Cyber Security Works
Cyber Security Works is a privately held MSSP providing vulnerability management, penetration testing, PCI ASV scanning, and threat intelligence services to large public, private, startup, and government organizations through a cloud-based platform and professional services delivered via direct sales and authorized resellers.
- Company typePrivate
- Founded2008
- HeadquartersAlbuquerque, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Cyber Security Works does
Cyber Security Works, Inc. (CSW) is a privately held Delaware corporation headquartered in Albuquerque, New Mexico, with an operations center in Chennai, India. Founded in 2008 and operating with 51-100 employees, the company provides managed security services and vulnerability management solutions to large public, private, and startup organizations, as well as federal government entities. Its offering combines a cloud-based unified threat and vulnerability management platform (the CSW Platform) with a broad professional services portfolio spanning penetration testing, PCI ASV scanning, AWS cloud security, ransomware attack surface assessment, red teaming, and PatchWatch vulnerability tracking. CSW holds CVE Numbering Authority designation and has discovered multiple zero-day vulnerabilities, including disclosures later catalogued by CISA's Known Exploited Vulnerabilities list.
The underlying technology is a SaaS platform licensed on an asset-based tiered subscription model (typically 12-month terms), supplemented by multi-year professional services contracts. AI and dark web mining capabilities, acquired through CYR3CON's threat management intellectual property in March 2022, support anomaly detection and predictive threat intelligence. The platform exposes APIs and integrates vulnerability management, attack surface management, and threat intelligence into a single workflow, with revenue generated through direct enterprise sales, authorized resellers, and tiered support services.
CSW's business model is enterprise sales-led, with quote-based pricing, Master Services Agreements governing customer relationships, and an authorized-reseller channel for professional services distribution. Go-to-market emphasizes content marketing (PatchWatch digests, Ransomware Spotlight Reports, zero-day disclosures) and thought leadership to drive inbound enterprise engagement, while delivery is split between US-based account teams and the India operations center. The company is bootstrapped/self-funded with no disclosed institutional investors, and only one named customer (Dreamspring) is referenced in the available data.
Cyber Security Works firmographics
Firmographics- Name
- Cyber Security Works
- Legal name
- Cyber Security Works, Inc.
- Website
- https://cybersecurityworks.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Cyber Security Works is a privately held MSSP providing vulnerability management, penetration testing, PCI ASV scanning, and threat intelligence services to large public, private, startup, and government organizations through a cloud-based platform and professional services delivered via direct sales and authorized resellers.
- Ownership category
- akta.pro rank
Cyber Security Works industry classification
Industry- Product category
- Cybersecurity Software / Vulnerability Management
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Cybersecurity Architecture & Security Integration (BPAEAAAL)
Keywords
Where Cyber Security Works is headquartered
LocationHeadquarters
- HQ city
- Albuquerque
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Cyber Security Works business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Revenue model
- Platform/SaaS Subscription: Cloud-based platform subscription model with fees due and payable in advance, typically for a 12-month term. Fees are based on the number of Assets registered, managed, and discovered by the Platform, as well as tier and restrictions contained in the Order.
- Professional Services: Penetration testing, vulnerability management, compliance, installation, implementation, training, and other professional services delivered directly or through authorized resellers.
- Support Services: Technical support services with tiered severity-based response times, provided in accordance with CSW's technical support policy and SLA.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Asset-based tiered pricing |
| Subscription | Multi-year contract | Professional Services pricing |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Cyber Security Works product offering
Product offeringCore offering
Cyber Security Works provides a cloud-based unified threat and vulnerability management SaaS platform that discovers and tracks Assets across on-premise, cloud, IoT, and mobile environments, enabling organizations to prioritize vulnerabilities and reduce security debt. The Platform is licensed per Asset on annual subscriptions and is delivered alongside modular Professional Services including penetration testing, vulnerability management, compliance, PCI ASV scanning, AWS cloud security, ransomware attack surface assessment, red teaming, PatchWatch, zero-day research, threat intelligence, and managed security. AI and dark web mining technology from the CYR3CON acquisition enables proactive, predictive threat detection.
Product overview
Cyber Security Works (CSW) offers a unified threat and vulnerability management platform combining a cloud-based software platform with modular professional services. The core CSW Platform provides the technical infrastructure, while surrounding services include Vulnerability Management as a Service, Penetration Testing Service (covering external, internal, web application, mobile, API, and network testing), PCI ASV scanning, AWS Cloud Security services, Ransomware Attack Surface Assessment, Red Teaming, PatchWatch vulnerability tracking, and Zero Days vulnerability discovery. The platform incorporates AI and dark web mining capabilities acquired from CYR3CON for predictive threat intelligence. CSW also publishes regular Ransomware Spotlight Reports tracking vulnerability and ransomware trends.
Differentiator
Problem solved
Functional benefit
Products and services
- CSW Platform (Unified Threat and Vulnerability Management SaaS) Cloud-based unified threat and vulnerability management SaaS platform that registers, manages, and discovers physical and virtual Assets (on-premise, cloud, IoT, mobile) and delivers scanning, vulnerability management, and threat intelligence through licensed APIs. Licensed to enterprise customers on an annual subscription.
- Vulnerability Management as a Service Ongoing managed vulnerability scanning, assessment, prioritization, and remediation guidance to help organizations reduce security debt across their environments.
- Penetration Testing Service Comprehensive penetration testing covering external, internal network, web application, mobile application, API, and social engineering tests to identify exploitable weaknesses in customer environments.
- PCI ASV Scanning Service Payment Card Industry Data Security Standard approved scanning vendor service providing quarterly vulnerability scans for merchants and service providers handling cardholder data.
- AWS Cloud Security Services Cloud security services tailored to Amazon Web Services environments, encompassing one-time AWS security assessments, ongoing managed Security-as-a-Service with continuous monitoring, configuration reviews, and compliance validation.
- Ransomware Attack Surface Assessment Specialized assessment that identifies vulnerabilities and exposures in an organization that could be exploited by ransomware operators, drawing on CSW's ransomware research and proprietary CVE database.
- Red Teaming Assessment Adversarial simulation service that emulates real-world attacker scenarios to evaluate an organization's detection, response, and overall security posture.
- PatchWatch Vulnerability Tracking Service Subscription-based patch tracking and notification service that summarizes security updates and known exploited vulnerabilities from major vendors (Microsoft, Cisco, Oracle, Apple, Adobe) and the CISA KEV catalog.
- Zero Days Vulnerability Discovery Program Zero-day vulnerability discovery, tracking, and responsible disclosure program operated by CSW as a CVE Numbering Authority, providing customers with early warning of previously unknown vulnerabilities.
- Managed Security Service Continuous managed security monitoring and management service delivering ongoing protection, threat detection, and incident response for customer environments.
- Threat Intelligence Service Threat intelligence gathering and analysis service that incorporates AI and dark web mining to deliver proactive, predictive threat detection and vulnerability management to enterprise customers.
- Risk and Compliance Service Risk assessment and compliance management service helping organizations align with regulatory and security standards requirements through assessments, gap analysis, and remediation support.
Quantifiable outcome
- Discovered 50th zero-day vulnerability in WordPress Microsoft Clarity plugin
- +1 more outcomes
Companies that use Cyber Security Works
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
Cyber Security Works technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
Cyber Security Works partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CYR3CONcoreCSW acquired CYR3CON's threat management intellectual property to enhance its threat intelligence capabilities with AI and dark web mining. The acquisition enables proactive, predictive threat detection and vulnerability management, expanding CSW's attack surface management and resilience offerings.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Cyber Security Works competitors and assessment
Company assessmentDirect peers
- Tenable: Tenable is the leading standalone vulnerability management platform (Nessus, Tenable.io, Tenable One ASM). It directly competes with CSW's CSW Platform across VM, ASM, and exposure management, and serves the same large-enterprise and government buyers.
- Rapid7: Rapid7 offers InsightVM (vulnerability management), penetration testing services, and managed detection — closely matching CSW's combination of VMaaS, pentesting, and managed security. It competes for the same enterprise and mid-market vulnerability management budget.
- Qualys: Qualys provides a cloud-based VM and attack surface management platform (Qualys VMDR, TruRisk) and competes directly with CSW's cloud-native SaaS model and asset-based pricing, particularly in PCI/compliance use cases.
- Secureworks: Secureworks is a pure-play MSSP offering managed VM, threat intelligence, and incident response. It is the most direct MSSP comparable to CSW, with overlapping services and a similar enterprise/government customer base.
- Trustwave: Trustwave is a global MSSP and cybersecurity services firm offering managed VM, penetration testing, PCI compliance, and threat intelligence — a near-perfect functional overlap with CSW's service portfolio and GTM motion.
Emerging players
- Bishop Fox: Bishop Fox is a specialized offensive security firm with strengths in penetration testing, red teaming, and attack surface management. It is closely comparable to CSW's professional services arm, though it is less SaaS-platform-centric.
- IOActive: IOActive is a specialist penetration testing and security consulting firm with a strong research practice — comparable to CSW's pentesting and zero-day research capabilities, though smaller and less platform-oriented.
Regional players
- NCC Group: NCC Group is a UK-headquartered cybersecurity services and software firm offering penetration testing, managed security, and threat intelligence. Comparable in services portfolio to CSW, but primarily serves Europe rather than the US/India footprint.
Broad incumbents
- Recorded Future (now Mastercard): Recorded Future is a leading threat intelligence platform with dark web monitoring, predictive analytics, and threat data feeds — a direct competitor to CSW's CYR3CON-derived threat intelligence offering, with much broader data and customer scale.
- CrowdStrike:
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks1 record
Key highlights7 records
Customer concentration
Cyber Security Works social profiles
Digital presenceCyber Security Works financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Security Works leadership team
Management profileNumber of profiles
Profiles4 records
Cyber Security Works funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Security Works M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Security Works
What does Cyber Security Works do?
Cyber Security Works provides a cloud-based unified threat and vulnerability management SaaS platform that discovers and tracks Assets across on-premise, cloud, IoT, and mobile environments, enabling organizations to prioritize vulnerabilities and reduce security debt. The Platform is licensed per Asset on annual subscriptions and is delivered alongside modular Professional Services including penetration testing, vulnerability management, compliance, PCI ASV scanning, AWS cloud security, ransomware attack surface assessment, red teaming, PatchWatch, zero-day research, threat intelligence, and managed security. AI and dark web mining technology from the CYR3CON acquisition enables proactive, predictive threat detection.
Is Cyber Security Works a public or private company?
Cyber Security Works is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber Security Works founded?
Cyber Security Works was founded in 2008. It employs 51 to 100 people.
Where is Cyber Security Works based?
Cyber Security Works is headquartered in Albuquerque, United States, in the North America region.
How does Cyber Security Works make money?
Three revenue lines are on record. Platform/SaaS Subscription is the primary driver. The others are professional Services and support Services.
Who are Cyber Security Works's main competitors?
Direct peers on record are Tenable, Rapid7, Qualys, Secureworks and Trustwave. Emerging players are Bishop Fox and IOActive. NCC Group is listed as a regional player. Broad incumbents are Recorded Future (now Mastercard) and CrowdStrike.
Does Cyber Security Works have an API?
Yes. The CSW Platform includes application programming interfaces (APIs) licensed to customers as part of the cloud solution and software programs. The Platform is defined in the Customer Legal Agreement as 'any CSW cloud solution and software programs (in object code format) and application programming interfaces (APIs) licensed by CSW to Customer' along with Updates and Documentation. No public API documentation URL, developer portal, SDK, or rate limits are specified in the provided source material.
What industry is Cyber Security Works in?
Cyber Security Works's product category is Cybersecurity Software / Vulnerability Management. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 54151 and its SIC code is 7373.