Talos
Talos is Cisco Systems' internal threat intelligence research organization, providing reputation data, vulnerability research, and incident response services that power Cisco's global security product portfolio and serve enterprise customers worldwide.
- Company typePrivate
- Founded2000
- HeadquartersFulton, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Talos does
Talos, marketed as Cisco Talos Intelligence Group, is the threat intelligence research organization embedded within Cisco Systems, Inc. Its core function is to produce security intelligence that powers the Cisco security product portfolio and is delivered to enterprise customers globally. Talos operates three primary product lines: the Intelligence Center (a platform providing web reputation scoring, content categorization, sender IP and domain reputation, file reputation lookups, and Snort-based IPS/IDS rules), Vulnerability Research (producing vulnerability reports, Microsoft advisories, and coordinated disclosures, with notable discoveries including CVE-2026-20245 in Cisco SD-WAN Manager and tracking of the UAT-8302 China-nexus APT), and Incident Response Services (spanning reactive emergency support, compromise assessments, threat hunting, and cyber range training). Supporting offerings include open-source security tools and a media portfolio comprising the Beers with Talos and Talos Takes podcasts, the Threat Source Newsletter, the Talos Intelligence Blog, and a YouTube channel.
Technically, Talos combines large-scale telemetry from Cisco's global security product footprint with human security expertise and an emerging AI-augmented workflow layer. The AI layer currently consists of large language models used to index unstructured threat intelligence reports and generate actionable advice, a local AI agent that exposes disassembler internals to assist reverse engineering of binaries, and AI-assisted threat hunting designed to identify adversaries that evade traditional detection thresholds. Talos does not publish proprietary foundation models or training pipelines; AI is positioned as an accelerator for human analysts rather than a replacement.
Commercially, Talos does not operate as a standalone business; it is a wholly owned internal division of Cisco Systems, Inc. (NASDAQ: CSCO). Revenue is not separately disclosed, and threat intelligence is bundled into the broader Cisco security portfolio, distributed through Cisco's enterprise field sales motion. Direct-to-enterprise Incident Response services are sold through quote-based engagements and retainers. Beyond the Cisco channel, Talos has begun to pursue adjacent verticals, evidenced by a January 2026 partnership with Huntington-Ingalls Industries (HII) and Shield AI for autonomous systems development supporting U.S. Navy modernization. The stated customer segments are Cisco security product users (primary) and defense contractors (emerging).
Talos firmographics
Firmographics- Name
- Talos
- Legal name
- Cisco Systems, Inc.
- Website
- https://talosintel.com
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Talos is Cisco Systems' internal threat intelligence research organization, providing reputation data, vulnerability research, and incident response services that power Cisco's global security product portfolio and serve enterprise customers worldwide.
- Ownership category
- akta.pro rank
Talos industry classification
Industry- Product category
- Threat Intelligence & Cybersecurity
- NAICS
- Other Computer Related Services (541519), Security Systems Services (56162)
- SIC
- Services-Services, Nec (8900)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
- akta.pro secondary industries
- Vulnerability Assessment & Scanning (HDADAHAA), Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH), Security Operations (SOC), Incident Response & Threat Hunting (EDAOAIAI)
Keywords
Where Talos is headquartered
LocationHeadquarters
- HQ city
- Fulton
- HQ country
- United States
- HQ region
- North America
Markets served
Talos business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Threat Intelligence Subscription Services: Cisco Talos provides threat intelligence that powers the Cisco security portfolio. Intelligence is delivered through the Intelligence Center platform providing reputation data, vulnerability research, and ongoing security updates to Cisco customers.
- Incident Response Services: Professional incident response services including emergency support, compromise assessments, threat hunting, and cyber range training. These are consultative professional services for organizations experiencing or preparing for security incidents.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
Talos product offering
Product offeringCore offering
Cisco Talos is a threat intelligence research organization that provides comprehensive security intelligence through its Intelligence Center platform (web reputation, content categorization, sender IP and domain reputation analysis, file reputation lookup, and IPS/IDS Snort rules). It also conducts vulnerability research and coordinated disclosure of security flaws, and delivers incident response services including reactive emergency support, proactive compromise assessments, threat hunting, and cyber range training.
Product overview
Cisco Talos is a threat intelligence research organization that provides a unified platform of security products and services. The core offerings include the Intelligence Center (providing web reputation, content categorization, and file/IP reputation analysis), Vulnerability Research (producing security advisories and reports), and Incident Response services (covering both reactive emergency response and proactive threat hunting). Supporting offerings include Open Source Security Tools and media products (Beers with Talos Podcast, Talos Takes Podcast, and Threat Source Newsletter). The portfolio is designed to deliver comprehensive protection through intelligence gathering, vulnerability analysis, and incident response capabilities.
Differentiator
Problem solved
Functional benefit
Brands
- Beers with Talos: Podcast featuring security experts discussing threat trends, vulnerability discoveries, and security news
- Talos Takes
- Talos Intelligence Blog
Products and services
- Intelligence Center
- Vulnerability Research
- Incident Response
Quantifiable outcome
- 686% increase in malicious n8n webhook emails detected in March 2025 compared to January 2025
Companies that use Talos
Customer profileSegments2 records
Ideal customer profiles2 records
Talos technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature5 records
Talos partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Huntington-Ingalls Industries (HII)coreHuntington-Ingalls Industries announced a technology partnership with Talos for autonomous systems development as part of the Navy's advanced capabilities strategy. This partnership was announced alongside other technology partnerships with Shield AI, positioning Talos as a key technology contributor to HII's defense contracting work for Navy modernization programs.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Talos competitors and assessment
Company assessmentDirect peers
- Recorded Future (Mastercard): Recorded Future is a leading commercial threat intelligence platform acquired by Mastercard for $2.6B. It provides machine-analyst threat data, vulnerability intelligence, and brand/reputation feeds that directly compete with Talos's Intelligence Center capabilities.
- Mandiant (Google Cloud): Mandiant is the most direct peer: a global threat intelligence and incident response firm (acquired by Google for $5.4B) offering emergency IR, compromise assessments, threat hunting, and frontline intelligence — directly overlapping Talos's IR and intel portfolio for the same enterprise buyer.
- CrowdStrike Intelligence: CrowdStrike's threat intelligence team combines adversary tracking, malware analysis, and intelligence embedded in the Falcon platform, competing head-to-head with Talos for enterprise intel and IR budgets, particularly in endpoint-heavy environments.
- Secureworks: Secureworks delivers managed detection, threat hunting, and incident response powered by its Counter Threat Unit research — a pure-play MSSP with in-house threat intel, comparable in mission and customer base to Talos's IR and proactive services.
- Palo Alto Networks Unit 42: Unit 42 is Palo Alto Networks' threat intelligence and incident response group, bundling intel, vulnerability research, and IR services the same way Talos does for Cisco — a direct structural twin and the closest large-vendor analog.
Emerging players
- Group-IB: Group-IB combines threat intelligence, fraud hunting, and incident response with strong research output — an emerging global peer to Talos, particularly relevant for EMEA and APAC threat coverage, and competing for the same high-end IR retainers.
- Anomali: Anomali is a threat intelligence platform vendor offering TIP, threat feeds, and detection analytics that overlap with the data-layer side of Talos's Intelligence Center, though without the same scale of embedded telemetry.
Broad incumbents
- Microsoft Threat Intelligence Center (MSTIC): MSTIC is Microsoft's global threat intelligence organization providing intelligence that powers Defender, Sentinel, and Azure security — the broadest incumbent analog to Talos in scale and product integration, embedded in a hyperscaler rather than a network/security vendor.
Others
- Mandiant Advantage / Google Cloud Security Operations: Google Cloud's broader security operations stack, including Chronicle and Mandiant Advantage, consumes and productizes threat intelligence at hyperscaler scale — an adjacent platform that both competes for intelligence-driven security spend and depends on the kind of intel Talos produces.
Regional players
- Kaspersky GReAT: Kaspersky's Global Research and Analysis Team is one of the most prolific APT research groups in the world, comparable to Talos in vulnerability disclosure cadence and reverse engineering depth, though its primary market and geographic restrictions differ from Talos's.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Talos social profiles
Digital presenceTalos financial estimates
Financial estimateRevenue estimate
Valuation estimate
Talos leadership team
Management profileNumber of profiles
Profiles1 record
Talos funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Talos M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Talos
What does Talos do?
Cisco Talos is a threat intelligence research organization that provides comprehensive security intelligence through its Intelligence Center platform (web reputation, content categorization, sender IP and domain reputation analysis, file reputation lookup, and IPS/IDS Snort rules). It also conducts vulnerability research and coordinated disclosure of security flaws, and delivers incident response services including reactive emergency support, proactive compromise assessments, threat hunting, and cyber range training.
Is Talos a public or private company?
Talos is a private company. It is classified as corporate owned and is currently operating.
When was Talos founded?
Talos was founded in 2000. It employs 1 to 10 people.
Where is Talos based?
Talos is headquartered in Fulton, United States, in the North America region.
How does Talos make money?
Two revenue lines are on record. Threat Intelligence Subscription Services are the primary driver. The others are incident Response Services.
Who are Talos's main competitors?
Direct peers on record are Recorded Future (Mastercard), Mandiant (Google Cloud), CrowdStrike Intelligence, Secureworks and Palo Alto Networks Unit 42. Emerging players are Group-IB and Anomali. Microsoft Threat Intelligence Center (MSTIC) is listed as a broad incumbent. Mandiant Advantage / Google Cloud Security Operations is listed as an others. Kaspersky GReAT is listed as a regional player.
Does Talos have an API?
No public API is recorded for Talos.
What industry is Talos in?
Talos's product category is Threat Intelligence & Cybersecurity. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting, with a secondary code of HDADAHAA, Vulnerability Assessment & Scanning. Its NAICS code is 541519 and its SIC code is 8900.