EverSec Group
EverSec Group is a boutique cybersecurity consulting firm founded in 2008 that provides advisory, security architecture, and curated third-party vendor management services to over 100 Global Fortune 500 clients in banking, hospitality, insurance, financial services, and global exchanges.
- Company typePrivate
- Founded2008
- HeadquartersTarrytown, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What EverSec Group does
EverSec Group, Inc. is a boutique cybersecurity consulting firm founded in 2008 by Stephen Harrison and headquartered in Tarrytown, New York. The company provides advisory and professional services — security architecture and implementation, security program strategy, enterprise risk and compliance (PCI-DSS, ISO-27001/2, GDPR, NYDFS, NIST/FISMA), staff augmentation, cloud services, vulnerability management, RFI/RFP outsourcing, and data privacy — and explicitly does not build proprietary security products. EverSec's functional positioning is that of an objective advisor helping clients navigate a fragmented vendor landscape of more than 1,400 cybersecurity providers, vetting emerging solutions and operationalizing best-of-breed third-party tools.
The firm's differentiation rests on its senior team, which collectively holds over 125 years of IT security experience across three Managing Partners (Harrison as CEO, Anthony Roffi as COO, Tim McSherry as CSO) and supporting executives including CTO Ryan Leonard and CIO Seth Lyons, with prior leadership tenure at Check Point, IBM, Intel, and senior security roles in fintech and currency trading. EverSec curates formal go-to-market partnerships with 40+ vendors across ten solution domains — Attack Surface Management, Cloud Security, Cyber Resiliency, Data Security Posture Management, EDR/EPP, Insider Threat/UBA, SaaS Security, Security Automation, App/API Security, and CTEM — including CrowdStrike, SentinelOne, Wiz, Zscaler, Rubrik, Exabeam, CyCognito, and others.
The business model is professional services revenue generated through long-term, consultative enterprise engagements priced on a per-engagement basis (no public pricing disclosed). Go-to-market is exclusively direct enterprise field sales targeting Global Fortune 500 clients in highly regulated industries — banking, hospitality, global exchanges, insurance, and financial services — with the firm explicitly positioning itself as an extension of client CISO and security teams. The company reports ongoing relationships with over 100 client organizations, is privately held and founder-controlled, has no disclosed institutional funding or parent company, and has begun broadening its stated addressable market to 'corporations of all sizes and all industry verticals' while entering adjacent emerging categories such as AI Agent governance via a 2025 partnership with Zenity.
EverSec Group firmographics
Firmographics- Name
- EverSec Group
- Legal name
- EverSec Group, Inc.
- Website
- https://eversecgroup.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- EverSec Group is a boutique cybersecurity consulting firm founded in 2008 that provides advisory, security architecture, and curated third-party vendor management services to over 100 Global Fortune 500 clients in banking, hospitality, insurance, financial services, and global exchanges.
- Ownership category
- akta.pro rank
EverSec Group industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Management Consulting Services (54161)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
Keywords
Where EverSec Group is headquartered
LocationHeadquarters
- HQ city
- Tarrytown
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
EverSec Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- Cyber Security Consulting Services: EverSec generates revenue through consulting and professional services, including security architecture and implementation, security program strategy, enterprise risk and compliance, staff augmentation, cloud services, cybersecurity services, and vulnerability management. The company develops strategic, long-term relationships and provides ongoing counsel as a trusted security advisor. Revenue is primarily derived from service engagements rather than product licensing.
Go-to-market motion2 records
Distribution channels1 record
Marketing channels1 record
EverSec Group product offering
Product offeringCore offering
EverSec Group is a boutique cybersecurity consulting firm that provides advisory services and strategic vendor management to Global Fortune 500 companies across highly regulated industries. The firm does not build proprietary products; instead, it vets, selects, deploys, and operationalizes best-of-breed third-party security solutions on behalf of clients, covering security architecture, program strategy, risk and compliance, staff augmentation, cloud services, vulnerability management, and data privacy. Engagements are sold as professional services through direct enterprise relationships, with the firm acting as an extension of clients' internal CISO teams.
Product overview
EverSec Group is a cybersecurity consulting company offering professional services rather than a unified product platform. The company provides a portfolio of security consulting services including Security Architecture & Implementation, Security Program Strategy, Enterprise Risk & Compliance, Staff Augmentation, Cloud Services, Cyber Security Services, InfoSec Services, RFI/RFP Outsource, Vulnerability Management, and Data Privacy Services. Additionally, EverSec offers security solutions organized by domain (Attack Surface Management, Cloud Security, Cyber Resiliency, Data Security Posture Management, EDR/EPP, Insider Threat/UBA, SaaS Security, Security Automation, App/API Security, and CTEM) delivered through strategic partnerships with leading security vendors. The company has invested over 8 years in identifying and vetting security vendors to help clients select and deploy the right solutions.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Architecture & Implementation Services Professional services covering design, planning, architecture, staging, coordination, project management, lab/POC testing, and deployment of security solutions for enterprise clients.
- Security Program Strategy Services Advisory services including co-designing security enhancements, security operations program design, and SIEM/SOAR/SOC reviews for enterprise security leaders.
- Enterprise Risk & Compliance Services Compliance consulting for PCI-DSS, ISO-27001/2, GDPR, NYDFS, NIST/FISMA, and CIS Benchmarking frameworks targeting regulated-industry enterprises.
- Staff Augmentation Services Flexible staffing support including patching, Windows hardening, security tool upgrades, SSL encryption/inspection tuning, and threat intelligence gateway deployments.
- Cloud Services Cloud strategy planning including application segmentation, serverless applications, platform migrations, connectivity, provisioning, and automation.
- Cyber Security Services Vulnerability assessments, penetration testing, attack surface testing, and red team testing delivered through third-party partnerships.
- InfoSec Services Documentation updates, acceptable use policies and procedures, app security testing, and infrastructure modernization planning.
- RFI/RFP Outsource Stakeholder fact gathering, consensus documentation, vendor outreach/NDAs, vendor short-listing, and negotiation of terms for clients evaluating security vendors.
- Vulnerability Management Services Application and infrastructure risk-defined cyber improvements, prioritizing vulnerability remediation, aligning vulnerability management with privileged access management, addressing shadow risk, and continuous adaptive risk trust assessment.
- Data Privacy Services Identifying and mapping PII, critical IP, and confidential data; addressing privileged access to intellectual property; data classification, digital rights management, and encryption; addressing business email compromise and accidental data disclosure.
- Attack Surface Management Solution Practice Managed service helping clients identify and address external attack surface vulnerabilities (Vulnerability Management 2.0) through partner vendors including CyCognito, Cymulate, Randori, Pentera, Vulcan, Axonius, and Ionix.
- Cloud Security Solution Practice Cloud security services leveraging partner vendors Wiz, JupiterOne, GuardiCore, and Aqua Security across multi-cloud and on-prem environments.
- Cyber Resiliency Solution Practice Cyber resilience services through partners Rubrik, Semperis, UpGuard, DarkWebIQ, XM Cyber, and CultureAI covering data backup, identity protection, third-party risk, and human risk management.
- Data Security Posture Management Solution Practice Data security posture management through partner vendors Concentric, SecuPi, Imperva, Polar Security, Laminar Security, and Eureka Security.
- EDR/EPP Solution Practice Endpoint detection and response and endpoint protection platform services through CrowdStrike, SentinelOne, and Halcyon for enterprise endpoint security.
- Insider Threat/UBA Solution Practice Insider threat detection and user behavior analytics through Corelight, DTEX, CyberHaven, Island, TrueFort, Exabeam, and Zscaler.
- SaaS Security Solution Practice SaaS security services through AppOmni, Obsidian, Adaptive Shield, DoControl, and Savvy Security covering SaaS visibility, access governance, and threat response.
- Security Automation Solution Practice Security automation services through CardinalOps, Cribl, Noetic, Anvilogic, and Tines for SOC, SIEM/XDR, and workflow automation.
- App/API Security Solution Practice Application and API security through Cequence, Salt, Noname, Illustria, Bionic, and Gomboc covering API protection, software supply chain, and cloud infrastructure remediation.
- CTEM (Continuous Threat Exposure Management) Solution Practice Continuous Threat Exposure Management services through Interpres Security, Reach Security, and Vena Security for proactive threat exposure reduction.
Companies that use EverSec Group
Customer profileNamed customers7 records
Segments2 records
Ideal customer profiles2 records
EverSec Group technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
EverSec Group partnerships and signals
Strategic signalPartnerships
52 partnerships are on record, tiered core.
- Interpres SecuritycoreInterpres Security is featured on EverSec's CTEM (Continuous Threat Exposure Management) providers page. The platform analyzes the dynamic relationship between defensive and adversarial capabilities, prioritizes actions, and optimizes the security ecosystem for the enterprise.
- Reach SecuritycoreReach Security is a generative AI platform purpose-built to empower enterprise security teams, featured as a CTEM provider on EverSec's website. Organizations can measure, manage, and improve their enterprise security posture at scale.
- Vena SecuritycoreVena Security is listed as a CTEM provider on EverSec's website. It defends against threats by continuously optimizing existing tool capabilities, coverage, and effectiveness while adapting to a constantly changing threat landscape.
- CequencecoreCequence is featured on EverSec's App/API Security page. It is described as the only API protection solution that eliminates unknown API security risks across all phases of the API security lifecycle, protecting against data loss, fraud, and disruption.
- SaltcoreSalt is featured on EverSec's App/API Security page. Salt delivers adaptive intelligence to protect APIs across build, deploy, and runtime phases, continuously monitoring and analyzing API traffic to detect and mitigate security risks.
- Noname SecuritycoreNoname Security is featured on EverSec's App/API Security page. It specializes in discovering and protecting APIs and ensuring the security of communications between applications, offering deep API visibility, risk assessment, and threat detection.
- IllustriacoreIllustria is featured on EverSec's App/API Security page. It proactively detects and stops malicious packages, maintainers, and behaviors while using open-source packages, offering agentless coverage throughout the software development lifecycle.
- BioniccoreBionic is featured on EverSec's App/API Security page. It uses an agentless approach to auto-discover every service, API call, and data flow across traditional and cloud native applications, providing visibility and reducing critical application risk.
- GomboccoreGomboc is featured on EverSec's App/API Security page. It uses AI to continuously remediate cloud infrastructure vulnerabilities by automatically sending remediation requests for review and approval.
- CardinalOpscoreCardinalOps is featured on EverSec's Security Automation page. It is a scalable, cloud-based platform for maximizing the efficiency and effectiveness of existing SIEM/XDR, using automation and MITRE ATT&CK to continuously assess detection posture.
- CriblcoreCribl is featured on EverSec's Security Automation page. The Cribl suite of products puts organizations back in control of their data, giving flexibility to choose, control, and format data on the fly.
- NoeticcoreNoetic is featured on EverSec's Security Automation page. It improves vulnerability management capabilities by providing a consistent view of the continually changing security environment, empowering teams with real-time insight.
- AnvilogiccoreAnvilogic is featured on EverSec's Security Automation page. It is a Detection Engineering and Hunting Platform for SOC teams to implement more accurate detections and hunt more efficiently across all logging platforms and data lakes.
- TinescoreTines is featured on EverSec's Security Automation page. Tines' no-code automation helps companies transform complex security workflows, bringing together business-critical processes across internal and external systems.
- AppOmnicoreAppOmni is featured on EverSec's SaaS Security page. It delivers visibility, data access management, and security controls to protect data across SaaS applications with in-depth coverage, continuous monitoring, and actionable insights.
- ObsidiancoreObsidian is featured on EverSec's SaaS Security page. It normalizes and analyzes data using machine learning and expert analysis to detect account compromise, insider threats, access misuse, data leaks, excessive privileges, and weak posture.
- Adaptive ShieldcoreAdaptive Shield is featured on EverSec's SaaS Security page. It enables enterprises to continue adopting SaaS applications while staying safe, protecting, detecting, and responding to threats throughout the entire SaaS stack.
- DoControlcoreDoControl is featured on EverSec's SaaS Security page. It provides a unified, automated, and risk-aware SaaS Security Platform that secures business-critical applications and data, reducing risk and preventing data breaches.
- Savvy SecuritycoreSavvy Security is featured on EverSec's SaaS Security page. It enables CISOs and security pros to support safe adoption and use of business SaaS apps through just-in-time security guardrails and automated security workflows.
- CorelightcoreCorelight is featured on EverSec's Insider Threat/UBA page. It provides real-time insights into network traffic that helps organizations identify and respond to advanced threats, offering protocol analysis and threat intelligence integration.
- DTEXcoreDTEX is featured on EverSec's Insider Threat/UBA page. It offers the first and only Workforce Cyber Intelligence Platform, capturing elements of typical employee behavior to create Indicators of Intent and deliver real-time awareness without invading personal privacy.
- CyberHavencoreCyberHaven is featured on EverSec's Insider Threat/UBA page. Built for the cloud-first, hybrid-work world, it protects important data from theft, misuse, and exposure across different exfiltration vectors by finding and following sensitive data anywhere it goes.
- IslandcoreIsland is featured on EverSec's Insider Threat/UBA page. It is the developer of the Enterprise Browser, the ideal enterprise workplace where work flows freely while remaining secure, giving organizations complete control, visibility, and governance.
- TrueFortcoreTrueFort is featured on EverSec's Insider Threat/UBA page. It specializes in application and workload protection and focuses on real-time application behavior analysis while helping organizations identify and respond to security threats.
- ExabeamcoreExabeam is featured on EverSec's Insider Threat/UBA page. It offers a cloud-native platform with security log management and powerful behavioral analytics to deliver an automated investigation experience that reduces routines and response time.
- ZscalercoreZscaler is featured on EverSec's Insider Threat/UBA page. Its platform verifies identity and context, determining which actions to allow or block, enabling users to confidently secure connections to applications over any network from anywhere.
- CrowdStrikecoreCrowdStrike is featured on EverSec's EDR/EPP page. The CrowdStrike Falcon Platform secures critical areas of enterprise risk including endpoints, cloud workloads, identity, and data, leveraging real-time indicators of attack, threat intelligence, and enriched telemetry.
- SentinelOnecoreSentinelOne is featured on EverSec's EDR/EPP page. Its Singularity XDR is a cybersecurity platform that empowers modern enterprises to act in real time with greater visibility of the dynamic attack surface using AI-powered automation.
- HalcyoncoreHalcyon is featured on EverSec's EDR/EPP page. It is the first Anti-Ransomware and Cyber Resilience Platform with automated encryption key capture and autonomous decryption capabilities to keep operations running 24/7/365.
- ConcentriccoreConcentric is featured on EverSec's Data Security Posture Management page. It is an agentless API-based solution using machine-learning technology to discover, categorize, and remediate data autonomously, helping organizations minimize risk of data breaches.
- SecuPicoreSecuPi is featured on EverSec's Data Security Posture Management page. It allows companies to protect their data by monitoring and controlling access, usage, and movement through data masking, activity monitoring, and user behavior analytics.
- ImpervacoreImperva is featured on EverSec's Data Security Posture Management page. It stops threat actors before entering the network and protects customer data and all paths to it, applying analytics, automation, machine learning, behavior analytics, and threat intelligence.
- Polar SecuritycorePolar Security is featured on EverSec's Data Security Posture Management page. It finds and eliminates publicly exposed data, stops data leaks between cloud and SaaS apps, reduces third-party exposure to sensitive data, and enforces data access policies.
- Laminar SecuritycoreLaminar Security is featured on EverSec's Data Security Posture Management page. It uses AI, machine learning, and behavioral analytics to detect threats in real-time, providing data security for the cloud while proactively uncovering and classifying cloud data.
- Eureka SecuritycoreEureka Security is featured on EverSec's Data Security Posture Management page. It helps maintain control and visibility over cloud data stores, connecting to cloud accounts via APIs, classifying data, and providing insight into data security posture.
- RubrikcoreRubrik is featured on EverSec's Cyber Resiliency page. It provides solutions for data backup, recovery, and archiving both on-prem and in the cloud, streamlining operations and meeting compliance requirements through automation and advanced analytics.
- SemperiscoreSemperis is featured on EverSec's Cyber Resiliency page. It specializes in identity-driven solutions for Active Directory and hybrid identity protection, helping companies mitigate cyber threats related to identity compromise.
- UpGuardcoreUpGuard is featured on EverSec's Cyber Resiliency page. It specializes in managing and mitigating third-party and vendor risk, helping identify and monitor potential vulnerabilities within the supply chain.
- DarkWebIQcoreDarkWebIQ is featured on EverSec's Cyber Resiliency page. It protects companies from cybercrime and disrupts criminals by infiltrating criminal supply chains and buying network access of their customers before ransomware gangs can.
- XM CybercoreXM Cyber is featured on EverSec's Cyber Resiliency page. It uncovers hidden attack paths across cloud and on-prem networks, pinpointing issues that put organizations at risk so they can proactively reduce their attack surface.
- CultureAIcoreCultureAI is featured on EverSec's Cyber Resiliency page. Its Human Risk Management Platform provides a comprehensive view of an organization's most prominent human risks, integrating with the modern tech stack and enabling targeted coaching and automated interventions.
- WizcoreWiz is featured on EverSec's Cloud Security page. It analyzes IaaS configurations, logs, and snapshots workloads to analyze hosts and containers, providing full visibility into cloud-native databases and instances running on cloud infrastructure.
- JupiterOnecoreJupiterOne is featured on EverSec's Cloud Security page. It provides a graphical-based CMDB across multi-cloud and on-prem environments, enabling Security Policy as Code through correlation of infrastructure, IAM, endpoint solutions, and vulnerability management.
- GuardiCorecoreGuardiCore is featured on EverSec's Cloud Security page. An innovator in internal data center security, it prevents the spread of breaches inside data centers and cloud environments through flow visualization, micro-segmentation, and automated analysis.
- Aqua SecuritycoreAqua Security is featured on EverSec's Cloud Security page. It enables enterprises to secure their container-based and cloud-native applications from development to production, providing full visibility into container activity and detecting suspicious activity.
- CyCognitocoreCyCognito is featured on EverSec's Attack Surface Management page. Its platform helps reduce business risk by letting organizations look from the attacker's perspective, providing insight into weak points and enabling proactive defense against emerging risks.
- CymulatecoreCymulate is featured on EverSec's Attack Surface Management page. It assesses cyber-risk by simulating attacks across any vector, evaluating where a company could be exposed, and recommending fixes for potential security gaps.
- RandoricoreRandori is featured on EverSec's Attack Surface Management page. It handles both Attack Surface Management and Continuous Automated Red Teaming, identifying and mapping external attack surfaces and prioritizing targets with vulnerability assessments.
- PenteracorePentera is featured on EverSec's Attack Surface Management page. It includes network, application, and endpoint testing, giving a true evaluation of an organization's security posture, and allows businesses to prioritize and address vulnerabilities.
- VulcancoreVulcan is featured on EverSec's Attack Surface Management page. It connects to existing security tools, consolidates all vulnerabilities in one unified platform, and adds context to scan data with remediation intelligence providing exact patches, config scripts, or solutions.
- AxoniuscoreAxonius is featured on EverSec's Attack Surface Management page. It gives customers confidence to control complexity by mitigating threats, navigating risk, automating response actions, and informing business-level strategy through cyber asset attack surface management.
- IonixcoreIonix is featured on EverSec's Attack Surface Management page. It uses Connective Intelligence to shine a spotlight on exploitable risks across the entire attack surface and digital supply chain, discovering and monitoring every internet-facing asset.
Scale indicators5 records
Recent moves5 records
Expansion highlights5 records
EverSec Group competitors and assessment
Company assessmentMarket position
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
EverSec Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
EverSec Group leadership team
Management profileNumber of profiles
Profiles5 records
EverSec Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
EverSec Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about EverSec Group
What does EverSec Group do?
EverSec Group is a boutique cybersecurity consulting firm that provides advisory services and strategic vendor management to Global Fortune 500 companies across highly regulated industries. The firm does not build proprietary products; instead, it vets, selects, deploys, and operationalizes best-of-breed third-party security solutions on behalf of clients, covering security architecture, program strategy, risk and compliance, staff augmentation, cloud services, vulnerability management, and data privacy. Engagements are sold as professional services through direct enterprise relationships, with the firm acting as an extension of clients' internal CISO teams.
Is EverSec Group a public or private company?
EverSec Group is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was EverSec Group founded?
EverSec Group was founded in 2008. It employs 1 to 10 people.
Where is EverSec Group based?
EverSec Group is headquartered in Tarrytown, United States, in the North America region.
How does EverSec Group make money?
One revenue line is on record: cyber Security Consulting Services.
Does EverSec Group have an API?
No public API is recorded for EverSec Group.
What industry is EverSec Group in?
EverSec Group's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments. Its NAICS code is 54161 and its SIC code is 8742.