NotSoSecure
NotSoSecure is a London-based boutique cybersecurity firm operating as part of Claranet Cyber Security, delivering penetration testing, cloud security, managed detection response, application security, and offensive/defensive training to enterprise and government clients across UK/Europe, North America, and Asia-Pacific.
- Company typePrivate
- Founded2007
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What NotSoSecure does
NotSoSecure is a boutique cybersecurity services firm delivering offensive security testing, cloud security, and training to enterprise and government clients across the UK/Europe, North America, and Asia-Pacific regions. Following its 2019 acquisition by Claranet Group, the company operates as the core of Claranet Cyber Security, headquartered at 17 Slingsby Place in London, with a named client roster spanning major technology vendors (Cisco, Google, Oracle, Salesforce, Workday), industrial manufacturers (Siemens, Philips, General Electric, Western Digital, Skechers), government and defense (US Army, Lockheed Martin, Federal Bureau of Investigation), financial services (J.P. Morgan Chase, S&P Global), and healthcare/consumer brands (Humana, Estee Lauder). The company cites 17 years of experience and is led by Founder & CEO Charles Nasser.
The service portfolio rests on manual expert testing augmented by proprietary open-source tooling and is organized into six core product lines: penetration testing across infrastructure, web applications, mobile applications, red team exercises, and social engineering; continuous security testing combining 24/7 managed scanning with expert-led retesting; cloud security including founding accredited AWS Managed Security Services Provider status; managed detection and response; application security code review and architecture review; and advisory consultancy for PCI DSS and Cyber Essentials compliance. The training division runs an offensive curriculum (Black Hat courses, Hacking 101, The Art of Hacking, basic and advanced web/infrastructure hacking, Hacking Cloud Infrastructure, Hacking Azure, Hacking LLM) and a defensive curriculum (DevSecOps, AppSec for Developers), delivered direct, via channel partners, and at conferences such as Black Hat events in Las Vegas, Europe, and Asia since at least 2010. Supporting the practice are in-house open-source tools (Serialized Payload Generator, NotSoCereal Lab, Project Blacklist3r, Cloud Services Enumeration scripts, SQL Injection Lab) and a technical blog plus webinar series used for top-of-funnel demand generation.
Revenue is generated through professional services engagements priced on a custom, quote-based scope under multi-year contracts, supplemented by managed services revenue from cloud security/MSSP engagements and recurring training delivery. Pricing is not publicly disclosed, and the consultative enterprise sales motion (quote-based, custom-scoped) is supplemented by inbound demand from content marketing, conference presence, and open-source tooling. The company's distribution mix pairs direct enterprise sales with channel partners (QA, Check Point) and conference-based training, and accreditations including CREST, CHECK Green Light, PCI QSA, PCI ASV, Cyber Essentials certification body status, and AWS Managed Security Services Provider accreditation form the regulatory and procurement gating for this go-to-market.
NotSoSecure firmographics
Firmographics- Name
- NotSoSecure
- Legal name
- NotSoSecure Global Services Limited
- Website
- https://notsosecure.com
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- NotSoSecure is a London-based boutique cybersecurity firm operating as part of Claranet Cyber Security, delivering penetration testing, cloud security, managed detection response, application security, and offensive/defensive training to enterprise and government clients across UK/Europe, North America, and Asia-Pacific.
- Ownership category
- akta.pro rank
NotSoSecure industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Training (61142), Investigation and Security Services (5616)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF)
Keywords
Where NotSoSecure is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
NotSoSecure business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Penetration Testing Services: Professional services revenue from comprehensive penetration testing including infrastructure, web application, mobile application testing, red team exercises, and social engineering assessments.
- Security Training: Revenue from delivering cybersecurity training courses globally including offensive security (Black Hat, Hacking 101, Advanced Web/Infrastructure Hacking, Cloud security) and defensive training (DevSecOps, AppSec for Developers). Available directly, through partners (QA, Check Point), and at conferences.
- Cloud Security Services: Managed security services for cloud environments including AWS managed security, cloud architecture assessments, and continuous security testing.
- Advisory Consultancy: Consulting services including PCI DSS compliance, Cyber Essentials certification, and security architecture reviews.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Enterprise security testing and training services with custom scoping |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels5 records
NotSoSecure product offering
Product offeringCore offering
NotSoSecure delivers offensive and defensive cybersecurity services including penetration testing (infrastructure, web, mobile, red team, social engineering), cloud and AWS managed security services, continuous security testing, managed detection and response, and advisory consultancy for PCI DSS and Cyber Essentials compliance. The training division runs hands-on offensive and defensive security courses globally through direct bookings, training partners (QA, Check Point), and Black Hat conferences, with curricula aligned to CREST CCT, CHECK, and TIGER SST certifications.
Product overview
NotSoSecure is a cybersecurity services and training company, part of Claranet Cyber Security, offering a portfolio of offensive security services and training courses. The core services include Penetration Testing (infrastructure, web application, mobile application, red team, social engineering), Cloud Security (including AWS Managed Security Services), Continuous Security Testing, Managed Detection and Response, and Advisory Consultancy (PCI DSS, Cyber Essentials). The training division offers Offensive Security Training courses (Black Hat, Hacking 101, The Art of Hacking, web/infrastructure/cloud hacking, LLM security) and Defensive Training including DevSecOps Training and AppSec for Developers courses. All services are delivered by certified security professionals with CREST accreditation and CHECK Green Light certification.
Differentiator
Problem solved
Functional benefit
Brands
- NotSoSecure Training: Offensive and defensive security training programs including Black Hat courses, Hacking 101, The Art of Hacking, and specialized cloud security training
Products and services
- Penetration Testing Comprehensive penetration testing services covering infrastructure, web applications, mobile applications, red team exercises, and social engineering assessments to identify and address security vulnerabilities for enterprise and government clients.
- Continuous Security Testing Combines 24/7 managed scanning with skilled manual penetration testing to rapidly identify vulnerabilities and maintain an ongoing security posture for enterprise clients.
- Cloud Security Managed security services for cloud environments that combine manual penetration testing with application-scanning technologies to deliver dynamic, collaborative security assessments for organizations operating in the cloud.
- AWS Managed Security Services Delivered as a founding accredited AWS Managed Security Services Provider, monitoring and managing AWS environment security on behalf of customers with cloud security expertise.
- Managed Detection and Response Continuous monitoring of cloud environments to identify cyber threats rapidly and provide expert response, available as a comprehensive managed service.
- Application Security Services focused on securing applications through code review, security architecture assessments, and integration of security into software development processes for development and product teams.
- IT Health Check / PSN Compliance Specialist IT Health Check services for Public Services Network (PSN) compliance, delivering critical network infrastructure security assessments for UK public sector organizations, with an operational track record since 2009.
- Advisory Consultancy Consultancy services covering PCI DSS compliance (as a Qualified Security Assessor and Approved Scanning Vendor), Cyber Essentials certification support, and security architecture reviews.
- Red Team Exercises Real-world security assessments using black-box testing approaches including penetration testing, wireless network compromising, physical access testing, and social engineering techniques.
- Social Engineering Assessments Full social engineering attack simulations including phishing, smishing, vishing, physical entry, baiting, impersonation, and watering hole attacks to assess staff vulnerability to human-targeted attacks.
- Offensive Security Training Hands-on offensive cybersecurity training courses covering Hacking 101, The Art of Hacking, Basic and Advanced Web Hacking, Basic and Advanced Infrastructure Hacking, Hacking Cloud Infrastructure, Hacking and Securing Cloud Infrastructure, Hacking LLM, and Hacking Azure, delivered direct, through partners, and at Black Hat conferences.
- DevSecOps Training 2-day intermediate course teaching DevOps and security professionals how to automate security into DevOps environments using open-source tools including Talisman, HashiCorp Vault, OWASP tools, Semgrep, and ELK Stack.
- AppSec for Developers 2-day intermediate hands-on course enabling developers to understand application security vulnerabilities, code with a security mindset, and implement threat modeling for secure development.
Companies that use NotSoSecure
Customer profileNamed customers18 records
Segments4 records
Ideal customer profiles4 records
NotSoSecure technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
NotSoSecure partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core, major and minor.
- Claranet GroupcoreNotSoSecure is part of the Claranet Cyber Security division. Claranet acquired NotSoSecure to strengthen its cybersecurity services portfolio. The acquisition positions NotSoSecure with significantly enhanced resources and capabilities as part of a larger cybersecurity organization.
- Amazon Web ServicescoreFounding accredited AWS Managed Security Services Provider. Partnership involves monitoring and managing AWS environment security as part of AWS's managed security services ecosystem.
- QA TrainingmajorAuthorized training partner offering NotSoSecure courses including AppSec for Developers and DevSecOps through QA's training delivery network.
- Check Point TrainingmajorAuthorized training partner offering NotSoSecure courses. Accepts Check Point Cyber-Security Learning Credits for training enrollment.
- Black HatmajorRegular training partner delivering cybersecurity courses at Black Hat events worldwide including Las Vegas, Europe, and Asia. Company has presented at Black Hat since at least 2010.
- OWASPminorDelivered training at OWASP AppSec Days Conference. Company mentions OWASP Top 10 extensively in training curriculum and security research.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
NotSoSecure competitors and assessment
Company assessmentMarket position
Strengths1 record
Weaknesses1 record
Competitive moat4 records
Key risks1 record
Key highlights1 record
Customer concentration
NotSoSecure social profiles
Digital presenceNotSoSecure compliance and trust
Trust signalCompliance10 records
NotSoSecure financial estimates
Financial estimateRevenue estimate
Valuation estimate
NotSoSecure leadership team
Management profileNumber of profiles
Profiles1 record
NotSoSecure funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NotSoSecure M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NotSoSecure
What does NotSoSecure do?
NotSoSecure delivers offensive and defensive cybersecurity services including penetration testing (infrastructure, web, mobile, red team, social engineering), cloud and AWS managed security services, continuous security testing, managed detection and response, and advisory consultancy for PCI DSS and Cyber Essentials compliance. The training division runs hands-on offensive and defensive security courses globally through direct bookings, training partners (QA, Check Point), and Black Hat conferences, with curricula aligned to CREST CCT, CHECK, and TIGER SST certifications.
Is NotSoSecure a public or private company?
NotSoSecure is a private company. It is classified as corporate owned and is currently operating.
When was NotSoSecure founded?
NotSoSecure was founded in 2007. It employs 11 to 50 people.
Where is NotSoSecure based?
NotSoSecure is headquartered in San Francisco, United States, in the North America region.
How does NotSoSecure make money?
Four revenue lines are on record. Penetration Testing Services are the primary driver. The others are security Training, cloud Security Services and advisory Consultancy.
Does NotSoSecure have an API?
No public API is recorded for NotSoSecure.
What industry is NotSoSecure in?
NotSoSecure's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 61142.