Convergent Risks
ConvergentDS is a cybersecurity and risk advisory firm delivering offensive security testing, assurance assessments, and advisory services to enterprise clients across Media & Entertainment, Financial Services, Healthcare, and Critical National Infrastructure from offices in the US, UK, and India.
- Company typePrivate
- Founded2014
- HeadquartersSherman Oaks, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Convergent Risks does
Convergent Risks, doing business as ConvergentDS, is a cybersecurity and risk advisory firm founded in 2014 and headquartered in Sherman Oaks, California. The company delivers professional services organized into three pillars: Offensive Security (penetration testing, AI penetration testing, application security, red team security, secure code reviews, social engineering), Assurance Services (TPN assessments, site security assessments, cloud security assessments, NCBA Committed to Security Program assessments, vulnerability management, and zero trust foundation work), and Advisory Services (privacy compliance, managed remediation, fractional CISO, and ISO/NIST/SOC2 readiness). Its target verticals are Media & Entertainment, Financial Services, Healthcare, Manufacturing, Leisure, and Critical National Infrastructure, with marquee clients including NBCUniversal, BBC Studios, Paramount, Walt Disney Company, HBO, Adobe, Framestore, Frame.io, and Newrez. The firm is an accredited Trusted Partner Network (TPN) assessor and an NCBA Committed to Security Program partner, anchoring its M&E content-security franchise.
The firm operates from four offices (Denver, Los Angeles, London, and Mumbai), providing global delivery coverage across North America, Europe, and South Asia. Revenue is generated primarily through project-based professional services engagements (penetration tests, TPN and site assessments, vulnerability management) supplemented by recurring revenue from retainer arrangements such as fractional CISO, managed remediation, and ongoing PE portfolio advisory. Pricing is custom and quote-based, with no publicly disclosed standard tiers; contract cadences extend to multi-year arrangements. GTM is sales-led, combining direct enterprise engagement, professional referrals, content marketing via The Red Team Download, and event presence such as the IBC Security Workshop.
The business is differentiated by Media & Entertainment domain depth, a multi-office global delivery model, and a track record with large enterprise customers. It has no disclosed funding rounds, is privately held, and reports a headcount of 11-50. Technology partner integrations (Vetting Solutions, CyberCPR, SanctumHub) extend the portfolio into background screening, incident response, and risk reporting without internal product buildout. AI capability is featured as a service line (AI Penetration Testing) rather than as a foundational layer of the firm's own operations.
Convergent Risks firmographics
Firmographics- Name
- Convergent Risks
- Website
- https://convergentrisks.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ConvergentDS is a cybersecurity and risk advisory firm delivering offensive security testing, assurance assessments, and advisory services to enterprise clients across Media & Entertainment, Financial Services, Healthcare, and Critical National Infrastructure from offices in the US, UK, and India.
- Ownership category
- akta.pro rank
Convergent Risks industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance (BPAEAPAG)
Keywords
Where Convergent Risks is headquartered
LocationHeadquarters
- HQ city
- Sherman Oaks
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Convergent Risks business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Assessment Services: One-time and recurring security testing engagements including penetration testing, vulnerability assessments, red team exercises, and security audits. Revenue is generated through project-based engagements with pricing based on scope, complexity, and client size.
- Assurance Services: Compliance and certification assessment services including TPN assessments, site security assessments, and cloud security assessments. These services help organizations meet industry standards and regulatory requirements.
- Advisory Services: Ongoing advisory engagements including fractional CISO services, ISO/NIST/SOC2 readiness preparation, privacy compliance consulting, and managed remediation. These create recurring revenue through retainer and project-based arrangements.
- Technology Partner Referrals: The company recommends and integrates third-party security technology solutions including background screening, incident response, and risk management reporting platforms, potentially generating referral or partnership revenue.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom engagement-based pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
Convergent Risks product offering
Product offeringCore offering
Convergent Risks (doing business as ConvergentDS) is a cybersecurity and risk advisory firm that delivers professional services across three pillars: Offensive Security (penetration testing, red team, secure code reviews, AI testing, social engineering), Assurance Services (TPN, site and cloud security assessments, vulnerability management, zero trust), and Advisory Services (fractional CISO, ISO/NIST/SOC2 readiness, privacy compliance, managed remediation). Engagements are project- or retainer-based and sold directly to enterprise and mid-market clients across Media & Entertainment, Financial Services, Healthcare, Manufacturing, and Critical National Infrastructure.
Product overview
ConvergentDS is a cybersecurity and risk advisory firm offering a portfolio of professional services organized into three core pillars: Offensive Security (testing and assessment services), Assurance Services (validation and compliance offerings), and Advisory Services (strategic consulting). The portfolio includes AI Penetration Testing, Application Security, Penetration Testing, Red Team Security, Secure Code Reviews, and Social Engineering under offensive security; TPN Assessments, Site Security Assessments, Cloud Security Assessments, NCBA Committed to Security Program, Vulnerability Management, and Zero Trust Foundation under assurance; and Privacy Compliance, Managed Remediation, Fractional CISO, and ISO/NIST/SOC2 Readiness under advisory. Technology partnerships with Vetting Solutions, CyberCPR, and Sanctum Hub provide supplementary tools for background screening, incident response, and risk management reporting. The firm serves industries including Media & Entertainment, Financial Services, Healthcare, Leisure, Manufacturing, and Critical National Infrastructure.
Differentiator
Problem solved
Functional benefit
Products and services
- AI Penetration Testing Security testing service that assesses AI systems and AI-powered applications for vulnerabilities including adversarial attacks, model poisoning, and prompt injection risks. Targeted at organizations deploying AI/ML in production.
- Application Security Testing Comprehensive security testing for software applications to identify vulnerabilities, insecure configurations, and coding flaws for enterprise development teams.
- Penetration Testing Simulated cyberattack exercises that identify and exploit vulnerabilities in networks, systems, and applications before adversaries can leverage them, delivered to enterprise clients.
- Red Team Security Adversary simulation exercises where security experts emulate real-world threat actors to test organizational detection and response capabilities for enterprise security leaders.
- Secure Code Reviews Systematic examination of source code to identify security vulnerabilities, logic flaws, and compliance issues before deployment, typically used by software development teams.
- Social Engineering Assessment Testing and assessment of human-based security vulnerabilities including phishing, pretexting, and physical security controls for enterprise awareness programs.
- TPN Assessments Trusted Partner Network assessments evaluating content security practices for media and entertainment organizations handling pre-release content.
- Site Security Assessments Physical and logical security evaluations of facility infrastructure, access controls, and operational security practices for media and enterprise sites.
- Cloud Security Assessments Security posture evaluation of cloud infrastructure and configurations across major cloud service providers for enterprise IT teams.
- NCBA Committed to Security Program
Quantifiable outcome
- 90% of penetration tests identify medium or higher level vulnerability
Companies that use Convergent Risks
Customer profileNamed customers16 records
Segments6 records
Ideal customer profiles4 records
Convergent Risks technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
Feature7 records
Convergent Risks partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- Trusted Partner Network (TPN)coreIndustry initiative for content security and supply chain security assessment. ConvergentDS conducts official TPN assessments and is recognized as a provider of TPN assessment services, site security assessments, and cloud security assessments. TPN is a global, vendor and content creator centric security accreditation organization for the media and entertainment industry.
- NCBA Committed to Security ProgramcoreStrategic partnership conducting NCBA security assessments for the National Association of Consumer Broadcasters. ConvergentDS offers NCBA Committed to Security Program assessments as a core service offering.
- IBC (International Broadcasting Convention)minorIndustry event partnership where ConvergentDS hosts security workshops. The company plans to attend IBC 2026 and host a Security Workshop at Studio QA on September 12th, 2026.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Convergent Risks competitors and assessment
Company assessmentDirect peers
- TrustedSec: Cybersecurity consulting firm specializing in penetration testing, red team operations, and incident response. Closely aligned boutique competitor with a comparable offensive-security-led service portfolio.
- NCC Group: UK-headquartered cybersecurity consulting and assurance firm offering penetration testing, red teaming, and managed security services globally. Directly comparable to ConvergentDS in offensive security and assurance offerings, with a similar vertical mix across financial services and media.
- Bishop Fox: US-based offensive security firm specializing in penetration testing, red teaming, and security assessments. Closely comparable boutique competitor focused on enterprise testing engagements, similar scale and service mix to ConvergentDS.
- Coalfire: Cybersecurity advisory firm offering penetration testing, vulnerability management, ISO/SOC2 readiness, and compliance services. Direct competitor in both offensive security and advisory/advisory services, serving similar enterprise and PE clients.
- Schellman: Top-tier cybersecurity compliance and assessment firm specializing in SOC 2, ISO 27001, and HITRUST audits alongside penetration testing. Direct competitor in assurance services and advisory engagements with overlapping enterprise and PE client base.
- Trail of Bits: Cybersecurity research and consulting firm specializing in application security, secure code reviews, and advanced penetration testing. Closely comparable specialist boutique with a similar offensive-security service mix, focused on technical depth.
- A-LIGN: Cybersecurity compliance and audit firm offering penetration testing, SOC 2 readiness, ISO certifications, and advisory services. A comparable mid-sized competitor with strong overlap in assurance services and advisory offerings to enterprise and PE clients.
Broad incumbents
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant is a scaled incident response and threat intelligence firm with a large offensive-security practice. A much larger incumbent competing for the same enterprise penetration testing and red team engagements as ConvergentDS.
- Unit 42 (Palo Alto Networks): Palo Alto Networks' threat intelligence and consulting arm offering penetration testing, red team, and incident response services. Broad incumbent competing for the same enterprise testing engagements as ConvergentDS, with significantly greater scale.
Others
- Trusted Partner Network (TPN): Industry-wide content security accreditation body for media and entertainment. ConvergentDS is a TPN assessor; other TPN assessors (e.g., Independent Security Evaluators, Xytech) compete for the same pool of M&E vendor assessments, making TPN itself an ecosystem anchor.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Convergent Risks social profiles
Digital presenceConvergent Risks financial estimates
Financial estimateRevenue estimate
Valuation estimate
Convergent Risks leadership team
Management profileNumber of profiles
Convergent Risks funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Convergent Risks M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Convergent Risks
What does Convergent Risks do?
Convergent Risks (doing business as ConvergentDS) is a cybersecurity and risk advisory firm that delivers professional services across three pillars: Offensive Security (penetration testing, red team, secure code reviews, AI testing, social engineering), Assurance Services (TPN, site and cloud security assessments, vulnerability management, zero trust), and Advisory Services (fractional CISO, ISO/NIST/SOC2 readiness, privacy compliance, managed remediation). Engagements are project- or retainer-based and sold directly to enterprise and mid-market clients across Media & Entertainment, Financial Services, Healthcare, Manufacturing, and Critical National Infrastructure.
Is Convergent Risks a public or private company?
Convergent Risks is a private company. It is classified as unknown and is currently operating.
When was Convergent Risks founded?
Convergent Risks was founded in 2014. It employs 11 to 50 people.
Where is Convergent Risks based?
Convergent Risks is headquartered in Sherman Oaks, United States, in the North America region.
How does Convergent Risks make money?
Four revenue lines are on record. Cybersecurity Assessment Services are the primary driver. The others are assurance Services, advisory Services and technology Partner Referrals.
Who are Convergent Risks's main competitors?
Direct peers on record are TrustedSec, NCC Group, Bishop Fox, Coalfire, Schellman, Trail of Bits and A-LIGN. Broad incumbents are Mandiant (Google Cloud) and Unit 42 (Palo Alto Networks). Trusted Partner Network (TPN) is listed as an others.
Does Convergent Risks have an API?
No public API is recorded for Convergent Risks.
What industry is Convergent Risks in?
Convergent Risks's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 54151 and its SIC code is 7370.