Information Security Forum
The Information Security Forum is a UK-based, not-for-profit membership association founded in 1989 that provides information security research, frameworks, methodologies, tools, and consultancy to over 400 global enterprise organizations, primarily serving CISOs and senior security leaders.
- Company typePrivate
- Founded1989
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Information Security Forum does
The Information Security Forum (ISF) is an independent, UK-registered not-for-profit membership association founded in 1989 that provides information security research, frameworks, tools, and consultancy to over 400 global organizations across financial services, manufacturing, retail, healthcare, technology, and government sectors. Its core intellectual property comprises the Standard of Good Practice for Information Security (SOGP), the IRAM2 and IRAM3 Information Risk Assessment Methodologies, the Threat Horizon Report Series (annual forecasting editions from 2021 through 2028), the ISF Aligned Tools Suite (including the Supply Chain Assurance Framework, Supplier Security Evaluation tool, and Maturity Model Accelerator), and the ISF Learning training and certification service. Delivery occurs primarily through the member-exclusive ISF Live collaboration platform, with reinforced engagement via the annual World Congress and a layer of regional chapters covering the UK & Ireland, Americas, EMEA, APAC, Nordics, and Africa.
The ISF generates revenue through organization-wide membership subscriptions with dedicated Account Managers, complemented by professional consultancy engagements (CISO-as-a-Service, Cyber Simulation Exercises, Security Assessment and Review, IRAM-based Risk Assessment, Supply Chain Management Assessment, and Human-Centred Security Assessment), and event sponsorship across Diamond, Gold, Silver, and Bronze tiers. The 2026 World Congress in Milan is sponsored by KPMG (Diamond), ZeroFox and Panorays (Gold), SecurityScorecard, BDO, and ProcessUnity (Silver), and ThreatLocker, CyberVadis, and Keeper Security (Bronze). Its go-to-market is community-led and event-driven, anchored on a peer network of CISO and senior security leaders from large enterprise member organizations.
Recent strategic activity has concentrated on methodology modernization (the May 2026 launch of IRAM3 with a dual-track qualitative and quantitative model), AI-themed research expansion (the AI Insights series on AI security governance, ethics, and agentic AI risk), and continued content franchise investment (Threat Horizon 2026–2028). Regional engagement is being intentionally widened into Greece, Cyprus, and India. Operationally, ISF runs lean with 11–50 employees split between London and a registered office in Worthing, indicating a content- and community-led operating model rather than a heavy services delivery function.
Information Security Forum firmographics
Firmographics- Name
- Information Security Forum
- Legal name
- Information Security Forum Limited
- Website
- https://securityforum.org
- Company type
- Private
- Founded year
- 1989
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- The Information Security Forum is a UK-based, not-for-profit membership association founded in 1989 that provides information security research, frameworks, methodologies, tools, and consultancy to over 400 global enterprise organizations, primarily serving CISOs and senior security leaders.
- Ownership category
- akta.pro rank
Information Security Forum industry classification
Industry- Product category
- Cybersecurity Advisory and Information Risk Management Services
- NAICS
- Business Associations (813910), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
Keywords
Where Information Security Forum is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Information Security Forum business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- ISF Membership: Organization-wide membership providing unlimited access to all tools, services, and events for member organizations worldwide. Each member is assigned an Account Manager to assist in gaining maximum value from membership. Membership includes access to ISF Live, the exclusive member resource library and interactive discussion platform.
- Consultancy Services: Award-winning consultancy services providing organisations globally with tailored, pragmatic support. Services include Cyber Simulation Exercise, Security Assessment and Review, Controls/Policies/Standards Support, Risk Assessment (IRAM2), and Supply Chain Management Assessment. These short-term professional services supplement implementation of ISF products.
- Event Sponsorship: ISF offers sponsorship opportunities at World Congress and regional events, providing non-member organizations access to senior security decision-makers. Sponsorship tiers include Diamond, Gold, Silver, and Bronze sponsors with varying levels of visibility and engagement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | ISF Full Membership - Organization-wide access |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels7 records
Information Security Forum product offering
Product offeringCore offering
The Information Security Forum sells organization-wide annual memberships that grant unlimited global access to its information security and risk management research, frameworks (notably the Standard of Good Practice, IRAM2 and IRAM3), assessment tools, the ISF Live member platform, regional meetings and the ISF World Congress. It also delivers short-term professional consultancy services (Cyber Simulation Exercises, Security Assessments, CISO as a Service, Supply Chain and Risk Assessments) and earns sponsorship revenue from cyber vendors at its flagship events.
Product overview
The Information Security Forum (ISF) offers a comprehensive portfolio of information security and risk management products and services built around its core Standard of Good Practice (SOGP) framework. The portfolio centers on the SOGP as the foundational security control framework, complemented by IRAM2/IRAM3 risk assessment methodologies for identifying, assessing and treating information risk. The ISF provides the Threat Horizon report series for strategic threat forecasting, the Aligned Tools Suite including supplier security tools and the maturity model accelerator, and various consultancy services such as Cyber Simulation Exercises, Security Assessments, and CISO as a Service. Additional offerings include the ISF Learning training programmes, ISF Live member platform, ISF World Congress annual events, and regional chapter meetings. The portfolio is delivered primarily to organisational members seeking to improve their cyber resilience through research, peer networks, practical tools, and professional support services.
Differentiator
Problem solved
Functional benefit
Products and services
- ISF Membership Annual organization-wide subscription that grants unlimited global access for all employees to ISF frameworks, tools, the ISF Live member portal, regional chapter meetings and the ISF World Congress, supported by an assigned Account Manager.
- Standard of Good Practice for Information Security (SOGP) Comprehensive, internationally-recognized security framework that guides organizations on all aspects of cyber security, information security and risk management.
- IRAM2 (Information Risk Assessment Methodology 2) Simple, practical yet rigorous approach to information risk assessments, enabling organizations to speak a common language with stakeholders; supported by four IRAM2 Assistants and the IRAM2 WebApp.
- IRAM3 (Information Risk Assessment and Management 3) Updated dual-track information risk assessment methodology that supports both qualitative and quantitative assessment within a single unified methodology, extending beyond assessment to provide end-to-end guidance on risk treatment, governance and reporting.
- Threat Horizon Report Series Annual strategic foresight reports predicting cyber risks; the series has reportedly predicted risks with 80% accuracy for over 15 years.
- ISF Aligned Tools Suite Collection of strategic information risk management tools to assess risk, qualify supplier security and assure prioritized cyber security investment, supporting assessment, compliance and assurance needs.
- Supplier Security Suite Risk-based approach to the end-to-end supplier management lifecycle, incorporating the Supply Chain Assurance Framework (SCAF) and the Supplier Security Evaluation (SSE) Accelerator Tool.
- ISF Maturity Model Accelerator Tool Accelerator tool that enables users to measure their security maturity across multiple security domains.
- ISF Live Member-exclusive portal serving as a resource library and interactive discussion platform that allows members to ask questions and share information in a secure environment.
- ISF Learning Training service delivering high-impact, best-in-class programmes and certifications for security professional development, with ISF attendance certificates issued for events and workshops.
- ISF World Congress Annual global gathering for leaders shaping the future of cyber, information security and risk management, featuring 100+ speakers, 44+ sessions, real-world case studies and closed-room roundtables.
- CISO as a Service Consultancy service providing professional security leadership support for organisations lacking internal CISO capability during upheaval or transition periods.
- Cyber Simulation Exercise Immersive, tailored scenarios that test an organisation's ability to navigate cyber attacks effectively.
- Security Assessment and Review Comprehensive assessment of security controls carried out by ISF experts to identify critical concerns and maximise return on security investment.
- Supply Chain Management Assessment Provides an up-to-date picture of information risk across the supply chain to reduce risk from external suppliers and improve cyber resilience.
- Risk Assessment and Review Expert-led risk assessments that give organisations an understanding of their greatest information risks, enabling justification for controls and protection investment.
- Human-Centred Security Assessment Determines the reasons behind poor security behaviour and engages the workforce to better protect organisations, with expert ISF support.
- Strategic Threat Analysis Reviews and sharpens the cyber security roadmap and creates board-ready outcomes to present strategy to senior stakeholders.
- ISF Assure Platform that swiftly identifies and mitigates key information risks, ensuring cyber resilience and operational stability.
- AI Insights Series Research series providing frameworks and actionable steps for mastering AI Security Governance, AI ethics and transparency, and agentic AI risks and responsibilities.
- Controls, Policies and Standards Support Consultancy service for the development, validation and improvement of security controls and policies based on the ISF SOGP, creating standards that staff across the business can easily follow.
Quantifiable outcome
- 80% accuracy in threat prediction for over 15 years
- +1 more outcomes
Companies that use Information Security Forum
Customer profileNamed customers7 records
Segments4 records
Ideal customer profiles2 records
Information Security Forum technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Information Security Forum partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered flagship, core and minor.
- KPMGflagshipDiamond sponsor of ISF World Congress Milan 2026. KPMG cyber security professionals offer multidisciplinary view of risk, helping organizations carry security throughout their organisation. KPMG firms can assess cyber security, develop advanced solutions, and help respond effectively to cyber incidents.
- ZeroFoxcoreGold sponsor of ISF World Congress. ZeroFox provides unified Cyber Threat Intelligence, Brand and Domain Protection, Attack Surface Intelligence, Executive Protection, and Physical Security Intelligence. Thousands of customers rely on ZeroFox for actionable intelligence.
- PanorayscoreGold sponsor of ISF World Congress. Leading provider of third-party cyber risk management solutions, helping businesses optimize defenses for each unique third-party relationship. Trusted by the most complex supply chains in the world.
- SecurityScorecardcoreSilver sponsor of ISF World Congress. Modernizes Third Party Risk Management (TPRM) using AI and threat intelligence. TITAN AI Platform unifies threat intelligence and third-party data for real-time supply chain risk visibility.
- BDOcoreSilver sponsor of ISF World Congress. BDO Canada LLP provides professional services across accounting, assurance, tax, and consulting. Deep industry knowledge positions BDO to advise clients with both domestic and global needs.
- ProcessUnitycoreSilver sponsor of ISF World Congress. Third-Party Risk Management company providing software platforms and data services. World's leading brands rely on ProcessUnity for effective and efficient third-party risk management.
- ThreatLockerminorBronze sponsor of ISF World Congress. Provides comprehensive zero trust security platform with controls to block untrusted software, limit lateral movement, and leverage telemetry and intelligence data for security alerts.
- CyberVadisminorBronze sponsor of ISF World Congress. Scalable third-party cyber risk management solution designed for enterprise. Combines sophisticated SaaS platform with high-touch managed service for vendor ecosystem assessment.
- Keeper SecurityminorBronze sponsor of ISF World Congress. Pioneer of zero-knowledge and zero-trust security for any IT environment. KeeperPAM is an AI-enabled, cloud-native platform protecting users, devices, and infrastructure from cyber attacks.
- CloudflareminorSponsor of ISF webinar on Managing Supply Chain Risk. Cloudflare is a leading security, performance, and reliability company powering more than 27 million Internet properties.
- Recorded FutureminorSponsor of CxO webinar series on Communicating in a Cyber Crisis. Delivers security intelligence to amplify effectiveness of security and IT teams with contextual, actionable intelligence.
- BeyondTrustminorSponsor of CxO webinar series. Worldwide leader in Privileged Access Management, preventing data breaches related to stolen credentials, misused privileges, and compromised remote access.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Information Security Forum competitors and assessment
Company assessmentDirect peers
- SANS Institute: Leading provider of cybersecurity training, GIAC certifications, and original security research. Overlaps with ISF on research content and member education, and addresses the same CISO and security practitioner audience with a more training-centric model.
- ISACA: Global not-for-profit membership association for IT governance, risk, cybersecurity, and audit professionals. ISACA is the closest direct peer to ISF - both sell enterprise memberships delivering frameworks (e.g. COBIT vs SOGP), certifications, research, and conferences to the same CISO/GRC buyer.
- (ISC)²: International non-profit membership body for cybersecurity professionals, offering the CISSP certification, research, and member benefits. Competes with ISF for the same enterprise security professional wallet and provides a comparable membership-and-content model.
- IAPP (International Association of Privacy Professionals): Global not-for-profit association for privacy and data protection professionals offering certifications (CIPP), research, and member events. Closely mirrors ISF's membership-community-credentialing model in the adjacent privacy domain.
- Cloud Security Alliance: Not-for-profit organisation delivering community-driven cybersecurity research, certifications (CCSK, CCSP), and frameworks focused on cloud security. Comparable membership-and-research model to ISF, though narrower in scope to cloud.
- Center for Internet Security (CIS): Community-driven non-profit producing the CIS Critical Security Controls and benchmarks widely adopted by enterprises. Competes with ISF's SOGP as an alternative authoritative control framework for the same enterprise security buyer.
Regional players
- ENISA (European Union Agency for Cybersecurity): EU agency publishing cybersecurity frameworks, threat intelligence, and guidance used by European enterprises. Comparable in scope to ISF's research output but as a public-sector regulator/advisor rather than a paid membership model.
Emerging players
- FAIR Institute: Non-profit organisation promoting the FAIR standard for quantitative cyber and operational risk analysis. Overlaps directly with ISF's IRAM3 dual-track qualitative/quantitative positioning, and represents a methodology-side peer in the same GRC conversation.
- OWASP Foundation: Open-source community producing widely adopted security standards (e.g. OWASP Top 10, ASVS). Comparable community-and-framework model to ISF, though free and open-source rather than a paid membership association.
Broad incumbents
- Gartner: Dominant global research and advisory firm with extensive cybersecurity, risk, and compliance coverage. Competes with ISF for the CISO advisory budget but at much larger scale, broader portfolio, and significantly higher price points.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Information Security Forum social profiles
Digital presenceInformation Security Forum compliance and trust
Trust signalCompliance1 record
Information Security Forum financial estimates
Financial estimateRevenue estimate
Valuation estimate
Information Security Forum leadership team
Management profileNumber of profiles
Profiles11 records
Information Security Forum funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Information Security Forum M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Information Security Forum
What does Information Security Forum do?
The Information Security Forum sells organization-wide annual memberships that grant unlimited global access to its information security and risk management research, frameworks (notably the Standard of Good Practice, IRAM2 and IRAM3), assessment tools, the ISF Live member platform, regional meetings and the ISF World Congress. It also delivers short-term professional consultancy services (Cyber Simulation Exercises, Security Assessments, CISO as a Service, Supply Chain and Risk Assessments) and earns sponsorship revenue from cyber vendors at its flagship events.
Is Information Security Forum a public or private company?
Information Security Forum is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Information Security Forum founded?
Information Security Forum was founded in 1989. It employs 11 to 50 people.
Where is Information Security Forum based?
Information Security Forum is headquartered in London, United Kingdom, in the Europe region.
How does Information Security Forum make money?
Three revenue lines are on record. ISF Membership is the primary driver. The others are consultancy Services and event Sponsorship.
Who are Information Security Forum's main competitors?
Direct peers on record are SANS Institute, ISACA, (ISC)², IAPP (International Association of Privacy Professionals), Cloud Security Alliance and Center for Internet Security (CIS). ENISA (European Union Agency for Cybersecurity) is listed as a regional player. Emerging players are FAIR Institute and OWASP Foundation. Gartner is listed as a broad incumbent.
Does Information Security Forum have an API?
No public API is recorded for Information Security Forum.
What industry is Information Security Forum in?
Information Security Forum's product category is Cybersecurity Advisory and Information Risk Management Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 813910 and its SIC code is 8600.