Stroz Friedberg
Stroz Friedberg, now operating within LevelBlue, provides digital forensics, incident response, threat intelligence, and managed security services to enterprise and government clients, with 300+ DFIR experts serving financial services, healthcare, and government verticals.
- Company typePrivate
- Founded2000
- HeadquartersNew York, United States
- Headcount251–500
- GTM typeB2B
- OfferingServices
What Stroz Friedberg does
Stroz Friedberg, founded in 2000 and headquartered in New York, is a technical consulting and services firm specializing in digital forensics, incident response, and litigation-minded cybersecurity. It is now consolidated within LevelBlue, which unified Stroz Friedberg's DFIR heritage with Trustwave's managed security platform and Cybereason's XDR/threat intelligence capabilities to deliver AI-driven MDR, XDR, threat intelligence, digital forensics, and incident response services. The company serves enterprise and government clients across government, financial services, healthcare, and other regulated verticals, with certified coverage across FISMA, HIPAA, GDPR, GLBA, SOX, CMMC, ISO 27001, PCI-DSS, and FedRAMP Moderate regimes.
The platform combines managed security services (USM Anywhere, Fusion Platform, MailMarshal Cloud) with a DFIR service portfolio that includes 24/7 incident response hotline support, the Resilience Retainer program (approved across 50+ cyber insurance carrier panels), SpiderLabs threat intelligence, Cyber Advisory, Intellectual Property Consulting, and expert witness services. Technology integrations with SentinelOne and Microsoft anchor co-delivered managed security operations, while the 300+ DFIR expert base is the operational backbone for incident readiness, tabletop exercises, purple teaming, and post-breach recovery work. The firm claims 9,000+ incidents investigated, 1,000+ tabletop exercises orchestrated, and 200,000+ hours of penetration testing delivered annually.
Revenue is generated through a mix of subscription-based managed security services, DFIR retainers (multi-year contracts), project-based professional services, and bespoke consulting engagements. Go-to-market is enterprise field sales with channel distribution through SentinelOne and Microsoft technology alliances, supported by analyst-recognized credibility (IDC MarketScape Major Player, 2026 Gartner Market Guide inclusion) and a formal RFP process targeting government and enterprise procurement. In October 2025, LevelBlue acquired Cybereason with backing from SoftBank, Vision Fund 2, and Liberty Strategic Capital, signaling an aggressive inorganic growth posture toward global MDR/XDR scale.
Stroz Friedberg firmographics
Firmographics- Name
- Stroz Friedberg
- Website
- https://strozfriedberg.com
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Stroz Friedberg, now operating within LevelBlue, provides digital forensics, incident response, threat intelligence, and managed security services to enterprise and government clients, with 300+ DFIR experts serving financial services, healthcare, and government verticals.
- Ownership category
- akta.pro rank
Stroz Friedberg industry classification
Industry- Product category
- Cybersecurity Consulting & Digital Forensics
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (except Locksmiths) (561621)
- SIC
- Security Brokers, Dealers & Flotation Companies (6211), Finance Services (6199)
- akta.pro primary industry
- Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring (BPAKAHAO)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Cybersecurity for Financial Services Compliance (controls, audits, SOC/ISO mapping) (FSAGAFAK)
Keywords
Where Stroz Friedberg is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Markets served
Stroz Friedberg business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services (MDR/XDR): Recurring subscription-based managed detection and response services providing continuous monitoring, threat detection, investigation, and response across customer attack surfaces. Revenue is subscription-based with annual or multi-year retainer structures.
- DFIR Retainer Services: Pre-paid incident response retainer providing faster response times, access to proactive services, and compliance with insurance and regulatory requirements. Includes the Resilience Retainer program with outcome-driven elements.
- Professional Services & Consulting: Bespoke cybersecurity consulting engagements including cyber advisory, incident readiness planning, tabletop exercises, purple teaming, digital forensics expert witness services, and IP consulting. Typically project-based or time-and-materials.
- Managed Cloud, Email, and Network Security: Subscription-based specialized security services covering cloud security posture management, email threat protection, and network security monitoring.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Resilience Retainer — flexible, outcome-driven IR retainer program |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels9 records
Stroz Friedberg product offering
Product offeringCore offering
Stroz Friedberg is a technical consulting and services firm providing digital forensics, incident response, cyber risk management, and litigation support services. Its offerings include DFIR retainer programs, expert witness testimony, IP consulting, and cyber advisory engagements, now unified under LevelBlue alongside Trustwave and Cybereason. The firm combines human-led digital forensics expertise with proactive threat intelligence (SpiderLabs) to serve enterprise and government clients facing complex cyber incidents and litigation.
Product overview
LevelBlue, which unifies expertise from Stroz Friedberg, Trustwave, and Cybereason, offers a comprehensive cybersecurity platform combining security operations platforms (USM Anywhere, Fusion Platform, MailMarshal Cloud) with managed services (MDR/TDIR, Managed Cloud Security, Email Security, Managed Network Security) and specialized consulting services (Incident Readiness and Response, Digital Forensics, Cyber Advisory, SpiderLabs Threat Intelligence). The portfolio also includes the Resilience Retainer program for proactive incident preparedness. The company delivers AI-driven cybersecurity offerings with 300+ DFIR experts providing litigation-minded, cyber insurance-approved response at global scale.
Differentiator
Problem solved
Functional benefit
Brands
- SpiderLabs: Elite global threat experts and intelligence team providing threat hunting and research capabilities.
- USM Anywhere
- Fusion Platform
- MailMarshal Cloud
Products and services
- Incident Readiness Service helping organizations develop and test cyber incident response plans, build playbooks, and train teams to respond quicker and more confidently to threats. Targeted at enterprise and government clients.
- Digital Forensics Service that identifies, collects, and analyzes digital evidence to support investigations, recovery, and legal requirements. Includes evidence identification and collection, chain of custody maintenance, remediation advice, litigation support, and technical guidance for post-breach recovery.
- Resilience Retainer Flexible, outcome-driven resilience program providing elite IR resources, proactive services (tabletop exercises, purple teaming), and discounts on services. Approved across 50+ cyber insurance carrier panels, enabling faster response times and pre-paid incident readiness.
- Incident Response Cyber incident response service providing expert guidance to assess impact, improve strategy, and reduce future risks for organizations that have suffered a security breach.
- Intellectual Property (IP) Consulting Technical expert testimony and consulting services in tech-focused intellectual property, contract disputes, and M&A software matters. Serves law firms and corporate legal departments.
- Digital Forensics Expert Witness Services Court-tested cybersecurity expertise to support all stages of litigation, providing expert witness testimony and technical analysis for legal proceedings.
- SpiderLabs Threat Intelligence
Quantifiable outcome
- 9,000+ security incidents investigated
- +4 more outcomes
Companies that use Stroz Friedberg
Customer profileNamed customers5 records
Segments8 records
Ideal customer profiles5 records
Stroz Friedberg technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature5 records
Stroz Friedberg partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship, core and minor.
- SentinelOneflagshipLevelBlue and SentinelOne have an expanded strategic global partnership to deliver AI-powered managed security operations and incident response. SentinelOne's AI-driven autonomous security platform is integrated with LevelBlue's MDR and DFIR services for combined threat detection and response.
- MicrosoftcoreMicrosoft is a technology alliance partner of LevelBlue, with LevelBlue unlocking the full power of Microsoft Security solutions for customers. LevelBlue operates as a Microsoft security technology partner offering integrated protection.
- PGA of AmericaminorLevelBlue is the official cybersecurity partner of the PGA of America, bringing cybersecurity messaging and protection to championship-level sporting events and audiences through a marketing and branding partnership.
Scale indicators7 records
Recent moves6 records
Expansion highlights7 records
Stroz Friedberg competitors and assessment
Company assessmentDirect peers
- Mandiant: Mandiant is the canonical direct competitor to Stroz Friedberg in incident response, digital forensics, and threat intelligence. Now part of Google Cloud, it offers nearly identical DFIR retainer, expert witness, and proactive threat hunting services to enterprise and government buyers.
- Palo Alto Networks Unit 42: Unit 42 is Palo Alto Networks' threat intelligence and incident response arm, directly competing with Stroz Friedberg/LevelBlue in DFIR retainers, breach response, and cyber insurance-approved incident services. It combines consulting services with Cortex XDR/MDR technology.
- CrowdStrike Services: CrowdStrike's Services division delivers incident response, proactive services, and threat intelligence alongside its Falcon XDR platform, directly overlapping with Stroz Friedberg/LevelBlue's DFIR and MDR offerings. It serves similar enterprise and government buyer segments.
- Kroll Cyber Risk: Kroll's Cyber Risk practice provides incident response, digital forensics, expert witness testimony, and breach notification services, closely mirroring Stroz Friedberg's traditional DFIR and litigation support offering for enterprises and law firms.
- Secureworks: Secureworks is a direct peer in managed detection and response and incident response services, combining Taegis XDR with global DFIR expertise. It targets the same enterprise and mid-market buyers as Stroz Friedberg/LevelBlue.
- Optiv Security: Optiv is a large cybersecurity solutions integrator and services provider offering advisory, managed security, and incident response capabilities that overlap with Stroz Friedberg/LevelBlue's consulting and MDR portfolio.
Broad incumbents
- IBM Security X-Force: IBM X-Force is a broad incumbent offering DFIR, threat intelligence, MDR, and security consulting at global scale. It competes with Stroz Friedberg/LevelBlue across enterprise consulting and managed services but as part of IBM's broader security portfolio rather than a DFIR specialist.
- Booz Allen Hamilton Cyber: Booz Allen Hamilton's commercial cyber practice offers incident response, threat hunting, and cybersecurity consulting similar to Stroz Friedberg, with deep federal government roots and a broader professional services portfolio.
Emerging players
- Bishop Fox: Bishop Fox is an offensive-security-focused firm offering penetration testing, red teaming, and DFIR-adjacent consulting. It competes with Stroz Friedberg/LevelBlue's offensive security and pen testing practices but lacks the same DFIR/MDR scale.
- ReliaQuest: ReliaQuest is a fast-growing MDR/XDR provider using an agentic AI platform (GreyMatter) to compete with LevelBlue's MDR offering. It focuses on enterprise security operations rather than litigation-grade DFIR but increasingly overlaps in the broader managed security market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key highlights7 records
Customer concentration
Stroz Friedberg social profiles
Digital presenceStroz Friedberg compliance and trust
Trust signalCompliance10 records
Stroz Friedberg financial estimates
Financial estimateRevenue estimate
Valuation estimate
Stroz Friedberg leadership team
Management profileNumber of profiles
Profiles5 records
Stroz Friedberg funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Stroz Friedberg M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Stroz Friedberg
What does Stroz Friedberg do?
Stroz Friedberg is a technical consulting and services firm providing digital forensics, incident response, cyber risk management, and litigation support services. Its offerings include DFIR retainer programs, expert witness testimony, IP consulting, and cyber advisory engagements, now unified under LevelBlue alongside Trustwave and Cybereason. The firm combines human-led digital forensics expertise with proactive threat intelligence (SpiderLabs) to serve enterprise and government clients facing complex cyber incidents and litigation.
Is Stroz Friedberg a public or private company?
Stroz Friedberg is a private company. It is classified as corporate owned and is currently operating.
When was Stroz Friedberg founded?
Stroz Friedberg was founded in 2000. It employs 251 to 500 people.
Where is Stroz Friedberg based?
Stroz Friedberg is headquartered in New York, United States, in the North America region.
How does Stroz Friedberg make money?
Four revenue lines are on record. Managed Security Services (MDR/XDR) is the primary driver. The others are DFIR Retainer Services, professional Services & Consulting and managed Cloud, Email, and Network Security.
Who are Stroz Friedberg's main competitors?
Direct peers on record are Mandiant, Palo Alto Networks Unit 42, CrowdStrike Services, Kroll Cyber Risk, Secureworks and Optiv Security. Broad incumbents are IBM Security X-Force and Booz Allen Hamilton Cyber. Emerging players are Bishop Fox and ReliaQuest.
Does Stroz Friedberg have an API?
No public API is recorded for Stroz Friedberg.
What industry is Stroz Friedberg in?
Stroz Friedberg's product category is Cybersecurity Consulting & Digital Forensics. Its primary akta.pro industry code is BPAKAHAO, Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 54151 and its SIC code is 6211.