Institute for Security and Open Methodologies
ISECOM is a Spain-based nonprofit open security research community that publishes the OSSTMM methodology and RAV/STAR tools, sells professional cybersecurity certifications and tiered memberships, and licenses its content through Training Partners, Licensed Auditors, and academic alliances worldwide.
- Company typePrivate
- Founded2001
- HeadquartersCardedeu, Spain
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Institute for Security and Open Methodologies does
The Institute for Security and Open Methodologies (ISECOM) is a private, nonprofit open security research community founded in January 2001 and headquartered in Cardedeu, Spain, with parallel co-founding in New York and Barcelona. Its core technical asset is the OSSTMM (Open Source Security Testing Methodology Manual), a complete methodology for penetration testing, security analysis, and operational security measurement, published freely under Copyleft and the Open Methodology License and accompanied by two standardised artefacts: the RAV Calculator (a spreadsheet for computing Risk Assessment Values and Attack Surface metrics) and the STAR (Security Test Audit Report), a standardised summary of security test results required when OSSTMM-certifying an organisation.
ISECOM monetises this methodology through a layered commercial portfolio. Direct revenue streams include a suite of ten professional certifications priced €99-€499 (CHA, OPSA, OPST, OPSE, OWSE, CTA, SAI, CHAT, CCT, CJH), three tiered annual memberships (Silver €99, Gold €299, Platinum €999) with progressively richer repository access, a Hacker Highschool cloud-lab licence at €199/year, and Amazon-distributed workbooks. Indirect and B2B revenue flows through partner programmes: a four-tier ILA Licensed Auditor accreditation (Bronze/Silver/Gold/Platinum) under which external firms deliver OSSTMM-compliant audits; an authorised Training Partner network spanning Spain, the Netherlands, Italy, Switzerland, Germany, Chile, Mexico, and the USA (Parell, Security Solutions Consultants, Dreamlab Technologies AG, Oneconsult AG, Yoroi Srl, HN Security, Tic Defense) that delivers certified training; and an Academic Alliance (pilot: College of Engineering and Architecture, Fribourg) that licenses ISECOM content into higher-education curricula. Security coaching seminars delivered on client infrastructure provide a professional-services layer.
The organisation serves four customer segments: security professionals and organisations seeking accredited OSSTMM certification; academic institutions integrating OSSTMM credentials into curricula; teenagers aged 12-20 and educators using the Hacker Highschool curriculum; and government/enterprise clients seeking vendor-neutral security training. Headcount is small (11-50), governance is distributed across a 13-person international Board and a multi-country operating team, and revenue is not publicly disclosed. All intellectual property is positioned as openly licensed, with monetisation dependent on certification fees, memberships, partner accreditation, and book sales rather than on proprietary product lock-in.
Institute for Security and Open Methodologies firmographics
Firmographics- Name
- Institute for Security and Open Methodologies
- Legal name
- Institute for Security and Open Methodologies
- Website
- https://isecom.org
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ISECOM is a Spain-based nonprofit open security research community that publishes the OSSTMM methodology and RAV/STAR tools, sells professional cybersecurity certifications and tiered memberships, and licenses its content through Training Partners, Licensed Auditors, and academic alliances worldwide.
- Ownership category
- akta.pro rank
Institute for Security and Open Methodologies industry classification
Industry- Product category
- Cybersecurity Training & Methodology Research
- NAICS
- Colleges, Universities, and Professional Schools (6113), Computer Systems Design and Related Services (54151)
- SIC
- Services-Educational Services (8200), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industries
- Information Technology (IT) & Cybersecurity Certifications (EDAAANAA), Application Security & Secure Software (DevSecOps) (EDAOAIAK), Information Technology & Cybersecurity Certification Prep (CompTIA, Cisco, Microsoft, AWS, ISC2/ISACA) (EDANAIAF)
Keywords
Where Institute for Security and Open Methodologies is headquartered
LocationHeadquarters
- HQ city
- Cardedeu
- HQ country
- Spain
- HQ region
- Europe
Offices3 records
Markets served
Institute for Security and Open Methodologies business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Certifications: Revenue from certification exams and credentials including OPSA (499€), OPSE (499€), CTA (299€), CHA (99€), CJH, CHAT, OWSE, CCT, and SAI. Certifications are available directly or through training partners.
- Membership Subscriptions: Three-tiered membership program: Silver (€99/year), Gold (€299/year), and Platinum (€999/year). Each tier provides progressive access to security research repositories, tools, checklists, and templates.
- Partnerships: Financing provided through partnerships including ILA (ISECOM Licensed Auditor) partnerships for OSSTMM accredited testing, Training Partner licensing, and Academic Alliance arrangements with educational institutions.
- Seminars: Revenue generated from security coaching and training seminars delivered on client infrastructure.
- Research Endowments: Funding from research endowments supporting the ongoing open security methodology research.
- Hacker Highschool License: Cloud-based lab network and repository access for individuals or classrooms at €199/year, allowing practice security and penetration testing against various systems.
- Book Sales: Sale of educational workbooks and study guides through Amazon, including 'How the Hacker Stole Christmas', 'Network Security Essentials Study Guide & Workbook Volume 1', 'Security Analysis Essentials Volume 2', and 'Hacking Essentials Volume 3'.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Silver Team — €99/year — Access to the Beta Repository with documents, presentations, checklists, and tools, plus special discounts for ISECOM events. |
| Subscription | Annual | Gold Team — €299/year — Access to Gold and Silver repositories, direct access to ISECOM for security questions, business support, and event discounts. |
| Subscription | Annual | Platinum Team — €999/year — Full project repository access, logo and link on ISECOM website, direct security advice, and event discounts. |
| Subscription | Annual | Hacker Highschool License — €199/year — Cloud-based lab network and full HHS repository access for individuals or classrooms. |
| One time/ perpetual license | Pay-as-you-go | OPSA — OSSTMM Professional Security Analyst — 499€ |
| Other | Pay-as-you-go | OPST — OSSTMM Professional Security Tester — Not publicly priced |
| One time/ perpetual license | Pay-as-you-go | OPSE — OSSTMM Professional Security Expert — 499€ |
| One time/ perpetual license | Pay-as-you-go | CTA — OSSTMM Certified Trust Analyst — 299€ |
| One time/ perpetual license | Pay-as-you-go | CHA — Certified Hacker Analyst — 99€ |
| One time/ perpetual license | Pay-as-you-go | CJH — Certified Junior Hacker — Price not publicly disclosed |
| One time/ perpetual license | Pay-as-you-go | CCT — Certified Cyber Trooper — 199€ |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels5 records
Institute for Security and Open Methodologies product offering
Product offeringCore offering
ISECOM develops, publishes, and maintains open-source security testing methodologies and frameworks — most notably the OSSTMM — and delivers corresponding professional certifications, training curricula, risk-assessment tools, and security awareness educational materials for security professionals, enterprises, governments, and educational institutions worldwide.
Product overview
The Institute for Security and Open Methodologies (ISECOM) is an open, security research community providing a unified portfolio of open-source security methodologies, certifications, educational programs, and membership services. The core offering is the OSSTMM (Open Source Security Testing Methodology Manual), a comprehensive methodology for penetration testing and security analysis, supplemented by tools including the RAV Calculator for Attack Surface measurement and the STAR (Security Test Audit Report) for standardized security testing results. ISECOM offers a suite of professional certifications (OPSA, OPST, OPSE, OWSE, CTA, SAI, CHA, CHAT, CCT, CJH) ranging from introductory to expert levels. Educational products include the Hacker Highschool cybersecurity curriculum for teens and published study guides/workbooks. Additional offerings include the Cybersecurity Playbook for SMEs, the Jack of All Trades security concept framework, the Invisibles ambient music research project, and Security Coaching services. ISECOM operates through tiered membership subscriptions (Silver, Gold, Platinum), partner programs for auditors (ILA) and training providers, and an Academic Alliance for educational institutions. All research and methodology are released under open licenses, with financing provided through partnerships, subscriptions, certifications, and licensing.
Differentiator
Problem solved
Functional benefit
Brands
- Hacker Highschool (HHS): An ever-growing collection of cybersecurity lessons written specifically for teens from 12-20 years old, covering subjects for teen cybersafety including web privacy, chat, mobile computing, and social networks.
- OSSTMM
- Invisibles
- Cybersecurity Playbook
- Jack of All Trades (JAT)
Products and services
- OSSTMM (Open Source Security Testing Methodology Manual) The flagship open-source methodology manual that provides a peer-reviewed, vendor-neutral framework for conducting measurable, results-based security tests. Used by security professionals, consultants, auditors, and government agencies worldwide as a standard reference for security testing.
- RAV (Risk Assessment Values) Calculator Standalone risk-assessment tool that quantifies and prioritizes security risks using the RAV framework, enabling consistent, comparable measurement of security posture across tests and over time.
- STAR (Security Test Audit Report) Standardized reporting template for documenting OSSTMM-compliant security test results, enabling consistent, comparable, and auditable security test reporting across auditors and organizations.
- Hacker Highschool Security awareness and ethical hacking curriculum designed for teen learners, licensed to schools and educational institutions to teach foundational cybersecurity skills and awareness.
- Cybersecurity Playbook Practical training playbook for security practitioners that operationalizes ISECOM's methodology for hands-on security testing and learning.
- Jack of All Trades Career handbook and reference guide for security professionals covering the multi-disciplinary knowledge required to operate effectively across security testing domains.
- OPSA Certification (OSSTMM Professional Security Analyst) Entry-level professional certification validating competency in applying the OSSTMM for security analysis, targeted at security analysts and testers.
- OPST Certification (OSSTMM Professional Security Tester) Professional certification validating practical competency in conducting OSSTMM-based security tests, targeted at hands-on security testers and penetration testers.
- OPSE Certification (OSSTMM Professional Security Expert) Expert-level professional certification validating advanced mastery of the OSSTMM for senior security practitioners and program leads.
- OWSE Certification (OSSTMM Wireless Security Expert) Specialist certification validating expertise in wireless security testing using OSSTMM-aligned methodologies, targeted at network and wireless security specialists.
- CTA Certification (Certified Trust Analyst) Certification validating competency in trust analysis as defined by ISECOM's methodology, for professionals assessing trust and assurance in systems and processes.
- ISECOM Membership Subscription Recurring subscription membership providing access to ISECOM methodology updates, research materials, and participation in the ISECOM community for individuals and organizations.
- Security Coaching Customized coaching service delivered by ISECOM experts to individuals and security teams to develop practical OSSTMM-based testing capabilities.
- ISECOM Training Partner Program Licensed partner program that authorizes training providers to deliver ISECOM-certified courses and exams under the ISECOM brand, generating revenue through partner licensing and royalties.
- ILA (ISECOM Licensed Auditor) Program Licensed auditor program authorizing individuals to conduct OSSTMM-compliant security audits under the ISECOM brand, generating revenue through auditor licensing and audit-related royalties.
- Academic Alliance Program Institutional licensing program enabling universities, colleges, and schools to adopt ISECOM curricula (including Hacker Highschool) and deliver ISECOM-aligned training under the Academic Alliance.
Companies that use Institute for Security and Open Methodologies
Customer profileSegments4 records
Ideal customer profiles3 records
Institute for Security and Open Methodologies technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
Feature7 records
Institute for Security and Open Methodologies partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and minor.
- Parell Informatiebeveiliging B.V.coreISECOM Training Partner authorized to provide official ISECOM training and certification in the Netherlands. Located at Velperweg 28A, 6824 BJ, Arnhem, Netherlands. Keeps certified OSSTMM trainers on staff trained directly by ISECOM.
- Security Solutions ConsultantscoreISECOM Training Partner authorized to provide official ISECOM training and certification in Italy. Located at Via Luigi Lilio, 62 - 00142 Roma RM, Italy, near Metro B Laurentina Station.
- Dreamlab Technologies AGcoreISECOM Training Partner with operations in Switzerland (Bern), Germany (Schwindegg), and Chile (Santiago). Provides official ISECOM training and certification across multiple regions. Contact: [email protected].
- Oneconsult AGcoreISECOM Training Partner operating in Switzerland (Zurich, Bern) and Germany (Munich). Authorized to provide official ISECOM training and certification. Contact: [email protected].
- Yoroi SrlcoreISECOM Training Partner based in Spain, operating from the ISECOM Cardedeu headquarters location. Authorized to provide official ISECOM training and certification.
- College of Engineering and Architecture (EIA-FR)minorAcademic Alliance partner in Fribourg, Switzerland. Certifies professors to provide ISECOM training and certifications to matriculated students under a special licensing agreement at reduced cost. Contact: Jean-Roland Schüler, Tel. +41 26 429 65 54.
- HN Security S.r.l.coreOSSTMM Expert ILA (Platinum tier) providing accredited OSSTMM tests and analysis. Located at Viale Oceano Pacifico, 66, 00144 Rome, Italy. Also offers Compliant ILA services under the Yoroi umbrella.
- Tic Defense S.A. de C.V.coreOSSTMM Certified ILA (Silver tier) providing OSSTMM-based security tests and analysis. Located at Seneca 134, piso 3, Colonia Polanco, Miguel Hidalgo, Ciudad de México, Mexico.
- Digital Encode Ltd.minorPlatinum member displayed on ISECOM website, indicating a high-level membership and partnership relationship.
- Dynacon Sp. z o.o.minorPlatinum member displayed on ISECOM website, indicating a high-level membership and partnership relationship.
- Audius GmbHminorPlatinum member displayed on ISECOM website, indicating a high-level membership and partnership relationship.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Institute for Security and Open Methodologies competitors and assessment
Company assessmentDirect peers
- Offensive Security: Provides the OSCP and other penetration testing certifications; directly competes with ISECOM's OPSE/OPSA/OPST in the offensive security credential market with overlapping target candidates and global training delivery.
- EC-Council: Issues the CEH (Certified Ethical Hacker) and related credentials that compete head-to-head with ISECOM's CHA, CJH, and OPSE for the entry-to-intermediate ethical hacking candidate segment.
Broad incumbents
- SANS Institute: Operates the GIAC certification family and SEC-class training courses. SANS is a much larger incumbent offering both penetration testing and broader cybersecurity certifications that compete for the same enterprise training budget as ISECOM's programs.
- (ISC)²: Global nonprofit issuing CISSP and other mainstream cybersecurity credentials. Competes with ISECOM at the professional-tier end and benefits from similar nonprofit positioning, though with a much larger membership base.
- CompTIA: Vendor-neutral IT certification body whose Security+ and PenTest+ credentials compete with ISECOM's CHA/CJH for early-career professionals, especially those entering cybersecurity from general IT backgrounds.
Emerging players
- INE Security (eLearnSecurity): Offers eJPT, eCPPT, and other practical penetration testing certifications with a self-paced, online-first delivery model — overlapping with ISECOM's OPSE in skill-based pen testing credentials.
- Hack The Box: Gamified platform for practicing penetration testing skills with CPTS, CWEE, and HTB Academy certifications — competing for the same self-directed candidates who might otherwise pursue ISECOM's CHA/OPSE.
- Pentester Academy (SecurityTube): Offers hands-on penetration testing and security courses with structured certifications, overlapping with ISECOM's OPST/OPSE audience but with a more online, lab-driven delivery model.
- TCM Security: Provides the PNPT and PJWT practical penetration testing certifications along with academy training, competing with ISECOM's OPSE for the practical, affordable certification segment.
- Cybrary: Cybersecurity training and certification prep platform serving entry-level and career-changer candidates — adjacent competition for ISECOM's junior certifications (CHA, CJH) and a potential channel partner.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Institute for Security and Open Methodologies social profiles
Digital presenceInstitute for Security and Open Methodologies compliance and trust
Trust signalCompliance1 record
Institute for Security and Open Methodologies financial estimates
Financial estimateRevenue estimate
Valuation estimate
Institute for Security and Open Methodologies leadership team
Management profileNumber of profiles
Profiles13 records
Institute for Security and Open Methodologies funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Institute for Security and Open Methodologies M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Institute for Security and Open Methodologies
What does Institute for Security and Open Methodologies do?
ISECOM develops, publishes, and maintains open-source security testing methodologies and frameworks — most notably the OSSTMM — and delivers corresponding professional certifications, training curricula, risk-assessment tools, and security awareness educational materials for security professionals, enterprises, governments, and educational institutions worldwide.
Is Institute for Security and Open Methodologies a public or private company?
Institute for Security and Open Methodologies is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Institute for Security and Open Methodologies founded?
Institute for Security and Open Methodologies was founded in 2001. It employs 11 to 50 people.
Where is Institute for Security and Open Methodologies based?
Institute for Security and Open Methodologies is headquartered in Cardedeu, Spain, in the Europe region.
How does Institute for Security and Open Methodologies make money?
Seven revenue lines are on record. Certifications are the primary driver. The others are membership Subscriptions, partnerships, seminars, research Endowments, hacker Highschool License and book Sales.
Who are Institute for Security and Open Methodologies's main competitors?
Direct peers on record are Offensive Security and EC-Council. Broad incumbents are SANS Institute, (ISC)² and CompTIA. Emerging players are INE Security (eLearnSecurity), Hack The Box, Pentester Academy (SecurityTube), TCM Security and Cybrary.
Does Institute for Security and Open Methodologies have an API?
No public API is recorded for Institute for Security and Open Methodologies.
What industry is Institute for Security and Open Methodologies in?
Institute for Security and Open Methodologies's product category is Cybersecurity Training & Methodology Research. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of EDAAANAA, Information Technology (IT) & Cybersecurity Certifications. Its NAICS code is 6113 and its SIC code is 8200.