Clarified Security
Clarified Security OÜ is an Estonian cybersecurity firm providing manual web application penetration testing, TIBER-EU compliant red teaming, cyber range exercises, and hands-on security training courses to government, financial, and enterprise clients primarily in Estonia, Scandinavia, and the Baltics.
- Company typePrivate
- Founded2011
- HeadquartersTallinn, Estonia
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Clarified Security does
Clarified Security OÜ is an Estonian private cybersecurity company founded in 2011 and headquartered in Tallinn, operating a boutique team of approximately 25 practitioners. Its core offerings are organized around manual, offensive-led security services: web application and network penetration testing conducted against OWASP ASVS Level 2 or higher, TIBER-EU compliant production-system red teaming for government and private sector clients (including financial entities subject to DORA), and customizable Cyber Range Exercises (CRX) for blue and red team training. The company is the sole Red Team service provider for NATO CCDCOE's Locked Shields exercise, a relationship held continuously since 2012.
The technical stack blends practitioner-led manual methodology with a small portfolio of proprietary tools: Tuoni, a cross-platform C2 framework with API-driven customization, in-memory execution, and operational-security features used both internally and inside the HOHA training course; Catapult, an Ansible-based open-source infrastructure deployment tool enabling 'Exercise as code' for cyber exercises and labs; and Providentia for infrastructure technical information management. The training catalog comprises five public courses (Web Application Security, Hands-on Hacking Essentials, Hands-on Hacking Advanced, Hunt the Hacker, Service Hardening), priced at €1,400-€2,800 per participant with maximum 12-person cohorts, and is delivered both as public cohorts and customized on-site corporate training.
Revenue mechanics rest entirely on professional services: per-participant training pricing with VAT, custom pentest and red team engagements sold via direct outreach ([email protected]), and channel partners BCS Koolitus and Nordic Koolitus distributing public courses in Estonia. Named enterprise customers include Telia Eesti AS, Elisa Eesti AS, Helmes AS, and Scoro, with frame agreements reportedly producing repeat business and discounts. The company holds ISO 9001 and ISO/IEC 27001 certifications, is founder/management controlled with no external funding or parent company, and explicitly identifies Estonia as its home market with a stated secondary focus on Scandinavia and the Baltics plus global remote and on-site delivery.
Clarified Security firmographics
Firmographics- Name
- Clarified Security
- Legal name
- Clarified Security OÜ
- Website
- https://clarifiedsecurity.com
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Clarified Security OÜ is an Estonian cybersecurity firm providing manual web application penetration testing, TIBER-EU compliant red teaming, cyber range exercises, and hands-on security training courses to government, financial, and enterprise clients primarily in Estonia, Scandinavia, and the Baltics.
- Ownership category
- akta.pro rank
Clarified Security industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where Clarified Security is headquartered
LocationHeadquarters
- HQ city
- Tallinn
- HQ country
- Estonia
- HQ region
- Europe
Offices1 record
Markets served
Clarified Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Penetration Testing Services: Manual WebApp pentesting (primarily), network pentesting, device/hardware testing, wireless systems testing. Delivered remotely over Internet/VPN or on-site. Based on OWASP ASVS Level 2 or higher methodology.
- Security Training Courses: Hands-on security training delivered as public courses (12 participants max) or internal group training. Courses include Web Application Security (4 days, 2800 EUR), Hands-on Hacking Essentials (2 days, 1400 EUR), Hands-on Hacking Advanced (3 days, 2100 EUR), Hunt the Hacker (2 days), Service Hardening (2 days, 1400 EUR).
- Red Teaming Services: Production systems Red Teaming for government and private sector. TIBER-EU compliant process. Includes threat-intelligence-based ethical red teaming per ECB framework, mandatory under DORA for financial entities.
- Cyber Range Exercises (CRX): Customizable turn-key cyber exercises for technical personnel. Can be enhanced with custom content and 'Cyber Physical' components. Supports Blue Team and Red Team training.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Unit Pricing | Per training session | Web Application Security (WAS) - 4 days |
| Unit Pricing | Per training session | Hands-on Hacking Essentials (HOHE) - 2 days |
| Unit Pricing | Per training session | Hands-on Hacking Advanced (HOHA) - 3 days |
| Unit Pricing | Per training session | Service Hardening - 2 days |
| Unit Pricing | Per training session | Hunt the Hacker - 2 days |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
Clarified Security product offering
Product offeringCore offering
Clarified Security is an Estonian cybersecurity company that provides manual penetration testing (primarily WebApp), Red Teaming services compliant with TIBER-EU, Cyber Range Exercises, and hands-on security training courses. Services target government entities, financial institutions, and enterprise software/IT teams across Estonia, Scandinavia, the Baltic region, and globally via remote and on-site delivery.
Product overview
Clarified Security is an Estonian cybersecurity company offering practical security services including manual WebApp penetration testing, Red Teaming, and Cyber Range Exercises, along with hands-on security training courses. The company also develops internal tools: Catapult (infrastructure deployment), Providentia (infrastructure information management), and Tuoni (red teaming C2 framework). The training portfolio includes Web Application Security (WAS), Hands-on Hacking Essentials (HOHE), Hands-on Hacking Advanced (HOHA), Hunt the Hacker (HtH), and Service Hardening courses. Services are delivered primarily in Estonia, Scandinavia, and Baltic regions, with remote and on-site capabilities globally.
Differentiator
Problem solved
Functional benefit
Brands
- Tuoni: Sophisticated, cross-platform red teaming framework
- Catapult
- Providentia
Products and services
- Penetration Testing Services Manual penetration testing primarily focused on web applications, conducted per OWASP ASVS Level 2 or higher methodology. Delivered remotely over Internet/VPN or on-site, covering web applications, networks, devices/hardware, and wireless systems. Intended for enterprise and government organizations seeking security validation.
- Red Teaming Services Threat-intelligence-based ethical red teaming on production systems, compliant with the ECB TIBER-EU framework and aligned to DORA requirements for financial entities and critical ICT providers. For government and enterprise organizations.
- Cyber Range eXercise (CRX) Customizable turn-key cyber exercises for technical personnel, supporting both Blue Team and Red Team training. Can be enhanced with custom content and Cyber Physical components. For enterprise and government organizations.
- Web Application Security (WAS) Training 4-day hands-on training covering Server Side Attacks and Browser Side Attacks modules, delivered as public courses or internal group training. Maximum 12 participants per group, priced at 2,800 EUR + VAT per participant. Targets WebApp developers, maintainers, web server/hosting providers, and information security specialists.
- Hands-on Hacking Essentials (HOHE) 2-day hands-on hacking course covering reconnaissance, remote exploitation, privilege escalation, and attack toolsets including Tuoni C2. Priced at 1,400 EUR + VAT per participant. For system administrators, information security specialists, and IT personnel.
- Hands-on Hacking Advanced (HOHA) 3-day advanced course with a Network Takeover scenario using the Tuoni C2 framework. Covers advanced techniques such as API-driven C2 customization, in-memory execution, tunneling, and operational security. Priced at 2,100 EUR + VAT per participant. Prior HOHE participation required.
- Hunt the Hacker (HtH) 2-day threat hunting training teaching attendees to discover hackers operating invisibly within networks. Uses Sysmon, Elastic Stack, Elastic Security, and Osquery. Maximum 12 participants. Prior HOHE recommended. For CISOs, Security Managers, SOC staffers, Incident Responders, and Forensic Analysts.
- Service Hardening Training
Quantifiable outcome
- Thousands of Blue Teamers trained at NATO Locked Shields exercises
- +2 more outcomes
Companies that use Clarified Security
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles3 records
Clarified Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Clarified Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered flagship and core.
- NATO CCDCOE (Cooperative Cyber Defence Centre of Excellence)flagshipLong-standing Red Team service provider for NATO CCDCOE's Locked Shields exercise since 2012. Also supports Crossed Swords exercise. Over a decade of partnership training thousands of military and government cyber defenders.
- BCS Koolitus AScoreAuthorized public training course reseller in Estonia. Handles registration and sales of Clarified Security's public courses for Estonian market.
- Nordic Koolitus OÜcoreAuthorized public training course reseller in Estonia. Distributes Clarified Security public courses alongside BCS Koolitus.
- European Central Bank (ECB)coreClarified Security's Red Teaming process is compliant with ECB's TIBER-EU (Threat-Intelligence-Based Ethical Red Teaming) framework. This framework is the de-facto standard for Red Teaming implementation under DORA regulation.
Scale indicators6 records
Recent moves7 records
Expansion highlights6 records
Clarified Security competitors and assessment
Company assessmentDirect peers
- Praetorian: US offensive security firm offering penetration testing, red teaming, and attack surface management. Comparable boutique, high-craft positioning in the offensive security space, primarily serving North American enterprises.
- SEC Consult: Austrian-headquartered cybersecurity consultancy with deep penetration testing, red team, and TIBER-EU-aligned services across DACH and broader Europe. Direct competitor for European financial-services TIBER-EU work and similar boutique-to-mid-market positioning.
- Trustwave SpiderLabs: Global cybersecurity firm whose SpiderLabs team provides penetration testing, red teaming, and threat intelligence. Comparable offensive security service offering, with broader MSSP/MDR portfolio and a global delivery model.
- NCC Group: Global leader in cyber resilience with a sizable penetration testing and red team practice serving financial services and government. Directly comparable service portfolio (pentest, red team, TIBER-style engagements) but at significantly larger scale and geographic reach.
- NetSPI: US-based penetration testing firm delivering manual pentesting, red teaming, and attack surface management at scale. Directly comparable in service mix (offensive security, advisory) with a stronger technology/platform underpinning.
- Bishop Fox: US-based pure-play offensive security firm specializing in pentesting, red teaming, and adversary simulation. Closely aligned with Clarified's manual, high-craft approach to offensive security and similar boutique positioning, though serving a North American client base.
- WithSecure (formerly F-Secure Consulting): Finnish-listed cybersecurity firm with a strong offensive security (pentesting, red teaming) consulting practice serving European enterprises. Closest geographic and business-model peer to Clarified Security, operating in adjacent Northern European markets with similar regulatory exposure.
Broad incumbents
- Mandiant (Google Cloud): Global incident response and cyber defense firm with a substantial offensive security practice (pentesting, red teaming, TIBER-style engagements). Significantly larger scale and broader capabilities, but a key reference point for premium red team engagements.
- Orange Cyberdefense: European MSSP and security consultancy owned by Orange, with an offensive security practice spanning pentesting, red teaming, and threat intelligence. Larger incumbent with overlapping capabilities but broader portfolio and global reach.
Regional players
- Nixu (DNV Cyber): Finnish cybersecurity firm (acquired by DNV) focused on defensive managed security, identity, and industrial cybersecurity. Comparable Nordic/Baltic origin story and customer base, but primarily defensive rather than offensive.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
Clarified Security social profiles
Digital presenceClarified Security compliance and trust
Trust signalCompliance2 records
Clarified Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Clarified Security leadership team
Management profileNumber of profiles
Profiles11 records
Clarified Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Clarified Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Clarified Security
What does Clarified Security do?
Clarified Security is an Estonian cybersecurity company that provides manual penetration testing (primarily WebApp), Red Teaming services compliant with TIBER-EU, Cyber Range Exercises, and hands-on security training courses. Services target government entities, financial institutions, and enterprise software/IT teams across Estonia, Scandinavia, the Baltic region, and globally via remote and on-site delivery.
Is Clarified Security a public or private company?
Clarified Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Clarified Security founded?
Clarified Security was founded in 2011. It employs 1 to 10 people.
Where is Clarified Security based?
Clarified Security is headquartered in Tallinn, Estonia, in the Europe region.
How does Clarified Security make money?
Four revenue lines are on record. Penetration Testing Services are the primary driver. The others are security Training Courses, red Teaming Services and cyber Range Exercises (CRX).
Who are Clarified Security's main competitors?
Direct peers on record are Praetorian, SEC Consult, Trustwave SpiderLabs, NCC Group, NetSPI, Bishop Fox and WithSecure (formerly F-Secure Consulting). Broad incumbents are Mandiant (Google Cloud) and Orange Cyberdefense. Nixu (DNV Cyber) is listed as a regional player.
Does Clarified Security have an API?
No public API is recorded for Clarified Security.
What industry is Clarified Security in?
Clarified Security's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 5616 and its SIC code is 7370.