Razorthorn Security
Razorthorn Security is a UK-based cybersecurity consultancy founded in 2007, delivering CREST-accredited penetration testing, compliance advisory (ISO 27001, PCI DSS, DORA, NIS2), managed security services, and its Razor's Edge CTEM platform to Fortune 500, financial services, and European enterprise clients.
- Company typePrivate
- Founded2007
- HeadquartersTunbridge Wells, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Razorthorn Security does
Razorthorn Security is a UK-based cybersecurity consultancy founded in 2007 and headquartered in Tunbridge Wells, Kent. The firm delivers professional services across three pillars: cybersecurity consultancy (security reviews, third-party risk management, DevSecOps assessments, CISO as a Service), cybersecurity testing (CREST-accredited penetration testing, vulnerability assessments, red/purple team exercises, social engineering), and managed services (24/7 threat intelligence, SIEM, phishing protection, vulnerability scanning). Razorthorn is also a PCI DSS Qualified Security Assessor (QSA), with Managing Director James Rees leading the practice, and holds CREST accreditation and Gartner market leader recognition. Its customers include Fortune 500 companies and major European organisations, with named segments spanning financial services, critical infrastructure, mid-market, and SMEs/public sector.
The firm's flagship technology offering is the Razor's Edge Continuous Threat Exposure Management (CTEM) platform, which combines 24/7 automated vulnerability scanning with CREST-accredited expert validation across on-premises, cloud, and SaaS environments. The platform is backed by a proprietary threat library of 11,000+ attack techniques and 70,000+ prevention signatures/detection rules updated daily, with results mapped to MITRE ATT&CK. Razorthorn also delivers compliance consultancy across ISO 27001, SOC 2, Cyber Essentials, DORA, NIS2, NIST, and GDPR. The CTEM platform won the 2024 Cyber Security Excellence Awards.
Razorthorn generates revenue primarily through bespoke, quote-based professional services engagements supplemented by subscription/managed services contracts for CTEM and 24/7 monitoring. Pricing is not publicly disclosed; CTEM contracts are multi-year with bespoke scoping, while DORA gap analysis is offered as a fixed-fee engagement. Go-to-market is sales-led and direct, using website content, free scoping calls, and consulting engagements to win enterprise and mid-market accounts across the UK and Europe. The firm has no disclosed external investors or parent company and operates as an independent, privately held entity with 11-50 employees.
Razorthorn Security firmographics
Firmographics- Name
- Razorthorn Security
- Legal name
- Razorthorn Security
- Website
- https://razorthorn.com
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Razorthorn Security is a UK-based cybersecurity consultancy founded in 2007, delivering CREST-accredited penetration testing, compliance advisory (ISO 27001, PCI DSS, DORA, NIS2), managed security services, and its Razor's Edge CTEM platform to Fortune 500, financial services, and European enterprise clients.
- Ownership category
- akta.pro rank
Razorthorn Security industry classification
Industry- Product category
- Cybersecurity Consultancy Services
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Data Security & Privacy Services (DLP, Encryption, Privacy Ops) (BPAKAHAM)
Keywords
Where Razorthorn Security is headquartered
LocationHeadquarters
- HQ city
- Tunbridge Wells
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Razorthorn Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consultancy: Professional consulting services including cybersecurity reviews, third-party risk management, DevSecOps assessments, CISO as a Service, and strategic security advice. Delivered through experienced consultants providing assessments, gap analyses, and implementation guidance.
- Compliance Consultancy: Compliance advisory services covering ISO 27001, PCI DSS (including QSA auditing), SOC 2, Cyber Essentials, DORA, NIS2, NIST, and GDPR. Includes gap analysis, remediation planning, and certification support.
- Security Testing Services: CREST accredited penetration testing across infrastructure, web applications, wireless networks, and mobile platforms. Includes vulnerability assessments, security control assessments, red team assessments, purple team assessments, and physical red team assessments.
- Managed Services (Razor's Edge CTEM): Continuous threat exposure management platform providing 24/7 monitoring, vulnerability scanning, expert validation, and remediation tracking. Subscription-based service with configurable service levels and optional modules.
- Managed Cybersecurity Services: 24/7 managed cybersecurity services including managed threat intelligence, managed SIEM services, managed phishing protection, and managed vulnerability scanning. Provided as an extension to in-house teams or as dedicated managed services partnership.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Bespoke pricing for CTEM platform determined by organizational requirements |
| One time/ perpetual license | Pay-as-you-go | DORA gap analysis fixed-fee engagement |
| Other | Pay-as-you-go | Red team assessment pricing based on scope, objectives, duration and attack vectors |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels4 records
Razorthorn Security product offering
Product offeringCore offering
Razorthorn Security is an information security and cyber intelligence consultancy providing cybersecurity consultancy, CREST-accredited security testing, compliance advisory, and 24/7 managed services. It also offers Razor's Edge, a Continuous Threat Exposure Management (CTEM) platform combining automated vulnerability scanning with expert validation.
Product overview
Razorthorn Security offers a comprehensive cybersecurity portfolio of professional services rather than a unified software product. The core offerings consist of three service pillars: Cybersecurity Consultancy (security reviews, compliance assessments, third-party risk management, DevSecOps, and CISO as a Service), Cybersecurity Testing (CREST-accredited penetration testing, vulnerability assessments, red/purple team exercises, and social engineering testing), and Managed Services (24/7 threat intelligence, SIEM, phishing protection, and vulnerability scanning). Their flagship product is the Razor's Edge CTEM Platform, a Continuous Threat Exposure Management solution that provides always-on automated vulnerability scanning with expert validation across cloud and hybrid environments. The company supports multiple compliance frameworks including ISO 27001, SOC 2, Cyber Essentials, DORA, NIS2, NIST, GDPR, and PCI DSS (where they hold QSA status). Razorthorn is CREST approved and Gartner-recognised, operating since 2007 with a focus on Fortune 500 and major organisations.
Differentiator
Problem solved
Functional benefit
Brands
- Razor's Edge: Continuous Threat Exposure Management (CTEM) platform providing 24/7 automated vulnerability scanning with expert validation, real-time alerting, and remediation assurance across cloud, on-premises, and SaaS environments.
Products and services
- Cybersecurity Consultancy Professional cybersecurity consulting services including security reviews, third-party risk management, DevSecOps assessments, and CISO as a Service, delivered by certified consultants.
- Cybersecurity Testing Comprehensive suite of security testing services including CREST-accredited penetration testing, vulnerability assessments, security control assessments, and red/purple team exercises.
- Managed Services 24/7 managed cybersecurity services including managed threat intelligence, managed SIEM, managed phishing protection, and managed vulnerability scanning.
- Razor's Edge CTEM Platform Continuous Threat Exposure Management platform providing always-on security through automated vulnerability scanning, expert validation, and real-time alerting across cloud, on-premises, and SaaS environments. Winner of the 2024 Cyber Security Excellence Awards.
- Cybersecurity Review Independent assessment identifying security gaps in controls, policies, and procedures, evaluating posture against ISO 27001, DORA, and NIST frameworks with comprehensive reporting and remediation recommendations.
- Third Party Risk Management Assessment and management of risks posed by suppliers, vendors, and partners, evaluating third-party security posture against industry standards and providing recommendations for supply chain risk exposure.
- PCI DSS Consultancy & QSA Auditing PCI DSS compliance consultancy and Qualified Security Assessor audit services covering gap analysis, remediation, certification, and ongoing maintenance for organisations handling payment card data.
- DevSecOps Assessment Evaluation of an organisation's DevSecOps practices including secure development training, continuous integration/delivery/testing/monitoring, providing a roadmap for continuous security improvement.
- CISO as a Service (CISOaaS) Outsourced security leadership providing Chief Information Security Officer expertise including strategic planning, risk management, compliance guidance, and team mentoring without hiring a full-time employee.
- Cyber Security Compliance Compliance consultancy covering multiple frameworks including ISO 27001, SOC 2, Cyber Essentials, DORA, NIS2, NIST, and GDPR with gap analysis, implementation, and certification support.
- ISO 27001 Compliance Consultancy for achieving ISO 27001 certification including gap analysis, ISMS implementation, risk assessment, and certification audit support for Information Security Management Systems.
- SOC 2 Compliance SOC 2 compliance audit services developed by AICPA for data storage and protection, covering Trust Service Criteria for security, availability, processing integrity, confidentiality, and privacy.
- Cyber Essentials Compliance UK government-backed Cyber Essentials and Cyber Essentials Plus certification consultancy covering baseline technical controls including firewalls, patch management, malware protection, and access controls.
- DORA Compliance Specialist Digital Operational Resilience Act compliance consultancy for financial institutions covering ICT risk management, incident reporting, resilience testing, and third-party oversight per EU Regulation 2022/2554.
- NIS2 Compliance Expert consultancy for NIS2 Directive compliance covering cybersecurity measures, risk assessments, and implementation planning for essential services in critical sectors including healthcare, energy, transport, and finance.
- NIST Compliance NIST Cybersecurity Framework compliance consultancy covering the five core functions (Identify, Protect, Detect, Respond, Recover) through gap analysis, risk assessments, and tailored implementation plans.
- GDPR Compliance Expert data protection consultancy for UK GDPR compliance covering data mapping, impact assessments, policy development, and implementation of privacy-by-design principles.
- CREST Accredited Penetration Testing CREST-accredited penetration testing across infrastructure, web applications, wireless networks, and mobile platforms using OWASP-aligned methodology with detailed vulnerability analysis and remediation guidance.
- Security Control Assessment Validation of security tool effectiveness against real-world threats including malware, ransomware, phishing, and data exfiltration, with MITRE ATT&CK framework mapping and actionable remediation guidance.
- Vulnerability Assessment Vulnerability scanning across internal and external infrastructure, networks, applications, and cloud environments with expert analysis, prioritisation, and remediation guidance.
- Cloud Security Reviews Comprehensive cloud security assessments for AWS, Azure, Google Cloud, Microsoft 365, and Google Workspace environments covering identity, access management, encryption, and compliance posture.
- Social Engineering Testing Testing of employee susceptibility to manipulation and deception through phishing, vishing, smishing, pretexting, and physical security breaches with actionable recommendations for improving awareness.
- Red Team Assessment CREST-certified adversary simulation testing entire security programmes through covert operations over 30-day engagements, assessing detection and response capabilities against realistic attacks mapped to MITRE ATT&CK.
- Purple Team Assessment Collaborative assessment combining red and blue team expertise for simultaneous testing and capability building, developing custom detection rules and improving incident response procedures.
- Physical Red Team Assessment Physical penetration testing evaluating physical security measures including access controls, social engineering, tailgating, and lock bypassing to assess facility security effectiveness.
Quantifiable outcome
- Reduced security incidents through continuous monitoring vs periodic testing
- +3 more outcomes
Companies that use Razorthorn Security
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles3 records
Razorthorn Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Razorthorn Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Razorthorn Technology PartnerscoreRazorthorn works in partnership with hand-picked, industry leading solution providers, carefully selected for quality, effectiveness and to complement the services offered. These technology partners provide tools and solutions that integrate with and enhance Razorthorn's cybersecurity consultancy and testing services.
Scale indicators6 records
Recent moves5 records
Expansion highlights5 records
Razorthorn Security competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Global MSSP and cybersecurity consultancy offering penetration testing, managed security, and compliance advisory. Competes for similar enterprise and financial services compliance budgets from a much larger platform.
- Orange Cyberdefense: European cybersecurity services arm of Orange operating across MSSP, consulting, threat intelligence, and compliance. Broader incumbent serving same DORA/NIS2-driven enterprise market across multiple geographies.
- Mandiant (Google Cloud): Premier cybersecurity consultancy specialising in incident response, threat intelligence, and security assessments including red teaming. Sets the upper bound of credibility Razorthorn competes against for Fortune 500 testing and advisory engagements.
- WithSecure (formerly F-Secure): European-headquartered cybersecurity provider offering managed detection, consulting, and security testing services. Overlaps with Razorthorn's compliance and testing portfolio as a larger incumbent.
Direct peers
- Pentest People: UK-based penetration testing and cybersecurity services firm delivering CREST-accredited testing, vulnerability assessments, and managed security services. Comparable UK mid-market competitor with similar service stack.
- NCC Group: UK-headquartered cybersecurity consultancy offering CREST-accredited penetration testing, compliance advisory, and managed security services. Most comparable peer given UK base, similar service breadth across testing and compliance, and enterprise customer overlap.
- Bishop Fox: US-based offensive security consultancy specialising in penetration testing, red teaming, and attack surface management. Closely comparable in service focus (testing-led) with similar boutique consulting profile.
- Cyberis: UK-based cybersecurity consultancy providing penetration testing, security assessments, and managed security services. Similar size, geography, and CREST-accredited testing focus as Razorthorn.
- Pen Test Partners: UK-based penetration testing and security consultancy specialising in CREST-accredited testing across web, infrastructure, cloud, and IoT. Direct competitor in the UK pen testing and security advisory market Razorthorn serves.
- NetSPI: Penetration testing and attack surface management firm offering CREST-aligned testing, vulnerability management, and continuous security testing platforms. Direct competitor in enterprise security testing and CTEM-adjacent services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Razorthorn Security social profiles
Digital presenceRazorthorn Security compliance and trust
Trust signalCompliance4 records
Razorthorn Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Razorthorn Security leadership team
Management profileNumber of profiles
Profiles1 record
Razorthorn Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Razorthorn Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Razorthorn Security
What does Razorthorn Security do?
Razorthorn Security is an information security and cyber intelligence consultancy providing cybersecurity consultancy, CREST-accredited security testing, compliance advisory, and 24/7 managed services. It also offers Razor's Edge, a Continuous Threat Exposure Management (CTEM) platform combining automated vulnerability scanning with expert validation.
Is Razorthorn Security a public or private company?
Razorthorn Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Razorthorn Security founded?
Razorthorn Security was founded in 2007. It employs 11 to 50 people.
Where is Razorthorn Security based?
Razorthorn Security is headquartered in Tunbridge Wells, United Kingdom, in the Europe region.
How does Razorthorn Security make money?
Five revenue lines are on record. Cybersecurity Consultancy is the primary driver. The others are compliance Consultancy, security Testing Services, managed Services (Razor's Edge CTEM) and managed Cybersecurity Services.
Who are Razorthorn Security's main competitors?
Broad incumbents on record are Trustwave, Orange Cyberdefense, Mandiant (Google Cloud) and WithSecure (formerly F-Secure). Direct peers are Pentest People, NCC Group, Bishop Fox, Cyberis, Pen Test Partners and NetSPI.
Does Razorthorn Security have an API?
No public API is recorded for Razorthorn Security.
What industry is Razorthorn Security in?
Razorthorn Security's product category is Cybersecurity Consultancy Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services.