ITG Cybersecurity
ITG Cybersecurity is a Boston-based private firm founded in 2021 that sells the AI-powered PISTOS compliance management platform and CISO advisory services to enterprise clients needing to manage cybersecurity frameworks such as CMMC, DFARS, SOC 2, ISO 27001, HIPAA, and PCI DSS.
- Company typePrivate
- Founded2021
- HeadquartersBoston, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What ITG Cybersecurity does
ITG Cybersecurity is a Boston-based private cybersecurity firm operating as ITG Cybersecurity LLC, founded in 2021 by Gunhan Unal, a 30-year industry veteran who previously served as Managing Partner at Ernst & Young building the New England and West Coast Information Security Practices. The company targets enterprise organizations with IT and Operational Technology environments that need to maintain compliance across multiple cybersecurity frameworks simultaneously, with particular traction among defense contractors (CMMC v2.0, DFARS, NIST 800-171), financial institutions subject to NYDFS, healthcare entities (HIPAA), payment processors (PCI DSS), and energy sector operators (NERC/CIP).
The company's core product is PISTOS, an AI-powered risk-based compliance management platform that supports over 50 frameworks in a single environment, featuring a self-configuring Intelligent Cybersecurity Framework Architect that maps threats, risks, controls and regulations, automated assessment scheduling and remediation workflows, a Vendor Risk Manager with a Vendor Trust Center, integrated asset management, evidence and task management, and cloud integrations with Azure, AWS, and Google Cloud. The platform is complemented by professional services covering framework assessment, design, implementation, certification, and ongoing monitoring.
ITG generates revenue through three streams: subscription access to PISTOS (recurring SaaS), recurring managed services including CISO-as-a-Service and Real-time Compliance Managed Services, and project-based professional services for compliance readiness and framework implementation. Distribution is entirely direct-to-enterprise via the company website's contact and "Get A Free Quote" forms, with custom annual contracts and no publicly disclosed pricing. The firm is privately held, founder-owned, has no disclosed institutional investors or funding rounds, and reports a headcount of 1-10 employees based in Boston.
ITG Cybersecurity firmographics
Firmographics- Name
- ITG Cybersecurity
- Legal name
- ITG Cybersecurity LLC
- Website
- https://www.itgsecurity.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ITG Cybersecurity is a Boston-based private firm founded in 2021 that sells the AI-powered PISTOS compliance management platform and CISO advisory services to enterprise clients needing to manage cybersecurity frameworks such as CMMC, DFARS, SOC 2, ISO 27001, HIPAA, and PCI DSS.
- Ownership category
- akta.pro rank
ITG Cybersecurity industry classification
Industry- Product category
- Cybersecurity Compliance Management Software
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
- akta.pro secondary industries
- IT Risk Management (ITRM) (HDADAIAD), ITSM Governance, Compliance & Audit Readiness (BPAEAJAM), ITSM Tooling Integration, Automation & Orchestration (BPAEAJAD)
Keywords
Where ITG Cybersecurity is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Markets served
ITG Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- PISTOS Compliance Management Platform: SaaS-based compliance management platform providing real-time monitoring, risk assessment, and framework certification management. Subscription-based access to the platform with automated workflows and reporting capabilities.
- CISO Services: Ongoing CISO-as-a-service providing executive-level cybersecurity leadership, quarterly gap analysis reports, 24/7 remote support, policy documentation, vulnerability scanning, and quarterly onsite meetings. Minimum hours per month with access to industry experts.
- Framework Implementation Services: Professional services for assessing, designing, and implementing security frameworks. Includes gap assessment, business impact analysis, security architecture design, and implementation assistance to achieve compliance certification.
- Compliance Readiness Services: Compliance preparation services including control evaluation against regulatory requirements, recommendations for missing controls, and building cybersecurity frameworks for ongoing compliance.
- Real-time Compliance Managed Services: Ongoing monitoring of compliance to selected frameworks in real-time with immediate remediation of any non-compliance instances discovered.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Contact-based pricing for enterprise compliance solutions |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels4 records
ITG Cybersecurity product offering
Product offeringCore offering
ITG Cybersecurity provides AI-powered cybersecurity framework and compliance management through its Pistos platform, supporting 50+ standards across IT and OT environments with real-time monitoring, vendor risk management, and cloud integrations. The company wraps the platform with professional services covering assessment, design, implementation, certification, and ongoing managed compliance for enterprise clients seeking certifications such as SOC 2, ISO 27001, CMMC v2.0, HIPAA, PCI DSS, DFARS, and NYDFS.
Product overview
ITG Cybersecurity offers a unified AI-powered compliance management platform called Pistos with integrated modules for compliance management, vendor risk management, and implementation services. The core Pistos platform provides AI-powered risk-based compliance management for IT and OT environments, supporting over 50 frameworks. The product portfolio includes Pistos Compliance Management for multi-framework certification management, Pistos Vendor Risk Manager for third-party risk assessment with a Vendor Trust Center, the Framework Certification Assistant for self-guided implementation, and ITG's Intelligent Cybersecurity Framework Architect for automated program scoping. Professional services include Pistos Implementation Services, CISO Services (virtual chief information security officer), Compliance Readiness Services, Real-time Compliance Managed Services, and Framework Implementation and Maintenance.
Differentiator
Problem solved
Functional benefit
Brands
- Pistos: AI Powered State of the art risk-based compliance management application that scales. Features IT & OT focus, over 50+ frameworks, Policies Standards and Guidelines module, Vendor Risk Management Module, cloud integration (Azure AWS Google Cloud), Asset Management Integration, Task and Evidence Management, Assessment module, Vendor Trust Center, and Robust Reporting.
Products and services
- Pistos Compliance Management Platform AI-powered risk-based compliance management application built for IT and OT enterprise environments, supporting 50+ security frameworks with policies/standards/guidelines, vendor risk management, cloud integrations (Azure, AWS, Google Cloud), asset management integration, task and evidence management, continuous assessment, and robust reporting. Sold as a subscription to enterprise organizations managing multi-framework cybersecurity and compliance programs.
- Pistos Vendor Risk Manager All-in-one vendor risk management solution providing centralized vendor data repository, automated risk assessments and scoring, real-time monitoring and alerts, customizable reporting and analytics, automated workflows, continuous monitoring, and compliance and audit readiness for enterprise customer organizations and the vendor Trust Center for self-service vendor trust verification.
- ITG Intelligent Cybersecurity Framework Architect (Framework Certification Assistant) AI-powered system that automatically scopes an organization's cybersecurity program by mapping threats, risks, controls, and regulations through a step-by-step guided assessment, self-configuring annual review schedules with pre-built content, workflow triggers, notifications, and reminders to streamline framework implementation and certification.
- Pistos Implementation Services Professional services to assess, design, and implement the required cybersecurity framework for enterprise clients, including security posture assessment, business impact analysis, and implementation assistance to achieve certification.
- CISO Services Virtual CISO partnership providing executive-level cybersecurity program design and maintenance, compliance evaluation and risk management, policy documentation, 24/7 remote support, quarterly gap analysis reports, vulnerability scanning, and quarterly onsite review meetings for client executive teams.
- Compliance Readiness Services Services to evaluate controls against regulatory requirements, recommend missing controls, strengthen weak controls, and build cybersecurity frameworks in preparation for compliance audits.
- Real-time Compliance Managed Services Ongoing managed service providing real-time monitoring of compliance to selected frameworks with immediate remediation of any non-compliance instances discovered.
- Framework Implementation and Maintenance Assistance with implementation and ongoing maintenance of security frameworks after initial purchase, ensuring continued compliance with framework requirements.
Quantifiable outcome
- Organizations can complete compliance certification framework implementation through a streamlined once-through process due to overlapping requirements across frameworks
Companies that use ITG Cybersecurity
Customer profileNamed customers1 record
Segments7 records
Ideal customer profiles5 records
ITG Cybersecurity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability4 records
Feature11 records
ITG Cybersecurity partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered minor.
- Unnamed Partner Logo 1minorPartner logo displayed in 'Our Valuable Clients' section on Framework page. Partner identity not specified in source materials.
- Unnamed Partner Logo 2minorPartner logo displayed in 'Our Valuable Clients' section on Framework page. Partner identity not specified in source materials.
- Unnamed Partner Logo 3minorPartner logo displayed in 'Our Valuable Clients' section on Framework page. Partner identity not specified in source materials.
- Unnamed Partner Logo 4minorPartner logo displayed in 'Our Valuable Clients' section on Framework page. Partner identity not specified in source materials.
- Unnamed Partner Logo 5minorPartner logo displayed in 'Our Valuable Clients' section on Framework page. Partner identity not specified in source materials.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
ITG Cybersecurity competitors and assessment
Company assessmentDirect peers
- Secureframe: Compliance automation platform with managed services overlay, supporting SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, and CMMC frameworks. Secureframe's combined SaaS + services model closely mirrors ITG's land-and-expand approach.
- Vanta: AI-powered compliance automation platform for SOC 2, ISO 27001, HIPAA, and dozens of other frameworks with continuous monitoring and an integrated auditor marketplace. Vanta is the most direct competitive analog to ITG's PISTOS platform in the compliance automation category.
- Drata: Continuous compliance and security monitoring SaaS automating evidence collection for SOC 2, ISO 27001, HIPAA, PCI, CMMC, and other frameworks. Drata competes head-to-head with PISTOS on multi-framework compliance automation for enterprise and mid-market buyers.
- Sprinto: Cloud-compliance automation platform targeting SaaS companies for SOC 2, ISO 27001, HIPAA, GDPR, and more with continuous monitoring. Sprinto competes in the same multi-framework compliance-as-a-service category as PISTOS.
- LogicGate: No-code GRC and risk management platform supporting third-party risk, compliance, and policy management use cases. LogicGate's Risk Cloud overlaps directly with PISTOS Compliance Management and Vendor Risk Manager modules.
- Hyperproof: Compliance operations platform supporting SOC 2, ISO 27001, NIST, HIPAA, FedRAMP, and other frameworks with evidence collection and control mapping. Hyperproof targets enterprise GRC buyers overlapping with PISTOS's IT/OT enterprise positioning.
Broad incumbents
- OneTrust (Tugboat Logic): Broad trust intelligence platform with a compliance automation module (originally Tugboat Logic) supporting SOC 2, ISO 27001, NIST, and other frameworks. OneTrust is a broader GRC/privacy incumbent that overlaps ITG's compliance and vendor risk management domains.
- ServiceNow Integrated Risk Management: Enterprise platform vendor offering IT GRC, risk management, and compliance modules as part of the broader ServiceNow platform. ServiceNow competes with PISTOS at large enterprises that already standardize on its platform for ITSM/IR.
- Diligent (AuditBoard): Enterprise GRC platform (acquired AuditBoard) covering audit, risk, compliance, and ESG for large organizations. Diligent is a broad incumbent that competes with ITG for enterprise governance, risk, and compliance budgets.
- Archer (Reservoir/Sword & Shield): Enterprise IT risk management and GRC platform with deep roots in operational risk and IT risk use cases. Archer is a long-standing broad incumbent that competes with PISTOS in enterprise IT GRC buying centers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key highlights6 records
Customer concentration
ITG Cybersecurity social profiles
Digital presenceITG Cybersecurity compliance and trust
Trust signalCompliance16 records
ITG Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
ITG Cybersecurity leadership team
Management profileNumber of profiles
Profiles1 record
ITG Cybersecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ITG Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ITG Cybersecurity
What does ITG Cybersecurity do?
ITG Cybersecurity provides AI-powered cybersecurity framework and compliance management through its Pistos platform, supporting 50+ standards across IT and OT environments with real-time monitoring, vendor risk management, and cloud integrations. The company wraps the platform with professional services covering assessment, design, implementation, certification, and ongoing managed compliance for enterprise clients seeking certifications such as SOC 2, ISO 27001, CMMC v2.0, HIPAA, PCI DSS, DFARS, and NYDFS.
Is ITG Cybersecurity a public or private company?
ITG Cybersecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ITG Cybersecurity founded?
ITG Cybersecurity was founded in 2021. It employs 1 to 10 people.
Where is ITG Cybersecurity based?
ITG Cybersecurity is headquartered in Boston, United States, in the North America region.
How does ITG Cybersecurity make money?
Five revenue lines are on record. PISTOS Compliance Management Platform is the primary driver. The others are CISO Services, framework Implementation Services, compliance Readiness Services and real-time Compliance Managed Services.
Who are ITG Cybersecurity's main competitors?
Direct peers on record are Secureframe, Vanta, Drata, Sprinto, LogicGate and Hyperproof. Broad incumbents are OneTrust (Tugboat Logic), ServiceNow Integrated Risk Management, Diligent (AuditBoard) and Archer (Reservoir/Sword & Shield).
Does ITG Cybersecurity have an API?
No public API is recorded for ITG Cybersecurity.
What industry is ITG Cybersecurity in?
ITG Cybersecurity's product category is Cybersecurity Compliance Management Software. Its primary akta.pro industry code is HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms, with a secondary code of HDADAIAD, IT Risk Management (ITRM). Its NAICS code is 5415 and its SIC code is 7370.