Cyber Engineering Services
CyberESI is a privately held Baltimore-based Managed Detection and Response provider founded in 2010, serving midsize enterprises, rural telecom providers, and federal-adjacent accounts via a 24/7 SOC and proprietary Blackhawk appliance for continuous monitoring, threat hunting, and incident response.
- Company typePrivate
- Founded2010
- HeadquartersBaltimore, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cyber Engineering Services does
Cyber Engineering Services, Inc. (CyberESI) is a privately held Managed Detection and Response (MDR) provider founded in 2010 and headquartered in Baltimore, Maryland. The company delivers continuous security monitoring, alert triage, threat hunting, and incident response through a 24/7 staffed Security Operations Center, targeting midsize enterprises with expanding cybersecurity needs as well as rural telecommunications providers and federal-adjacent accounts. Its proprietary Blackhawk appliance — a purpose-built 2U or 4U device with dual compute nodes and proprietary solid-state storage — houses custom full-packet capture software, custom IDS, and an integrated network visibility stack claimed to analyze traffic exceeding 10Gb/sec. Services are sold à la carte or in bundles via subscription MDR contracts, monthly vulnerability scanning subscriptions, pre-paid incident response retainers, and project-based professional services (Virtual CISO, risk assessment, cyber risk management plans aligned to NIST CSF, controls system cybersecurity for DoD projects, and incident response/IR Emergency Room). The company is founder-controlled by CEO Joseph Drissel, with COO Matt Barrett (ex-NIST CSF program lead, joined February 2019) leading growth, and has no disclosed venture or private equity backing. GTM is a combination of direct enterprise field sales, event-driven thought leadership (NTCA, RWA, NCSA/NASDAQ summits), a self-service web portal for emergency incident response, and a channel partnership with Womble Bond Dickinson for legal-bundled cyber retainers. The company is registered as Cyber Engineering Services, Incorporated in Maryland, USA.
Cyber Engineering Services firmographics
Firmographics- Name
- Cyber Engineering Services
- Legal name
- Cyber Engineering Services, Incorporated
- Website
- https://cyberesi.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CyberESI is a privately held Baltimore-based Managed Detection and Response provider founded in 2010, serving midsize enterprises, rural telecom providers, and federal-adjacent accounts via a 24/7 SOC and proprietary Blackhawk appliance for continuous monitoring, threat hunting, and incident response.
- Ownership category
- akta.pro rank
Cyber Engineering Services industry classification
Industry- Product category
- Managed Security Services
- NAICS
- Computer Facilities Management Services (541513), Other Computer Related Services (541519), Computer Systems Design Services (541512)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industry
- Cybersecurity Architecture & Security Integration (BPAEAAAL)
Keywords
Where Cyber Engineering Services is headquartered
LocationHeadquarters
- HQ city
- Baltimore
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Cyber Engineering Services business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Revenue model
- Managed Detection and Response (MDR) Services: Comprehensive security monitoring and incident response services provided on a continuous basis. Includes continuous monitoring, alert triage, threat hunting, and incident response. Services can be tailored and are available à la carte or as part of a Service Bundle.
- Incident Response Retainer: Pre-paid incident response support with discounted rates. Hours can be used during cybersecurity incidents. Tasks performed onsite or remotely depending on requirements. Monthly hours do not carry over.
- Incident Response Professional Services: Initial incident response including preliminary investigation, scope determination, mitigation recommendations. Full incident response with extended analysis, mitigation development, stakeholder reporting, and comprehensive final report documentation.
- Vulnerability Scanning Subscription: Monthly subscription service providing external and internal vulnerability scanning, penetration testing, and security assessments. Typical subscriptions include external, internal, or combined external-internal vulnerability scanning with semi-annual scans and annual penetration testing.
- Cyber Response Retainer (via Womble Bond Dickinson): Annual service offering discounted incident response hours, cyber awareness education, legal consultation, Attorney-Client Privilege for key work products, and secure data exchange via Cyber Risk Management portal.
- Cybersecurity Consulting Services: Services including Cybersecurity Consulting (Virtual CISO, policy development, risk assessment, compliance analysis), Cyber Response Readiness (incident response plans, tabletop exercises, digital forensics), Custom Solutions (architecture, design, engineering, implementation, operations), and Controls System Cybersecurity.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Case Review & Consultation - Panel of incident response experts for business hours case review |
| Subscription | Monthly | Vulnerability Scanning Subscription - Monthly scanning and penetration testing service |
| Subscription | Monthly | Incident Response Retainer - Pre-paid incident response support |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
Cyber Engineering Services product offering
Product offeringCore offering
Cyber Engineering Services (CyberESI) provides managed detection and response (MDR), incident response, and cybersecurity consulting to midsize enterprises with mission-critical networks. Services are delivered 24/7 from a Baltimore Operations Center and are built around a proprietary Blackhawk network capture and analysis appliance. The firm also sells subscription vulnerability scanning, penetration testing, incident response retainers, a Virtual CISO service, and emergency incident response through its Incident Response Emergency Room (IR ER).
Product overview
Cyber Engineering Services (CyberESI) offers a unified managed detection and response platform focused on midsize enterprises with expanding cybersecurity needs. The core offering is the Managed Detection and Response (MDR) service augmented by specialized cybersecurity services. The proprietary Blackhawk hardware appliance (available in 2U and 4U configurations) serves as the foundational technology for network capture, analysis, and security monitoring. Services are delivered through a 24/7 Security Operations Center and include threat hunting, incident response and forensics, SIEM services, vulnerability assessment, penetration testing, cybersecurity consulting, cyber response readiness, custom solutions, and subscription-based vulnerability scanning. Add-on modules include Virtual CISO, Cyber Risk Management Plan aligned to NIST CSF, Risk Assessment, Controls System Cybersecurity for DoD projects, Incident Response Retainer, and the Incident Response Emergency Room for active breach situations.
Differentiator
Problem solved
Functional benefit
Brands
- Blackhawk: Purpose-built multi-server and storage device housing proprietary software for network capture, log aggregation, forensic investigations, and intrusion detection.
Products and services
- Managed Detection and Response (MDR) Continuous security monitoring, alert triage, and incident response service providing defense-in-depth with threat hunting to identify previously undetected cyber threats. Available à la carte or as part of a Service Bundle, targeted at midsize enterprises with expanding cybersecurity needs.
- Incident Response Incident response procedures for examining computer security incidents including preliminary investigation, scope determination, mitigation recommendations, extended analysis, stakeholder reporting, and comprehensive final report documentation. Delivered onsite or remotely by experienced incident response professionals.
- Vulnerability Scanning Subscription Monthly subscription providing external and internal vulnerability scanning (up to 150 external or 255 internal IP addresses) with semi-annual scans and annual penetration testing. Includes combined external-internal scanning packages for organizations needing comprehensive vulnerability assessment.
- Blackhawk Appliance Purpose-built, multi-server and storage device housing proprietary software including custom network capture software with unique indexing and analysis technologies. Available in 2U and 4U configurations with dual compute nodes and proprietary solid-state hard drives. Captures, stores, and analyzes network traffic exceeding 10Gb per second.
- Incident Response Emergency Room (IR ER) Emergency incident response service for active security breaches with case review and consultation by a panel of incident response experts. Includes a web portal for service requests and a fee-based initial consultation, with pay-as-you-go monthly and per-gigabyte billing for ongoing services.
- Incident Response Retainer Pre-paid incident response support providing discounted response hours for use during cybersecurity incidents. Available as a standalone retainer or via Womble Bond Dickinson partnership with added cyber awareness education, legal consultation, Attorney-Client Privilege for key work products, and secure data exchange via the Cyber Risk Management portal.
- Virtual CISO (vCISO) Part-time experienced cybersecurity professional providing strategic guidance and support to manage cyber risks, develop policies, and increase cyber risk management focus for organizations that need executive-level security leadership without a full-time hire.
- Cyber Risk Management Plan NIST CSF-aligned cyber risk management plan customized to organization, sector, and business model with supply chain risk management practices. Designed for compliance with regulatory and grant requirements including FCC, NTIA BEAD, and USDA Rural eConnectivity programs.
- Controls System Cybersecurity UFGS 25 05 11 compliance solution for securing facility-related control systems (FRCS). Targeted at construction firms delivering DoD or federal projects that require compliance with federal cybersecurity standards for operational technology environments.
- Penetration Testing Validation that security controls are in place and working properly by viewing the network through the eyes of both a malicious actor and an experienced cybersecurity expert. Typically packaged as part of the annual penetration testing component of the Vulnerability Scanning Subscription.
Quantifiable outcome
- Reduced Mean Time to Detection (MTtD) and Mean Time to Resolution (MTtR)
- +1 more outcomes
Companies that use Cyber Engineering Services
Customer profileNamed customers1 record
Segments2 records
Ideal customer profiles2 records
Cyber Engineering Services technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Cyber Engineering Services partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered secondary and core.
- National Cyber Security Alliance (NCSA)secondaryCyberESI's COO Matt Barrett participated in panel at the 2019 NCSA and NASDAQ Cybersecurity Summit in New York City. Theme was 'Incident Response and Recovery' focusing on resilience and recovery following cyber attacks. Summit included security professionals from Department of Homeland Security.
- Womble Bond Dickinson (US) LLPcoreCyberESI works in service to Womble Bond Dickinson to provide a Cyber Incident Response and Recovery Retainer service. The partnership offers discounted incident response hours, cyber awareness education, legal consultation including customization of a Cyber Incident Response Plan, Attorney-Client Privilege for key work products, and highly secure data exchange via the Cyber Risk Management portal. Joint marketing efforts through Womble Bond Dickinson's privacy and cybersecurity practice.
- Telcom Insurance GroupsecondaryTelcom Insurance Group participates alongside CyberESI in panel discussions at NTCA CyberShare and RWA Infrastructure Summit conferences. Panels focus on cybersecurity challenges for small rural telecommunications providers. Topics include Salt Typhoon threats, funding cybersecurity mechanisms, and building cybersecurity village communities.
- Rural Wireless Association (RWA)secondaryCyberESI executives regularly participate in RWA Infrastructure Summit panels addressing cybersecurity topics relevant to rural telecommunications providers. Panels cover cyber risk management planning, Salt Typhoon threats, and cybersecurity comfort food strategies.
- NTCA - The Rural Broadband AssociationsecondaryActive participation in NTCA CyberShare conferences with panel discussions on topics including 'Cybersecurity: It Takes a Village', 'Jeoparty: Funding Cybersecurity Mechanisms', and 'Cybersecurity in the Land of Oz'. Features collaboration with Telcom Insurance Group and Womble Bond Dickinson.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Cyber Engineering Services competitors and assessment
Company assessmentDirect peers
- Arctic Wolf: Arctic Wolf is a leading MDR provider offering 24x7 security monitoring, threat detection, and response for mid-market and enterprise customers. It is a direct competitor to CyberESI in the midsize-enterprise MDR segment with overlapping subscription and concierge service models.
- eSentire: eSentire provides managed detection and response with a global SOC, focused on mid-market organizations. It directly competes with CyberESI on continuous monitoring, threat hunting, and incident response for midsize enterprises with mission-critical networks.
- Expel: Expel is a transparent MDR provider delivering 24x7 security monitoring, threat detection, and incident response with a SaaS-native platform. It competes directly with CyberESI for mid-market enterprise MDR contracts with a comparable subscription model.
- Huntress: Huntress provides managed detection and response focused on small and mid-market businesses with a focus on endpoint, identity, and SIEM telemetry. It is a direct competitor in the SMB/midsize MDR segment where CyberESI also competes.
- Binary Defense: Binary Defense provides MDR, threat hunting, and counter-threat intelligence services with an analyst-driven SOC model similar to CyberESI's. It is a closely comparable peer in continuous monitoring, IR retainers, and intelligence-led detection.
- Deepwatch: Deepwatch delivers managed detection and response with a cloud-native SOC platform focused on enterprise customers. It is a direct competitor in the MDR market with subscription and managed service models overlapping CyberESI's offerings.
Broad incumbents
- Secureworks: Secureworks is a broad cybersecurity incumbent offering managed detection and response, incident response, and consulting globally. It overlaps with CyberESI across MDR, IR, and compliance services, but operates at much larger scale across many verticals.
- CrowdStrike (Falcon Complete): CrowdStrike's Falcon Complete is a fully managed MDR offering built on its endpoint protection platform, serving enterprise and mid-market customers. It is a broad incumbent that competes with CyberESI on managed detection and response, particularly among platform-driven buyers.
- Rapid7 (Managed Services): Rapid7 offers managed detection and response, vulnerability management, and incident response as part of a broader security analytics platform. It overlaps with CyberESI's MDR and vulnerability scanning subscription offerings with comparable mid-market positioning.
- Sophos (Managed Detection and Response): Sophos provides managed detection and response services built on its endpoint and firewall platform for mid-market organizations. It is a broad incumbent with overlapping MDR and incident response capabilities serving a similar midsize enterprise customer base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Cyber Engineering Services compliance and trust
Trust signalCompliance1 record
Cyber Engineering Services financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Engineering Services leadership team
Management profileNumber of profiles
Profiles2 records
Cyber Engineering Services funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Engineering Services M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Engineering Services
What does Cyber Engineering Services do?
Cyber Engineering Services (CyberESI) provides managed detection and response (MDR), incident response, and cybersecurity consulting to midsize enterprises with mission-critical networks. Services are delivered 24/7 from a Baltimore Operations Center and are built around a proprietary Blackhawk network capture and analysis appliance. The firm also sells subscription vulnerability scanning, penetration testing, incident response retainers, a Virtual CISO service, and emergency incident response through its Incident Response Emergency Room (IR ER).
Is Cyber Engineering Services a public or private company?
Cyber Engineering Services is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber Engineering Services founded?
Cyber Engineering Services was founded in 2010. It employs 11 to 50 people.
Where is Cyber Engineering Services based?
Cyber Engineering Services is headquartered in Baltimore, United States, in the North America region.
How does Cyber Engineering Services make money?
Six revenue lines are on record. Managed Detection and Response (MDR) Services are the primary driver. The others are incident Response Retainer, incident Response Professional Services, vulnerability Scanning Subscription, cyber Response Retainer (via Womble Bond Dickinson) and cybersecurity Consulting Services.
Who are Cyber Engineering Services's main competitors?
Direct peers on record are Arctic Wolf, eSentire, Expel, Huntress, Binary Defense and Deepwatch. Broad incumbents are Secureworks, CrowdStrike (Falcon Complete), Rapid7 (Managed Services) and Sophos (Managed Detection and Response).
Does Cyber Engineering Services have an API?
No public API is recorded for Cyber Engineering Services.
What industry is Cyber Engineering Services in?
Cyber Engineering Services's product category is Managed Security Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEAAAL, Cybersecurity Architecture & Security Integration. Its NAICS code is 541513 and its SIC code is 7373.