Legato Security
- Company typePrivate
- Founded2020
- HeadquartersSalt Lake City, United States
- Headcount51–100
- GTM typeB2B
- OfferingServices
Legato Security firmographics
Firmographics- Name
- Legato Security
- Legal name
- Legato Security
- Website
- https://legatosecurity.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Ownership category
- akta.pro rank
Legato Security industry classification
Industry- Product category
- Managed Security Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Management Services (8741)
- akta.pro primary industry
- Managed Security Services (MSSP) & 24/7 SOC Operations (BPAKAHAA)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Enterprise Application Security, GRC & Compliance Services (BPAEAGAL), Threat Intelligence Services (BPAEADAC)
Keywords
Where Legato Security is headquartered
LocationHeadquarters
- HQ city
- Salt Lake City
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Legato Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services: Recurring managed security services including MDR+, EDR, XDR, SIEMaaS, SOCaaS, Vulnerability Management, Firewall Administration, Compliance Services, Threat Hunting, and Email Security. Delivered as subscription-based services with 24/7 monitoring and support.
- Strategic Security Services: Ongoing strategic guidance including vCISO/fCISO services and Security Consulting for executive-level insights and long-term security planning.
- Professional Security Services: Customized security solutions including Security Assessments, Penetration Testing, Incident Response, Tabletop Exercises, Compromise Assessments, Policy Generation, and Third Party Risk Assessments. Typically project-based or one-time engagements.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Legato Security product offering
Product offeringCore offering
Legato Security is a technology-agnostic Managed Security Services Provider (MSSP) that delivers 24/7 cybersecurity monitoring, threat detection, and response through its proprietary Ensemble Security Operations Platform. The company provides managed services (MDR+, EDR, XDR, SIEMaaS, SOCaaS, Vulnerability Management, Firewall Administration, Compliance Readiness, Threat Hunting, Email Security), strategic services (Security Consulting, vCISO/fCISO), and professional services (Security Assessments, Penetration Testing, Incident Response, Tabletop Exercises, Compromise Assessments, Policy Generation, Third Party Risk Assessments).
Product overview
Legato Security operates as a technology-agnostic Managed Security Services Provider (MSSP) offering a comprehensive suite of cybersecurity services organized across three layers: Managed Security Services, Strategic Security Services, and Professional Security Services. The core platform is Ensemble, a Security Operations Platform that unifies visibility, asset intelligence, and automation across existing security tools. The managed services portfolio includes MDR+ (the flagship offering combining MDR with CAASM-based asset intelligence), EDR, XDR, SOCaaS, SIEMaaS, Vulnerability Management, Firewall Administration, Regulatory & Compliance Readiness, Threat Hunting, and Email Security. Strategic services encompass Security Consulting and vCISO/fCISO. Professional services cover Security Assessments, Penetration Testing, Incident Response, Tabletop Exercises, Compromise Assessments, Policy Generation, and Third Party Risk Assessments. Together these services form an integrated security operations ecosystem designed for IT and security professionals.
Differentiator
Problem solved
Functional benefit
Brands
- Ensemble: The Legato Security Operations Platform - a Security Operations Platform designed to enhance visibility, reduce complexity, and increase efficiency by providing centralized visibility, real-time asset intelligence, and automation capabilities.
- MDR+
- SOCaaS
- SIEMaaS
Products and services
- Ensemble Security Operations Platform Legato's proprietary security operations platform that unifies visibility, real-time asset intelligence, and automation across an organization's existing security tools to reduce alert fatigue and improve mean time to remediation.
- MDR+ (Managed Detection and Response Plus) Advanced managed detection and response service combining traditional MDR with CAASM-based asset intelligence for real-time threat detection, visibility, and context across all network assets, 24/7.
- Endpoint Security Management (EDR) Managed endpoint protection service delivering real-time threat detection and response for devices on the network, using machine learning and behavior analysis to neutralize malware, ransomware, and phishing attacks.
- XDR (Extended Detection and Response) Managed extended detection and response service that correlates threats across endpoints, networks, and cloud environments for a unified security approach.
- SIEMaaS (Security Information and Event Management as a Service) Vendor-agnostic managed SIEM service providing real-time monitoring, log analysis, threat detection, and correlation across diverse data sources to support compliance and threat visibility.
- SOCaaS (Security Operations Center as a Service) Fully managed Security Operations Center providing 24/7/365 monitoring, continuous threat defense, proactive threat management, and custom incident response workflows.
- Vulnerability Management Managed service to identify, assess, and remediate security weaknesses across an organization's environment, helping prioritize vulnerabilities and reduce attack surface.
- Firewall Administration Expert management of firewall policies and configurations including rule base optimization, change management, compliance assurance, and real-time threat intelligence integration.
- Regulatory & Compliance Readiness Service to help organizations stay ahead of evolving security regulations and achieve or maintain compliance with CMMC, GDPR, HIPAA, and PCI-DSS through continuous monitoring and security control alignment.
- Threat Hunting Proactive threat hunting service that searches for hidden threats using human-led hypothesis-driven investigations, advanced analytics, and AI/ML techniques to identify anomalous behavior evading automated defenses.
- Email Security Managed email security service providing protection against phishing, malware, and email-based attacks through machine learning, threat intelligence, sandboxing, and encryption.
- Security Consulting Strategic security advisory providing expert guidance to strengthen an organization's security posture, benchmark against peers, and deliver technology-agnostic recommendations.
- vCISO / fCISO Virtual or fractional CISO service offering on-demand executive security leadership and strategy development for organizations needing senior security guidance without a full-time hire.
- Security Assessment Comprehensive evaluation of an organization's security landscape to identify vulnerabilities, gaps, and improvement opportunities with actionable recommendations.
- Tabletop Exercises Simulated security incident scenarios designed to test and improve an organization's response plans and preparedness for real-world cyber events.
- Penetration Testing Simulated cyber attacks to uncover vulnerabilities in systems and infrastructure before adversaries can exploit them, with detailed remediation guidance.
- Compromise Assessment Proactive assessment to detect ongoing and past cyber attacks, identify indicators of compromise (IoCs), and uncover hidden threats in an organization's environment.
- Incident Response Rapid containment and remediation of security incidents, providing expert-led response to minimize damage, restore systems, and implement preventive measures.
- Policy Generation Custom security policy development service creating tailored policies aligned with an organization's business needs, regulatory requirements, and industry best practices.
- Third Party Risk Assessment Service to assess and mitigate vendor and third-party security risks, evaluating the security posture of suppliers and partners to prevent supply chain vulnerabilities.
Quantifiable outcome
- Up to 60% reduction in total cost of security operations
- +3 more outcomes
Companies that use Legato Security
Customer profileNamed customers6 records
Segments3 records
Ideal customer profiles3 records
Legato Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability5 records
Feature5 records
Legato Security partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship, minor and core.
- AcronisflagshipLegato Security serves as regional partner for Acronis MDR by Acronis TRU in North America. The partnership provides 24/7 managed detection and response service combining threat monitoring, triage, incident response, patch management, attack rollback, and business continuity tools.
- Regional MSSP Partners (UK, Australia, Singapore, Japan, Europe)minorLegato Security coordinates with regional MSSP partners across UK, Australia, Singapore, Japan, and Europe for Acronis MDR service delivery in those markets.
- Technology Partners (Security Vendor Ecosystem)coreTechnology-agnostic approach integrating with multiple security vendors including Securonix, Qualys, Fortinet, SentinelOne, CrowdStrike, Tenable, Proofpoint, Trend Micro, Zscaler, Google SecOps, DoControl, Sumologic, Area 1, Drata, Stelar Cyber, and Whistic.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Legato Security competitors and assessment
Company assessmentDirect peers
- eSentire: eSentire is a pure-play MDR provider offering 24/7 SOC, threat hunting, and incident response services globally. Comparable in core MDR/SOC service delivery, customer segmentation, and reliance on partner ecosystem for technology integration.
- ReliaQuest: ReliaQuest is a large MSSP offering MDR, security operations, and threat intelligence through its GreyMatter platform with a technology-agnostic, integrate-not-replace philosophy. Highly comparable to Legato in vendor-neutral positioning and enterprise customer targeting, though at a larger scale.
- Deepwatch: Deepwatch is a managed security services provider offering MDR, SIEM-as-a-service, and vulnerability management with a cloud-native security operations platform. Closely aligned with Legato's SIEMaaS, SOCaaS, and Ensemble platform approach.
- Expel: Expel provides transparent, technology-agnostic MDR services with a focus on customer experience and integration with existing security stacks. Closely matches Legato's technology-agnostic positioning and Ensemble platform philosophy of integrating with customer investments.
- Huntress: Huntress provides managed detection and response for endpoints, identities, and SaaS applications, primarily targeting SMB and mid-market customers. Comparable in managed services delivery model, EDR/XDR focus, and channel-led GTM motion.
- Arctic Wolf Networks: Arctic Wolf is a leading MDR/managed security services provider offering 24/7 SOC-as-a-service, MDR, and vulnerability management to mid-market and enterprise customers. Most directly comparable to Legato Security in service portfolio, technology-agnostic approach, and target customer base.
- Binary Defense: Binary Defense provides managed detection and response, threat hunting, and SOC-as-a-service with an open-XDR platform. Comparable in managed security services portfolio and similar mid-market/enterprise customer profile.
- Critical Start: Critical Start is an MDR provider offering 24/7 SOC, threat hunting, and security operations services with a focus on reducing false positives through alert analysis. Directly comparable in MDR/SOC service offerings and enterprise customer targeting.
Broad incumbents
- CrowdStrike Falcon Complete: CrowdStrike's Falcon Complete is a fully managed MDR service bundled with its industry-leading Falcon endpoint platform. Represents a key competitive threat as a platform vendor offering native MDR that can disintermediate pure-play MSSPs like Legato.
- Sophos Managed Detection and Response: Sophos (owned by Thoma Bravo) offers MDR as part of its broader cybersecurity portfolio including endpoint, network, and email security. Overlaps with Legato's EDR/XDR and MDR services but operates as part of a much wider product portfolio rather than as a pure-play MSSP.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Legato Security compliance and trust
Trust signalCompliance1 record
Legato Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Legato Security leadership team
Management profileNumber of profiles
Profiles4 records
Legato Security funding detail
Funding detailFunding overview
Funding rounds1 record
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Legato Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Legato Security
What does Legato Security do?
Legato Security is a technology-agnostic Managed Security Services Provider (MSSP) that delivers 24/7 cybersecurity monitoring, threat detection, and response through its proprietary Ensemble Security Operations Platform. The company provides managed services (MDR+, EDR, XDR, SIEMaaS, SOCaaS, Vulnerability Management, Firewall Administration, Compliance Readiness, Threat Hunting, Email Security), strategic services (Security Consulting, vCISO/fCISO), and professional services (Security Assessments, Penetration Testing, Incident Response, Tabletop Exercises, Compromise Assessments, Policy Generation, Third Party Risk Assessments).
Is Legato Security a public or private company?
Legato Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Legato Security founded?
Legato Security was founded in 2020. It employs 51 to 100 people.
Where is Legato Security based?
Legato Security is headquartered in Salt Lake City, United States, in the North America region.
How does Legato Security make money?
Three revenue lines are on record. Managed Security Services are the primary driver. The others are strategic Security Services and professional Security Services.
Who are Legato Security's main competitors?
Direct peers on record are eSentire, ReliaQuest, Deepwatch, Expel, Huntress, Arctic Wolf Networks, Binary Defense and Critical Start. Broad incumbents are CrowdStrike Falcon Complete and Sophos Managed Detection and Response.
Does Legato Security have an API?
No public API is recorded for Legato Security.
What industry is Legato Security in?
Legato Security's product category is Managed Security Services. Its primary akta.pro industry code is BPAKAHAA, Managed Security Services (MSSP) & 24/7 SOC Operations, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 5415 and its SIC code is 8741.