Black Hills Information Security
Black Hills Information Security is a US-based offensive cybersecurity firm founded in 2008, offering penetration testing, continuous validation (AntiSOC), AI security assessments, incident response, and managed SOC services to enterprise organizations and high-profile individuals, supported by a proprietary AI-augmented Fusion AI testing platform.
- Company typePrivate
- Founded2008
- HeadquartersSpearfish, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Black Hills Information Security does
Black Hills Information Security (BHIS) is a US-based, privately held offensive cybersecurity firm founded in 2008 by John Strand and headquartered in Sturgis, South Dakota. The company sells penetration testing and security validation services to enterprise organizations and high-profile individuals, spanning traditional external/internal pentesting, web application testing, continuous penetration testing (AntiSOC), AI security assessments, blue team services, blockchain security, incident response, and a managed SOC offering (ActiveSOC). Revenue is generated primarily through professional services engagements with an increasing shift toward recurring subscription revenue via AntiSOC and multi-year contracts tied to the new Fusion AI product.
The firm's technology stack centers on two proprietary platforms: Fusion AI, an agentic AI-augmented external penetration testing system that combines automated scanning, attack-chain analysis, and senior human validation at roughly one-third the cost of traditional external pentests; and AntiSOC, a continuous adversary validation platform combining automated adversary simulation, AI-augmented continuous testing, and exposure validation. BHIS also distributes free open-source tools (notably RITA via sister entity Active Countermeasures) and an incident-response card game (Backdoors & Breaches). The company does not publish pricing and operates a direct, consultative sales motion with no disclosed channel partners.
BHIS extends well beyond services into a tightly integrated ecosystem branded as the "Tribe of Companies" — Active Countermeasures, Wild West Hackin' Fest (annual Deadwood conference), Antisyphon Training, REKCAH Comics, and Backdoors & Breaches — supported by a content and community engine that includes the weekly Talkin' Bout [Infosec] News podcast, free webcasts, YouTube, a blog, Discord, LinkedIn, X, and Bluesky. The Tribe functions as a top-of-funnel flywheel for service leads while diversifying into training, events, tools, and media. The firm is privately held with no disclosed outside funding, no published revenue, and limited leadership disclosure beyond COO Christopher Cox.
Black Hills Information Security firmographics
Firmographics- Name
- Black Hills Information Security
- Legal name
- Black Hills Information Security, Inc.
- Website
- https://blackhillsinfosec.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Black Hills Information Security is a US-based offensive cybersecurity firm founded in 2008, offering penetration testing, continuous validation (AntiSOC), AI security assessments, incident response, and managed SOC services to enterprise organizations and high-profile individuals, supported by a proprietary AI-augmented Fusion AI testing platform.
- Ownership category
- akta.pro rank
Black Hills Information Security industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Testing Laboratories and Services (54138), Testing Laboratories and Services (541380)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC), Vulnerability Assessment & Scanning (HDADAHAA), Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF)
Keywords
Where Black Hills Information Security is headquartered
LocationHeadquarters
- HQ city
- Spearfish
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Black Hills Information Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Penetration Testing Services: Professional services revenue generated from traditional and continuous penetration testing engagements. Pricing varies by scope, complexity, and engagement type. Includes external/internal network testing, web application testing, red team operations, and specialized assessments.
- Continuous Security Monitoring (AntiSOC): Recurring subscription-based revenue from continuous penetration testing and threat exposure management services. Provides ongoing validation of security controls throughout the year.
- AI Security Assessments: Specialized assessments for organizations deploying AI-powered platforms, including red teaming against adversarial attacks like prompt injection, model extraction, and data poisoning.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Hybrid | Multi-year contract | Fusion AI External Pentest - approximately 1/3 cost of traditional pentest |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels9 records
Black Hills Information Security product offering
Product offeringCore offering
Black Hills Information Security provides offensive and continuous security testing services to organizations, including traditional and AI-augmented (Fusion) penetration testing, continuous adversary validation (AntiSOC), web application testing, AI security assessments, incident response, managed SOC (ActiveSOC), blue team, blockchain, and high-profile risk assessments. Its proprietary Fusion AI platform combines autonomous agents with senior human tester sign-off on every finding to deliver external penetration testing at approximately one-third the cost of traditional engagements.
Product overview
Black Hills Information Security (BHIS) offers a portfolio of cybersecurity services led by penetration testing offerings, including Traditional Penetration Testing, the AI-augmented Fusion Penetration Testing service, and AntiSOC for continuous adversary validation. The company provides complementary services including Web Application Testing, ActiveSOC managed services, AI Security Assessments, Incident Response, Blue Team Services, Blockchain Security, and High-Profile Risk Assessments. BHIS also maintains educational and community-focused brands including Antisyphon Training, the Wild West Hackin' Fest conference, and free resources like the Backdoors & Breaches card game and PROMPT# zine. The company takes an AI-positive approach to security testing, using AI to augment rather than replace human testers.
Differentiator
Problem solved
Functional benefit
Brands
- AntiSOC: Continuous adversary validation platform combining automated adversary simulation, AI-augmented continuous penetration testing, and exposure validation
- Fusion Penetration Testing
- Backdoors & Breaches
- PROMPT# Zine
- Talkin' Bout [Infosec] News
Products and services
- Traditional Penetration Testing
Quantifiable outcome
- Fusion AI runs at approximately one-third the cost of traditional external pentests
- +1 more outcomes
Companies that use Black Hills Information Security
Customer profileSegments2 records
Ideal customer profiles3 records
Black Hills Information Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability9 records
Feature5 records
Black Hills Information Security partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- Active CountermeasurescorePart of the BHIS Tribe of Companies. Active Countermeasures provides free security tools including AC-Hunter and RITA (Realtime Intelligence Threat Analysis). Deep operational and strategic integration with BHIS security testing services.
- Wild West Hackin' FestcorePart of the BHIS Tribe of Companies. An annual hands-on cybersecurity conference held in Deadwood, South Dakota. Provides training, talks, and networking opportunities for security professionals, aligned with BHIS's educational mission.
- Antisyphon TrainingcorePart of the BHIS Tribe of Companies. Training organization providing cybersecurity education and professional development. Hosts the AI Security Summit and other training events.
- Backdoors & BreachescorePart of the BHIS Tribe of Companies. An incident response card game created by BHIS to help organizations conduct IR tabletop exercises and learn attack tactics, tools, and methods.
- REKCAH ComicsminorPart of the BHIS Tribe of Companies. Security-themed comic content for the cybersecurity community.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Black Hills Information Security competitors and assessment
Company assessmentDirect peers
- Praetorian: Offensive security firm offering penetration testing, red team, and attack surface management services. Closely comparable in scope and boutique scale, with similar emphasis on continuous validation.
- NCC Group: Global cybersecurity consulting firm with a large dedicated penetration testing practice across infrastructure, web, and cloud. Directly comparable to BHIS as a professional-services pentest provider, though significantly larger and UK-headquartered.
- Coalfire: Cybersecurity advisory firm with substantial penetration testing and compliance services practice. Comparable to BHIS in offering breadth across technical testing and advisory, though larger and more compliance-focused.
- TrustedSec: Offensive security consultancy offering penetration testing, red teaming, and incident response. Comparable boutique practitioner-led model, similar community-driven brand, and overlapping customer base of enterprise buyers.
- NetSPI: Pentesting and attack surface management firm with a strong continuous/managed testing offering (NetSPI Resolve). Highly comparable to BHIS on traditional pentesting and on the continuous-testing subscription model embodied by AntiSOC.
- Bishop Fox: Boutique offensive security firm specializing in penetration testing, red teaming, and attack surface management. Closely comparable to BHIS in offering mix, boutique scale, and practitioner-led delivery model.
Broad incumbents
- CrowdStrike: Endpoint security leader that has expanded into exposure management, ASM, and offensive security testing. Comparable as a competitor for adjacent services buyers, with much larger platform scale and enterprise sales motion.
- Mandiant (Google Cloud): Large incident response and security testing firm now part of Google Cloud, with deep penetration testing and red team offerings. Represents the scaled incumbent competing for enterprise IR and offensive security engagements.
- Rapid7: Security platform vendor (Metasploit owner) offering vulnerability management, ASM, and managed testing services. Comparable in adjacent vulnerability testing categories, with broader portfolio and significantly larger scale.
Emerging players
- HackerOne: Platform for crowdsourced and continuous penetration testing connecting enterprises to a researcher community. Comparable to BHIS's continuous testing direction but uses a crowdsourced delivery model rather than in-house practitioner teams.
Market position
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Black Hills Information Security social profiles
Digital presenceBlack Hills Information Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Black Hills Information Security leadership team
Management profileNumber of profiles
Profiles2 records
Black Hills Information Security subsidiaries and ownership
Company hierarchySubsidiaries5 records
Black Hills Information Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Black Hills Information Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Black Hills Information Security
What does Black Hills Information Security do?
Black Hills Information Security provides offensive and continuous security testing services to organizations, including traditional and AI-augmented (Fusion) penetration testing, continuous adversary validation (AntiSOC), web application testing, AI security assessments, incident response, managed SOC (ActiveSOC), blue team, blockchain, and high-profile risk assessments. Its proprietary Fusion AI platform combines autonomous agents with senior human tester sign-off on every finding to deliver external penetration testing at approximately one-third the cost of traditional engagements.
Is Black Hills Information Security a public or private company?
Black Hills Information Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Black Hills Information Security founded?
Black Hills Information Security was founded in 2008. It employs 101 to 250 people.
Where is Black Hills Information Security based?
Black Hills Information Security is headquartered in Spearfish, United States, in the North America region.
How does Black Hills Information Security make money?
Three revenue lines are on record. Penetration Testing Services are the primary driver. The others are continuous Security Monitoring (AntiSOC) and AI Security Assessments.
Who are Black Hills Information Security's main competitors?
Direct peers on record are Praetorian, NCC Group, Coalfire, TrustedSec, NetSPI and Bishop Fox. Broad incumbents are CrowdStrike, Mandiant (Google Cloud) and Rapid7. HackerOne is listed as an emerging player.
Does Black Hills Information Security have an API?
No public API is recorded for Black Hills Information Security.
What industry is Black Hills Information Security in?
Black Hills Information Security's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54138 and its SIC code is 8734.