Onward Security
- Company typePrivate
- Founded2014
- HeadquartersTaipei, Taiwan
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
Onward Security firmographics
Firmographics- Name
- Onward Security
- Legal name
- Onward Security Corp.
- Website
- https://onwardsecurity.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Ownership category
- akta.pro rank
Onward Security industry classification
Industry- Product category
- Cybersecurity Compliance Testing & Assessment
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Security Systems Services (56162)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Cybersecurity Architecture & Security Integration (BPAEAAAL)
- akta.pro secondary industries
- Security Awareness, Training & Compliance Attestation (HDADAIAJ), Vulnerability Management, Pen Testing & Attack Surface Management (ASM) (HLACAJAN), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where Onward Security is headquartered
LocationHeadquarters
- HQ city
- Taipei
- HQ country
- Taiwan
- HQ region
- Asia
Offices1 record
Markets served
Onward Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Testing and Assessment Services: Professional penetration testing, vulnerability assessment, and security testing services for IoT devices, industrial control systems, automotive, medical devices, and enterprise networks. Services include CREST authorized penetration testing, CTIA IoT cybersecurity certification testing, and compliance testing against international standards (IEC 62443, ETSI EN 303 645, FIPS 140-3).
- Security Assessment Products: Sale and licensing of HERCULES security assessment platform products including SecDevice (IoT vulnerability testing), SecSAM (security assessment management), and SecFlow (product security management). Products use AI and machine learning for automated vulnerability detection.
- Cybersecurity Training and Education: Training services covering cybersecurity standards and compliance including EN 18031, FIPS 140-3, IEC 62443-3-3, ISO/SAE 21434, UK PSTI, mobile app security testing, and general cybersecurity awareness training.
- Compliance and Certification Consulting: Consulting services for international cybersecurity certification including IEC 62443, ISO 15408 (Common Criteria), ETSI EN 303 645, FIPS 140-3, FDA medical device cybersecurity, and EU RED-DA compliance. Helps manufacturers obtain security certifications for global market access.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Enterprise Professional Services |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Onward Security product offering
Product offeringCore offering
Onward Security delivers IoT and connected-device cybersecurity testing, assessment, and certification services paired with the HERCULES product suite (SecSAM for open-source and SBOM risk management, SecDevice for AI-driven IoT vulnerability and fuzz testing, SecDDoS for distributed denial-of-service simulation, and SecFlow for SSDLC and product security management). It also operates ISO 17025-accredited laboratories holding Asia-exclusive accreditations such as CTIA Authorized Test Lab, Amazon Alexa authorized lab, and CREST recognition to issue international cybersecurity certifications for manufacturers.
Product overview
Onward Security provides a comprehensive IoT cybersecurity compliance solution platform consisting of AI-powered security assessment products and professional testing services. The core product portfolio includes HERCULES SecSAM (open-source risk management and SBOM platform), HERCULES SecDevice (AI-powered IoT vulnerability testing tool with patented machine learning technology), SecDDoS (DDoS simulation and monitoring system), and SecFlow (product security management system for SSDLC). These products work together to enable organizations to manage open-source software risks, detect known and unknown vulnerabilities, automate security workflows, and maintain continuous security monitoring throughout the product lifecycle. Complementing the product suite are professional services including CREST-accredited penetration testing, red team exercises, enterprise security assessments, DDoS defense training, and product security evaluations. The company operates Asia's most comprehensive cybersecurity testing laboratory with international certifications for testing services across network security, OT security, medical devices, cryptographic security, and Alexa integration.
Differentiator
Problem solved
Functional benefit
Products and services
- HERCULES SecSAM (Security Assessment Management System) Security Assessment Management platform that manages open-source software risk and Software Bill of Materials (SBOM) for organizations developing connected products and software, integrating third-party vulnerability reports, CI/CD tool integration, and vulnerability management, tracking, and warning throughout the software development lifecycle.
- HERCULES SecDevice (IoT Vulnerability Testing Tool) Automated security assessment tool for connected IoT products featuring vulnerability testing, fuzz testing, and web security testing, equipped with patented AI machine learning technology that accelerates vulnerability discovery across 140+ security test items covering IEC 62443, OWASP TOP 10, and CWE/SANS TOP 25.
- SecDDoS (Distributed DDoS Simulation and Monitoring System) Distributed denial-of-service drilling (simulation) and monitoring system that helps organizations simulate DDoS attacks and monitor network resilience against such attacks, designed for enterprise security and operations teams.
- SecFlow (Product Security Management System) Product security management system that helps organizations link development, security, and maintenance teams to establish Secure Software Development Lifecycle (SSDLC), with security flow management, vulnerability database management, and proactive product security event monitoring and reporting.
- Penetration Testing & Red Team Services CREST-accredited penetration testing and vulnerability assessment services for systems, networks, mobile applications, and IoT devices, integrating architecture review, static code analysis, and performance testing into a comprehensive security assessment engagement.
- Enterprise Cybersecurity Diagnostics (Security Health Check) Enterprise cybersecurity assessment service that identifies internal and external security issues and delivers security audits, education, and training solutions for enterprise customers.
- DDoS Attack and Defense Training (Drill Service) DDoS attack and defense drill service designed to ensure enterprise information security protections are operating correctly to block distributed denial-of-service attacks.
- Product Security Assessment Service Security assessment service for connected products covering vulnerability testing, compliance verification, and support for international security certifications.
- HERMAS Cybersecurity Testing Laboratory ISO 17025-accredited cybersecurity testing laboratory offering comprehensive assessment services for IoT, industrial, automotive, medical, and consumer devices with international certifications across network security, OT security, medical devices, cryptographic security, and Alexa integration.
- Cybersecurity Standards Training Programs Structured training services covering cybersecurity standards and compliance topics including EN 18031, FIPS 140-3, IEC 62443-3-3, ISO/SAE 21434, UK PSTI, mobile application security testing, and general cybersecurity awareness training for enterprise teams.
Quantifiable outcome
- Vulnerability processing time reduced from 2-3 months to 2 weeks
- +3 more outcomes
Companies that use Onward Security
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles6 records
Onward Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability4 records
Feature4 records
Onward Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- DEKRAflagshipOnward Security was acquired by DEKRA in March 2023, becoming part of the DEKRA family. This acquisition expanded DEKRA's cybersecurity portfolio and testing accreditations globally. Onward Security provides comprehensive security compliance solutions for automotive, healthcare, industrial, and consumer IoT markets as a DEKRA company.
Scale indicators11 records
Recent moves7 records
Expansion highlights6 records
Onward Security competitors and assessment
Company assessmentBroad incumbents
- DEKRA: Parent company and global testing, inspection, and certification leader (€3.7B revenue, 60+ countries). Directly comparable as a testing/certification conglomerate; Onward Security is its Asia cybersecurity arm.
- TÜV SÜD: Global testing and certification company offering cybersecurity certification services for IoT, industrial, automotive, and medical devices. Competes for the same enterprise certification engagements, particularly under IEC 62443 and ISO/SAE 21434.
- TÜV Rheinland: Global TIC provider with active cybersecurity testing and certification practice across IoT, automotive, and industrial verticals. Direct competitor in regulated device cybersecurity testing.
- UL Solutions: Global safety science organization with cybersecurity testing and certification capabilities, including IoT (UL MCV 1376) and industrial standards. Overlaps with Onward Security's testing lab offerings.
- SGS: World's largest testing, inspection, and certification company with growing cybersecurity and connected device practice. Competes for international IoT certification engagements.
- BSI Group: Global standards and certification body (originator of many ISO standards) with active IoT and cybersecurity certification services. Direct competitor for IEC 62443 and ISO 27001 testing engagements.
Direct peers
- NCC Group: UK-based cybersecurity services firm providing penetration testing, vulnerability assessment, and IoT/connected device security testing under CREST accreditation. Closely aligned with Onward Security's CREST pen testing and red team practice.
Emerging players
- Riscure: Specialist in security testing and vulnerability analysis for embedded devices, smart cards, and IoT products. Direct comparable in IoT device vulnerability assessment tooling and lab services.
- atsec information security: Specialized cybersecurity testing and evaluation lab focused on Common Criteria (ISO 15408), FIPS 140-3, and payment security. Direct overlap with Onward Security's cryptographic and Common Criteria certification work.
- Fime: Global testing and consulting lab for payments, mobile, IoT, and identity, with security evaluation and certification services. Comparable in regulated device security testing and certification scope.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Onward Security social profiles
Digital presenceOnward Security compliance and trust
Trust signalCompliance17 records
Onward Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Onward Security leadership team
Management profileNumber of profiles
Profiles3 records
Onward Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Onward Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Onward Security
What does Onward Security do?
Onward Security delivers IoT and connected-device cybersecurity testing, assessment, and certification services paired with the HERCULES product suite (SecSAM for open-source and SBOM risk management, SecDevice for AI-driven IoT vulnerability and fuzz testing, SecDDoS for distributed denial-of-service simulation, and SecFlow for SSDLC and product security management). It also operates ISO 17025-accredited laboratories holding Asia-exclusive accreditations such as CTIA Authorized Test Lab, Amazon Alexa authorized lab, and CREST recognition to issue international cybersecurity certifications for manufacturers.
Is Onward Security a public or private company?
Onward Security is a private company. It is classified as corporate owned and is currently acquired.
When was Onward Security founded?
Onward Security was founded in 2014. It employs 51 to 100 people.
Where is Onward Security based?
Onward Security is headquartered in Taipei, Taiwan, in the Asia region.
How does Onward Security make money?
Four revenue lines are on record. Cybersecurity Testing and Assessment Services are the primary driver. The others are security Assessment Products, cybersecurity Training and Education and compliance and Certification Consulting.
Who are Onward Security's main competitors?
Broad incumbents on record are DEKRA, TÜV SÜD, TÜV Rheinland, UL Solutions, SGS and BSI Group. NCC Group is listed as a direct peer. Emerging players are Riscure, atsec information security and Fime.
Does Onward Security have an API?
No public API is recorded for Onward Security.
What industry is Onward Security in?
Onward Security's product category is Cybersecurity Compliance Testing & Assessment. Its primary akta.pro industry code is BPAEAAAL, Cybersecurity Architecture & Security Integration, with a secondary code of HDADAIAJ, Security Awareness, Training & Compliance Attestation. Its NAICS code is 54151 and its SIC code is 7373.