Tangible Security
Tangible Security is a private U.S. cybersecurity consulting firm, founded in 1998, delivering penetration testing, GRC/FedRAMP/CMMC advisory, incident response, secure development, and security training to government, defense, healthcare, financial, energy, and technology clients globally.
- Company typePrivate
- Founded1998
- HeadquartersColumbia, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Tangible Security does
Tangible Security is a privately held cybersecurity consulting firm headquartered in Knightdale, North Carolina, founded in 1998 and operating with 101-250 employees. The firm delivers five core practice areas: Penetration and Security Testing (network, web, mobile, IoT, cloud, ICS/OT), Governance/Risk/Compliance (including fractional CISO, FedRAMP and CMMC advisory, ISO 27001, HIPAA, PCI DSS, SOC 2, GDPR/CCPA), Incident Response and Digital Forensics, Secure Development Lifecycle and Security Engineering, and Security Training. It also develops proprietary software — most notably the ProV Common Access Card Smart Card Access Software licensed to the U.S. Department of Defense — and publishes educational content including the 'Preparing for AI Compliance' eBook and a dedicated AI Application Penetration Testing service module evaluating AI and LLM vulnerabilities.
The business model is predominantly professional services engagement-based, with multi-year contracts, custom pricing, free estimates, and a price-match guarantee. Go-to-market combines direct enterprise sales with a Partner/Reseller program and a paid referral program, supplemented by content marketing (blog, webinars, eBooks, datasheets), social channels (LinkedIn, X, YouTube), and industry events. The firm markets to six primary verticals — Government and Defense Contractors, Technology and Software, Healthcare, Energy and Manufacturing, Financial Services, and Nonprofits/Education — with named engagements spanning the Georgia Tech Foundation, City of Greensboro NC, a large gas utility, a casino corporation, a UK insurer, a Japan-based medical/industrial device manufacturer, a Fortune 500 building materials supplier, a global financial institution, and global industrial manufacturers. International delivery is supported via teams in Poland and India for global clients across the UK, Japan, EU, and other regions.
Tangible Security firmographics
Firmographics- Name
- Tangible Security
- Legal name
- Tangible Security
- Website
- https://tangiblesecurity.com
- Company type
- Private
- Founded year
- 1998
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Tangible Security is a private U.S. cybersecurity consulting firm, founded in 1998, delivering penetration testing, GRC/FedRAMP/CMMC advisory, incident response, secure development, and security training to government, defense, healthcare, financial, energy, and technology clients globally.
- Ownership category
- akta.pro rank
Tangible Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where Tangible Security is headquartered
LocationHeadquarters
- HQ city
- Columbia
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Tangible Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Cybersecurity Services: Core revenue from consulting engagements including penetration testing, vulnerability assessments, security program assessments, incident response, digital forensics, and compliance consulting. Services are typically project-based with custom pricing.
- Security Training: Revenue from security awareness training, secure development training, technical security training, and compliance/regulatory training programs
- Staff Augmentation: Revenue from providing cybersecurity talent including fractional CISO services, security team augmentation, and remediation services
- Software Products: Revenue from ProV Smart Card Access Software licensing for the Department of Defense
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
Tangible Security product offering
Product offeringCore offering
Tangible Security is a professional services firm that delivers customized cybersecurity consulting across penetration testing, governance/risk/compliance, incident response and forensics, secure development lifecycle, and security training. The company provides fractional CISO services, FedRAMP/CMMC advisory, and remediation support to government agencies, defense contractors, and commercial enterprises. Tangible also licenses its proprietary ProV Common Access Card Software to the U.S. Department of Defense.
Product overview
Tangible Security is a full-service cybersecurity consulting firm offering a comprehensive portfolio of services organized around five core practice areas: Penetration and Security Testing, Governance/Risk/Compliance, Incident Response and Forensics, Secure Development Lifecycle and Security Engineering, and Security Training. The company also develops proprietary software (ProV Common Access Card Software for the DoD) and provides educational resources (AI Compliance eBook). Services are delivered by certified cybersecurity experts through direct consulting engagements, assessments, and training programs. The firm specializes in both offensive security testing (network, application, mobile, IoT, cloud, ICS/OT) and defensive security services (GRC, compliance, incident response, security engineering).
Differentiator
Problem solved
Functional benefit
Brands
- ProV Common Access Card Software: Smart Card Access Software for the Department of Defense
Products and services
- Penetration and Security Testing Services Comprehensive penetration testing services including network, web application, mobile application, product/IoT, cloud security, and ICS/OT penetration testing, along with vulnerability assessments, source code reviews, red/purple team exercises, social engineering testing, and physical security assessments. Delivered by certified cybersecurity experts for organizations that need to identify and remediate security weaknesses before attackers exploit them.
- Governance, Risk Management & Compliance Services GRC consulting including fractional CISO services, security program development, compliance gap assessments, FedRAMP and CMMC advisory, secure supply chain assessments, and human cyber risk management. Targeted at organizations needing to comply with CMMC, FedRAMP, HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, and SOX.
- Incident Response and Forensics Incident response program assessment, plan and playbook development, tabletop exercises, compromise assessments, triage and analysis, and digital forensics services. Provides breach response capabilities and proactive readiness work for organizations that need to manage cyber incidents and forensic investigations.
- Secure Development Lifecycle and Security Engineering SDLC services, threat modeling, secure design and architecture review, security controls and configuration review, security team augmentation, and remediation services. Helps software-driven organizations build secure products and remediate identified vulnerabilities.
- Security Training Services Security awareness training, phishing/social engineering simulation, secure development training, technical security training, compliance and regulatory training, and GRC management training. Delivered to organizations looking to address human cyber risk and upskill technical staff.
- ProV Common Access Card Software Smart card access software customized for the Department of Defense providing Common Access Card (CAC) authentication and access control capabilities. Sold via licensing to a single government customer.
Quantifiable outcome
- Short-term remediation verification testing included at no additional cost
Companies that use Tangible Security
Customer profileNamed customers12 records
Segments6 records
Ideal customer profiles6 records
Tangible Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
Tangible Security partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered community.
- Blue Angels FoundationcommunityBlue Angels Foundation supports America's wounded veterans from all services, focusing on the continuum of care from military discharge to civilian career. Tangible Security supports this nonprofit working with wounded veterans.
- Neighbor2NeighborcommunityNeighbor to Neighbor is a nonprofit 501(c)(3) community development organization in Raleigh's Southpark community. Tangible is helping develop their Teen STEM Center and serving as one of the first sponsors for the STEM center initiative, supporting youth STEM education.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Tangible Security competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-headquartered cybersecurity consultancy offering penetration testing, managed detection, incident response, and GRC advisory to government and enterprise — directly comparable services portfolio and buyer profile to Tangible Security.
- Bishop Fox: Boutique offensive-security firm specializing in penetration testing, red teaming, and security consulting for Fortune 500 and high-growth tech — directly comparable to Tangible's offensive-security-led service mix.
- Coalfire: U.S. cybersecurity advisory firm focused on FedRAMP, CMMC, HITRUST, and PCI compliance, plus penetration testing — closely overlaps with Tangible's GRC and federal compliance practice.
- Optiv: Large U.S. security solutions integrator delivering advisory, managed security, and offensive testing to enterprises — competes with Tangible on the same enterprise GTM motion and service stack.
- Mandiant (Google Cloud): Premier incident response, threat intelligence, and security consulting firm — directly comparable to Tangible's IR, forensics, and security assessment offerings.
- Trustwave: Global cybersecurity firm delivering managed detection, penetration testing, and GRC services to enterprise and government — broad overlap with Tangible's service lines.
- Secureworks: Managed security services and consulting provider with strong incident response and compliance advisory practices — competes with Tangible across IR, GRC, and offensive security.
- Schellman & Co. Top-tier compliance and audit-focused firm (SOC 2, ISO 27001, FedRAMP, HITRUST) — overlaps directly with Tangible's GRC and compliance gap assessment services.
Broad incumbents
- Booz Allen Hamilton: Large federal and defense consulting firm with a substantial cyber practice serving DoD and intelligence community — competes for the same federal cyber mandates that anchor Tangible's public-sector work.
- ManTech International (now Constellis): Federal IT and cybersecurity services provider with deep DoD/IC customer footprint — directly comparable buyer base and contract profile to Tangible's defense work.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Tangible Security social profiles
Digital presenceTangible Security compliance and trust
Trust signalCompliance9 records
Tangible Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Tangible Security leadership team
Management profileNumber of profiles
Profiles5 records
Tangible Security funding detail
Funding detailFunding overview
Funding rounds1 record
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Tangible Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Tangible Security
What does Tangible Security do?
Tangible Security is a professional services firm that delivers customized cybersecurity consulting across penetration testing, governance/risk/compliance, incident response and forensics, secure development lifecycle, and security training. The company provides fractional CISO services, FedRAMP/CMMC advisory, and remediation support to government agencies, defense contractors, and commercial enterprises. Tangible also licenses its proprietary ProV Common Access Card Software to the U.S. Department of Defense.
Is Tangible Security a public or private company?
Tangible Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Tangible Security founded?
Tangible Security was founded in 1998. It employs 101 to 250 people.
Where is Tangible Security based?
Tangible Security is headquartered in Columbia, United States, in the North America region.
How does Tangible Security make money?
Four revenue lines are on record. Professional Cybersecurity Services are the primary driver. The others are security Training, staff Augmentation and software Products.
Who are Tangible Security's main competitors?
Direct peers on record are NCC Group, Bishop Fox, Coalfire, Optiv, Mandiant (Google Cloud), Trustwave, Secureworks and Schellman & Co.. Broad incumbents are Booz Allen Hamilton and ManTech International (now Constellis).
Does Tangible Security have an API?
No public API is recorded for Tangible Security.
What industry is Tangible Security in?
Tangible Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics). Its NAICS code is 5616 and its SIC code is 8700.