ORPHEUS CYBER
Orpheus Cyber is a UK Government-accredited cyber threat intelligence SaaS provider delivering ML-driven, externally observable cyber risk scores and third-party risk management to enterprises, governments, financial institutions, and cyber insurers across the UK and US.
- Company typePrivate
- Founded2015
- HeadquartersDevizes, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What ORPHEUS CYBER does
Orpheus Cyber Limited is a UK-registered (company number 10499131) cybersecurity firm headquartered in London with a US regional office in McLean, Virginia. The company positions itself as the only UK Government-accredited cyber threat intelligence provider and serves enterprise security teams, government agencies, financial institutions, cyber insurers, and managed security service providers across the UK, US, and broader global market. Its product portfolio spans six core SaaS modules — External Attack Surface Management, Third-Party Risk Management (with an integrated Security Questionnaire), Cyber Insurance Solutions, Risk-Based Vulnerability Management, Cyber Threat Intelligence, and Regulatory Compliance (covering DORA, NIS2, ISO 27001) — complemented by four professional services covering intelligence-led testing, advisory, training, and bespoke intelligence. The platform's principal differentiator is its proprietary Orpheus Vulnerability Severity Score (OVSS) and externally observable cyber risk scoring model, which uses machine learning to convert real-time threat signals into dynamic risk scores; this model is independently validated by Gallagher Re, a leading global reinsurance broker, as predictive of real-world cyber claims.
Underlying the platform is a combination of machine learning models, real-time threat signal analysis, and externally observable attack surface data, producing risk scores without reliance on self-reported questionnaires. Orpheus holds an unusually broad UK accreditation stack — including CREST, CBEST, TBEST, STAR-FS, STAR Threat Intelligence, CTIPs, Bank of England CBEST Approved status, FCA Accredited Supplier, Crown Commercial Service, and Cyber Essentials Plus — positioning it for government, defence, and regulated financial-sector work. The business model is freemium-led SaaS subscription via the Orpheus Portal (orpheus-portal.com), layered with quote-based enterprise contracts and a multi-channel distribution architecture that includes direct enterprise field sales (UK and US), UK mid-market distribution through Alpha Generation, embedded integrations with third-party risk platforms (Achilles, Aravo), insurance broker/carrier channels (DUAL North America, Lockton Re), and a retail platform integration (Virtualstock). Strategic positioning is reinforced by the 2021 SC Magazine 'Best Use of Machine Learning/AI' award, three finalist nominations at the Cyber Insurance Awards USA 2026, and inclusion in Lockton Re's cyber risk scoring report.
ORPHEUS CYBER firmographics
Firmographics- Name
- ORPHEUS CYBER
- Legal name
- Orpheus Cyber Limited
- Website
- https://orpheus-cyber.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Orpheus Cyber is a UK Government-accredited cyber threat intelligence SaaS provider delivering ML-driven, externally observable cyber risk scores and third-party risk management to enterprises, governments, financial institutions, and cyber insurers across the UK and US.
- Ownership category
- akta.pro rank
ORPHEUS CYBER industry classification
Industry- Product category
- Cybersecurity Risk Intelligence Software
- NAICS
- Other Computer Related Services (541519), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Threat Intelligence Platforms (TIP) (HDADAGAD)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
Keywords
Where ORPHEUS CYBER is headquartered
LocationHeadquarters
- HQ city
- Devizes
- HQ country
- United Kingdom
- HQ region
- Europe
Offices3 records
Markets served
ORPHEUS CYBER business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription Platform: Orpheus delivers its cyber threat intelligence and risk scoring as a cloud-based platform subscription, accessed via the Orpheus Portal. Customers can start a free trial and upgrade to paid plans for ongoing monitoring, reporting, and third-party risk management.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free trial available for initial risk assessment |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels7 records
ORPHEUS CYBER product offering
Product offeringCore offering
Orpheus Cyber provides a UK Government-accredited SaaS platform for cyber risk scoring and threat intelligence, combining machine learning with human analyst expertise to deliver dynamic cyber risk scores, external attack surface monitoring, third-party risk management, risk-based vulnerability prioritisation, and regulatory compliance mapping (DORA, NIS2, ISO 27001). The platform is complemented by professional services including intelligence-led security testing, advisory, training, and bespoke intelligence. Scores are independently validated by Gallagher Re as predictive of real-world cyber incidents.
Product overview
Orpheus Cyber is a UK Government-accredited cyber threat intelligence provider offering an integrated SaaS platform for cyber risk ratings and threat intelligence. The core portfolio consists of six interconnected solution modules: External Attack Surface Management, Third-Party Risk Management (with Security Questionnaire), Cyber Insurance Solutions, Risk-Based Vulnerability Management, Cyber Threat Intelligence, and Regulatory Compliance. These are complemented by four professional services: Intelligence-Led Security Testing, Advisory Services, Intelligence-Driven Training, and Bespoke Intelligence Solutions. The platform uses machine learning and AI to deliver predictive analytics, translating real-time threat signals into dynamic Cyber Risk Scores that are independently validated by Gallagher Re as predictive of real-world cyber incidents.
Differentiator
Problem solved
Functional benefit
Products and services
- External Attack Surface Management Discovers how hackers perceive an organisation by continuously monitoring the external attack surface beyond vulnerabilities, prioritising high-risk issues, validating security measures, and uncovering shadow IT. For CISOs, IT directors, and security teams needing to understand their real-world risk landscape.
- Third-Party Risk Management A threat-led platform that continuously monitors and assesses third-party attack surfaces, displaying risks in an intuitive heat map with detailed intelligence reports. Enables swift onboarding and risk mitigation within hours. For procurement, vendor risk, and supply chain security teams managing third-party cyber risk at scale.
- Cyber Insurance Solutions Cyber risk scores validated by Gallagher Re and other leading insurance firms as predictive of real-world cyber incidents, enabling insurers to improve underwriting, pricing, and policy evaluation. For cyber insurance underwriters, reinsurers, and brokers.
- Risk-Based Vulnerability Management Predictive intelligence that dynamically prioritises risks using the Orpheus Vulnerability Severity Score (OVSS), which updates in real-time, leveraging machine learning alongside threat intelligence to predict future exploitations. For IT directors, vulnerability managers, and security operations teams.
- Cyber Threat Intelligence Machine-learning models validated by analysts surface threats relevant to organisations and suppliers, enabling teams to act on what matters when it matters with real-time intelligence. For SOC teams, MSSPs, and threat intelligence analysts.
- Regulatory Compliance Maps DORA, NIS2, and ISO 27001 to real-world risk with evidence from the platform, then tracks remediation to keep audits straightforward for regulated organisations. For DPOs, compliance leaders, and regulatory teams.
- Intelligence-Led Security Testing Advisory service providing intelligence-led penetration testing and security assessments using real-world threat intelligence to guide testing priorities. For organisations requiring CREST/CBEST-aligned assurance testing.
- Advisory Services Consulting services helping organisations develop cyber risk management strategies, implement security improvements, and align with regulatory requirements such as DORA, NIS2, and ISO 27001. For CISOs and security leadership teams.
- Intelligence-Driven Training Training services that build organisational capacity in cyber threat intelligence, risk assessment, and security awareness using the company's intelligence expertise. For SOC teams and security analysts.
- Bespoke Intelligence Solutions Custom intelligence solutions tailored to specific organisational needs, including investigations, research, and targeted threat assessments. For organisations with unique threat profiles or custom requirements.
Quantifiable outcome
- Organisations in Orpheus' highest-risk tier are 3.2x more likely to suffer a ransomware claim (validated by Gallagher Re)
- +2 more outcomes
Companies that use ORPHEUS CYBER
Customer profileNamed customers8 records
Segments8 records
Ideal customer profiles6 records
ORPHEUS CYBER technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability5 records
Feature5 records
ORPHEUS CYBER partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core.
- Gallagher RecoreGallagher Re, one of the world's leading reinsurance brokers, independently validated Orpheus' cyber risk scoring model. Their analysis confirmed that organisations in Orpheus' highest-risk tier are 3.2x more likely to suffer ransomware incidents and 2.3x more likely to suffer other cyber attacks. This validation is a foundational credibility signal for Orpheus' insurance sector value proposition.
- DUAL North AmericacoreDUAL North America announced a strategic collaboration with Orpheus Cyber to bring unprecedented insights and proactive solutions to cyber risk management. Through cutting-edge threat intelligence and continuous monitoring, Orpheus Cyber empowers DUAL's brokers and carrier partners to stay ahead of potential threats and vulnerabilities, taking a proactive approach to cybersecurity.
- AchillescoreAchilles partnered with Orpheus to offer supply chain cyber risk management and intelligence, integrating Orpheus' validated risk ratings into Achilles' supply chain assessment ecosystem.
- Alpha GenerationcoreAlpha Generation was selected by Orpheus as its UK distribution partner, reselling and distributing Orpheus' cyber threat intelligence and award-winning cyber risk ratings to the UK mid-market and broader channel.
- AravocoreAravo and Orpheus Cyber partnered to effectively manage third-party security risks, integrating Orpheus' threat-led cyber risk ratings into Aravo's third-party risk management platform.
- Lockton RecoreOrpheus Cyber was featured in Lockton Re's groundbreaking report on cyber risk scoring technologies, positioning Orpheus as a recognised player in the reinsurance and cyber insurance risk scoring ecosystem.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
ORPHEUS CYBER competitors and assessment
Company assessmentDirect peers
- BitSight: BitSight is the most direct competitor to Orpheus in external cyber risk ratings and third-party risk management. Both deliver externally observable security ratings used by enterprises and insurers, but BitSight operates at a much larger scale with broader geographic coverage.
- SecurityScorecard: SecurityScorecard is a direct competitor offering cyber risk ratings, attack surface intelligence, and third-party risk management. Both companies target CISOs, insurers, and procurement teams with continuous externally observable risk scoring.
- Panorays: Panorays provides third-party cyber risk management combining external attack surface scanning with questionnaire automation, competing directly with Orpheus' Third-Party Risk Management module and Security Questionnaire add-on.
- UpGuard: UpGuard delivers third-party risk management and cyber risk ratings for enterprises and their vendors, overlapping directly with Orpheus' TPRM and EASM capabilities for enterprise customers.
- Black Kite: Black Kite specialises in cyber risk quantification for the insurance market using external scanning and the FAIR methodology, directly overlapping with Orpheus' Cyber Insurance Solutions and predictive scoring validated by reinsurers.
Emerging players
- Kovrr: Kovrr provides enterprise cyber risk quantification for insurers and large enterprises, addressing the same underwriting and portfolio risk management use cases as Orpheus' Cyber Insurance Solutions module but from a pure quantification angle.
- CyberCube: CyberCube delivers cyber risk analytics specifically for the insurance industry, including portfolio management and single-risk modelling. Orpheus competes for the same insurer/broker budget, though CyberCube is more software-suite focused and Orpheus is more risk-rating focused.
- RiskLens: RiskLens is a cyber risk quantification platform built on the FAIR standard, serving CISOs and insurance underwriters. It overlaps with Orpheus' risk scoring and insurance solutions but uses a fundamentally different (probabilistic) methodology.
Broad incumbents
- Recorded Future: Recorded Future (now Mastercard) is a leading threat intelligence platform that competes with Orpheus' Cyber Threat Intelligence product, but operates at a much larger scale with broader intelligence feeds and broader enterprise/government customer bases.
- Tenable: Tenable is a broad vulnerability management and exposure platform incumbent whose Risk-Based Vulnerability Management capabilities overlap with Orpheus' OVSS-driven predictive vulnerability prioritisation. Tenable brings a much larger installed base but a less insurance-validated scoring approach.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
ORPHEUS CYBER social profiles
Digital presenceORPHEUS CYBER compliance and trust
Trust signalCompliance11 records
ORPHEUS CYBER financial estimates
Financial estimateRevenue estimate
Valuation estimate
ORPHEUS CYBER leadership team
Management profileNumber of profiles
ORPHEUS CYBER funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ORPHEUS CYBER M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ORPHEUS CYBER
What does ORPHEUS CYBER do?
Orpheus Cyber provides a UK Government-accredited SaaS platform for cyber risk scoring and threat intelligence, combining machine learning with human analyst expertise to deliver dynamic cyber risk scores, external attack surface monitoring, third-party risk management, risk-based vulnerability prioritisation, and regulatory compliance mapping (DORA, NIS2, ISO 27001). The platform is complemented by professional services including intelligence-led security testing, advisory, training, and bespoke intelligence. Scores are independently validated by Gallagher Re as predictive of real-world cyber incidents.
Is ORPHEUS CYBER a public or private company?
ORPHEUS CYBER is a private company. It is classified as unknown and is currently operating.
When was ORPHEUS CYBER founded?
ORPHEUS CYBER was founded in 2015. It employs 11 to 50 people.
Where is ORPHEUS CYBER based?
ORPHEUS CYBER is headquartered in Devizes, United Kingdom, in the Europe region.
How does ORPHEUS CYBER make money?
One revenue line is on record: saaS Subscription Platform.
Who are ORPHEUS CYBER's main competitors?
Direct peers on record are BitSight, SecurityScorecard, Panorays, UpGuard and Black Kite. Emerging players are Kovrr, CyberCube and RiskLens. Broad incumbents are Recorded Future and Tenable.
Does ORPHEUS CYBER have an API?
No public API is recorded for ORPHEUS CYBER.
What industry is ORPHEUS CYBER in?
ORPHEUS CYBER's product category is Cybersecurity Risk Intelligence Software. Its primary akta.pro industry code is HDADAGAD, Threat Intelligence Platforms (TIP), with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 541519 and its SIC code is 7373.