Open Security
Open Security Inc. is a veteran-run cybersecurity services firm that delivers penetration testing, vulnerability management, threat simulation, security audits, and training to mid-market and enterprise clients in banking, healthcare, and manufacturing, anchored by its open-source Sirius Scan platform.
- Company typePrivate
- Founded2014
- HeadquartersSan Antonio, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Open Security does
Open Security Inc. is a veteran-run cybersecurity services firm headquartered in San Antonio, Texas, founded in 2014 and operating with 11-50 employees. The company delivers offensive security services to mid-market and enterprise clients across banking/financial, healthcare, and manufacturing verticals, with offerings spanning penetration testing, vulnerability management, threat simulation, security audits, and training and awareness programs. Its service portfolio is detailed by sub-discipline, including network, application, hardware, manufacturing operations, and remote-hire penetration testing, as well as ransomware emulation, red/blue/purple team exercises, social engineering simulations, and cloud, code, and cryptocurrency security audits.
The firm's underlying technology centers on Sirius Scan, an enterprise-grade, open-source vulnerability management platform that provides continuous scanning, risk prioritization, and remediation tracking. This product is positioned alongside the professional services practice rather than replacing it; Sirius Scan supports ongoing vulnerability assessment programs while the firm's engineers deliver the hands-on, consultative engagements that differentiate the offering from automated scan-only vendors.
Open Security operates a sales-led, direct go-to-market model targeting mid-market and enterprise customers through website contact forms, phone outreach, and consultative selling led by a dedicated CRO, VP Sales, and Business Development Manager. Pricing is quote-based and not publicly disclosed, with services typically structured as multi-year engagements. The company is privately held with no disclosed institutional funding, no parent entity, and no documented acquisitions or restructuring events. Revenue is generated through professional services billing per engagement, with the open-source Sirius Scan platform serving as a complementary lead-generation and retention asset rather than a recurring SaaS revenue line.
Open Security firmographics
Firmographics- Name
- Open Security
- Legal name
- Open Security Inc.
- Website
- https://opensecurity.io
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Open Security Inc. is a veteran-run cybersecurity services firm that delivers penetration testing, vulnerability management, threat simulation, security audits, and training to mid-market and enterprise clients in banking, healthcare, and manufacturing, anchored by its open-source Sirius Scan platform.
- Ownership category
- akta.pro rank
Open Security industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industry
- Cybersecurity Awareness & Digital Safety Training for Security Personnel (BPAKAOAO)
Keywords
Where Open Security is headquartered
LocationHeadquarters
- HQ city
- San Antonio
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Open Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Professional Cybersecurity Services: Revenue generated from professional cybersecurity consulting and testing services including penetration testing, vulnerability assessments, threat simulation, security audits, and training programs. Services are tailored to client needs and billed per engagement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise pricing |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels5 records
Open Security product offering
Product offeringCore offering
Open Security delivers professional offensive cybersecurity services including penetration testing (network, application, hardware, manufacturing, remote-hire), vulnerability management assessments and audits, threat simulation (ransomware emulation, red/blue/purple team exercises, social engineering), security audits (cloud, code, crypto, application security), and training & awareness programs. The company also offers Sirius Scan, an enterprise-grade open-source vulnerability management platform that provides continuous scanning, risk prioritization, and remediation tracking.
Product overview
Open Security is a veteran-run cybersecurity services company offering a portfolio of professional security services and one core technology product. The primary product is Sirius Scan, an enterprise-grade, open-source vulnerability management platform that provides continuous scanning and risk prioritization. The services include Penetration Testing (covering network, hardware, application, manufacturing, and remote-hire testing), Vulnerability Management (assessments, monthly scans, and program audits), Threat Simulation (ransomware emulation, team exercises, social engineering), Security Audits (cloud, code, crypto, and application security), and Training & Awareness (tabletop exercises and phishing simulations). Together, these offerings provide a comprehensive offensive security suite for businesses requiring risk-prioritized, executive-ready assessments.
Differentiator
Problem solved
Functional benefit
Brands
- Sirius Scan: Enterprise-grade, open-source vulnerability management platform
Products and services
- Sirius Scan Enterprise-grade, open-source vulnerability management platform that provides continuous scanning, risk prioritization, and remediation tracking for enterprise environments. Offered by Open Security.
- Penetration Testing Security assessment service that tests systems the way real attackers would, identifying weaknesses in networks, applications, hardware, and manufacturing operations for businesses requiring hands-on offensive security testing.
- Vulnerability Management Ongoing vulnerability assessment service including internal/external vulnerability assessments, monthly network scans, and vulnerability management program creation and audits.
- Threat Simulation Adversary simulation service including ransomware emulation, red/blue/purple team exercises, and social engineering/phishing simulations to test organizational response to real-world threats.
- Security Audits Comprehensive security audit services covering cloud security, development code evaluations, cryptocurrency security, and rapid application security updates.
- Training & Awareness Security training and awareness service including tabletop exercises and social engineering awareness programs with phishing simulations to improve organizational security posture.
Companies that use Open Security
Customer profileSegments4 records
Ideal customer profiles4 records
Open Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Open Security partnerships and signals
Strategic signalRecent moves5 records
Expansion highlights4 records
Open Security competitors and assessment
Company assessmentEmerging players
- Trail of Bits: Research-driven offensive security firm offering pen testing, security audits (especially cryptography and code), and security engineering consulting. Comparable in the security audits and code evaluation services Open Security offers.
- Schellman: Specialized security and compliance firm providing penetration testing, vulnerability assessments, and SOC 2/PCI audits for mid-market and enterprise. Highly comparable as an assessment-led boutique with overlap in pen testing and audit categories.
Broad incumbents
- Tenable: Public vulnerability management and exposure management platform (Nessus, Tenable.io). Adjacent competitor since Open Security's Sirius Scan and vulnerability assessment services address the same buyer pain points (continuous scanning, risk prioritization).
- NCC Group: Global cybersecurity services firm with extensive pen testing, vulnerability management, and incident response offerings. Operates at much larger scale across multiple geographies but with overlapping service categories and target customers.
- Rapid7: Public cybersecurity platform combining vulnerability management (InsightVM), pen testing services (Rapid7 Metasploit), and managed detection. Comparable because Open Security's Sirius Scan competes in the same vulnerability management space.
- Optiv: Large cybersecurity solutions integrator and advisory firm delivering pen testing, vulnerability management, risk assessments, and managed security to mid-market and enterprise. Comparable enterprise-channeled delivery model.
- Secureworks: MSSP and security services firm offering penetration testing, vulnerability management, threat simulation, and 24/7 SOC services. Comparable breadth of services, though Secureworks operates at substantially greater scale and global reach.
Direct peers
- Coalfire: Cybersecurity advisory and assessment firm specializing in penetration testing, security audits, and compliance-driven testing (PCI, SOC 2, HITRUST, FedRAMP). Directly comparable service portfolio targeting banking, healthcare, and enterprise.
- Bishop Fox: Offensive security firm focused on penetration testing, red teaming, and vulnerability management for enterprise clients. Directly comparable as a boutique, offensive-first consultancy with similar testing methodologies and mid-market/enterprise focus.
- TrustedSec: Veteran-founded offensive security consultancy offering pen testing, red/purple team, vulnerability assessments, and training. Highly comparable given similar veteran-run positioning, offensive-first approach, and training event presence.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks6 records
Key highlights6 records
Customer concentration
Open Security social profiles
Digital presenceOpen Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Open Security leadership team
Management profileNumber of profiles
Profiles8 records
Open Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Open Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Open Security
What does Open Security do?
Open Security delivers professional offensive cybersecurity services including penetration testing (network, application, hardware, manufacturing, remote-hire), vulnerability management assessments and audits, threat simulation (ransomware emulation, red/blue/purple team exercises, social engineering), security audits (cloud, code, crypto, application security), and training & awareness programs. The company also offers Sirius Scan, an enterprise-grade open-source vulnerability management platform that provides continuous scanning, risk prioritization, and remediation tracking.
Is Open Security a public or private company?
Open Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Open Security founded?
Open Security was founded in 2014. It employs 11 to 50 people.
Where is Open Security based?
Open Security is headquartered in San Antonio, United States, in the North America region.
How does Open Security make money?
One revenue line is on record: professional Cybersecurity Services.
Who are Open Security's main competitors?
Emerging players on record are Trail of Bits and Schellman. Broad incumbents are Tenable, NCC Group, Rapid7, Optiv and Secureworks. Direct peers are Coalfire, Bishop Fox and TrustedSec.
Does Open Security have an API?
No public API is recorded for Open Security.
What industry is Open Security in?
Open Security's product category is Cybersecurity Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of BPAKAOAO, Cybersecurity Awareness & Digital Safety Training for Security Personnel. Its NAICS code is 541519 and its SIC code is 7373.