REN-ISAC
REN-ISAC is a non-profit, Indiana University-hosted cybersecurity information sharing and analysis center serving 782+ higher education and research member institutions globally with threat intelligence, peer-led security assessments, passive DNS, and discounted SANS training.
- Company typePrivate
- Founded2003
- HeadquartersBloomington, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What REN-ISAC does
REN-ISAC (Research & Education Networks Information Sharing & Analysis Center) is a non-profit cybersecurity information sharing and analysis center founded in 2003 and hosted at Indiana University in Bloomington, Indiana. It serves higher education institutions, research and education networks, teaching hospitals and medical centers, and government-funded research organizations across the United States, Australia, Canada, New Zealand, the United Kingdom, and Switzerland. As of May 5, 2026, the organization counted 782 member institutions and over 3,000 active member representatives in its vetted trust community, governed by formal nomination and vetting procedures and using CISA's Traffic Light Protocol for classified information exchange.
REN-ISAC firmographics
Firmographics- Name
- REN-ISAC
- Legal name
- Research & Education Networks Information Sharing & Analysis Center
- Website
- https://ren-isac.net
- Company type
- Private
- Founded year
- 2003
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- REN-ISAC is a non-profit, Indiana University-hosted cybersecurity information sharing and analysis center serving 782+ higher education and research member institutions globally with threat intelligence, peer-led security assessments, passive DNS, and discounted SANS training.
- Ownership category
- akta.pro rank
REN-ISAC industry classification
Industry- Product category
- Cybersecurity Information Sharing and Threat Intelligence
- NAICS
- Security Systems Services (56162)
- SIC
- Services-Membership Organizations (8600)
- akta.pro primary industry
- Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF)
- akta.pro secondary industries
- Identity & Access Management (SSO/MFA) for Education (EDAFALAI), Identity & Access Security Services (IAM, PAM, Zero Trust) (BPAKAHAI)
Keywords
Where REN-ISAC is headquartered
LocationHeadquarters
- HQ city
- Bloomington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
REN-ISAC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Marketing or Sales
Revenue model
- Annual Membership Fees: REN-ISAC operates as a membership-based organization with annual fees structured in four tiers based on institution type and size. Fees range from $1,525 to $3,325 annually.
- SANS Training Partnership: Through partnership with SANS Institute, REN-ISAC enables higher education and K-12 organizations to purchase security training at 50%+ discounts. Aggregate purchase windows occur twice yearly (June-July and December-January).
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Fee Group A: Doctoral Universities with Highest Research Activity |
| Subscription | Annual | Fee Group B: Doctoral Universities with Higher Research Activity |
| Subscription | Annual | Fee Group C: Doctoral Universities with Moderate Research Activity |
| Subscription | Annual | Fee Group D: Smaller Institutions |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
REN-ISAC product offering
Product offeringCore offering
REN-ISAC operates a vetted trust community that delivers cybersecurity operational protection and response for higher education and research institutions through member-only threat intelligence sharing (Members' Wiki, Daily Watch Report, MISP, Passive DNS, Slack collaboration), coordinated incident response (CSIRT), peer-based security assessments and advisory services (ISAAS), and a SANS Institute training partnership at 50%+ discounts. Public offerings such as the HECVAT cloud vendor assessment tool, alerts, and white papers extend selected capabilities to non-members.
Product overview
REN-ISAC is a higher education and research network cybersecurity information sharing alliance offering a dual public/member-exclusive product portfolio. Public offerings include the Cloud Vendor Assessment Tool (HECVAT), incident response information, biannual SANS training discounts, and publicly available white papers and alerts. Member-exclusive services form the core value proposition: the Members' Wiki platform (backed by WikiJS) for threat intelligence and documentation, the Daily Watch Report for daily situational awareness, Passive DNS (pDNS) for DNS intelligence using Farsight Security infrastructure, the Security Event System (SES) for threat aggregation, MISP for automated threat indicator sharing, a private Slack instance for real-time collaboration, and Community Discussion Lists across OPS/General/Officer communities. Assessment and Advisory Services (ISAAS) provide Comprehensive General Assessments using NIST CSF, Policy/Process/Compliance Reviews, Penetration Testing, InfoSec Kickstart engagements, and Incident Response Tabletop Exercises—all conducted by peer assessors from other higher education institutions. Cybersecurity Training is delivered through a SANS Institute partnership offering OnDemand, Live Online, NetWars Continuous, and Security Awareness Training at over 50% cost savings. The annual RIMM conference provides networking and education for the community.
Differentiator
Problem solved
Functional benefit
Products and services
- Members' Wiki A WikiJS-backed, members-only information sharing and documentation platform providing TLP:GREEN or stricter alerts, advisories, service information, webinar recordings, and other information products accessible to member institutions of REN-ISAC.
- Daily Watch Report A members-only daily situational awareness periodical summarizing the latest vulnerabilities, attacks, events, and detailed cybersecurity reports curated for higher education and research member institutions.
- Passive DNS (pDNS) A DNS intelligence service that builds a searchable database of anonymized DNS request and response data contributed by participating higher education member institutions using Farsight Security Inc. sensors, with data shared through DomainTools Security Information Exchange (SIE).
- REN-ISAC Security Event System (SES) A threat intelligence repository that aggregates, correlates, and analyzes security events and shares the resulting intelligence with REN-ISAC members to enable timely cyber protection across the higher education community.
- Malware Information Sharing Platform (MISP) REN-ISAC's managed MISP instance enabling automated threat intelligence sharing within the community and providing high-confidence feeds of threat indicator data (IoCs) for use in member firewalls, SIEMs, and other security tools.
- Members Slack Instance A private, members-only Slack workspace enabling real-time communication and collaboration with REN-ISAC staff, Steering Committee members, and fellow member institutions, gated by SSO authentication.
- Community Discussion Lists Email-based discussion forums (OPS, General, and Officer lists) for threat intelligence sharing, best practices, peer questions, and announcements across the REN-ISAC member community.
- Higher Ed Incident Response Team (CSIRT) A computer security incident response team providing 24/7 incident response support and coordination for higher education institutions through the CSIRT Watch Desk ([email protected], +1 317-274-7228).
- Information and Security Assessment and Advisory Services (ISAAS) A comprehensive portfolio of peer-delivered assessment and advisory services covering Comprehensive General Assessments, Policy/Process/Compliance Reviews, Penetration Testing, InfoSec Kickstart Engagements, and Incident Response Tabletop Exercises, staffed by trained security professionals from fellow higher education institutions.
- Comprehensive General Assessments Full security program assessments aligned to the NIST Cybersecurity Framework, conducted by peer assessors from other higher education institutions over a four-day on-campus engagement for member institutions.
- Policy, Process, and Compliance Reviews Focused peer reviews of member policies, processes, or compliance efforts covering HIPAA, FERPA, GLBA, NIST SP 800-171 gap analysis, security operations, physical security, and incident response plans.
- Penetration Testing External and assumed-breach penetration tests, including cloud deployment testing, conducted by trained peer assessors from other higher education member institutions.
- InfoSec Kickstart Engagements Three-tiered affordable engagements for smaller colleges and universities including workshops, tabletop exercises, and security assessments to launch or improve their information security management programs.
- Incident Response Tabletop Exercises Three tiers of tabletop exercises from general scenario validation to custom scenarios with after-action reports, helping member organizations clarify roles and improve incident response plans.
- Blended Threat Workshops Hands-on tabletop exercises combining physical and information security scenarios such as ransomware attacks, public health events, and controversial speaker situations, producing after-action best-practice reports for the member community.
- SANS Cybersecurity Training (Aggregate Purchase Program) Partnership offering with SANS Institute enabling US and Canadian higher education and K-12 organizations to purchase SANS security training, certifications, and NetWars Continuous at over 50% discounts through biannual aggregate purchase windows (June 1 - July 31 and December 1 - January 31), available to both members and non-members.
- REN-ISAC Member Meeting (RIMM) Annual member conference featuring public and member-only sessions on cybersecurity trends, threat briefings, and peer networking for the REN-ISAC community, combined with OmniSOC Con as of 2026 (1,215 member-only and 2,124 public registrations at RIMM 2026).
- Cloud Vendor Assessment Tool (HECVAT) A public, free tool for assessing cloud service vendor security, available to both REN-ISAC members and non-members for evaluating vendor security posture in higher education procurement.
Quantifiable outcome
- 782 member institutions representing higher education and research globally
- +2 more outcomes
Companies that use REN-ISAC
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles5 records
REN-ISAC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
Feature3 records
REN-ISAC partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and strategic.
- SANS InstitutecorePartnership enabling higher education and K-12 organizations in the US and Canada to purchase SANS security training at over 50% cost savings. Aggregate purchase windows occur twice yearly (June 1-July 31 and December 1-January 31). Training includes certification in cyber defense, penetration testing, incident response, threat hunting, management, industrial control systems, and application security.
- Farsight Security Inc.coreProvides the sensor software for REN-ISAC's Passive DNS (pDNS) system. Sensors are installed at contributing member institutions to collect DNS request/response data for threat intelligence sharing.
- DomainToolscoreProvides the Security Information Exchange (SIE) platform for REN-ISAC's pDNS data collection. REN-ISAC shares collected data with DomainTools which distributes it to vetted security researchers and DNSDB customers.
- Internet2coreCollaborative partner supporting research and education networks. Internet2 is a member of REN-ISAC and co-hosts events including EDUCAUSE.
- EDUCAUSEcorePartner organization supporting higher education IT professionals. EDUCAUSE collaborates with REN-ISAC on events and shares cybersecurity resources with the higher education community.
- OmniSOCcoreCollaborative SOC for higher education providing 24/7 threat detection and response. OmniSOC and REN-ISAC co-hosted RIMM 2026 as a combined event. OmniSOC presents at REN-ISAC webinars and member meetings.
- CISA (Cybersecurity and Infrastructure Security Agency)strategicGovernment partner providing cybersecurity guidance, alerts, and supporting information sharing frameworks. REN-ISAC shares information with CISA and distributes CISA alerts to members.
- Indiana UniversitycoreIndiana University hosts REN-ISAC and provides infrastructure support. REN-ISAC is part of the Indiana University Cybersecurity Community. The organization is located at IU's Bloomington campus.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
REN-ISAC competitors and assessment
Company assessmentEmerging players
- MISP Project (Malware Information Sharing Platform): MISP is the open-source threat intelligence sharing platform that REN-ISAC uses and operates a managed instance of. While not a direct competitor, MISP represents an alternative model for community threat sharing that some institutions might pursue independently.
Others
- EDUCAUSE: EDUCAUSE is a nonprofit association serving higher education IT professionals and a REN-ISAC partner. Adjacent ecosystem organization that supports the same community but focuses on broader IT leadership rather than cybersecurity operations specifically.
- SANS Institute: SANS Institute is REN-ISAC's primary training partner, offering 50%+ discounted cybersecurity courses to higher education and K-12 organizations via REN-ISAC's aggregate purchase program. Adjacent ecosystem participant rather than direct competitor.
- Internet2: Internet2 is a U.S. research and education networking consortium that is both a REN-ISAC member and a strategic partner. Adjacent ecosystem participant providing the network infrastructure on which higher education cybersecurity depends; not a direct competitor.
Direct peers
- Health-ISAC: The Health Information Sharing and Analysis Center serves healthcare organizations with threat intelligence sharing, similar to how REN-ISAC serves higher education. REN-ISAC even serves teaching hospitals as members given the healthcare-education intersection.
- FS-ISAC: The Financial Services Information Sharing and Analysis Center is the most mature sector-specific ISAC. REN-ISAC follows the same ISAC model - vetted trust communities for threat intelligence sharing - applied to the higher education sector instead of financial services.
- IT-ISAC: The IT Information Sharing and Analysis Center serves IT industry vendors and operators with threat intelligence sharing. Shares the ISAC operating model with REN-ISAC and overlaps in membership given many higher education institutions run IT departments similar to enterprise IT shops.
- OmniSOC: OmniSOC is a collaborative 24/7 Security Operations Center for higher education institutions and a close operational partner of REN-ISAC (co-hosted RIMM 2026 with REN-ISAC). Highly comparable as a higher-education-specific cybersecurity service organization with overlapping member base.
- MS-ISAC (Multi-State ISAC / CIS): The Multi-State Information Sharing and Analysis Center, now part of the Center for Internet Security, provides threat intelligence and cybersecurity services to U.S. state, local, tribal, and territorial governments. Operates the same ISAC structure as REN-ISAC but for government entities.
- E-ISAC: The Electricity Information Sharing and Analysis Center serves the North American electricity industry with threat intelligence and incident response coordination. Functions as a sector-specific ISAC analogous to REN-ISAC's higher education focus.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
REN-ISAC social profiles
Digital presenceREN-ISAC financial estimates
Financial estimateRevenue estimate
Valuation estimate
REN-ISAC leadership team
Management profileNumber of profiles
Profiles12 records
REN-ISAC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
REN-ISAC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about REN-ISAC
What does REN-ISAC do?
REN-ISAC operates a vetted trust community that delivers cybersecurity operational protection and response for higher education and research institutions through member-only threat intelligence sharing (Members' Wiki, Daily Watch Report, MISP, Passive DNS, Slack collaboration), coordinated incident response (CSIRT), peer-based security assessments and advisory services (ISAAS), and a SANS Institute training partnership at 50%+ discounts. Public offerings such as the HECVAT cloud vendor assessment tool, alerts, and white papers extend selected capabilities to non-members.
Is REN-ISAC a public or private company?
REN-ISAC is a private company. It is classified as state government owned and is currently operating.
When was REN-ISAC founded?
REN-ISAC was founded in 2003. It employs 11 to 50 people.
Where is REN-ISAC based?
REN-ISAC is headquartered in Bloomington, United States, in the North America region.
How does REN-ISAC make money?
Two revenue lines are on record. Annual Membership Fees are the primary driver. The others are SANS Training Partnership.
Who are REN-ISAC's main competitors?
MISP Project (Malware Information Sharing Platform) is listed as an emerging player. Others are EDUCAUSE, SANS Institute and Internet2. Direct peers are Health-ISAC, FS-ISAC, IT-ISAC, OmniSOC, MS-ISAC (Multi-State ISAC / CIS) and E-ISAC.
Does REN-ISAC have an API?
No public API is recorded for REN-ISAC.
What industry is REN-ISAC in?
REN-ISAC's product category is Cybersecurity Information Sharing and Threat Intelligence. Its primary akta.pro industry code is BPAKADAF, Security Architecture & Engineering Advisory (Zero Trust, IAM, Network), with a secondary code of EDAFALAI, Identity & Access Management (SSO/MFA) for Education. Its NAICS code is 56162 and its SIC code is 8600.