Secure Ideas
Secure Ideas is a CREST-accredited penetration testing and information security consulting firm founded in 2010, serving Fortune 100 enterprises, federal contractors, and SMBs with offensive security services, a subscription-based PETaaS testing platform, and expert witness support.
- Company typePrivate
- Founded2010
- HeadquartersOrange Park, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Secure Ideas does
Secure Ideas, operating under the 'Professionally Evil' brand, is a CREST-accredited penetration testing and information security consulting firm founded in 2010 by Kevin Tackett (formerly Kevin Johnson) and headquartered in Jacksonville, Florida. The firm delivers offensive security services — network, web application, mobile, API, red team, purple team, physical, and IoT penetration testing — alongside expert witness services for legal proceedings and a CISSP mentorship training program. Core technology assets include the PETaaS (Professionally Evil Testing as a Service) subscription platform, three productized 'Scout' modules (CloudScout, NetworkScout, WebScout) for continuous cloud, network, and web application monitoring, and proprietary tools such as ASERepCatcher, the BILE Classification Scheme, and the open-source SamuraiWTF training environment.
The firm operates on a professional-services-plus-recurring-revenue model. Penetration tests are quoted per project (typical range $10,000-$45,000) at a published $340/hour rate, while PETaaS bundles ongoing advisory and flexible testing credits into subscription engagements. Secure Ideas monetizes through direct enterprise sales, a tiered Silver/Gold/Platinum reseller partner program for MSPs and VARs, and a federal government teaming program for prime contractors. Notable client signals include 50+ Fortune 100 logos over 15 years, an 85 NPS, and verticals spanning enterprise, federal contractors, PCI-regulated organizations, and small-to-medium businesses.
The leadership bench — Kevin Tackett (CEO, SANS course author and OWASP Global Board member), Britiney Tackett (CRO), Jeff Man (Executive Director PCI, former NSA cryptanalyst), and Principal Security Consultant Eric Kuehn (former technical leader for one of the world's largest banks' Active Directory infrastructure) — provides defensible domain authority. The firm contributes extensively to open-source security tooling and runs two podcasts and an extensive technical blog, generating inbound pipeline through thought leadership rather than paid marketing.
Secure Ideas firmographics
Firmographics- Name
- Secure Ideas
- Legal name
- Secure Ideas LLC
- Website
- https://secureideas.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Secure Ideas is a CREST-accredited penetration testing and information security consulting firm founded in 2010, serving Fortune 100 enterprises, federal contractors, and SMBs with offensive security services, a subscription-based PETaaS testing platform, and expert witness support.
- Ownership category
- akta.pro rank
Secure Ideas industry classification
Industry- Product category
- Penetration Testing and Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where Secure Ideas is headquartered
LocationHeadquarters
- HQ city
- Orange Park
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Secure Ideas business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Penetration Testing Services: Core revenue stream from various penetration testing services including network, web application, mobile, API, red team, purple team, physical, and IoT testing. Billed at $340/hour with typical project costs between $10,000-$45,000. Includes deliverables such as detailed reports, executive summaries, and attestation letters.
- Security Consulting & Advisory: Ongoing advisory services bundled with PETaaS offering. Provides continuous security guidance, remediation support, and strategic security consulting.
- Training Services: Security training programs including CISSP mentorship, classes, and corporate training. Instructor-led and self-paced options available.
- Testing as a Service (PETaaS): Subscription-based testing credits model providing ongoing penetration testing, cloud monitoring (CloudScout), network scanning (NetworkScout), and web application testing (WebScout) on a recurring basis.
- Expert Witness Services: Legal expert witness services for court cases involving cybersecurity matters, including testimony and documentation support.
- Vulnerability Management: Vulnerability identification and management consulting services to enhance security posture.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Hourly consulting rate of $340 per hour for security services |
| Outcome Based/ Performance | Multi-year contract | Penetration testing project base cost: $10,000-$45,000 |
| Other | Annual | Partner program tiered discount structure: Silver, Gold, Platinum |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
Secure Ideas product offering
Product offeringCore offering
Secure Ideas delivers penetration testing, security assessments, and advisory services across network, web, mobile, API, cloud, IoT, physical, and red team/purple team attack surfaces, supported by the PETaaS subscription model and proprietary Scout testing tools (CloudScout, NetworkScout, WebScout). The firm combines hands-on offensive security testing with continuous advisory, dark web monitoring, vulnerability management, expert witness services, and cybersecurity training (including CISSP mentorship) for enterprise, government, and SMB clients.
Product overview
Secure Ideas, operating under the Professionally Evil brand, is a penetration testing and information security consulting firm offering a portfolio of security testing services and products. The core offering is PETaaS® (Professionally Evil Testing as a Service), a flagship product providing ongoing advisory services and flexible penetration testing. This flagship service is complemented by specialized Scout products including CloudScout, NetworkScout, and WebScout, which focus on specific attack surfaces (cloud infrastructure, networks, and web applications respectively). The company also offers Threat Exposure Management for dark web monitoring. Beyond products, the portfolio includes professional services such as Penetration Testing, Consulting & Advisory Services, Expert Witness Services, Security Assessments, Vulnerability Management, Training, and a CISSP Mentorship Program.
Differentiator
Problem solved
Functional benefit
Brands
- PETaaS: Professionally Evil Testing as a Service - flagship product offering ongoing advisory services and flexible penetration testing.
- CloudScout
- NetworkScout
- WebScout
Products and services
- PETaaS (Professionally Evil Testing as a Service) Subscription-based ongoing advisory and flexible penetration testing service offering continuous security posture improvement and risk reduction through testing credits and advisory services for organizations needing continuous offensive security engagement.
Quantifiable outcome
- Net Promoter Score of 85 indicating high customer satisfaction
- +2 more outcomes
Companies that use Secure Ideas
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles5 records
Secure Ideas technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
Secure Ideas partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- MSPs and VARs (Managed Service Providers and Value-Added Resellers)corePartner program aligns with IT service organizations including MSPs and VARs to augment their service offerings and realize new growth opportunities while strengthening client security posture. Partners receive access to subject matter experts, discounted service rates, partner portal, training access, and private Slack communication.
- Federal Government ContractorscoreTeaming partnerships for government contractors pursuing federal contracts. Secure Ideas provides capabilities statements, past performance documentation, and subcontractor support for winning and performing government security contracts.
- IANS ResearchminorCEO Kevin Johnson serves as a faculty member at IANS, providing cybersecurity training and thought leadership through this research and training organization.
- OWASP (Open Web Application Security Project)coreKevin Johnson served as Vice-Chair and was elected to OWASP Global Board. Jason Gillam serves on OWASP Project committee and leads SamuraiWTF project. Company actively contributes to OWASP Top 10, Security Knowledge Framework, and other open projects.
- SANS InstituteminorKevin Johnson served as instructor and author for SANS Institute, creating SEC542, SEC642, and SEC571 courses. Jason Gillam also associated with SANS training programs.
- BSides OklahomaminorSenior consultant Aaron Moss is co-founder and organizer of BSides Oklahoma, the state's largest information security/hacker conference.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Secure Ideas competitors and assessment
Company assessmentDirect peers
- TrustedSec: Cybersecurity consulting firm specializing in penetration testing, incident response, and advisory services. Comparable mid-sized boutique serving enterprise and government clients with similar subscription and project-based offerings.
- Trail of Bits: Security consulting firm offering penetration testing, security audits, and custom security engineering. Comparable boutique with similar thought-leadership brand, conference presence, and developer-focused technical depth.
- Praetorian: Offensive security and attack surface management firm offering penetration testing, red team, and continuous security testing. Comparable in service portfolio, customer base, and subscription-oriented offerings.
- Bishop Fox: Leading boutique offensive security firm offering penetration testing, red teaming, and attack surface management to Fortune 500 enterprises. Closest comparable to Secure Ideas in service mix, customer profile, and boutique premium positioning.
- NetSPI: Penetration testing as a service platform with proprietary technology (Resolve) for continuous offensive security testing. Direct competitor to Secure Ideas' PETaaS subscription model, serving Fortune 500 and large enterprises.
- Coalfire: Large cybersecurity advisory firm with deep penetration testing and PCI compliance practices. Direct peer particularly relevant given Secure Ideas' PCI practice expansion with Jeff Man.
- Schellman Compliance: Major cybersecurity assessment firm combining penetration testing with extensive compliance practice. Overlapping customer base with Secure Ideas in regulated industries and SaaS companies.
Broad incumbents
- Rapid7: Public cybersecurity platform offering vulnerability management, pen testing (Metasploit, Managed Pen Testing services), and broader security operations. Larger incumbent absorbing parts of the boutique pen testing value chain.
- NCC Group: Global cybersecurity consulting firm with extensive penetration testing, red team, and managed security services. Broader incumbent with overlapping capabilities but much larger scale and global footprint than Secure Ideas.
- Schellman & Co. Top-tier cybersecurity assessment and compliance firm with significant penetration testing practice alongside SOC 2, ISO 27001, and PCI services. Adjacent competitor in compliance-focused security testing for enterprise and SaaS clients.
Market position
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Secure Ideas social profiles
Digital presenceSecure Ideas financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secure Ideas leadership team
Management profileNumber of profiles
Profiles28 records
Secure Ideas funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secure Ideas M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secure Ideas
What does Secure Ideas do?
Secure Ideas delivers penetration testing, security assessments, and advisory services across network, web, mobile, API, cloud, IoT, physical, and red team/purple team attack surfaces, supported by the PETaaS subscription model and proprietary Scout testing tools (CloudScout, NetworkScout, WebScout). The firm combines hands-on offensive security testing with continuous advisory, dark web monitoring, vulnerability management, expert witness services, and cybersecurity training (including CISSP mentorship) for enterprise, government, and SMB clients.
Is Secure Ideas a public or private company?
Secure Ideas is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secure Ideas founded?
Secure Ideas was founded in 2010. It employs 11 to 50 people.
Where is Secure Ideas based?
Secure Ideas is headquartered in Orange Park, United States, in the North America region.
How does Secure Ideas make money?
Six revenue lines are on record. Penetration Testing Services are the primary driver. The others are security Consulting & Advisory, training Services, testing as a Service (PETaaS), expert Witness Services and vulnerability Management.
Who are Secure Ideas's main competitors?
Direct peers on record are TrustedSec, Trail of Bits, Praetorian, Bishop Fox, NetSPI, Coalfire and Schellman Compliance. Broad incumbents are Rapid7, NCC Group and Schellman & Co..
Does Secure Ideas have an API?
No public API is recorded for Secure Ideas.
What industry is Secure Ideas in?
Secure Ideas's product category is Penetration Testing and Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 54151 and its SIC code is 7371.