GMO Cybersecurity by Ierae
GMO Cybersecurity by Ierae is a Japan-based offensive cybersecurity subsidiary of GMO Internet Group offering vulnerability assessment, penetration testing, ASM SaaS tools (Netde Shindan), managed SOC, and incident response to enterprises, financial institutions, and SMBs primarily in Japan.
- Company typePrivate
- Founded2013
- HeadquartersTokyo, Japan
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What GMO Cybersecurity by Ierae does
GMO Cybersecurity by Ierae is a Japan-based offensive cybersecurity firm operating as a subsidiary of GMO Internet Group (TSE: 9449). Formed in 2023 from the combination of GMO Internet Group's infrastructure with Ierae Security's elite white-hat talent, the company delivers vulnerability assessment, penetration testing, managed SOC, incident response, and security consulting alongside a recurring-revenue SaaS product line. It serves large enterprises, financial institutions, manufacturers, telecommunications carriers, government agencies, and SMB customers, and holds the No. 1 domestic market share in web application vulnerability diagnosis, smartphone application vulnerability diagnosis, and penetration testing per ITR Market View 2025, plus three consecutive DEF CON Cloud Village CTF world championships (2023–2025).
The core technology portfolio combines two subscription SaaS tools — Netde Shindan ASM (Attack Surface Management) for external asset discovery and continuous vulnerability monitoring, and Netde Shindan for Web Apps (reimplemented OWASP ZAP with custom signatures and reproduction-code reporting) — with the proprietary SOLOBAN SIEM, which uses a Security Event Metadata (SEM) architecture on AWS Athena to convert analyst knowledge into automated detection rules delivered across WAF platforms. WAF Aid operationalizes this for AWS WAF and Cloudflare. The company also maintains a CVE research pipeline (269+ filings across Windows, macOS, and other platforms) that feeds back into detection signatures.
Commercially, revenue is generated through a hybrid model: subscription SaaS (¥40,000/month Self-Service and ¥120,000/month Accompaniment plans), professional services (manual pentesting across web, mobile, cloud, network, IoT, red team, and physical categories, plus AI security testing), managed SOC services with 24/7 monitoring, and Ierae Academy training (OSCP and incident response courses). GTM is sales-led with a direct enterprise motion, a no-quota channel partner program covering network equipment resellers, cloud SIs, and financial-sector service providers, and bundling into the GMO Internet Group hosting/domain ecosystem for SMB reach.
GMO Cybersecurity by Ierae firmographics
Firmographics- Name
- GMO Cybersecurity by Ierae
- Legal name
- GMOサイバーセキュリティ byイエラエ株式会社
- Website
- https://gmo-cybersecurity.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- GMO Cybersecurity by Ierae is a Japan-based offensive cybersecurity subsidiary of GMO Internet Group offering vulnerability assessment, penetration testing, ASM SaaS tools (Netde Shindan), managed SOC, and incident response to enterprises, financial institutions, and SMBs primarily in Japan.
- Ownership category
- akta.pro rank
GMO Cybersecurity by Ierae industry classification
Industry- Product category
- Cybersecurity Services and Vulnerability Management
- NAICS
- Computer Facilities Management Services (541513), Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Cybersecurity Operations Outsourcing (SOC / SecOps) (BPAEAMAG)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Cybersecurity Architecture & Security Integration (BPAEAAAL), Cybersecurity Support Operations (SOC Triage, Incident Intake) (BPAAACAF)
Keywords
Where GMO Cybersecurity by Ierae is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices2 records
Markets served
GMO Cybersecurity by Ierae business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Vulnerability Assessment and Penetration Testing Services: Manual security assessment services performed by world-class white hat hackers. Covers web application, mobile app, cloud, network, IoT, red team, and physical penetration testing.
- ネットde診断 ASM (Self-serve SaaS tool): Subscription-based ASM tool with two tiers: Self-Service Plan (¥40,000/month) and Accompaniment Plan (¥120,000/month). Revenue from monthly/annual subscriptions with pricing per domain/site.
- SOC (Security Operations Center) Services: Managed SOC services including 24/7 monitoring, alert analysis, threat response, and second opinion services for logs from any vendor or product.
- AI Security Services: AI-specific threat assessment including prompt injection and privilege escalation testing for AI applications and agents.
- Ierae Academy (Security Training): Offensive security certification courses (OSCP) and incident response training programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Self-Service Plan (自走プラン): Tool-only usage for basic vulnerability scanning |
| Subscription | Monthly | Accompaniment Plan (伴走プラン): Expert advisory support with regular meetings |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels8 records
GMO Cybersecurity by Ierae product offering
Product offeringCore offering
GMO Cybersecurity by Ierae provides offensive-led cybersecurity services and SaaS tools, including manual vulnerability assessment and penetration testing, Attack Surface Management (netde Shindan ASM) and web application scanning (netde Shindan for Web Apps) SaaS products, 24/7 managed SOC operations built on its proprietary SOLOBAN SIEM, automated WAF operations (WAF Aid) for AWS WAF and Cloudflare, incident response and digital forensics, AI security testing, and security training through Ierae Academy. Offerings are delivered primarily to enterprise and government clients in Japan.
Product overview
GMO Cybersecurity by Ierae offers a unified platform combining automated SaaS vulnerability scanning tools with expert-led managed security services. The product portfolio is organized as two core SaaS tools — ネットde診断 ASM (ASM tool for external asset discovery and vulnerability monitoring) and ネットde診断 for Web Apps (deep web application vulnerability scanner built on OWASP ZAP) — alongside a suite of professional services including manual penetration testing across multiple categories (web, mobile, cloud, network, IoT, internal, red team), AI security testing, managed SOC services with proprietary SIEM (SOLOBAN), WAF Aid automated operations, digital forensics and incident response, security consulting, and Ierae Academy training programs. The two SaaS tools serve different segments: ASM targets enterprise-wide external asset management and broad scanning, while the Web Apps scanner targets developers seeking detailed, authenticated application-level testing with reproduction codes.
Differentiator
Problem solved
Functional benefit
Brands
- ネットde診断 ASM: Attack Surface Management (ASM) tool for discovering and managing external-facing IT assets and vulnerabilities. Features passive and active scanning, dark web monitoring, and regular vulnerability reporting.
- ネットde診断 for Webアプリ
- WAFエイド
- SOCサービス
- イエラエアカデミー
Products and services
- Netde Shindan ASM (GMO Cyber Attack Netde Shindan) Attack Surface Management (ASM) SaaS tool that automatically discovers externally exposed IT assets (domains, IPs, servers) and performs passive and active vulnerability scanning to support enterprise-wide risk management. Offered in Self-Service Plan and Accompaniment Plan tiers.
- Netde Shindan for Web Apps Web application vulnerability scanner built on reimplemented OWASP ZAP with proprietary signatures, enabling in-house recurring security testing with up to 35 scans per month per subscription and automated crawling plus reproduction codes in reports.
- Vulnerability Assessment and Penetration Testing Services Manual expert-led security testing covering web application, mobile app, cloud, network, IoT, internal network, red team, NFT/blockchain, game cheat, desktop app, and physical penetration testing performed by 200+ white hat hackers.
- SOC (Security Operations Center) Services 24/7 security monitoring, alert analysis, threat response, and a Second Opinion advisory service for logs from any vendor or product, powered by the proprietary SOLOBAN SIEM platform using SEM architecture on AWS Athena.
- WAF Aid Automated WAF operations management service that connects to AWS WAF and Cloudflare to deliver managed rules, signature updates, and misdetection resolution based on GMO Ierae's threat intelligence.
- AI Security Services
Quantifiable outcome
- 90%+ intrusion success rate for penetration testing engagements
- +5 more outcomes
Companies that use GMO Cybersecurity by Ierae
Customer profileNamed customers34 records
Segments6 records
Ideal customer profiles3 records
GMO Cybersecurity by Ierae technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability2 records
Feature5 records
GMO Cybersecurity by Ierae partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered standard.
- Network Equipment Sales Agency PartnersstandardSales partners that bundle netde Shindan diagnostic services as part of maintenance contracts for network equipment such as VPN and UTM devices. Partners resell vulnerability scanning services alongside their core networking product offerings.
- Cloud Platform SI PartnersstandardCloud platform system integrators (e.g., AWS-focused SIs) that offer WAF Aido automated WAF operations management service as an option in their cloud deployment engagements. Partners expand the addressable market for managed WAF services.
- Financial Sector Service Provider PartnersstandardService providers operating in the financial sector who resell penetration testing services to their banking and financial institution clients. These partners leverage existing relationships in the regulated financial sector to deliver expert security assessments.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
GMO Cybersecurity by Ierae competitors and assessment
Company assessmentDirect peers
- LAC Co., Ltd. LAC is a major Japanese cybersecurity services firm offering vulnerability assessment, penetration testing, SOC, and incident response with deep enterprise reach. Directly comparable as a Japan-focused offensive security and managed security services provider competing for the same enterprise and financial-sector customers as Ierae.
- NRI Secure Technologies: NRI Secure is a leading Japanese security consulting and managed services firm under Nomura Research Institute, offering vulnerability diagnostics, SOC, and consulting. Comparable in offering breadth and target enterprise/financial client base within the Japanese market.
- SecureWorks: SecureWorks is a global MSSP offering managed detection, vulnerability management, and offensive security testing. Comparable as a managed security and assessment services provider; demonstrates the international scaling benchmark Ierae could pursue beyond Japan.
- Trustwave: Trustwave is a global MSSP providing managed security, vulnerability assessment, penetration testing, and incident response. Comparable as a direct peer offering the same suite of managed security services and offensive testing as Ierae.
- Bishop Fox: Bishop Fox is a US-based offensive security firm specializing in penetration testing, red teaming, and vulnerability research with a strong reputation for elite consultants. Comparable as a direct peer in expert-led offensive security services and adversary simulation.
Broad incumbents
- Internet Initiative Japan (IIJ): IIJ is a major Japanese network and cloud provider with a sizable security services division covering managed SOC, vulnerability assessment, and consulting. Comparable as a broad incumbent with overlapping managed security and assessment services targeting the same Japanese enterprise base.
- Trend Micro Japan: Trend Micro is a global cybersecurity vendor with strong Japanese enterprise penetration, offering endpoint, network, and managed detection services. Comparable as a broad incumbent that competes with Ierae on managed SOC and security services within Japanese enterprise accounts.
- NTT Data Group / NTT Security: NTT Data is a dominant Japanese IT services conglomerate with broad cybersecurity consulting, managed security, and system integration capabilities. Comparable as a broad incumbent with deeper enterprise integration reach and overlapping managed security and vulnerability assessment services.
- Rapid7: Rapid7 offers vulnerability management, managed detection, and offensive security services globally, including Japan. Comparable as a broad incumbent with a SaaS vulnerability management platform and managed services that compete for the same enterprise buyers as Ierae's ASM and SOC offerings.
Regional players
- Macnica Networks: Macnica is a Japanese network/security distributor and integrator offering managed security services and vulnerability assessment as part of its portfolio. Comparable as a regional channel and services player competing for enterprise security budget in Japan.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
GMO Cybersecurity by Ierae social profiles
Digital presenceGMO Cybersecurity by Ierae financial estimates
Financial estimateRevenue estimate
Valuation estimate
GMO Cybersecurity by Ierae leadership team
Management profileNumber of profiles
Profiles9 records
GMO Cybersecurity by Ierae funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GMO Cybersecurity by Ierae M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GMO Cybersecurity by Ierae
What does GMO Cybersecurity by Ierae do?
GMO Cybersecurity by Ierae provides offensive-led cybersecurity services and SaaS tools, including manual vulnerability assessment and penetration testing, Attack Surface Management (netde Shindan ASM) and web application scanning (netde Shindan for Web Apps) SaaS products, 24/7 managed SOC operations built on its proprietary SOLOBAN SIEM, automated WAF operations (WAF Aid) for AWS WAF and Cloudflare, incident response and digital forensics, AI security testing, and security training through Ierae Academy. Offerings are delivered primarily to enterprise and government clients in Japan.
Is GMO Cybersecurity by Ierae a public or private company?
GMO Cybersecurity by Ierae is a private company. It is classified as corporate owned and is currently operating.
When was GMO Cybersecurity by Ierae founded?
GMO Cybersecurity by Ierae was founded in 2013. It employs 51 to 100 people.
Where is GMO Cybersecurity by Ierae based?
GMO Cybersecurity by Ierae is headquartered in Tokyo, Japan, in the Asia region.
How does GMO Cybersecurity by Ierae make money?
Five revenue lines are on record. Vulnerability Assessment and Penetration Testing Services are the primary driver. The others are ネットde診断 ASM (Self-serve SaaS tool), SOC (Security Operations Center) Services, AI Security Services and ierae Academy (Security Training).
Who are GMO Cybersecurity by Ierae's main competitors?
Direct peers on record are LAC Co., Ltd., NRI Secure Technologies, SecureWorks, Trustwave and Bishop Fox. Broad incumbents are Internet Initiative Japan (IIJ), Trend Micro Japan, NTT Data Group / NTT Security and Rapid7. Macnica Networks is listed as a regional player.
Does GMO Cybersecurity by Ierae have an API?
No public API is recorded for GMO Cybersecurity by Ierae.
What industry is GMO Cybersecurity by Ierae in?
GMO Cybersecurity by Ierae's product category is Cybersecurity Services and Vulnerability Management. Its primary akta.pro industry code is BPAEAMAG, Cybersecurity Operations Outsourcing (SOC / SecOps), with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 541513 and its SIC code is 7373.