NuHarbor Security
NuHarbor Security is a US-based managed cybersecurity services firm serving 500+ organizations across state and local government, higher education, healthcare, and finance. It delivers SOC-as-a-Service, MDR, security testing, and compliance advisory by combining expert analysts with integrated CrowdStrike, Microsoft, Splunk, and Tenable platforms.
- Company typePrivate
- Founded2014
- HeadquartersEssex Junction, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What NuHarbor Security does
NuHarbor Security is a privately held, US-based cybersecurity services firm founded in 2014 and headquartered in Colchester, Vermont, with 101-250 employees and a stated base of 500+ customer organizations. The company delivers end-to-end managed and advisory cybersecurity services organized around four pillars: Security Testing (penetration testing, vulnerability scanning), Assessment and Compliance (NIST 800-53, HIPAA, ISO 27001, PCI, CJIS, MARS-E, ARC-AMPE, 23 NYCRR 500), Advisory and Planning (virtual CISO, security strategy, incident response planning), and Managed Services (SOC-as-a-Service, MDR, vulnerability management, threat intelligence).
The firm's core technical architecture is not a proprietary product platform but rather an integration layer that combines expert human analysts with best-of-breed security technologies from CrowdStrike, Microsoft, Splunk, and Tenable. This is operationalized through vendor-branded managed offerings (CrowdStrike MDR, Microsoft Security Managed Services, Splunk Managed Services, Tenable Managed Services) plus a SOC-as-a-Service that runs 24/7 monitoring and incident response on top of those platforms. NuHarbor also produces proprietary thought-leadership IP, notably the annual SLED Cybersecurity Priorities Report and the Pwned podcast, which function as both demand-generation and sector positioning assets in the State, Local, and Education vertical.
Revenue is generated through two primary streams: recurring subscription-style managed security services (SOC-as-a-Service, MDR, vulnerability management) and professional services for testing, compliance assessments, and advisory work. The go-to-market combines direct consultative enterprise sales (with "Consult with an expert" CTAs and quote-based pricing) with emerging channel partnerships, including resellers Right! Systems and WEI and a statewide security operations mandate with the Georgia Technology Authority. Primary customer verticals are State and Local Government, Higher Education, Healthcare, and Finance, with Federal and Insurance as secondary segments. The company is founder-led by CEO Justin Fimlaid, a former Global CISO at Keurig Green Mountain Coffee, with Jack Danahy as VP of Strategy and Innovation and Rupal Patel as CFO; no external funding rounds are disclosed, indicating either bootstrapped or self-sustaining growth.
NuHarbor Security firmographics
Firmographics- Name
- NuHarbor Security
- Legal name
- NuHarbor Security
- Website
- https://nuharborsecurity.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- NuHarbor Security is a US-based managed cybersecurity services firm serving 500+ organizations across state and local government, higher education, healthcare, and finance. It delivers SOC-as-a-Service, MDR, security testing, and compliance advisory by combining expert analysts with integrated CrowdStrike, Microsoft, Splunk, and Tenable platforms.
- Ownership category
- akta.pro rank
NuHarbor Security industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
Keywords
Where NuHarbor Security is headquartered
LocationHeadquarters
- HQ city
- Essex Junction
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
NuHarbor Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Security Services: Recurring managed security services including SOC as a Service, MDR, and vulnerability management. Delivered through integrations with CrowdStrike, Microsoft, Splunk, and Tenable platforms.
- Security Testing Services: One-time and periodic penetration testing, vulnerability scanning, and security assessments across infrastructure, applications, and wireless networks.
- Compliance and Advisory Services: Assessment and advisory services for regulatory compliance including ARC-AMPE, CJIS, NIST 800-53, HIPAA, ISO 27001, MARS-E, NY Cybersecurity, and PCI standards. Also includes virtual CISO and security strategy services.
Go-to-market motion2 records
Distribution channels2 records
Marketing channels8 records
NuHarbor Security product offering
Product offeringCore offering
NuHarbor Security is an end-to-end cybersecurity services company that delivers managed security services, security testing, assessment and compliance, and advisory and planning services to public-sector and commercial organizations. Service delivery combines thoroughly vetted security analysts with deep integrations into best-of-breed security platforms (CrowdStrike, Microsoft Security, Splunk, and Tenable) to provide 24/7 SOC monitoring, managed detection and response, penetration testing, vulnerability management, and regulatory compliance support across verticals such as SLED, healthcare, finance, insurance, and federal.
Product overview
NuHarbor Security offers a comprehensive cybersecurity services portfolio built around four core pillars: Security Testing (penetration testing, vulnerability scanning), Assessment & Compliance (NIST 800-53, HIPAA, ISO 27001, PCI, CJIS, MARS-E, ARC-AMPE, 23 NYCRR 500), Advisory & Planning (virtual CISO, incident response, security strategy), and Managed Services. The managed services layer integrates with best-of-breed technology platforms including CrowdStrike, Microsoft (Sentinel/Defender/Purview), Splunk, and Tenable to deliver SOC as a Service, MDR, and specialized monitoring. Services are offered both as standalone offerings and as integrated solutions, with technology partnerships enabling managed services on client-preferred platforms.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC as a Service 24/7 security operations center monitoring with continuous monitoring, high-fidelity alerting, real-time investigation, and actionable threat intelligence designed to minimize time to detect attacks or vulnerabilities. Delivered to organizations that need outsourced security operations.
- Security Testing Services Penetration testing and vulnerability scanning services including infrastructure, application, wireless, internal, and external penetration testing, using tools and techniques employed by real threat actors to identify critical vulnerabilities and provide remediation guidance and retesting.
- Assessment & Compliance Services Compliance assessment services covering ARC-AMPE, CJIS, NIST 800-53, HIPAA Security Standards, ISO 27001, MARS-E Security Standards, New York Cybersecurity (23 NYCRR 500), and PCI compliance, helping organizations meet regulatory and standards-based requirements.
- Advisory & Planning Services Strategic security advisory including Security Strategy, Incident Response Planning, Security Program Reviews, Security Risk Assessments, Virtual CISO, and Policy Review services, supporting clients in building and maturing cybersecurity programs.
- Microsoft Security Managed Services Managed services across the Microsoft Security ecosystem, managing Sentinel, Defender, Purview, and more to achieve stronger detection, compliance, and protection for organizations standardized on Microsoft.
- Splunk Managed Services Managed services for the Splunk platform, providing security monitoring and enabling clients to build or operate an in-house security operations center while leveraging Splunk for analytics.
- Tenable Managed Services Managed vulnerability management services built on Tenable, including scan schedule setup, policy management, asset coverage assurance, and timely vulnerability risk mitigation advice.
- CrowdStrike Managed Detection and Response (MDR) Managed detection and response combining CrowdStrike technology with NuHarbor's human expertise to perform threat hunting, monitoring, and response for organizations standardized on CrowdStrike.
- Vendor Security Assessments Third-party vendor security assessments that identify security risk exposure and establish accountability for business partnerships, supporting third-party and supply-chain risk management.
- Curated Threat Intelligence Relevant, up-to-date threat intelligence fed into client systems and/or prepared as threat briefings on client terms, supporting proactive threat awareness and defense.
- Vulnerability Management Ongoing vulnerability management including scan schedules, policy management, asset coverage, and timely advice to mitigate vulnerability risk for organizations needing continuous exposure reduction.
Quantifiable outcome
- Organizations report customized dashboards and regular updates that keep them informed and empowered to make smarter security decisions
- +2 more outcomes
Companies that use NuHarbor Security
Customer profileNamed customers1 record
Segments6 records
Ideal customer profiles3 records
NuHarbor Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
Feature3 records
NuHarbor Security partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core.
- Right! Systems, Inc.coreStrategic partnership enabling Right! Systems to resell NuHarbor's managed detection and response and security operations capabilities. The agreement integrates security services into Right! Systems' existing infrastructure, cloud, and networking offerings, allowing customers to access IT and security services through a single partner relationship. The collaboration combines Right! Systems' 30+ years of IT infrastructure expertise with NuHarbor's security capabilities.
- WEIcorePartnership to expand cybersecurity services for organizations requiring operational support beyond technology deployment. The collaboration combines WEI's security architecture and implementation expertise with NuHarbor's managed security services including 24/7 SOC monitoring, managed detection and response, threat hunting, and incident response capabilities. Targets high-risk sectors including government, education, healthcare, and critical infrastructure.
- Georgia Technology AuthoritycoreStatewide security operations partnership to support security across Georgia Executive Branch agencies. NuHarbor provides enterprise-grade security services to strengthen visibility, coordination, and resilience across the state's agencies, protecting critical public services including taxation, licensing, and regulation that residents rely on daily.
- CrowdStrikecoreStrategic technology partner for endpoint security and managed detection and response services. NuHarbor combines CrowdStrike technology with human expertise for threat hunting, monitoring, and response capabilities.
- MicrosoftcoreStrategic technology partner providing security analytics and SIEM capabilities. NuHarbor offers Microsoft Security Managed Services, managing Sentinel, Defender, Purview, and more to drive stronger detection, compliance, and protection.
- SplunkcoreStrategic technology partner for security analytics and SIEM. NuHarbor provides Splunk Managed Services and security monitoring leveraging the Splunk platform, helping organizations build in-house security operations centers.
- TenablecoreStrategic technology partner for vulnerability management. NuHarbor offers Tenable Managed Services including scan schedule setup, policy management, asset coverage assurance, and vulnerability risk mitigation advice.
Scale indicators1 record
Recent moves5 records
Expansion highlights5 records
NuHarbor Security competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Global cybersecurity company offering managed security services, MDR, penetration testing, and compliance advisory. Comparable service breadth to NuHarbor but with significantly larger headcount and international presence.
- CrowdStrike: Endpoint security platform vendor with Falcon Complete native MDR service. While a NuHarbor technology partner, CrowdStrike's growing in-house MDR offering directly competes with NuHarbor's CrowdStrike MDR managed service layer.
- Secureworks: Large, established MSSP/MDR provider (now part of DXC Technology) offering Taegis XDR and a broad managed security portfolio. Overlaps significantly with NuHarbor's SOC and MDR capabilities but operates at much larger scale with broader geographic reach.
Direct peers
- Pondurance: MDR and digital forensics provider with strong focus on mid-market, healthcare, financial services, and public sector. Closely comparable to NuHarbor's SLED/healthcare/finance vertical specialization and managed services model.
- ReliaQuest: Enterprise-focused SOC platform and MDR provider using automation and GreyMatter to deliver detection, response, and threat intelligence. Comparable to NuHarbor's SOC-as-a-Service and MDR offerings but skewing toward larger enterprise customers.
- Expel: Managed detection and response provider offering transparent, tech-enabled SOC services across cloud, endpoint, network, and SaaS. Highly comparable to NuHarbor's MDR and SOC-as-a-Service portfolio and mid-market/enterprise go-to-market.
- eSentire: Pure-play MDR provider serving mid-market organizations across financial services, healthcare, and public sector. Comparable to NuHarbor in managed detection and response delivery and regulatory compliance focus.
- GuidePoint Security: Cybersecurity services and solutions provider offering professional services, managed security, and risk advisory across government and commercial markets. Comparable to NuHarbor's compliance, advisory, and managed services stack with similar vertical breadth.
- Arctic Wolf Networks: Leading MDR/SOC-as-a-Service provider delivering 24/7 threat detection and response across mid-market and enterprise. Directly comparable to NuHarbor's core SOC-as-a-Service and MDR offerings, with similar reliance on best-of-breed technology integrations.
- Avertium: MSSP providing managed detection, response, and compliance services with deep mid-market and regulated-industry focus. Comparable to NuHarbor's managed services plus compliance and advisory service mix.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
NuHarbor Security social profiles
Digital presenceNuHarbor Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
NuHarbor Security leadership team
Management profileNumber of profiles
Profiles2 records
NuHarbor Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NuHarbor Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NuHarbor Security
What does NuHarbor Security do?
NuHarbor Security is an end-to-end cybersecurity services company that delivers managed security services, security testing, assessment and compliance, and advisory and planning services to public-sector and commercial organizations. Service delivery combines thoroughly vetted security analysts with deep integrations into best-of-breed security platforms (CrowdStrike, Microsoft Security, Splunk, and Tenable) to provide 24/7 SOC monitoring, managed detection and response, penetration testing, vulnerability management, and regulatory compliance support across verticals such as SLED, healthcare, finance, insurance, and federal.
Is NuHarbor Security a public or private company?
NuHarbor Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was NuHarbor Security founded?
NuHarbor Security was founded in 2014. It employs 101 to 250 people.
Where is NuHarbor Security based?
NuHarbor Security is headquartered in Essex Junction, United States, in the North America region.
How does NuHarbor Security make money?
Three revenue lines are on record. Managed Security Services are the primary driver. The others are security Testing Services and compliance and Advisory Services.
Who are NuHarbor Security's main competitors?
Broad incumbents on record are Trustwave, CrowdStrike and Secureworks. Direct peers are Pondurance, ReliaQuest, Expel, eSentire, GuidePoint Security, Arctic Wolf Networks and Avertium.
Does NuHarbor Security have an API?
No public API is recorded for NuHarbor Security.
What industry is NuHarbor Security in?
NuHarbor Security's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5616 and its SIC code is 7370.