Cresco Cybersecurity
Cresco Cybersecurity is a Belgian pure-play cybersecurity firm specializing in penetration testing, red teaming, managed EDR (Cresco.detection), phishing simulations, and GRC advisory, serving SMEs and select enterprises across Belgium and France through subsidized government programs and direct consultative sales.
- Company typePrivate
- Founded2020
- HeadquartersBrussels, Belgium
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cresco Cybersecurity does
Cresco Cybersecurity SRL is a Belgian pure-play cybersecurity firm founded in 2020 and headquartered in Diegem (Brussels), with secondary offices in Ottignies-Louvain-la-Neuve (Wallonia) and Paris, France. The company specializes in penetration testing, red teaming, social engineering, managed EDR (Cresco.detection), phishing simulation with a 36+ module micro-learning academy, incident response, and GRC advisory, organized around four service pillars: Assess, Protect, Educate, and Monitor. Delivery is structured as fixed-scope cybersecurity improvement trajectories (START 10 days, MEDIUM 20 days, PLUS 30 days, with extension packs) plus an ongoing Expertise Point retainer, and is supported by a proprietary Cresco.detection managed EDR platform and a continuous phishing simulation toolchain.
The business model is project-based professional services with a managed services tail. Pricing is heavily subsidized through five Belgian and federal programs — VLAIO (50%), KMO Portfolio (35-45%), MonBee (40-60%), Walloon Cheques Entreprises (75%), and FPS Économie/European Commission (fully subsidized 5-9 manday trajectories) — which serve as both demand-generation channels and price-reduction mechanisms for SME clients. Go-to-market is consultative, sales-led, and inbound-driven via the cresco.be website (multilingual EN/NL/FR), LinkedIn, a 30+ post case-study blog, and approved-partner listings on government portals. Customers span Belgian and French SMEs, government agencies, industry associations (Agoria, CCI, Cybersecurity Coalition, Infopole, Digital Wallonia), and selected enterprises (Mastercard, Caribou Digital, French Tech), with a reported volume of 150+ projects and 10,000+ pentest hours per year.
Cresco Cybersecurity firmographics
Firmographics- Name
- Cresco Cybersecurity
- Legal name
- Cresco Cybersecurity SRL
- Website
- https://cresco.be
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Cresco Cybersecurity is a Belgian pure-play cybersecurity firm specializing in penetration testing, red teaming, managed EDR (Cresco.detection), phishing simulations, and GRC advisory, serving SMEs and select enterprises across Belgium and France through subsidized government programs and direct consultative sales.
- Ownership category
- akta.pro rank
Cresco Cybersecurity industry classification
Industry- Product category
- Cybersecurity Services
- akta.pro primary industry
- Customer Service, Support & Contact Center CRM (HDAEAFAC)
- akta.pro secondary industry
- Industry-Specific CRM (Vertical CRM Suites) (HDAEAFAH)
Keywords
Where Cresco Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- Brussels
- HQ country
- Belgium
- HQ region
- Europe
Offices3 records
Markets served
Cresco Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Professional Cybersecurity Services: Project-based cybersecurity consulting and testing services including penetration testing, red teaming, social engineering, security assessments, incident response, managed EDR, training, and implementation support. Delivered through structured improvement trajectories (START/MEDIUM/PLUS packages) ranging from 10 to 50 days. Revenue is primarily one-time project fees with potential for recurring engagement via the Expertise Point (ongoing advisory retainer model).
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | START: 10-day cybersecurity improvement trajectory |
| Subscription | Multi-year contract | MEDIUM: 20-day cybersecurity improvement trajectory |
| Subscription | Multi-year contract | PLUS: 30-day cybersecurity improvement trajectory |
| Subscription | Multi-year contract | Extension Pack A: 10 additional days |
| Subscription | Multi-year contract | Extension Pack B: 10 additional days |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels5 records
Cresco Cybersecurity product offering
Product offeringCore offering
Cresco Cybersecurity is a Belgian pure-play cybersecurity firm that delivers penetration testing, red teaming, social engineering, security assessments, managed EDR (Cresco.detection), incident response, GRC advisory, and employee awareness training. Services are packaged into structured cybersecurity improvement trajectories and delivered by certified ethical hackers to SMEs and enterprises across Belgium and France.
Product overview
Cresco Cybersecurity is a pure-player cybersecurity company offering a comprehensive portfolio of managed security services organized around four pillars: Assess (security assessments, penetration testing, red teaming, social engineering), Protect (consultancy, implementation, reporting), Educate (phishing simulations, IT training, awareness training), and Monitor (Managed EDR via Cresco.detection, expertise point, incident response). The company also facilitates access to government subsidy programs including VLAIO improvement paths (START/MEDIUM/PLUS), KMO Portfolio, MonBee, and Walloon Cheques Entreprises. Services are delivered by certified ethical hackers holding industry certifications including OSCP, OSCE, CISSP, and various ISO 27001 qualifications.
Differentiator
Problem solved
Functional benefit
Brands
- Cresco.detection: Managed Endpoint Detection & Response (EDR) service providing 24/7 threat monitoring, detection, and response capabilities for endpoints.
Products and services
- Assess Services Cybersecurity assessment services including penetration testing, red teaming, and social engineering that identify vulnerabilities before attackers exploit them. Targeted at SMEs and enterprises seeking to validate their security posture.
- Cresco.detection (Managed EDR) Managed Endpoint Detection & Response service providing 24/7 endpoint monitoring, automated threat intelligence updates, manual and automated threat hunting, and certified SOC analyst triage of alerts. Detects ransomware, malware, keyloggers, Trojans, and modern threats.
- Protect Services Security implementation services including vulnerability remediation, cloud security configuration across Azure/GCP/AWS, Microsoft 365 hardening, network hardening, and incident response planning. Designed for organizations needing to translate assessment findings into deployed controls.
- Expertise and Consultancy Cybersecurity advisory services providing tailored expertise, vulnerability management, governance support, and proactive threat monitoring for organizations that need ongoing strategic security guidance.
- Awareness Training Employee cybersecurity training program built on the '7 Steps to Cyber Success' curriculum covering phishing, social engineering, and incident response. Targets organizations seeking to reduce human-factor cyber risk.
- Phishing Simulations and Academy Continuous phishing simulation campaigns paired with an online micro-learning academy of 36+ modules, real-time threat alerts, and an admin dashboard. Provides employee awareness scoring and metrics such as open rates, click rates, and credential submission rates.
- IT and Ethical Hacking Training Hands-on cybersecurity training for IT professionals covering penetration testing techniques and ethical hacking methodologies. Aimed at technical teams needing to upskill on offensive security.
- Incident Response Structured incident response service covering detection, analysis, containment, eradication, and post-incident recovery. Accessed via an emergency contact channel ([email protected]) for organizations facing active cyber incidents.
- Reporting and Action Plan Detailed technical penetration test reports with executive summary, OWASP/OSSTMM methodology, CVSS scoring, proof-of-concept documentation, prioritized remediation recommendations, and short/medium/long-term strategic roadmap.
- Expert Point (Expertise Punt) Ongoing cybersecurity advisory and support service providing continuous guidance, remediation verification, and long-term security partnership for clients needing a retained expert relationship.
Quantifiable outcome
- 48% of SMEs have reported a cyber incident (Belgian statistics, 2024)
- +7 more outcomes
Companies that use Cresco Cybersecurity
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles2 records
Cresco Cybersecurity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Cresco Cybersecurity partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- VLAIOcoreVLAIO (Flanders Innovation & Entrepreneurship) is Cresco's primary subsidy partner for Flemish SMEs. Cresco is an approved partner offering VLAIO-subsidized cybersecurity improvement trajectories covering up to 50% of trajectory costs. Services include START (10 days), MEDIUM (20 days), and PLUS (30 days) packages, plus optional extension packs. VLAIO acts as the subsidizing body while Cresco delivers the services.
- KMO PortfoliocoreKMO Portfolio is a Flemish government subsidy program for SMEs. Cresco is an approved KMO Portfolio partner, offering subsidized cybersecurity services with 45% subsidy for small enterprises and 35% for medium-sized enterprises. Flemish SMEs apply through the VLAIO e-loket portal.
- MonBeecoreMonBee is a Brussels-Capital Region consultancy subsidy program. Cresco is an approved MonBee partner providing cybersecurity expertise, training, and assessments to Brussels SMEs. Subsidy rates range from 40% to 60% depending on criteria met by the SME.
- Walloon Cheques EntreprisescoreWalloon Cheques Entreprises is a Walloon Region subsidy program for SMEs. Cresco is an approved partner offering subsidized cybersecurity services, with small enterprises receiving a 75% subsidy. Services include expert guidance, training, and comprehensive security assessments.
- FPS Économie / FOD Economie (Federal Public Service Economy)coreFPS Économie (Federal Public Service for Economy) partnered with Cresco to offer fully subsidized cybersecurity improvement trajectories (5-9 mandays) for Belgian SMEs, funded by the Belgian federal government and the European Commission. Cresco's goal is to support over 100 SMEs through this program.
Scale indicators5 records
Recent moves6 records
Expansion highlights4 records
Cresco Cybersecurity competitors and assessment
Company assessmentDirect peers
- NVISO Security: Belgian-headquartered cybersecurity services firm offering penetration testing, red teaming, security assessments, and managed security services to European enterprises and SMEs — the closest functional twin to Cresco, differing mainly in larger headcount and broader geographic reach.
- Secforce: UK/European offensive-security boutique specializing in penetration testing, red teaming, and managed EDR — analogous pure-play positioning to Cresco with comparable talent-certification depth (CREST, OSCP) and similar target customer profile.
- Approach Cyber: Belgian cybersecurity services firm offering penetration testing, security assessments, and awareness training — direct neighborhood competitor operating in the same Belgian SME and enterprise segments Cresco addresses.
- Toreon: Belgian/European cybersecurity consultancy focused on penetration testing, application security, and secure code review — comparable pure-play offensive security boutique with similar SMB-to-enterprise footprint.
Broad incumbents
- Orange Cyberdefense: European MSSP arm of Orange providing managed EDR, SOC, penetration testing, GRC advisory, and incident response across multiple countries — overlaps with Cresco on assessment, monitoring, and incident response services but at much broader scale and portfolio breadth.
- Sogeti Cybersecurity: Capgemini subsidiary providing cybersecurity consulting, pentesting, and managed security services across Europe — a broad incumbent that competes for the same Belgian and French enterprise clients Cresco targets while offering a much wider service catalog.
- Kudelski Security: Swiss-based cybersecurity services and product firm delivering penetration testing, managed security, GRC, and incident response — directly overlaps Cresco's service pillars and targets European regulated industries similar to Cresco's NIS2-focused segments.
- WithSecure (formerly F-Secure Business): Finnish-headquartered cybersecurity firm providing managed EDR, vulnerability management, and incident response — broad incumbent whose managed EDR offering directly overlaps Cresco.detection.
Emerging players
- Outpost24: European cybersecurity firm delivering vulnerability management, penetration testing as a service, and managed EDR — overlaps with Cresco's Assess and Monitor pillars while increasingly partnering with consultancies for delivery.
- Hadrian: Amsterdam-headquartered startup providing AI-driven continuous penetration testing and attack surface management — adjacent emerging player targeting the same European enterprise pentest budget that Cresco competes for.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Cresco Cybersecurity social profiles
Digital presenceCresco Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cresco Cybersecurity leadership team
Management profileNumber of profiles
Profiles3 records
Cresco Cybersecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cresco Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cresco Cybersecurity
What does Cresco Cybersecurity do?
Cresco Cybersecurity is a Belgian pure-play cybersecurity firm that delivers penetration testing, red teaming, social engineering, security assessments, managed EDR (Cresco.detection), incident response, GRC advisory, and employee awareness training. Services are packaged into structured cybersecurity improvement trajectories and delivered by certified ethical hackers to SMEs and enterprises across Belgium and France.
Is Cresco Cybersecurity a public or private company?
Cresco Cybersecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cresco Cybersecurity founded?
Cresco Cybersecurity was founded in 2020. It employs 11 to 50 people.
Where is Cresco Cybersecurity based?
Cresco Cybersecurity is headquartered in Brussels, Belgium, in the Europe region.
How does Cresco Cybersecurity make money?
One revenue line is on record: professional Cybersecurity Services.
Who are Cresco Cybersecurity's main competitors?
Direct peers on record are NVISO Security, Secforce, Approach Cyber and Toreon. Broad incumbents are Orange Cyberdefense, Sogeti Cybersecurity, Kudelski Security and WithSecure (formerly F-Secure Business). Emerging players are Outpost24 and Hadrian.
Does Cresco Cybersecurity have an API?
No public API is recorded for Cresco Cybersecurity.
What industry is Cresco Cybersecurity in?
Cresco Cybersecurity's product category is Cybersecurity Services. Its primary akta.pro industry code is HDAEAFAC, Customer Service, Support & Contact Center CRM, with a secondary code of HDAEAFAH, Industry-Specific CRM (Vertical CRM Suites).