Global Resilience Federation
Global Resilience Federation is a non-profit that operates a federation of sector-specific ISACs and ISAOs, providing cross-sector threat intelligence sharing, operational resilience frameworks, and collective defense services to thousands of member organizations across five continents.
- Company typePrivate
- Founded2017
- HeadquartersReston, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Global Resilience Federation does
Global Resilience Federation (GRF) is a U.S.-based non-profit organization that builds, develops, and connects collective defense communities across the global information sharing ecosystem. Operated by an 11–50 person team headquartered in Fairfax, Virginia with an Asia Pacific headquarters in Singapore, GRF functions as the organizational umbrella for eight affiliated ISACs and ISAOs — including the Business Resilience Council (BRC), K12 SIX, Energy Analytic Security Exchange (EASE), Legal Services ISAO (LS-ISAO), Manufacturing ISAC (MFG-ISAC), Operational Technology ISAC (OT-ISAC), ProSIX, and Construction ISAC. The federation traces its institutional lineage to the 1998 U.S. Presidential Decision Directive 63 and was spun off from FS-ISAC's Sector Services team in May 2017 as an independent entity. Its core product is the GRF Network itself: a multi-vertical threat intelligence sharing community spanning thousands of organizations across five continents that delivers 24/7 follow-the-sun security visibility, analyst-curated threat reports (including the Semiannual Ransomware Report), the Operational Resilience Framework (ORF), cross-sector chat rooms, a situational awareness dashboard, and emergency member coordination during incidents.
GRF's business model is membership-driven, with tiered annual subscription pricing ranging from $2,000 to $20,000 per organization (Business Resilience Council Tier IV to Tier I), supplemented by event revenue from the annual Summit on Security & Third-Party Risk (practitioner badges $500–$750, vendor badges $1,200, combined summit-plus-membership packages at $3,000) and educational webinars. Secondary streams include the OT Security Training Program (with Dragos OT-CERT), the AI Security Program (developed with KPMG), and an AI-powered Third-Party Risk Management platform offered through a partnership with SAFE and the FAIR Institute. The organization also distributes co-developed publications, including AI governance guides and ransomware trend reports, and contributes to industry research consumed by the World Economic Forum, MITRE Center for Threat-Informed Defense, and Verizon's Data Breach Investigations Report. Customers are primarily enterprise security, risk, and resilience professionals across critical infrastructure, manufacturing, energy, OT, education, legal, professional services, and construction sectors.
Global Resilience Federation firmographics
Firmographics- Name
- Global Resilience Federation
- Legal name
- Global Resilience Federation
- Website
- https://grf.org
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Global Resilience Federation is a non-profit that operates a federation of sector-specific ISACs and ISAOs, providing cross-sector threat intelligence sharing, operational resilience frameworks, and collective defense services to thousands of member organizations across five continents.
- Ownership category
- akta.pro rank
Global Resilience Federation industry classification
Industry- Product category
- Cybersecurity Threat Intelligence Sharing
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG)
Keywords
Where Global Resilience Federation is headquartered
LocationHeadquarters
- HQ city
- Reston
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Global Resilience Federation business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Membership Fees: GRF generates revenue through tiered annual membership fees for the Business Resilience Council (BRC) and other affiliated communities. Membership tiers range from $2,000 to $20,000 annually, providing access to threat intelligence, best practices, analyst-curated information, working groups, and collaboration platforms.
- Event Registration: Revenue from summit and conference registrations including the annual Summit on Security & Third-Party Risk. Practitioner badges range from $500-$750, vendor badges at $1,200, and combined summit + membership packages at $3,000.
- Webinar and Training Programs: Educational webinars and training programs including OT Security Training Program in partnership with Dragos OT-CERT, providing free resources and training to small and medium suppliers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | BRC Annual Membership Tier IV |
| Subscription | Annual | BRC Annual Membership Tier III |
| Subscription | Annual | BRC Annual Membership Tier II |
| Subscription | Annual | BRC Annual Membership Tier I |
| One time/ perpetual license | Multi-year contract | 2026 Practitioner Summit Badge - Early Bird |
| One time/ perpetual license | Multi-year contract | 2026 Vendor Summit Badge |
| Hybrid | Annual | 2026 Summit Badge + BRC Membership |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Global Resilience Federation product offering
Product offeringCore offering
Global Resilience Federation (GRF) is a non-profit hub that builds, develops, and connects collective defense communities and information sharing and analysis centers (ISACs/ISAOs). It operates the Business Resilience Council (BRC), sector-specific ISACs (manufacturing, energy, OT, legal, education, construction, professional services), and delivers threat intelligence, the Operational Resilience Framework (ORF), ransomware reporting, AI security resources, and the annual Summit on Security & Third-Party Risk.
Product overview
Global Resilience Federation (GRF) is a nonprofit network that manages and supports collective defense communities and information sharing and analysis centers (ISACs/ISAOs) for critical infrastructure protection. The core offering centers on the Business Resilience Council (BRC), a member-driven, analyst-supported multi-sector community, supplemented by the Operational Resilience Framework (ORF) for service continuity during disruptions. GRF provides threat intelligence products including the Semiannual Ransomware Report tracking attack trends, AI Security Program resources developed with KPMG, and an AI-powered Automated Third-Party Risk Management Platform in partnership with SAFE and the FAIR Institute. Educational services include webinars on cyber threats and resilience topics, the annual Summit on Security & Third-Party Risk conference, and the OT Security Training Program. GRF also operates affiliated ISAC communities including K12 SIX (education), Manufacturing ISAC (MFG-ISAC), OT-ISAC (operational technology), EASE (energy), LS-ISAO (legal services), and Construction ISAC, enabling cross-sector threat intelligence sharing across five continents.
Differentiator
Problem solved
Functional benefit
Brands
- Business Resilience Council (BRC): A member-driven, analyst-supported, multi-sector community providing business continuity, disaster response, and resilience information and best practices on physical security issues and cyber threats
- K12 SIX
- EASE
- LS-ISAO
- MFG-ISAC
- OT-ISAC
- ProSIX
- Construction ISAC
Products and services
- Business Resilience Council (BRC) A member-driven, analyst-supported, multi-sector community providing business continuity, disaster response, and resilience information and best practices on physical security issues, cyber threats, pandemics, natural disasters, geopolitical threats, civil unrest, terrorism, and destructive malware attacks.
- Operational Resilience Framework (ORF) A multi-sector framework developed by the BRC to help organizations ensure continuity of mission-critical services during disruptions, focusing on providing services in an impaired state rather than just data recovery.
- GRF Semiannual Ransomware Report (SARR) Tracks ransomware attacks based on public sources and closed criminal forums, providing trend analysis and industry-specific targeting data to help organizations understand the evolving ransomware threat landscape.
- AI Security Program Comprehensive AI governance and security resources including whitepapers on responsible AI innovation, practitioners guides for managing AI security, and leadership guides for securing AI, developed in partnership with KPMG and 20+ leading organizations.
- GRF Webinars Educational sessions covering trending cyber threats, risk and vendor management, third-party security challenges, intelligence sharing, and emerging compliance and regulation topics.
- Summit on Security & Third-Party Risk Annual conference (9th edition in October 2026) featuring practitioner-presenters discussing third-party risk management, cyber threat intelligence, geopolitical risk mitigation, and AI/ML threat management.
- OT Security Training Program Partnership between Dragos OT-CERT and MFG-ISAC providing free live virtual training, portal access to training materials, and chat tools for small and medium OT-centric business suppliers.
- GRF Newsletter Monthly newsletter covering GRF activities, threat intelligence updates, sector-specific briefings, and industry news delivered to subscribers.
- Automated Third-Party Risk Management Platform AI-powered TPRM platform offered in partnership with SAFE and the FAIR Institute, providing automated risk assessments for up to 10 vendors per member at no additional cost.
- K12 SIX (Education ISAC) K-12 education sector cybersecurity threat intelligence community providing national-level security coordination for schools and districts.
- Manufacturing ISAC (MFG-ISAC) Manufacturing sector information sharing and analysis center providing threat intelligence and best practices for safeguarding digital environments in manufacturing.
- Operational Technology ISAC (OT-ISAC) Operational Technology ISAC focused on critical infrastructure security and OT threat intelligence sharing.
- Energy Analytic Security Exchange (EASE) Energy sector utilities threat intelligence community providing electric utilities with vital threat intelligence through the Energy Analytic Security Exchange.
- Legal Services ISAO (LS-ISAO) Legal services sector threat intelligence information sharing and analysis organization.
- Professional Services ISAC (ProSIX) Professional services sector threat intelligence community.
- Construction ISAC Construction industry threat intelligence and collective defense community serving primes and subcontractors with operational resilience and cybersecurity threat intelligence sharing.
Quantifiable outcome
- Manufacturing has been the most targeted industry in ransomware for eight consecutive reports, with 590 victims in H2 2025. GRF provides intelligence to help these organizations defend against growing threats.
- +1 more outcomes
Companies that use Global Resilience Federation
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles5 records
Global Resilience Federation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature1 record
Global Resilience Federation partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core, minor and major.
- Google CloudcoreGoogle Cloud joined four GRF-affiliated groups: Business Resilience Council (BRC), Manufacturing ISAC, Operational Technology ISAC (OT-ISAC), and Energy Analytic Security Exchange (EASE). Google Cloud brings its cyber and supply chain maturity to strengthen operational and security environments of GRF's collective defense communities. Google Cloud CISO Phil Venables cited importance of engaging customers and organizations to prevent cascading impacts from cyber attacks and supply chain disruptions.
- TrustMAPPminorThrough its partnership with GRF, TrustMAPP offers complimentary Ransomware Readiness Mini-assessments to all GRF members. This short, 33-question mini-assessment based on NIST CSF and NIST SP 1800-26 gives organizations a rapid way to gauge their ransomware readiness.
- SAFEminorGRF partnered with SAFE and the FAIR Institute to offer each member a 100% automated, AI-powered TPRM (Third-Party Risk Management) platform for risk assessments of up to 10 vendors, free to all GRF members.
- FAIR InstituteminorGRF partnered with SAFE and the FAIR Institute to offer each member a 100% automated, AI-powered TPRM platform for risk assessments of up to 10 vendors, free to all GRF members.
- Dragos OT-CERTcoreOT Security Training Program is a partnership between Dragos OT-CERT and MFG-ISAC that gathers small and medium suppliers of large OT-centric businesses and provides free resources and training. The program offers live virtual training and a portal to access training materials and guides, with a chat tool for participants to communicate and operationalize training materials.
- ISTARIminorGRF and ISTARI partnered to offer executive training on cybersecurity and resilience, providing advanced educational programs for GRF member organizations.
- KPMGcoreKPMG worked with GRF to lead interviews and working sessions with corporate leaders on AI governance. KPMG facilitated in-depth discussions among AI and security practitioners from more than 20 leading companies, think tanks, academic institutions, and industry organizations to develop AI security guides.
- World Economic Forum (WEF)majorGRF contributed to WEF's Global Cybersecurity Outlook 2025 and other cybersecurity reports. GRF also contributed to WEF's cybersecurity playbook for manufacturing sector, strengthening global cybersecurity policy and resilience efforts.
- VerizonminorGRF Network contributed to Verizon's Data Breach Investigations Report (DBIR), sharing intelligence on cybersecurity trends and breach patterns from GRF member communities.
- MITREminorGlobal Resilience Federation joined MITRE Center for Threat-Informed Defense, contributing to collaborative defense research and threat-informed defense methodologies.
Scale indicators2 records
Recent moves7 records
Expansion highlights5 records
Global Resilience Federation competitors and assessment
Company assessmentDirect peers
- FS-ISAC: The Financial Services Information Sharing and Analysis Center is a direct peer; GRF actually spun out of FS-ISAC's Sector Services team in May 2017. Both organizations operate threat intelligence sharing communities for sector-specific and cross-sector defense.
- Health-ISAC: Health Information Sharing and Analysis Center is a direct peer operating sector-specific threat intelligence sharing for healthcare. H-ISAC was an early GRF member community after GRF's 2017 spin-off.
- Retail & Hospitality ISAC (RH-ISAC): RH-ISAC is a direct peer operating threat intelligence sharing for the retail and hospitality sector. RH-ISAC became a GRF member community in December 2017 and represents a parallel sector ISAC model.
- MS-ISAC (Multi-State Information Sharing & Analysis Center): MS-ISAC is a direct peer focused on cyber threat prevention, protection, response, and recovery for U.S. state, local, tribal, and territorial governments. GRF began sharing with MS-ISAC in 2020.
- Auto-ISAC: Automotive Information Sharing and Analysis Center is a direct peer providing a trusted environment for automotive industry threat intelligence sharing, comparable to GRF's OT-ISAC and MFG-ISAC operations.
- Aviation ISAC (A-ISAC): Aviation Information Sharing and Analysis Center is a direct peer for aviation-sector threat intelligence sharing. GRF began sharing with Aviation ISAC in 2021, reflecting parallel sector ISAC structure.
- Space ISAC: Space Information Sharing and Analysis Center is a direct peer for space-industry threat intelligence sharing. GRF began sharing with Space ISAC in 2021, operating a comparable sector ISAC model.
- Cyber Threat Alliance (CTA): CTA is a direct peer operating as a non-profit organization for threat intelligence sharing among cybersecurity vendors and practitioners. Both CTA and GRF run member-driven, cross-organizational threat intelligence sharing platforms.
- ONG-ISAC (Oil & Natural Gas ISAC): ONG-ISAC is a direct peer for oil and natural gas sector threat intelligence sharing. ONG-ISAC and GRF began their partnership in September 2015, and ONG-ISAC became a GRF member community in August 2017.
Broad incumbents
- Information Sharing and Analysis Organization (ISAO) Standards Organization: ISAO Standards Organization is a broad incumbent that established standards and best practices for information sharing organizations. It is comparable to GRF as both serve as institutional anchors for the ISAO/ISAC ecosystem, though ISAO focuses on standards rather than operating communities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Global Resilience Federation social profiles
Digital presenceGlobal Resilience Federation financial estimates
Financial estimateRevenue estimate
Valuation estimate
Global Resilience Federation leadership team
Management profileNumber of profiles
Profiles4 records
Global Resilience Federation subsidiaries and ownership
Company hierarchySubsidiaries8 records
Global Resilience Federation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Global Resilience Federation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Global Resilience Federation
What does Global Resilience Federation do?
Global Resilience Federation (GRF) is a non-profit hub that builds, develops, and connects collective defense communities and information sharing and analysis centers (ISACs/ISAOs). It operates the Business Resilience Council (BRC), sector-specific ISACs (manufacturing, energy, OT, legal, education, construction, professional services), and delivers threat intelligence, the Operational Resilience Framework (ORF), ransomware reporting, AI security resources, and the annual Summit on Security & Third-Party Risk.
Is Global Resilience Federation a public or private company?
Global Resilience Federation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Global Resilience Federation founded?
Global Resilience Federation was founded in 2017. It employs 11 to 50 people.
Where is Global Resilience Federation based?
Global Resilience Federation is headquartered in Reston, United States, in the North America region.
How does Global Resilience Federation make money?
Three revenue lines are on record. Membership Fees are the primary driver. The others are event Registration and webinar and Training Programs.
Who are Global Resilience Federation's main competitors?
Direct peers on record are FS-ISAC, Health-ISAC, Retail & Hospitality ISAC (RH-ISAC), MS-ISAC (Multi-State Information Sharing & Analysis Center), Auto-ISAC, Aviation ISAC (A-ISAC), Space ISAC, Cyber Threat Alliance (CTA) and ONG-ISAC (Oil & Natural Gas ISAC). Information Sharing and Analysis Organization (ISAO) Standards Organization is listed as a broad incumbent.
Does Global Resilience Federation have an API?
No public API is recorded for Global Resilience Federation.
What industry is Global Resilience Federation in?
Global Resilience Federation's product category is Cybersecurity Threat Intelligence Sharing. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of BPAEADAJ, Governance, Risk & Compliance (GRC) Managed Services.