Comsec
Privately-held Israeli cybersecurity consulting firm (founded 1987) delivering offensive security, GRC, testing, training and advisory services to large enterprises in financial services, healthcare and EU-facing sectors, with offices in Tel Aviv and Amsterdam and channel partnerships via Getronics and Checkmarx.
- Company typePrivate
- Founded1987
- HeadquartersTel Aviv-yafo, Israel
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Comsec does
Comsec is a privately held cybersecurity consulting firm founded in 1987 and headquartered in Tel Aviv, Israel, with a regional office in Amsterdam, Netherlands. The company delivers professional cybersecurity services across five practice areas: offensive security (red team attack simulation, phishing campaigns), governance, risk and compliance (PCI DSS, HIPAA/HITRUST, GDPR, ISO 27001), security testing and assessments (application, mobile, infrastructure, cloud, code and design review), education and training (security awareness, secure development), and advisory/managed services (24/7 incident response, CISO-as-a-Service, SSDLC implementation). Service delivery is anchored on certified practitioner expertise — most notably Certified Qualified Security Assessors for PCI DSS and dual HIPAA/HITRUST certified specialists — and on codified proprietary methodologies such as a four-level red team framework, a six-phase OSINT-driven phishing process, and a SANS-based incident response Execution Chain.
The underlying technology stack is human-delivery rather than product-platform: senior consultants perform manual penetration testing, code review, architecture review and risk assessment against standards such as NIST, PTES, CVSS, OWASP, CIS and ISO 27001. Pricing is quote-based with project-based and multi-year retainer structures, and the gtm motion is enterprise field sales executed through direct consultation, website contact, partner referrals and conference presence. Distribution is augmented through strategic partnerships with Getronics (global ICT services, 180+ countries via the Global Workspace Alliance) and Checkmarx (DevSecOps integration). Target customers are large enterprises — primarily in financial services/payments (PCI DSS), healthcare (HIPAA/HITRUST) and EU-facing organisations (GDPR) — seeking compliance certification, security assessment, or executive-level security leadership, with Comsec claiming 49+ enterprise client relationships across multiple countries.
Operationally, Comsec maintains 51-100 employees, runs 24/7 incident response with sub-15-minute response time, and reports customer satisfaction metrics alongside three decades of brand presence. No funding rounds, M&A activity, or public financial disclosures are documented; ownership remains private with leadership identified as Itzak Weinreb (CEO) and David Ferrara (Founder). The careers page is hosted through a 'Hub Technologies' Comeet portal, hinting at potential affiliation with a broader IT services group that is not formally disclosed in the source material.
Comsec firmographics
Firmographics- Name
- Comsec
- Legal name
- Comsec Ltd
- Website
- https://comsecglobal.com
- Company type
- Private
- Founded year
- 1987
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Privately-held Israeli cybersecurity consulting firm (founded 1987) delivering offensive security, GRC, testing, training and advisory services to large enterprises in financial services, healthcare and EU-facing sectors, with offices in Tel Aviv and Amsterdam and channel partnerships via Getronics and Checkmarx.
- Ownership category
- akta.pro rank
Comsec industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Application Security & Secure Software (DevSecOps) (EDAOAIAK)
Keywords
Where Comsec is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv-yafo
- HQ country
- Israel
- HQ region
- Middle East
Offices2 records
Markets served
Comsec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
Revenue model
- Professional Cybersecurity Consulting Services: Project-based and retainer engagements providing cybersecurity assessments, penetration testing, compliance certifications, and security training. Revenue generated through hourly consulting fees, fixed-price project engagements, and ongoing advisory retainers for managed security services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels4 records
Comsec product offering
Product offeringCore offering
Comsec delivers professional cybersecurity consulting services including penetration testing, red team attack simulations, phishing campaigns, and security testing across applications, mobile, infrastructure, and cloud environments. The firm also provides governance, risk, and compliance certification support for PCI DSS, HIPAA/HITRUST, GDPR, and ISO 27001, alongside advisory services such as 24/7 incident response, CISO-as-a-Service, SSDLC implementation, and security awareness training.
Product overview
Comsec is a cybersecurity services firm offering a comprehensive portfolio of professional security services delivered by experts with over 30 years of experience. The portfolio spans five main categories: (1) Offensive Security including Red Team/Cyber Attack Simulation and Phishing Campaigns; (2) Governance, Risk & Compliance covering GDPR Readiness, PCI-DSS (via certified QSAs), Cybersecurity Health Check, Digital Health Security & Compliance, HIPAA/HITRUST, and ISO 27000 Series Compliance; (3) Security Tests & Assessments including Application Security Testing, Mobile App Security Testing, Secure Code Review, Infrastructure Security Testing, Cloud Security, Design Review, Architecture Review, and Risk Assessment; (4) Education & Training covering Security Awareness Training and Secure Development Training; and (5) Advisory & Managed Services including Incident Response (24/7), CISO as a Service, SSDLC implementation, Secure Coding Guidelines, and Table-Top Cyber Drill simulations. The company operates offices in Tel Aviv, Israel and Amsterdam, Netherlands.
Differentiator
Problem solved
Functional benefit
Products and services
- Red Team - Cyber Attack Simulation
Quantifiable outcome
- 4-6 months to ISO 27001 certification
- +3 more outcomes
Companies that use Comsec
Customer profileSegments5 records
Ideal customer profiles5 records
Comsec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Comsec partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- GetronicscoreGetronics is a global ICT services company headquartered in the Netherlands, employing around 4,000 people across Europe, Asia-Pacific, and Latin America. They serve over 2,000 clients and are a founding member of the Global Workspace Alliance, offering IT solutions in over 180 countries. The partnership provides Comsec with enhanced global reach and access to international markets through Getronics' extensive client network.
- CheckmarxcoreCheckmarx makes software security essential infrastructure unified with DevOps and seamlessly embedded into the entire CI/CD pipeline, from uncompiled code to runtime testing. Their platform sets the new standard for instilling security into modern development methodologies and services. The partnership enhances Comsec's application security offerings with integrated DevSecOps capabilities.
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
Comsec competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-listed cybersecurity consulting firm offering penetration testing, compliance (PCI DSS, ISO 27001), incident response, and managed security services — directly overlapping with Comsec's full-stack service portfolio across enterprise and regulated buyers.
- Bishop Fox: US-based offensive security consultancy specializing in penetration testing, red team operations, and application security — closely mirrors Comsec's Offensive Security and Security Testing pillars.
- Trustwave: Global cybersecurity firm combining managed detection and response, penetration testing, and PCI DSS QSA services — directly comparable to Comsec across GRC, testing, and managed security offerings.
- IOActive: Global security consultancy with strong offensive security, application security testing, and hardware/IoT security practices — directly comparable to Comsec's penetration testing and SSDLC offerings.
- Praetorian: US cybersecurity consultancy offering offensive security, cloud security assessments, and managed detection — directly comparable in offensive security, cloud, and continuous security assessment services.
- Kudelski Security: Swiss-based cybersecurity services firm providing consulting, managed security, and incident response across enterprise and regulated industries — closely comparable in GRC, advisory, and IR services.
- Coalfire: US-based cybersecurity advisory firm specializing in PCI DSS, HITRUST, HIPAA, and FedRAMP compliance assessments — directly comparable to Comsec on regulated-industry GRC services.
Broad incumbents
- Optiv Security: Large US-based cybersecurity solutions integrator offering advisory, managed security, and compliance services across enterprise — competes with Comsec on enterprise GRC and advisory engagements at broader scale.
- Secureworks: Public global MSSP combining managed detection, incident response, and consulting — overlapping with Comsec's advisory/managed services and incident response lines, though at much larger scale.
Emerging players
- SANS Institute: Global cybersecurity training and certification organization whose methodologies (e.g., SANS IR framework) Comsec explicitly follows and leverages — comparable on the training and awareness pillar.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Comsec social profiles
Digital presenceComsec compliance and trust
Trust signalCompliance2 records
Comsec financial estimates
Financial estimateRevenue estimate
Valuation estimate
Comsec leadership team
Management profileNumber of profiles
Profiles2 records
Comsec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Comsec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Comsec
What does Comsec do?
Comsec delivers professional cybersecurity consulting services including penetration testing, red team attack simulations, phishing campaigns, and security testing across applications, mobile, infrastructure, and cloud environments. The firm also provides governance, risk, and compliance certification support for PCI DSS, HIPAA/HITRUST, GDPR, and ISO 27001, alongside advisory services such as 24/7 incident response, CISO-as-a-Service, SSDLC implementation, and security awareness training.
Is Comsec a public or private company?
Comsec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Comsec founded?
Comsec was founded in 1987. It employs 51 to 100 people.
Where is Comsec based?
Comsec is headquartered in Tel Aviv-yafo, Israel, in the Middle East region.
How does Comsec make money?
One revenue line is on record: professional Cybersecurity Consulting Services.
Who are Comsec's main competitors?
Direct peers on record are NCC Group, Bishop Fox, Trustwave, IOActive, Praetorian, Kudelski Security and Coalfire. Broad incumbents are Optiv Security and Secureworks. SANS Institute is listed as an emerging player.
Does Comsec have an API?
No public API is recorded for Comsec.
What industry is Comsec in?
Comsec's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 54151 and its SIC code is 7371.