Redlegg
RedLegg is a privately held, Chicago-based managed cybersecurity services provider founded in 2008 that delivers MDR, penetration testing, identity, and advisory services to healthcare, financial services, legal, and manufacturing enterprises.
- Company typePrivate
- Founded2008
- HeadquartersGeneva, Switzerland
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Redlegg does
RedLegg, operated by Illinois-domiciled parent entity GLW Specialty, is a managed cybersecurity services provider founded in 2008 and headquartered in Chicago. The firm delivers a portfolio built around Managed Detection and Response (MDR), packaged in four tiers: MDR with Managed SIEM, MDR with Managed EDR, MDR Complete, and MDR Cyberfusion. The MDR backbone is supplemented by an Automation-as-a-Service module powered by SOAR/XSOAR playbooks and a Phishing Response service that pairs automated email enrichment with analyst review. The 2024 operational footprint includes approximately 250,000 cases handled and 12,000 threats escalated, with reported average Mean Time to Detect for critical alerts of 4 minutes 54 seconds.
Redlegg firmographics
Firmographics- Name
- Redlegg
- Legal name
- GLW Specialty
- Website
- https://redlegg.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- RedLegg is a privately held, Chicago-based managed cybersecurity services provider founded in 2008 that delivers MDR, penetration testing, identity, and advisory services to healthcare, financial services, legal, and manufacturing enterprises.
- Ownership category
- akta.pro rank
Redlegg industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Management Consulting Services (8742)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Data Security & Privacy Services (DLP, Encryption, Privacy Ops) (BPAKAHAM)
Keywords
Where Redlegg is headquartered
LocationHeadquarters
- HQ city
- Geneva
- HQ country
- Switzerland
- HQ region
- Europe
Offices1 record
Markets served
Redlegg business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Detection and Response (MDR): Recurring subscription-based managed security services including 24/7 monitoring, threat detection, and incident response. Sold as MDR with Managed SIEM, MDR with Managed EDR, MDR Complete, and MDR Cyberfusion tiers.
- Penetration Testing Services: One-time and recurring security assessment services including network, application, physical, and continuous penetration testing, as well as vulnerability scanning.
- Advisory Services: Strategic security consulting including vCISO services, tabletop exercises, GRC gap assessments, HIPAA risk assessments, and NIST CSF assessments.
- Identity Services: Identity and access management, identity governance and administration, and privileged access management solutions.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise pricing based on organization requirements |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels6 records
Redlegg product offering
Product offeringCore offering
RedLegg provides managed cybersecurity services led by a 24/7 Security Operations Center, offering Managed Detection and Response tiers combined with managed SIEM, managed EDR, and SOAR-driven automation. The portfolio is complemented by penetration testing (network, application, physical, continuous, SCADA, vulnerability scanning), identity services (IAM, IGA, PAM), and advisory services (vCISO, tabletop exercises, GRC, HIPAA, NIST CSF, and business impact assessments) for enterprise and regulated-industry clients.
Product overview
RedLegg is a managed cybersecurity services provider offering a modular MDR (Managed Detection and Response) platform as its core offering, with multiple service delivery options including MDR with Managed SIEM, MDR with Managed EDR, MDR Complete, and MDR Cyberfusion. These MDR tiers are supplemented by add-on modules including Automation-as-a-Service (SOAR-powered playbook automation), Phishing Response, and dedicated OT Cybersecurity for Manufacturing services. Beyond MDR, the portfolio spans four additional service lines: Penetration Testing (covering network, application, physical, continuous, SCADA, and vulnerability scanning), Identity Services (IAM, IGA, PAM), Advisory Services (vCISO, Tabletop Exercises, GRC Gap Assessment, HIPAA Risk Assessment, Business Impact Analysis, NIST CSF Assessment, and Cyber Incident Response & Digital Forensics), and Threat Intelligence. The MDR services form the central platform while the penetration testing, identity, and advisory offerings operate as complementary service pillars.
Differentiator
Problem solved
Functional benefit
Products and services
- MDR with Managed SIEM Managed Detection and Response service combined with Security Information and Event Management, providing 24/7 monitoring, threat detection, and centralized log analysis for enterprise IT environments.
- MDR with Managed EDR Managed Detection and Response paired with Endpoint Detection and Response, providing real-time endpoint monitoring and threat mitigation at the device level for organizations.
- MDR Complete Comprehensive MDR service combining SIEM and EDR capabilities with full Security Operations Center support for integrated threat detection and response across all environments.
- MDR Cyberfusion Advanced MDR offering that integrates cyber fusion capabilities to correlate threats across multiple data sources and accelerate incident response workflows.
- Automation-as-a-Service Customized, scalable automation solutions powered by SOAR technology (including XSOAR) that enhance security operations efficiency, reduce response times, and handle repetitive alert triage through playbook-driven automation.
- Phishing Response Service combining automated email enrichment with expert human analysis to investigate suspicious emails, decide on ambiguous threats, and execute response actions quickly.
- Network Penetration Testing Assessment services that uncover vulnerabilities in network infrastructure through simulated attacks targeting external and internal network security controls.
- Application Assessment Security testing service evaluating web applications and software for vulnerabilities including injection flaws, authentication weaknesses, and business-logic issues.
- Physical Penetration Testing Testing service evaluating physical security controls including building access, badge systems, and social-engineering vectors to identify physical security gaps.
- Continuous Penetration Testing Ongoing penetration testing service providing persistent vulnerability discovery and validation without the limitations of point-in-time assessments.
- Vulnerability Scanning Automated scanning service identifying known vulnerabilities across network assets, applications, and systems on a recurring basis.
- SCADA Penetration Testing Specialized penetration testing for Industrial Control Systems and SCADA environments that identifies vulnerabilities in operational technology without disrupting manufacturing operations.
- Identity & Access Management Cloud-based identity management service providing centralized access control, authentication, and user lifecycle management for enterprise environments.
- Identity Governance and Administration Service providing access reviews, role management, and compliance controls for identity governance that ensure least-privilege access across systems handling sensitive data.
- Privileged Access Management Service securing elevated access rights through session monitoring, credential management, and just-in-time access provisioning for critical systems.
- vCISO Virtual Chief Information Security Officer service providing strategic security leadership, custom-tailored security programs, and executive-level guidance for organizations lacking dedicated CISO resources.
- Tabletop Exercise Facilitated discussion-based cybersecurity incident simulation validating incident response plans, uncovering operational gaps, and strengthening team readiness through realistic scenario rehearsals.
- GRC Gap Assessment Governance-based gap assessment evaluating security controls against industry frameworks to identify compliance deficiencies and prioritize remediation efforts.
- HIPAA Risk Assessment Risk assessment for healthcare organizations evaluating security and privacy controls against the HIPAA Security, Privacy, and Breach Notification Rules.
- Business Impact Analysis Assessment analyzing potential business consequences of disruptions to identify critical functions, recovery priorities, and resilience requirements.
- NIST CSF Assessment Assessment evaluating organizational security posture against the NIST Cybersecurity Framework to identify gaps, maturity levels, and prioritize improvements aligned with NIST standards.
- Cyber Incident Response & Digital Forensics Incident response and digital forensics service providing scope investigation, root-cause analysis, and compliance-required forensics for suspected security incidents.
- OT Cybersecurity for Manufacturing Specialized operational technology security service for industrial environments, including OT threat detection, SCADA security testing, and NIST 800-82 aligned risk assessments for manufacturing operations.
- Threat Intelligence Intelligence-driven security service providing evidence-based knowledge about threats, emerging hazards, and indicators of compromise to support proactive defense strategies.
Quantifiable outcome
- Average MTTD for critical alerts: 4:54 minutes
- +3 more outcomes
Companies that use Redlegg
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
Redlegg technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability4 records
Feature5 records
Redlegg partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core.
- ExabeamcoreTechnology partnership for security information and event management (SIEM) and behavioral analytics integration within RedLegg's MDR services.
- TenablecoreTechnology partnership for vulnerability management and exposure management platform integration.
- Palo Alto NetworkscoreTechnology partnership for next-generation firewall, cloud security, and SOC automation integration.
- DelineacoreTechnology partnership for privileged access management (PAM) integration within identity services.
- CrowdStrikecoreTechnology partnership for endpoint protection and EDR integration within managed detection and response services.
- Trend MicrocoreTechnology partnership for hybrid cloud security and endpoint protection integration.
- VezacoreTechnology partnership for data security platform and authorization management integration.
- Horizon3.aicoreTechnology partnership for autonomous penetration testing and attack surface management integration.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Redlegg competitors and assessment
Company assessmentDirect peers
- Arctic Wolf Networks: A leading pure-play MDR / managed security operations provider offering 24/7 SOC-as-a-service to mid-market and enterprise customers. Directly comparable to RedLegg's MDR with Managed SIEM and MDR Complete offerings, including a similar vertical-focused go-to-market and recurring subscription model.
- Expel: Transparent MDR provider combining managed detection and response with SOAR-driven automation for mid-market and enterprise customers. Competes head-to-head with RedLegg's MDR and Automation-as-a-Service offerings, particularly for organizations seeking fast onboarding and integrated remediation.
- eSentire: Pure-play MDR provider with 24/7 SOC, threat hunting, and managed vulnerability services targeting mid-market and enterprise clients. Closely comparable to RedLegg's core MDR portfolio and recurring managed services revenue model.
- Pondurance: Mid-market-focused MDR and digital forensics provider with strong regulatory and compliance expertise across healthcare and financial services. Directly comparable to RedLegg in vertical mix (Healthcare, Financial) and the combination of MDR with advisory/compliance services.
- Binary Defense: MDR provider specializing in 24/7 SOC operations, threat hunting, and managed EDR/SIEM for mid-market organizations. Closely comparable to RedLegg on operational model, technology partner mix, and target customer profile.
Broad incumbents
- Secureworks: Established global MSSP offering MDR, vulnerability management, and incident response at large-enterprise scale. A broader incumbent than RedLegg but overlapping significantly in managed detection, SOC operations, and compliance-driven advisory services.
- Rapid7 (Managed Services): Public cybersecurity vendor offering managed detection and response alongside its InsightIDR/XDR platform. Overlaps with RedLegg's MDR with Managed EDR and vulnerability management offerings as part of a broader product suite.
- CrowdStrike (Falcon Complete MDR): Endpoint security market leader that also offers Falcon Complete, a fully managed MDR service built on its own platform. A dual-role counterpart to RedLegg — both a critical EDR technology partner and a competing managed service provider.
- Trustwave: Global MSSP delivering MDR, managed security testing, and GRC advisory services. Comparable to RedLegg's full-stack portfolio (MDR, penetration testing, advisory) at a larger scale across enterprise and government clients.
- ReliaQuest: Enterprise-focused security operations platform provider combining MDR, SIEM, SOAR, and threat intelligence. Overlaps with RedLegg's MDR Cyberfusion tier and integrated SOAR/automation capabilities, though at a much larger enterprise scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Redlegg social profiles
Digital presenceRedlegg compliance and trust
Trust signalCompliance11 records
Redlegg financial estimates
Financial estimateRevenue estimate
Valuation estimate
Redlegg leadership team
Management profileNumber of profiles
Profiles5 records
Redlegg funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Redlegg M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Redlegg
What does Redlegg do?
RedLegg provides managed cybersecurity services led by a 24/7 Security Operations Center, offering Managed Detection and Response tiers combined with managed SIEM, managed EDR, and SOAR-driven automation. The portfolio is complemented by penetration testing (network, application, physical, continuous, SCADA, vulnerability scanning), identity services (IAM, IGA, PAM), and advisory services (vCISO, tabletop exercises, GRC, HIPAA, NIST CSF, and business impact assessments) for enterprise and regulated-industry clients.
Is Redlegg a public or private company?
Redlegg is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Redlegg founded?
Redlegg was founded in 2008. It employs 51 to 100 people.
Where is Redlegg based?
Redlegg is headquartered in Geneva, Switzerland, in the Europe region.
How does Redlegg make money?
Four revenue lines are on record. Managed Detection and Response (MDR) is the primary driver. The others are penetration Testing Services, advisory Services and identity Services.
Who are Redlegg's main competitors?
Direct peers on record are Arctic Wolf Networks, Expel, eSentire, Pondurance and Binary Defense. Broad incumbents are Secureworks, Rapid7 (Managed Services), CrowdStrike (Falcon Complete MDR), Trustwave and ReliaQuest.
Does Redlegg have an API?
No public API is recorded for Redlegg.
What industry is Redlegg in?
Redlegg's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 54151 and its SIC code is 7370.