ECQ
ECQ (E-CQURITY) is a Southeast Asia-based offensive cybersecurity consultancy, founded 2001, delivering penetration testing, red team operations, OT/ICS security, and compliance services to financial, industrial, government, and technology clients across Singapore, Thailand, Vietnam, and the USA.
- Company typePrivate
- Founded2001
- HeadquartersBangkok, Thailand
- Headcount51–100
- GTM typeB2B
- OfferingServices
What ECQ does
ECQ (E-CQURITY) is a Southeast Asia-based offensive cybersecurity services firm founded in 2001, delivering penetration testing, red team/adversary simulation, compromise assessment, secure code review, OT/ICS security, and compliance consulting from offices in Singapore (regional headquarters), Bangkok, Ho Chi Minh City, and South Carolina, USA. Its service portfolio is structured around proprietary, branded methodologies — the RAPID five-phase pentest framework, the DRAMA secure code review approach, and the AID ICS framework for industrial control systems — supplemented by the HackGrid Cyber Range training platform and resold Gleg Exploit Packs. ECQ also publishes a Zero-Day Tracker vulnerability database and white papers as thought leadership, and holds ISO/IEC 27001 and CREST accreditations.
ECQ earns revenue primarily through project-based professional services engagements, with custom quotes and no publicly disclosed pricing tiers; engagements span penetration tests, red team operations, compliance consulting (PCI-DSS, ISO 27001, PDPA, OIC, SEC), and training. Its go-to-market is enterprise field sales direct to financial institutions, industrial operators, technology companies, and government agencies, supplemented by event-driven brand building through CTF competitions (KISA Asean CTF, GCC Thailand/Singapore CTF, Pwn2Own ICS/SCADA). The company's competitive positioning rests on elite offensive talent — demonstrated by multiple CTF wins and a deep bench of certifications including OSCE, OSEP, OSED, OSCP, GXPN, and CREST — rather than on a software platform or AI-driven automation.
ECQ firmographics
Firmographics- Name
- ECQ
- Legal name
- E-CQURITY Pte Ltd
- Website
- https://e-cq.net
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- ECQ (E-CQURITY) is a Southeast Asia-based offensive cybersecurity consultancy, founded 2001, delivering penetration testing, red team operations, OT/ICS security, and compliance services to financial, industrial, government, and technology clients across Singapore, Thailand, Vietnam, and the USA.
- Ownership category
- akta.pro rank
ECQ industry classification
Industry- Product category
- Offensive Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511), Computer Training (611420)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industries
- Cybersecurity (General) (EDAOAIAB), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
Keywords
Where ECQ is headquartered
LocationHeadquarters
- HQ city
- Bangkok
- HQ country
- Thailand
- HQ region
- Asia
Offices4 records
Markets served
ECQ business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Security Services: ECQ generates revenue through professional services engagements including penetration testing, red team operations, security assessments, compliance consulting, and training services. Revenue is project-based with engagements typically structured as one-time assessments or retainer-based consulting arrangements.
Go-to-market motion2 records
Distribution channels1 record
Marketing channels4 records
ECQ product offering
Product offeringCore offering
ECQ (E-CQURITY) is an offensive cybersecurity services firm founded in 2001 that delivers penetration testing, adversary simulation, code review, cryptography review, compliance consulting (PCI DSS, GDPR, ISO 27001), ICS/OT security assessments and cyber-range training. The firm applies proprietary methodologies — RAPID, DRAMA, AID ICS, Zero-Day Tracker and the HackGrid Cyber Range — to enterprise clients in financial services, healthcare, industrial automation and government sectors across Southeast Asia and the United States.
Product overview
ECQ (E-CQURITY) is an offensive security services company offering a comprehensive portfolio of security assessment and consulting services. The core offering centers on the proprietary RAPID Penetration Test Framework and Adversary Simulation service, supplemented by specialized assessment services including Web Application, Mobile App, Wireless, and Scenario-based Penetration Tests, plus Compromise Assessment for detecting existing breaches. These are complemented by Analysis services (Secure Code Review, Application Security Analysis, and Cryptography Services) and Compliance services (PCI, ISO 27001, and regional regulations). ECQ also offers proprietary frameworks like the AID ICS Framework for industrial control systems security, the HackGrid Cyber Range for training, and Exploit Packs through its Gleg partnership. The portfolio is structured as a unified service offering rather than a software platform.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Services Authorized simulated attacks against enterprise networks, web/mobile applications and cloud environments to identify exploitable vulnerabilities before adversaries do. Targeted at enterprise security teams and CISOs in financial, healthcare, government and technology firms.
- Adversary Simulation (Red Teaming) Full-scope red-team exercises that emulate advanced persistent threats (APTs) to test an organization's detection, response and resilience. Designed for mature enterprise security programs and government/defence-adjacent organizations.
- ICS/SCADA & OT Security Assessment Security assessments of operational-technology and industrial-control-system environments, covering vulnerability discovery, exploitation testing and safety impact analysis. Targeted at operators of critical infrastructure, manufacturing plants and industrial automation providers.
- Compliance Consulting Consulting engagements that prepare and assess organizations against PCI DSS, GDPR and ISO 27001 standards, with the firm itself certified to ISO 27001. Serves regulated enterprises that need certification or audit support.
- Source Code & Cryptography Review Manual and automated review of application source code and cryptographic implementations to identify logic flaws, insecure designs and weak cryptography. Targeted at software-development organizations and fintech/security vendors.
- Cyber Range Training Hands-on offensive and defensive training programs delivered through the HackGrid Cyber Range, including Capture-the-Flag content and team-upskilling curricula. Targeted at corporate security teams, government cyber-units and educational institutions.
Quantifiable outcome
- 1st place in KISA Asean CTF 2024
- +3 more outcomes
Companies that use ECQ
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles2 records
ECQ technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
ECQ partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- GlegcoreECQ partners with Gleg to offer Exploit Packs including Agora, D2 pack, DefPack, SCADA, and ZDI. These exploit packs provide specialized vulnerability and exploitation tools for security assessments, complementing ECQ's penetration testing services.
- SkillsparminorPartner logo displayed on ECQ About page, indicating a business relationship for cybersecurity training or services collaboration.
- Vector InfotechminorPartner logo displayed on ECQ About page, indicating a business relationship for technology or services collaboration.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
ECQ competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-headquartered global cybersecurity consultancy with a large offensive-security practice including penetration testing, red team, and OT/ICS assessments. Closely comparable business model and service mix to ECQ, but at significantly larger scale and global reach.
- Bishop Fox: US-based offensive-security firm specializing in penetration testing, red team, and attack-surface management. Highly comparable to ECQ in service portfolio and elite-talent positioning, serving similar enterprise financial and technology clients.
- Trustwave: Global cybersecurity consultancy and MDR provider with a strong penetration testing and adversary simulation practice. Overlaps directly with ECQ's pentest and red team services for enterprise and government clients.
- Secarma: UK-based penetration testing and cybersecurity consultancy offering pentest, red team, and compliance services. Closely matches ECQ's consulting-led, CREST-aligned service model at small-to-mid scale.
- Nettitude: CREST-accredited offensive-security consultancy providing pentest, red team, and OT security services. Highly comparable to ECQ in accreditation profile, service mix, and enterprise delivery model.
Broad incumbents
- NCC Group (iTrust / Arcanum-style OT practice) — represented via NCC above; secondary listed: Mandiant (Google Cloud): Global incident-response and threat-intelligence leader (now part of Google Cloud) with a sizable offensive-security consulting practice. Competes with ECQ for red team and OT engagements but as part of a much broader intelligence and IR portfolio.
- F-Secure (WithSecure): European cybersecurity firm with a dedicated offensive-security consulting practice covering pentest, red team, and managed detection. Broader portfolio than ECQ but directly competes for enterprise offensive-security engagements.
Emerging players
- Positive Technologies: Russia-origin cybersecurity firm with strong offensive-security research and SCADA/ICS focus, including exploit research and pentest tooling. Comparable to ECQ's OT/ICS specialization and vulnerability-research reputation, with broader product portfolio.
- HackerOne: Bug-bounty and pentest-as-a-service platform that competes for the same enterprise offensive-security budget as ECQ, though via a crowdsourced platform model rather than a traditional consultancy. Useful comparator for productization trajectory.
Regional players
- NSFOCUS: Asia-Pacific-headquartered cybersecurity vendor with a meaningful APAC pentest and security-services presence. Comparable to ECQ as a regional player expanding into enterprise and government accounts across Southeast Asia.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
ECQ social profiles
Digital presenceECQ compliance and trust
Trust signalCompliance2 records
ECQ financial estimates
Financial estimateRevenue estimate
Valuation estimate
ECQ leadership team
Management profileNumber of profiles
Profiles1 record
ECQ funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ECQ M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ECQ
What does ECQ do?
ECQ (E-CQURITY) is an offensive cybersecurity services firm founded in 2001 that delivers penetration testing, adversary simulation, code review, cryptography review, compliance consulting (PCI DSS, GDPR, ISO 27001), ICS/OT security assessments and cyber-range training. The firm applies proprietary methodologies — RAPID, DRAMA, AID ICS, Zero-Day Tracker and the HackGrid Cyber Range — to enterprise clients in financial services, healthcare, industrial automation and government sectors across Southeast Asia and the United States.
Is ECQ a public or private company?
ECQ is a private company. It is classified as unknown and is currently operating.
When was ECQ founded?
ECQ was founded in 2001. It employs 51 to 100 people.
Where is ECQ based?
ECQ is headquartered in Bangkok, Thailand, in the Asia region.
How does ECQ make money?
One revenue line is on record: professional Security Services.
Who are ECQ's main competitors?
Direct peers on record are NCC Group, Bishop Fox, Trustwave, Secarma and Nettitude. Broad incumbents are NCC Group (iTrust / Arcanum-style OT practice) — represented via NCC above; secondary listed: Mandiant (Google Cloud) and F-Secure (WithSecure). Emerging players are Positive Technologies and HackerOne. NSFOCUS is listed as a regional player.
Does ECQ have an API?
No public API is recorded for ECQ.
What industry is ECQ in?
ECQ's product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of EDAOAIAB, Cybersecurity (General). Its NAICS code is 54151 and its SIC code is 7370.