platform.
- Company typePrivate
- Founded2018
- HeadquartersCleveland, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What RISCPoint does
RISCPoint is a Cleveland, Ohio-based cybersecurity and compliance consulting firm founded in 2018, serving U.S. federal, state, and local government agencies, defense industrial base contractors, healthcare organizations, and technology/SaaS companies. The firm provides advisory, assessment, implementation, and continuous monitoring services across a broad range of regulatory frameworks including FedRAMP, StateRAMP/GovRAMP, CMMC, FISMA, TX-RAMP, HITRUST, SOC 2, ISO 27001, HIPAA, GDPR, and SEC Regulation S-K Item 106. RISCPoint is accredited as a FedRAMP and StateRAMP Third Party Assessment Organization (3PAO) and holds CMMC Registered Provider Organization (RPO) status, enabling it to independently assess organizations for federal and state authorization.
The firm's core technology is RADAR Security, an AI-powered platform launched in 2024 that combines real-time vulnerability detection with expert-led penetration testing as a service. Beyond RADAR, RISCPoint's delivery model is built around subject matter experts using a proprietary five-stage methodology (Identify-Understand-Design-Optimize-Sustain) and a Virtual Executive Team offering (vCISO, vISSO, vCTO) for ongoing fractional security leadership. The company also maintains technology integrations with AWS (Advanced Tier Partner as of November 2024), CrowdStrike, Datadog, and Vanta.
RISCPoint operates a project-based professional services model with multi-year contracts and quote-based pricing. Revenue is generated through three primary streams: compliance consulting engagements, cybersecurity advisory (penetration testing, red teaming, vulnerability assessments), and managed virtual executive services. The go-to-market is sales-led and event-driven, leveraging content marketing (whitepapers, webinars), industry conference participation (Black Hat, DEFCON), and AWS Marketplace distribution. The firm is privately held with no disclosed funding rounds and leadership centered around founder Jake Nix, CEO Matt Drewyor, Chief Solutions Officer Tony Bai, and EVP of Compliance Services Chad Gross.
RISCPoint firmographics
Firmographics- Name
- RISCPoint
- Legal name
- RISCPoint
- Website
- https://riscpoint.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- RISCPoint is a Cleveland-based cybersecurity and compliance consulting firm serving U.S. government agencies, defense contractors, healthcare organizations, and SaaS companies with FedRAMP, CMMC, SOC 2, HITRUST, and HIPAA advisory services, supported by an AI-powered RADAR Security platform.
- Ownership category
- akta.pro rank
RISCPoint industry classification
Industry- Product category
- Cybersecurity & Compliance Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Other Computer Related Services (541519), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Managed Security Services (MSSP) & 24/7 SOC Operations (BPAKAHAA)
- akta.pro secondary industries
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI), Data Security & Privacy Managed Services (DLP/Encryption) (BPAEADAL), Threat Intelligence Services (BPAEADAC)
Keywords
Where RISCPoint is headquartered
LocationHeadquarters
- HQ city
- Cleveland
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
RISCPoint business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Compliance Consulting Services: Professional services revenue generated through consulting engagements for compliance frameworks including FedRAMP, StateRAMP, CMMC, SOC 2, ISO 27001, HITRUST, HIPAA, and others. Services include assessments, implementation support, audit facilitation, and continuous monitoring.
- Cybersecurity Advisory Services: Revenue from penetration testing, red teaming, social engineering, application security, vulnerability assessments, and security engineering services
- Virtual Executive Services: On-demand virtual CISO, ISSO, and CTO services providing executive-level cybersecurity leadership to client organizations
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom Professional Services |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
RISCPoint product offering
Product offeringCore offering
RISCPoint provides cybersecurity and compliance consulting services to government entities and private organizations, covering frameworks such as FedRAMP, StateRAMP/GovRAMP, CMMC, FISMA, TX-RAMP, SOC 2, ISO 27001, HITRUST, HIPAA, NIST CSF, and WCAG/Section 508. The firm also delivers cybersecurity services including penetration testing, red teaming, vulnerability assessments, and security engineering, along with virtual executive team services (vCISO, vISSO, vCTO). Their proprietary RADAR Security platform provides AI-powered continuous threat discovery and penetration testing as a service.
Product overview
RISCPoint offers a comprehensive suite of cybersecurity and compliance consulting services, anchored by Radar Security, an AI-powered platform for continuous threat discovery and penetration testing. The broader portfolio includes specialized service lines for Public Sector (FedRAMP, GovRAMP, CMMC, FISMA, TX-RAMP), Cybersecurity (Penetration Testing, Red Teaming, Vulnerability Assessments), Cloud (AWS, Azure, GCP), Compliance (SOC, ISO, HITRUST, NIST CSF, WCAG), Risk Management (Risk Assessments, Third-Party Risk, vCISO/vISSO/vCTO Virtual Executive Team), and Privacy (HIPAA, CCPA, GDPR). The offering includes both direct consulting services and a proprietary AI-powered technology platform (Radar Security) for automated threat detection.
Differentiator
Problem solved
Functional benefit
Brands
- Radar Security: AI-powered platform combining real-time vulnerability detection and expert-led penetration testing, marketed as continuous threat discovery and penetration testing as a service.
Products and services
- RADAR Security AI-powered continuous threat discovery and penetration testing as a service platform that combines real-time vulnerability detection with expert-led penetration testing services for enterprise and government clients.
- Public Sector Services Compliance and security services for government entities covering FedRAMP, DOD IL4-IL6, GovRAMP/StateRAMP, TX-RAMP, CMMC (NIST 800-171 & 172), and FISMA (NIST RMF) standards.
- Cybersecurity Services Protection services including Penetration Testing, Red Teaming, Social Engineering, Application Security, Vulnerability Assessments, and Security Engineering for enterprise and government clients.
- Cloud Services Secure cloud solutions for AWS, Azure, and GCP environments including AWS Well-Architected Review, AWS GovCloud, Azure Government, and Google Cloud Platform security services.
- Compliance Services Compliance frameworks including SOC, ISO (27001, 27017, 27018), HITRUST, NIST CSF, and WCAG/Section 508, supported by the Virtual Compliance Team offering.
- Risk Management Services Risk mitigation services including Risk Assessments, HIPAA Business Associate Governance, Third-Party Risk Management, Plan Simulations (BC/DR, Incident Response), SEC Regulations Risk Management, and Virtual Executive Team (vCISO, vISSO, vCTO).
- Privacy Services Data protection and compliance services covering HIPAA (NIST 800-66), CCPA & CPRA, and GDPR regulations for organizations handling personal and patient data.
Quantifiable outcome
- Successfully guided organizations through FedRAMP, HITRUST, and other major compliance certifications
- +1 more outcomes
Companies that use RISCPoint
Customer profileNamed customers2 records
Segments5 records
Ideal customer profiles4 records
RISCPoint technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
RISCPoint partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Amazon Web Services (AWS)coreRISCPoint is an AWS Partner Network member achieving Advanced Tier Services Partner status in November 2024. They offer AWS Well-Architected Reviews, security assessments for AWS GovCloud, and compliance services for AWS environments. Their partnership enables them to serve AWS customers requiring FedRAMP and other security certifications.
- anecdotescoreStrategic partnership announced April 4, 2024 to offer enterprise-grade cybersecurity and compliance management solutions tailored for startups and SMBs. The collaboration leverages data-driven approaches and RISCPoint's expertise to enable rapid adoption of compliance frameworks and build trust-based security programs.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
RISCPoint competitors and assessment
Company assessmentEmerging players
- Drata: Drata is a compliance automation platform that automates SOC 2, ISO 27001, HIPAA, and other framework audits. It is an emerging competitor to the compliance advisory portion of RISCPoint's business, particularly for SaaS and technology clients seeking faster, lower-cost certification.
- Vanta: Vanta is a leading compliance automation platform that streamlines SOC 2, ISO 27001, and HIPAA evidence collection. While RISCPoint lists Vanta as a technology partner, Vanta also competes with RISCPoint's compliance advisory services by reducing the manual hours clients need from firms like RISCPoint.
- Secureframe: Secureframe is a compliance automation platform for SOC 2, ISO 27001, HIPAA, and PCI DSS, with managed services layered on top. It overlaps with RISCPoint's compliance practice and represents an emerging, technology-enabled alternative to traditional consulting engagements.
Broad incumbents
- Optiv Security: Optiv is a large, established cybersecurity services integrator offering advisory, managed security, and risk services across federal and commercial clients. It overlaps broadly with RISCPoint's cybersecurity and compliance offerings but operates at much larger scale and with a wider portfolio.
Direct peers
- A-LIGN: A-LIGN is a cybersecurity and compliance audit and advisory firm offering SOC 2, ISO 27001, HITRUST, FedRAMP, and penetration testing services. It is a direct peer given its comparable mix of compliance audits, cybersecurity testing, and federal authorization support, and notably counts RISCPoint's EVP of Compliance, Chad Gross, as a former senior leader.
- Coalfire: Coalfire is one of the largest FedRAMP 3PAOs and a major cybersecurity advisory firm covering cloud compliance, penetration testing, and risk management. It is a direct peer to RISCPoint, particularly in the federal and cloud service provider compliance space where both firms compete for 3PAO engagements.
- KirkpatrickPrice: KirkpatrickPrice is a cybersecurity and compliance audit firm providing SOC, ISO, HITRUST, and PCI audits along with penetration testing. It is a direct peer in the mid-market compliance advisory segment that RISCPoint serves.
- Linford & Co: Linford & Co is a smaller, similarly sized cybersecurity and compliance audit firm offering SOC 2, ISO 27001, HITRUST, and penetration testing. It is a direct peer given comparable headcount range and service mix targeting SaaS and regulated technology clients.
- BARR Advisory: BARR Advisory is a cybersecurity and compliance consulting firm delivering SOC 2, ISO 27001, HITRUST, HIPAA, and FedRAMP services to SaaS and technology companies. It competes with RISCPoint in the same mid-market compliance and cybersecurity advisory segment.
- Schellman & Co. Schellman is a top-tier cybersecurity assessment firm providing SOC 2, ISO 27001, HITRUST, FedRAMP, PCI, and penetration testing services. It directly competes with RISCPoint across the same frameworks, with similar focus on regulated industries and recurring compliance engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
RISCPoint social profiles
Digital presenceRISCPoint compliance and trust
Trust signalCompliance3 records
RISCPoint financial estimates
Financial estimateRevenue estimate
Valuation estimate
RISCPoint leadership team
Management profileNumber of profiles
Profiles4 records
RISCPoint funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RISCPoint M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RISCPoint
What does RISCPoint do?
RISCPoint provides cybersecurity and compliance consulting services to government entities and private organizations, covering frameworks such as FedRAMP, StateRAMP/GovRAMP, CMMC, FISMA, TX-RAMP, SOC 2, ISO 27001, HITRUST, HIPAA, NIST CSF, and WCAG/Section 508. The firm also delivers cybersecurity services including penetration testing, red teaming, vulnerability assessments, and security engineering, along with virtual executive team services (vCISO, vISSO, vCTO). Their proprietary RADAR Security platform provides AI-powered continuous threat discovery and penetration testing as a service.
Is RISCPoint a public or private company?
RISCPoint is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RISCPoint founded?
RISCPoint was founded in 2018. It employs 11 to 50 people.
Where is RISCPoint based?
RISCPoint is headquartered in Cleveland, United States, in the North America region.
How does RISCPoint make money?
Three revenue lines are on record. Compliance Consulting Services are the primary driver. The others are cybersecurity Advisory Services and virtual Executive Services.
Who are RISCPoint's main competitors?
Emerging players on record are Drata, Vanta and Secureframe. Optiv Security is listed as a broad incumbent. Direct peers are A-LIGN, Coalfire, KirkpatrickPrice, Linford & Co, BARR Advisory and Schellman & Co..
Does RISCPoint have an API?
No public API is recorded for RISCPoint.
What industry is RISCPoint in?
RISCPoint's product category is Cybersecurity & Compliance Consulting. Its primary akta.pro industry code is BPAKAHAA, Managed Security Services (MSSP) & 24/7 SOC Operations, with a secondary code of BPAEADAI, Security Incident Response (IR) & Digital Forensics Services. Its NAICS code is 54151 and its SIC code is 7371.