The Security Factory - TSF
- Company typePrivate
- Founded2012
- HeadquartersSchelle, Belgium
- Headcount11–50
- GTM typeB2B
- OfferingServices
The Security Factory - TSF firmographics
Firmographics- Name
- The Security Factory - TSF
- Legal name
- The Security Factory
- Website
- https://thesecurityfactory.be
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
The Security Factory - TSF industry classification
Industry- Product category
- Cybersecurity / Penetration Testing Services
- NAICS
- Testing Laboratories and Services (541380)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
Keywords
Where The Security Factory - TSF is headquartered
LocationHeadquarters
- HQ city
- Schelle
- HQ country
- Belgium
- HQ region
- Europe
Offices1 record
Markets served
The Security Factory - TSF business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Penetration Testing Services: Expert-led security assessments combining tool-assisted scanning with deep contextual analysis. Services include external, internal, cloud, web application, mobile application, API, fat/thick client, kiosk breakout, wireless, and red team testing. Delivered as project-based engagements with customized scoping.
- Pentesting as a Service (PTaaS): Ongoing penetration testing subscription model providing continuous security assessment rather than one-time tests. Includes real-time reporting platform access and collaborative remediation support.
- Social Engineering Services: Digital and physical social engineering assessments including phishing simulations, vishing, baiting, and tailgating exercises. Often bundled with awareness training and live hacking demonstrations.
- Security Awareness Training: Phishing awareness and security training services, primarily delivered through partnership with Phished.io platform. Includes customized phishing simulations and training programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom Scope-Based Pricing |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels4 records
The Security Factory - TSF product offering
Product offeringCore offering
The Security Factory (TSF) provides expert-led cybersecurity testing and human-factor security services. Its core deliverables include manual penetration testing across networks, web applications, cloud, mobile, APIs, wireless, kiosk, and thick client environments, complemented by social engineering, red team exercises, and phishing awareness training delivered in partnership with Phished.io. The firm also offers Pentesting-as-a-Service (PTaaS), a recurring subscription model featuring real-time findings visibility through its proprietary online reporting platform.
Product overview
The Security Factory (TSF) is a cybersecurity services company offering a portfolio of expert-led penetration testing and security assessment services. The core offering includes traditional penetration testing (network, web application, cloud, mobile, API) and social engineering services (phishing simulations, physical security testing, red teaming, live hacking demos). TSF delivers services through a combination of certified ethical hackers and an proprietary real-time reporting platform that provides customers with live visibility into findings during testing. Phishing awareness training is delivered in partnership with Phished.io. Services are customized to each client's context and include follow-up review meetings, remediation guidance, and retesting options.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Expert-led security assessment combining tool-assisted scanning with deep contextual manual analysis to identify and exploit vulnerabilities across customer systems. Coverage spans network (external/internal), web application, cloud (AWS, Azure, Google Cloud), mobile (iOS, Android), API, wireless, kiosk breakout, and fat/thick client environments, with reports customized to business logic and delivered to enterprise and SME clients.
- Pentesting as a Service (PTaaS) Subscription-based ongoing penetration testing model providing continuous security assessment rather than one-time tests. Includes real-time reporting platform access, collaborative remediation support between developers and pentesters, and issue-based retest requests.
- Social Engineering Services Assessment of human vulnerabilities through digital social engineering (phishing, vishing, smishing), physical social engineering (tailgating, badge access), USB drop tests, and pretexting scenarios. Often bundled with awareness training and live hacking demonstrations.
- Phishing Simulation and Awareness Training Phishing simulation exercises and security awareness training delivered through partnership with the Phished.io platform, creating personalized training profiles for each employee based on their interactions with simulated phishing campaigns.
- Red Team Exercise Full-scope, multi-layered simulation of real-world attacks combining social engineering, phishing, physical intrusions, and technical methods over an extended period to test detection and response capabilities of customer organizations.
- Live Hacking Demo Interactive demonstrations showcasing real-time cyberattack methodologies, displaying hacker perspectives and target systems simultaneously to visually and emotionally engage audiences at client sites and industry events.
- Threat-Led Penetration Testing (TLPT) Advanced penetration testing simulating attacks from real-world threat actor perspectives, mandated under DORA regulation for financial institutions every three years. Includes TLP-focused intelligence-driven adversary emulation.
- Code Review Optional source code review offered alongside web application tests, enabling detection of complex issues that are difficult to surface through testing alone and accelerating remediation by pinpointing exact code locations.
- Real-Time Penetration Test Reporting Platform Proprietary interactive online dashboard that delivers validated security findings in near real-time during penetration testing, replacing traditional static PDF reporting. Enables direct collaboration between developers and pentesters, supports issue-based retesting, and provides Excel and XML export options.
Quantifiable outcome
- Over 90% improvement in organization protection within months through proper end-user training
Companies that use The Security Factory - TSF
Customer profileNamed customers4 records
Segments3 records
Ideal customer profiles3 records
The Security Factory - TSF technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
The Security Factory - TSF partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core and flagship.
- Phished.iocorePhished.io is a phishing awareness and simulation platform that automates phishing training processes. TSF partners with Phished.io to provide comprehensive phishing awareness services, with Phished.io handling the automated simulation and training while TSF provides strategic consulting on human security.
- Resilience GroupflagshipTSF joined forces with Infosentry and DPO Consultancy to form Resilience Group, an integrated Benelux platform for security and privacy solutions. TSF contributes technical cybersecurity expertise (penetration testing, red teaming, security awareness) while the group provides end-to-end services in information security and privacy. The companies continue operating under their own names while collaborating under the Resilience Group umbrella.
Scale indicators2 records
Recent moves7 records
Expansion highlights6 records
The Security Factory - TSF competitors and assessment
Company assessmentDirect peers
- NCC Group: One of the largest dedicated cybersecurity testing firms globally, with a heavy pentesting and assurance practice serving European enterprises. Directly comparable to TSF in service lines (web app, infrastructure, red teaming) and target regulated industries including financial services.
- Bishop Fox: US-headquartered offensive security firm specialising in penetration testing, red teaming, and product security assessments. Closely comparable to TSF on methodology, certification-led talent model, and enterprise customer focus, though larger and more global.
- Securify: Benelux-focused cybersecurity company with pentesting, red teaming, and managed security services for mid-market and enterprise customers. Comparable to TSF on regional focus, manual testing methodology, and SME-to-enterprise customer mix.
- NetSPI: US-based penetration testing services firm with a PTaaS platform offering, comparable in methodology (manual, expert-led) and enterprise target market. Direct competitive analogue to TSF's Pentesting-as-a-Service value proposition.
- Hunt & Hackett: Dutch offensive security firm delivering pentesting, red teaming, and managed security services to Benelux enterprises. Comparable to TSF in regional focus, service portfolio, and target customer profile.
- Computest (now Northwave): Dutch cybersecurity firm with a strong pentesting and security testing practice serving Benelux enterprise and financial services. Similar service mix and customer profile to TSF, differentiated by Dutch rather than Belgian base.
Broad incumbents
- Trustwave: Global cybersecurity provider offering penetration testing as part of a broader MDR and consulting portfolio. Targets the same regulated enterprise customers as TSF but competes through bundled, multi-service contracts.
- Orange Cyberdefense: European cybersecurity arm of Orange, offering pentesting, managed detection, and consulting across Benelux and broader EU. Overlaps with TSF on offensive security services but bundles them in a much larger MSSP portfolio competing for the same Belgian enterprise customers.
- WithSecure (formerly F-Secure): Nordic-headquartered cybersecurity vendor with a dedicated offensive security services line including pentesting and red teaming. Comparable offensive-testing capability to TSF, with broader product portfolio and larger scale.
Emerging players
- HackerOne: Bug bounty and crowdsourced penetration testing platform, increasingly an alternative to traditional manual pentest engagements. Competes with TSF for SME and enterprise security testing budgets via a platform-based, on-demand delivery model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
The Security Factory - TSF social profiles
Digital presenceThe Security Factory - TSF compliance and trust
Trust signalCompliance5 records
The Security Factory - TSF financial estimates
Financial estimateRevenue estimate
Valuation estimate
The Security Factory - TSF leadership team
Management profileNumber of profiles
Profiles8 records
The Security Factory - TSF funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
The Security Factory - TSF M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about The Security Factory - TSF
What does The Security Factory - TSF do?
The Security Factory (TSF) provides expert-led cybersecurity testing and human-factor security services. Its core deliverables include manual penetration testing across networks, web applications, cloud, mobile, APIs, wireless, kiosk, and thick client environments, complemented by social engineering, red team exercises, and phishing awareness training delivered in partnership with Phished.io. The firm also offers Pentesting-as-a-Service (PTaaS), a recurring subscription model featuring real-time findings visibility through its proprietary online reporting platform.
Is The Security Factory - TSF a public or private company?
The Security Factory - TSF is a private company. It is classified as private equity controlled and is currently operating.
When was The Security Factory - TSF founded?
The Security Factory - TSF was founded in 2012. It employs 11 to 50 people.
Where is The Security Factory - TSF based?
The Security Factory - TSF is headquartered in Schelle, Belgium, in the Europe region.
How does The Security Factory - TSF make money?
Four revenue lines are on record. Penetration Testing Services are the primary driver. The others are pentesting as a Service (PTaaS), social Engineering Services and security Awareness Training.
Who are The Security Factory - TSF's main competitors?
Direct peers on record are NCC Group, Bishop Fox, Securify, NetSPI, Hunt & Hackett and Computest (now Northwave). Broad incumbents are Trustwave, Orange Cyberdefense and WithSecure (formerly F-Secure). HackerOne is listed as an emerging player.
Does The Security Factory - TSF have an API?
No public API is recorded for The Security Factory - TSF.
What industry is The Security Factory - TSF in?
The Security Factory - TSF's product category is Cybersecurity / Penetration Testing Services. Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS). Its NAICS code is 541380 and its SIC code is 8734.