SecAlliance
SecAlliance is a UK-headquartered cyber threat intelligence firm that delivers managed CTI, the ThreatMatch portal, and regulatory consulting (CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT) to banks, central banks, government agencies, and critical national infrastructure operators across EMEA and Hong Kong.
- Company typePrivate
- Founded2018
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SecAlliance does
SecAlliance (legal entity Security Alliance Limited, UK; Security Alliance B.V., Netherlands) is a pure-play cyber threat intelligence product and services firm headquartered in London at One Canada Square, Canary Wharf, with regional offices in The Hague and Groningen. Founded circa 2018 (firmographics records a 2007 origin), the company employs over 35 CTI professionals and operates within the CSIS Security Group, while being a member of the Allurity family of cybersecurity companies.
The firm serves a systemically critical customer base: banks, central banks and financial market infrastructures; UK government departments and EU agencies; international organisations; and critical national infrastructure operators in telecommunications, power, and transport. Its offering is anchored by ThreatMatch, a proprietary collaborative threat intelligence portal built around the MITRE ATT&CK framework with STIX 2.1 and MISP taxonomy APIs, alongside three core service lines: Managed Cyber Threat Intelligence, Intelligence Sharing community facilitation, and Physical Intelligence for OT-bearing organisations. A consulting arm delivers intelligence-led testing under accredited regulatory frameworks including CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT, and CREST STAR/STAR-FS, supplemented by CTI Maturity, Supply Chain, and Cyber Threat Assessments.
Revenue is generated through subscription managed CTI and ThreatMatch access, multi-year retainers, project-based regulatory consulting engagements, and managed intelligence sharing community services; pricing is entirely quote-based with no public disclosure. Distribution is exclusively direct enterprise sales with a consultative, demo-led motion, supported by thought-leadership content marketing across blog, Twitter, LinkedIn, and YouTube, and PR/earned media. The firm holds ISO 9001 (QMS) and ISO 27001 (ISMS) certifications and positions itself as a founding contributor to CBEST and an early TIBER-EU adopter.
SecAlliance firmographics
Firmographics- Name
- SecAlliance
- Legal name
- Security Alliance Limited
- Website
- https://secalliance.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SecAlliance is a UK-headquartered cyber threat intelligence firm that delivers managed CTI, the ThreatMatch portal, and regulatory consulting (CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT) to banks, central banks, government agencies, and critical national infrastructure operators across EMEA and Hong Kong.
- Ownership category
- akta.pro rank
SecAlliance industry classification
Industry- Product category
- Cyber Threat Intelligence Services
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where SecAlliance is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices3 records
Markets served
SecAlliance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Cyber Threat Intelligence Services: Proactive, targeted, relevant CTI services delivered as ongoing subscriptions or retainer arrangements, providing real-time intelligence tailored to client industry, infrastructure, and mission. Includes threat alerts, threat actor profiles, attack scenarios, and periodic reporting.
- Consulting Engagements: Individual consulting and research engagements for CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT, CREST STAR/STAR-FS, Cyber Threat Assessments, CTI Maturity Assessments, and Supply Chain Threat Assessments. One-time project-based engagements with regulatory frameworks.
- ThreatMatch Portal Subscription: SaaS-style subscription to the ThreatMatch platform providing access to threat alerts, profiles, scenarios, reports, collaboration tools, API integrations, and community features. Delivered as part of ThreatMatch subscription.
- Intelligence Sharing Communities: Facilitation and support of trusted cyber information sharing communities for essential services and industries at sectoral, national, EU and global level. Compliant with DORA requirements for intelligence sharing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Enterprise CTI services - custom pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
SecAlliance product offering
Product offeringCore offering
SecAlliance delivers cyber threat intelligence (CTI) services through managed CTI subscriptions, intelligence sharing community facilitation, physical intelligence, and a proprietary threat intelligence portal (ThreatMatch). The consulting arm runs threat-led penetration testing and threat assessments under regulatory frameworks including CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT, and CREST STAR/STAR-FS for banks, central banks, financial market infrastructures, government agencies, and critical national infrastructure operators.
Product overview
SecAlliance delivers a platform-plus-services portfolio anchored by ThreatMatch, a collaborative threat intelligence portal supporting STIX 2.1 and MISP taxonomies with MITRE ATT&CK integration. The core service suite comprises Managed Cyber Threat Intelligence, Intelligence Sharing, and Physical Intelligence Services. The consulting arm encompasses multiple regulatory testing frameworks: CBEST, TIBER-EU, GBEST, TBEST, iCAST, and DORA TLPT for threat-led penetration testing; supplemented by Supply Chain Threat Assessment, CTI Maturity Assessment, Cyber Threat Assessment, and CREST STAR/STAR-FS services. The portfolio serves banks, central banks, financial market infrastructures, governmental and EU agencies, international organisations, and critical national infrastructure operators.
Differentiator
Problem solved
Functional benefit
Products and services
- ThreatMatch
Quantifiable outcome
- Clear picture of most likely and dangerous threats organisations face
- +3 more outcomes
Companies that use SecAlliance
Customer profileNamed customers5 records
Segments6 records
Ideal customer profiles5 records
SecAlliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
SecAlliance partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- CSIS Security GroupcoreSecAlliance is part of CSIS Security Group, as indicated by the logo 'Logo_SA_partofCSISSecurityGroup_white_v1.svg' displayed on the website. The CSIS Security Group affiliation provides SecAlliance with emergency response consulting capabilities, accessible via csis.com/emergency-response-consulting/.
- Allurity FamilycoreSecAlliance is a member of the Allurity family of companies. This affiliation positions SecAlliance within a broader network of cybersecurity companies. Website states 'Learn more' link to about-us/overview#allurity for additional information on the Allurity relationship.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
SecAlliance competitors and assessment
Company assessmentBroad incumbents
- Recorded Future: Largest independent pure-play threat intelligence platform, now owned by Mastercard. Directly comparable cyber threat intelligence offering with broader data scale, intelligence feeds, and integrations than SecAlliance, but a much larger generalist footprint rather than niche regulatory CTI specialist.
- Mandiant (Google Cloud): Mandiant delivers threat intelligence plus intelligence-led adversary simulation and incident response. Highly comparable to SecAlliance across CTI subscriptions, TLPT-style red team engagements, and financial-sector framework coverage (TIBER-EU, CBEST).
- CrowdStrike (Falcon Intelligence): Endpoint security leader with significant threat intelligence module bundled into its Falcon platform. Overlaps with SecAlliance on financial-sector CTI customers and threat-led assessments, but bundled into a much broader XDR platform rather than a pure-play CTI proposition.
- Palo Alto Networks (Unit 42): Unit 42 provides threat intelligence, incident response, and threat-led red team services comparable to SecAlliance's regulated financial-sector CTI work, but again sits within a much broader cybersecurity platform portfolio.
Direct peers
- EclecticIQ: European-headquartered threat intelligence platform vendor with analyst-led services. Closest direct peer to SecAlliance ThreatMatch on platform and to managed CTI services for government and critical infrastructure clients in EMEA.
- Anomali: Threat intelligence platform with STIX/TAXII and MITRE ATT&CK aligned offerings and managed intelligence services. Comparable threat intelligence portal functionality to ThreatMatch and similar enterprise financial-sector customer base.
- ThreatConnect: Threat intelligence platform combining TIP capabilities with intel-driven analytics and orchestration. Directly comparable to ThreatMatch on STIX/MITRE ATT&CK integration and recurring SaaS delivery of curated CTI.
- Flashpoint: Commercial threat intelligence provider offering finished intelligence, vulnerability intelligence, and physical security intelligence. Comparable mix of cyber and physical intelligence services akin to SecAlliance's combined digital/physical intelligence offering.
- NCC Group: UK-based cybersecurity consultancy with strong CBEST/TIBER-EU accredited threat intelligence and TLPT delivery for financial institutions. One of the most direct competitors for SecAlliance's regulated financial-sector CTI assessments in EMEA.
Others
- CREST (Accreditation Body): Not a competitor but the accreditation body whose CREST STAR/STAR-FS intelligence-led testing framework SecAlliance delivers under. Included as an ecosystem participant that defines demand-side requirements SecAlliance's services are built to satisfy.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
SecAlliance social profiles
Digital presenceSecAlliance compliance and trust
Trust signalCompliance2 records
SecAlliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
SecAlliance leadership team
Management profileNumber of profiles
Profiles1 record
SecAlliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SecAlliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SecAlliance
What does SecAlliance do?
SecAlliance delivers cyber threat intelligence (CTI) services through managed CTI subscriptions, intelligence sharing community facilitation, physical intelligence, and a proprietary threat intelligence portal (ThreatMatch). The consulting arm runs threat-led penetration testing and threat assessments under regulatory frameworks including CBEST, TIBER-EU, GBEST, TBEST, iCAST, DORA TLPT, and CREST STAR/STAR-FS for banks, central banks, financial market infrastructures, government agencies, and critical national infrastructure operators.
Is SecAlliance a public or private company?
SecAlliance is a private company. It is classified as corporate owned and is currently operating.
When was SecAlliance founded?
SecAlliance was founded in 2018. It employs 11 to 50 people.
Where is SecAlliance based?
SecAlliance is headquartered in London, United Kingdom, in the Europe region.
How does SecAlliance make money?
Four revenue lines are on record. Managed Cyber Threat Intelligence Services are the primary driver. The others are consulting Engagements, threatMatch Portal Subscription and intelligence Sharing Communities.
Who are SecAlliance's main competitors?
Broad incumbents on record are Recorded Future, Mandiant (Google Cloud), CrowdStrike (Falcon Intelligence) and Palo Alto Networks (Unit 42). Direct peers are EclecticIQ, Anomali, ThreatConnect, Flashpoint and NCC Group. CREST (Accreditation Body) is listed as an others.
Does SecAlliance have an API?
Yes. ThreatMatch provides API endpoints mapped to STIX 2.1 and MISP taxonomies, with a JSON endpoint for an enriched feed enabling access to all content via preferred security tools. The API is designed for integration with SIEM and SOAR platforms.
What industry is SecAlliance in?
SecAlliance's product category is Cyber Threat Intelligence Services. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services.