Redscan
Redscan, a London-based cybersecurity services firm founded in 2015 and acquired by Kroll in 2025, provides Managed Detection and Response, CREST Penetration Testing, Red Teaming, and Breach and Attack Simulation for enterprise buyers and M&A due diligence.
- Company typePrivate
- Founded2015
- HeadquartersLondon, United Kingdom
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Redscan does
Redscan is a UK-headquartered cybersecurity services provider founded in 2015 and based in London. The company delivers Managed Detection and Response, CREST-accredited Penetration Testing, and Red Teaming services, and was acquired by global risk consultancy Kroll in 2025, at which point it became a subsidiary within Kroll's cybersecurity portfolio. Its customer targeting spans organizations conducting M&A transactions requiring technical cybersecurity due diligence, alongside enterprises needing continuous security validation.
The company's core technology centers on Breach and Attack Simulation (BAS) for exposure management and security-control validation. This capability has been repositioned from traditional point-in-time testing use cases toward continuous, operational validation of security controls, with the stated differentiator being accuracy and precision in simulated attack execution. Redscan has also been positioned within the cybersecurity M&A due-diligence segment as one of 20 profiled vendors offering technical validation of acquisition targets' cyber postures. Industry recognition includes a 2025 placement on CybersecurityNews' Top 50 Best Penetration Testing Companies list.
Redscan operates on a professional-services revenue model, monetizing through direct enterprise engagements rather than disclosed product or subscription pricing. Its go-to-market is sales-led and enterprise-focused, delivered through direct engagement with buyers requiring cybersecurity assessments for M&A transactions and broader security-control validation. The leadership team includes Mark Nicholls as CTO, Tom Cox as VP of Platform Architecture for Cyber Risk, and Mike Fenton as Managing Director.
Redscan firmographics
Firmographics- Name
- Redscan
- Website
- https://redscan.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Short description
- Redscan, a London-based cybersecurity services firm founded in 2015 and acquired by Kroll in 2025, provides Managed Detection and Response, CREST Penetration Testing, Red Teaming, and Breach and Attack Simulation for enterprise buyers and M&A due diligence.
- Ownership category
- akta.pro rank
Redscan industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Security Incident Response (IR) & Digital Forensics Services (BPAEADAI)
- akta.pro secondary industry
- Breach & Attack Simulation (BAS) (HDADAHAD)
Keywords
Where Redscan is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Markets served
Redscan business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Due Diligence Services: Professional cybersecurity assessment services for M&A transactions, providing technical validation of security postures for acquiring organizations
Go-to-market motion1 record
Distribution channels1 record
Redscan product offering
Product offeringCore offering
Redscan provides managed cybersecurity services including Managed Detection and Response (MDR), CREST-accredited penetration testing, and red team engagements, as well as cybersecurity due diligence assessments for M&A transactions. The firm also operates Breach and Attack Simulation (BAS) capabilities to validate security controls and exposure management for enterprise customers.
Product overview
Redscan is a cybersecurity company that was acquired by Kroll. Based on the available sources, the company provides penetration testing services and cybersecurity due diligence services for mergers and acquisitions transactions. The specific product portfolio details are not available from the provided source content, which primarily consists of third-party news articles and a website loading page that could not be fully accessed.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Detection and Response (MDR)
- CREST Penetration Testing
- Red Teaming
- Cybersecurity Due Diligence for M&A
- Breach and Attack Simulation (BAS)
Companies that use Redscan
Customer profileSegments1 record
Ideal customer profiles2 records
Redscan technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Redscan partnerships and signals
Strategic signalScale indicators2 records
Recent moves4 records
Expansion highlights4 records
Redscan competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-headquartered cybersecurity services firm offering CREST-accredited penetration testing, red teaming, and managed detection services to enterprise and government clients; highly comparable geographic and service overlap with Redscan.
- F-Secure (WithSecure): European cybersecurity services and MDR provider offering penetration testing, managed detection and response, and exposure management; competes directly with Redscan in mid-market and enterprise European accounts.
- Secureworks: MSSP and MDR provider with managed detection, incident response, and adversarial testing services; competes with Redscan in the MDR and offensive security services market for mid-market and enterprise.
- Bishop Fox: Specialist offensive security firm offering penetration testing, red teaming, and attack surface management; a close comparable to Redscan's red teaming and pen testing practice.
- Pen Test Partners: UK-based CREST-accredited penetration testing and red teaming consultancy serving enterprise clients; direct competitor in the UK pen testing market alongside Redscan.
Broad incumbents
- Mandiant (Google Cloud): Global incident response, MDR, and cyber threat intelligence leader, now part of Google Cloud; competes with Redscan on MDR and IR services at the enterprise tier and sets pricing benchmarks in the market.
- CrowdStrike: Endpoint and MDR heavyweight with a growing services arm including penetration testing, red teaming, and exposure management; overlaps with Redscan across MDR and BAS-adjacent validation use cases.
- Rapid7: Cybersecurity analytics and managed services provider offering MDR, vulnerability management, and pen testing services; comparable managed services and exposure validation positioning to Redscan.
- Orange Cyberdefense: European MSSP with managed detection, incident response, and offensive security services; broad incumbent with overlapping offerings in the same geographies Redscan serves.
Others
- Kroll Cyber Risk: Parent organization's cyber risk practice, providing incident response, digital forensics, and risk advisory; relevant as the internal peer post-acquisition and as the route through which Redscan's services are now distributed.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Redscan social profiles
Digital presenceRedscan financial estimates
Financial estimateRevenue estimate
Valuation estimate
Redscan leadership team
Management profileNumber of profiles
Profiles3 records
Redscan funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Redscan M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Redscan
What does Redscan do?
Redscan provides managed cybersecurity services including Managed Detection and Response (MDR), CREST-accredited penetration testing, and red team engagements, as well as cybersecurity due diligence assessments for M&A transactions. The firm also operates Breach and Attack Simulation (BAS) capabilities to validate security controls and exposure management for enterprise customers.
Is Redscan a public or private company?
Redscan is a private company. It is classified as corporate owned and is currently acquired.
When was Redscan founded?
Redscan was founded in 2015. It employs 51 to 100 people.
Where is Redscan based?
Redscan is headquartered in London, United Kingdom, in the Europe region.
How does Redscan make money?
One revenue line is on record: cybersecurity Due Diligence Services.
Who are Redscan's main competitors?
Direct peers on record are NCC Group, F-Secure (WithSecure), Secureworks, Bishop Fox and Pen Test Partners. Broad incumbents are Mandiant (Google Cloud), CrowdStrike, Rapid7 and Orange Cyberdefense. Kroll Cyber Risk is listed as an others.
Does Redscan have an API?
No public API is recorded for Redscan.
What industry is Redscan in?
Redscan's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAI, Security Incident Response (IR) & Digital Forensics Services, with a secondary code of HDADAHAD, Breach & Attack Simulation (BAS). Its NAICS code is 561621 and its SIC code is 8734.