Closed Door Security
Closed Door Security is a CREST- and NCSC-accredited cybersecurity consultancy founded in 2019 in Scotland, delivering penetration testing, compliance auditing and a proprietary Insights PTaaS platform to 320+ customers across financial services, healthcare, government, technology and OT verticals in the UK, US and UAE.
- Company typePrivate
- Founded2019
- HeadquartersStornoway, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Closed Door Security does
Closed Door Security is a CREST- and NCSC-accredited cybersecurity consultancy founded in 2019 in Stornoway, Scotland, specialising in penetration testing and regulatory compliance services for regulated mid-market and enterprise clients across the UK, US and UAE. Its core service portfolio covers CREST-accredited penetration testing across 14+ domains — web application, network, mobile, API, cloud, OT/ICS, social engineering, supply chain, maritime, super yacht and family office testing — alongside compliance and auditing work spanning Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI DSS, SOC 2, GDPR, DORA, TIBER-EU, VARA and DFSA. Delivery is led by in-house certified professionals (William Wright, Scotland's First Chartered Cyber Security Professional, heads a team holding 200+ collective certifications) rather than subcontractors, which supports shorter lead times and direct tester accountability.
The firm's proprietary Insights platform is a Penetration Testing as a Service (PTaaS) system that provides real-time vulnerability tracking, in-engagement re-testing, and 12 months of bundled quarterly PCI-DSS approved scanning per project; it is built on Cyver Core infrastructure hosted on Microsoft Azure (Netherlands/EU) under SOC 2 Type 2 compliance. A self-service 'Build a Pentest' configurator on the website enables prospects to scope and request custom proposals, while a 90-day post-report remediation window with the original tester is bundled into engagements. Customers span financial services, healthcare and research, government, technology and critical infrastructure/OT, with named engagements including Burt Financial Planning, Cancer Research Wales, an NHS Trust and a major UK bank.
The business model is primarily professional services, project-based and proposal-priced, with pricing determined per scope rather than from published rate cards. The PTaaS model and bundled quarterly scanning introduce a recurring-touchpoint layer intended to drive repeat engagement and upsell. Distribution combines direct enterprise field sales (regulated industries, multinational accounts served across UK/US/UAE offices), a product-led self-service channel via 'Build a Pentest', and earned-media-led demand generation through 380+ media features and a 100+ article blog. The company is privately held, founder-operated, and bootstrapped with no disclosed external funding or institutional ownership.
Closed Door Security firmographics
Firmographics- Name
- Closed Door Security
- Legal name
- Closed Door Security LTD
- Website
- https://cdsec.co.uk
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Closed Door Security is a CREST- and NCSC-accredited cybersecurity consultancy founded in 2019 in Scotland, delivering penetration testing, compliance auditing and a proprietary Insights PTaaS platform to 320+ customers across financial services, healthcare, government, technology and OT verticals in the UK, US and UAE.
- Ownership category
- akta.pro rank
Closed Door Security industry classification
Industry- Product category
- Cybersecurity Penetration Testing Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Penetration Testing Platforms (PTaaS) (HDADAHAG), Vulnerability Assessment & Scanning (HDADAHAA), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
Keywords
Where Closed Door Security is headquartered
LocationHeadquarters
- HQ city
- Stornoway
- HQ country
- United Kingdom
- HQ region
- Europe
Offices3 records
Markets served
Closed Door Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Penetration Testing Services: Professional services revenue from conducting penetration tests across multiple domains (web application, network, mobile, API, cloud, OT/ICS, social engineering, supply chain, etc.). Engagement types include standard penetration testing, threat-led penetration testing (TLPT), and red/purple team exercises. Revenue is project-based with scope varying by target infrastructure and testing depth.
- Compliance & Auditing Services: Advisory and certification support services for compliance frameworks including Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI DSS, SOC 2, GDPR, and sector-specific regulations (DORA, TIBER-EU, VARA, DFSA). Includes gap analysis, implementation support, pre-audit preparation, and certification support.
- PTaaS Platform Subscription: The Insights platform is provided as part of penetration testing engagements, with 12 months of quarterly vulnerability scanning included per project. The platform enables ongoing client engagement, re-testing requests, and historical tracking, supporting recurring touchpoints and renewal opportunities for subsequent testing cycles.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based custom penetration testing proposals |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Closed Door Security product offering
Product offeringCore offering
Closed Door Security is a cybersecurity consultancy delivering CREST certified penetration testing across 14+ testing domains (web application, network, mobile, API, cloud, OT/ICS, social engineering, supply chain, maritime, super yacht, and family office) alongside compliance and auditing services for Cyber Essentials, ISO 27001, PCI DSS, SOC 2, GDPR, DORA, TIBER-EU, VARA, and DFSA frameworks. The proprietary Insights PTaaS platform provides real-time vulnerability tracking, live re-testing, and 12 months of quarterly PCI-DSS approved vulnerability scanning for every engagement.
Product overview
Closed Door Security offers a cybersecurity consultancy portfolio centered around penetration testing and security assessments. The core offering is the Insights PTaaS (Penetration Testing as a Service) platform, which provides real-time vulnerability tracking, live re-testing capabilities, and quarterly vulnerability scanning. This platform is supported by a comprehensive suite of testing services including Threat Led Penetration Testing, Red Team, Purple Team, and domain-specific testing (Web Application, Network, Mobile, Cloud, API, OT/ICS, Maritime, Super Yacht, Family Office). Compliance and Auditing services complement the testing offerings, covering Cyber Essentials, ISO 27001, PCI DSS, SOC 2, and GDPR. The 'Build a Pentest' tool enables custom engagement scoping. Vulnerability Management services provide ongoing scanning and remediation support. Together, these services form an integrated security testing ecosystem with the Insights platform serving as the central hub for client access and reporting.
Differentiator
Problem solved
Functional benefit
Brands
- Insights: Real-time penetration testing platform (PTaaS) providing live vulnerability tracking, dashboard monitoring, and expert remediation support
Products and services
- Insights PTaaS Platform Real-time PTaaS platform enabling clients to track vulnerabilities as they are discovered, access live dashboards, request remediation validation, and book new tests on-demand. Built on Cyver Core infrastructure, it supports recurring client engagement through re-testing, historical tracking, and quarterly scanning. Targeted at enterprises needing continuous security testing visibility.
- Penetration Testing Services Comprehensive CREST certified penetration testing services covering 14+ testing domains to identify vulnerabilities before attackers exploit them. Includes specialised methodologies such as Threat Led Penetration Testing, Red Team, and Purple Team exercises, plus domain-specific testing for OT/ICS, maritime, super yacht, and family office environments. Offered to regulated industries and global enterprises.
- Compliance & Auditing Services Advisory and certification support services helping organisations achieve and maintain regulatory compliance across UK, EU, and UAE frameworks. Includes gap analysis, implementation support, pre-audit preparation, and certification support with a 98% first-time pass rate. Serves clients pursuing Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI DSS, SOC 2, GDPR, DORA, TIBER-EU, VARA, and DFSA certifications.
- Security Assessment Services Integrated security assessment solutions combining penetration testing, vulnerability assessments, and compliance auditing to identify vulnerabilities and strengthen overall cybersecurity posture. Designed for organisations seeking a unified testing and compliance programme.
- Vulnerability Management Scotland Ongoing vulnerability management service for Scottish businesses, combining continuous vulnerability scanning, risk-based prioritisation, expert remediation guidance, compliance reporting, and continuous monitoring. Bundled with quarterly scans under the Insights PTaaS platform.
Quantifiable outcome
- 320+ organisations protected globally
- +3 more outcomes
Companies that use Closed Door Security
Customer profileNamed customers5 records
Segments6 records
Ideal customer profiles5 records
Closed Door Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Closed Door Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Cyver Core (Cyver B.V.)coreCyver Core is the pentest management platform used by Closed Door Security to host and manage penetration testing engagements, vulnerability findings, reports, and project communication. It is hosted on Microsoft Azure infrastructure in the Netherlands (EU). The platform is SOC 2 Type 2 compliant. Closed Door Security has conducted comprehensive due diligence including SOC2 Type 2 compliance verification, security policy review, GDPR compliance review, and execution of a Data Processing Agreement. Closed Door Security remains the data controller.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Closed Door Security competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-headquartered cybersecurity consultancy with CREST accreditation offering penetration testing, threat intelligence, and managed security services across financial services and government. Direct competitor for the same regulated buyer profile Closed Door Security serves in the UK and globally.
- Bishop Fox: US-based boutique penetration testing firm offering CREST-equivalent accredited offensive security services to Fortune 500 enterprises. Comparable in operating model (boutique, senior testers, recurring client engagement) though at meaningfully larger scale.
- Cyberis: UK-based cybersecurity consultancy specialising in penetration testing, threat-led assessments, and incident response for regulated industries. Comparable in scale, accreditation footprint, and focus on financial services and public sector buyers.
- Pen Test People: UK-based CREST-accredited penetration testing specialist with a similar PTaaS-style delivery model and similar focus on regulated SMB and mid-market customers. Closest scale and product analog to Closed Door Security.
- Cobalt: Pioneer of the PTaaS model with an on-demand pentest platform connecting customers to vetted testers. Direct competitor to the Insights platform specifically, though Cobalt operates a marketplace model rather than in-house testers.
- Secarma: UK-based CREST-accredited penetration testing specialist serving financial services and enterprise customers. Comparable boutique profile and similar regulatory compliance focus as Closed Door Security.
Broad incumbents
- WithSecure (formerly MWR InfoSecurity / F-Secure Cyber Security Services): European-headquartered cybersecurity firm with a dedicated offensive security arm offering penetration testing, red teaming, and threat intelligence. Larger and broader portfolio than Closed Door Security but competes for the same enterprise buyers.
- Trustwave: Global MSSP with CREST-equivalent accreditations offering penetration testing as part of a broader managed security, MDR, and consulting portfolio. Competes primarily on bundled enterprise deals where Closed Door also bids.
- Optiv: Large North American cybersecurity solutions integrator and MSSP with offensive security capabilities. Competes in the enterprise segment where Closed Door also serves large financial services and healthcare clients.
Emerging players
- HackerOne: Bug bounty and PTaaS platform enabling crowdsourced and managed penetration testing. Overlaps with Closed Door's PTaaS offering though targets a different buyer profile (often more developer-led, less regulated verticals).
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Closed Door Security social profiles
Digital presenceClosed Door Security compliance and trust
Trust signalCompliance6 records
Closed Door Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Closed Door Security leadership team
Management profileNumber of profiles
Profiles4 records
Closed Door Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Closed Door Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Closed Door Security
What does Closed Door Security do?
Closed Door Security is a cybersecurity consultancy delivering CREST certified penetration testing across 14+ testing domains (web application, network, mobile, API, cloud, OT/ICS, social engineering, supply chain, maritime, super yacht, and family office) alongside compliance and auditing services for Cyber Essentials, ISO 27001, PCI DSS, SOC 2, GDPR, DORA, TIBER-EU, VARA, and DFSA frameworks. The proprietary Insights PTaaS platform provides real-time vulnerability tracking, live re-testing, and 12 months of quarterly PCI-DSS approved vulnerability scanning for every engagement.
Is Closed Door Security a public or private company?
Closed Door Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Closed Door Security founded?
Closed Door Security was founded in 2019. It employs 1 to 10 people.
Where is Closed Door Security based?
Closed Door Security is headquartered in Stornoway, United Kingdom, in the Europe region.
How does Closed Door Security make money?
Three revenue lines are on record. Penetration Testing Services are the primary driver. The others are compliance & Auditing Services and PTaaS Platform Subscription.
Who are Closed Door Security's main competitors?
Direct peers on record are NCC Group, Bishop Fox, Cyberis, Pen Test People, Cobalt and Secarma. Broad incumbents are WithSecure (formerly MWR InfoSecurity / F-Secure Cyber Security Services), Trustwave and Optiv. HackerOne is listed as an emerging player.
Does Closed Door Security have an API?
No public API is recorded for Closed Door Security.
What industry is Closed Door Security in?
Closed Door Security's product category is Cybersecurity Penetration Testing Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of HDADAHAG, Penetration Testing Platforms (PTaaS). Its NAICS code is 5616 and its SIC code is 7371.