Parameter Security
Parameter Security is a St. Louis-based cybersecurity professional services firm delivering penetration testing, PCI QSA compliance, virtual CISO advisory, and digital forensics/incident response to mid-market and enterprise clients, including regulated and legal-sector organizations across the U.S. and 22 countries.
- Company typePrivate
- Founded2007
- HeadquartersSaint Peters, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Parameter Security does
Parameter Security, operating as Parameter LLC (Missouri), is a cybersecurity professional services firm founded in 2006/2007 by Dave Chronister and headquartered in Chesterfield, in the St. Louis metro area. The company delivers human-led information security services rather than a software product, spanning Assessment Services (external/internal penetration testing, vulnerability assessments, OWASP-based web application assessments, and regulatory readiness reviews), Advisory Services (Virtual CISO, risk assessment, BCP/DRP planning, policy development), PCI Compliance Services (it has been a PCI Qualified Security Assessor since 2014, issuing ROC, SAQ, and AOC attestations and bundling managed ASV scanning, vulnerability scanning, phishing simulations, and security awareness training), and Digital Forensics & Incident Response (breach investigation, ransomware response, threat hunting, expert witness testimony, and litigation support, enabled by Missouri Private Investigator License #2012039253). Service delivery relies on industry-standard methodologies (PTES, OWASP, NIST SP800-115) and certified practitioners (CISSP, CISA, CISM, QSA, GPEN, PCIP) rather than proprietary AI/ML automation.
The firm operates under a hybrid revenue model. Project-based assessments and DFIR engagements are billed on a progressive 50%/25%/25% schedule or 100% upfront, while MDR, SIEM, Security Awareness Training, and Virtual CISO services are billed monthly in advance with seat-based true-ups, creating a mix of episodic and recurring revenue. Go-to-market is sales-led: direct client engagement through the website, phone, and channel partners, supplemented by thought leadership via the company-operated ShowMeCon security conference, a blog authored by executives, and founder media exposure on ABC, Fox Business, CNBC, MSNBC, CNN, Popular Science, and the Associated Press. The company serves organizations requiring PCI compliance, regulated industries (healthcare, financial services), mid-market to enterprise firms, and legal/litigation clients across nearly every U.S. state and 22 countries, with a disclosed headcount band of 11-50 employees. Parameter Security is privately held, bootstrapped, and shows no evidence of external institutional investment.
Parameter Security firmographics
Firmographics- Name
- Parameter Security
- Legal name
- Parameter LLC
- Website
- https://parametersecurity.com
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Parameter Security is a St. Louis-based cybersecurity professional services firm delivering penetration testing, PCI QSA compliance, virtual CISO advisory, and digital forensics/incident response to mid-market and enterprise clients, including regulated and legal-sector organizations across the U.S. and 22 countries.
- Ownership category
- akta.pro rank
Parameter Security industry classification
Industry- Product category
- Cybersecurity Professional Services
- NAICS
- Other Computer Related Services (541519), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI), Vulnerability Assessment & Scanning (HDADAHAA)
Keywords
Where Parameter Security is headquartered
LocationHeadquarters
- HQ city
- Saint Peters
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Parameter Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Project-Based Assessment Services: Penetration testing, vulnerability assessments, and security audits billed on a project basis with progressive payment terms (50% on order, 25% on scheduling, 25% on delivery) or full payment upon signing.
- Managed Detection & Response (MDR): Monthly billed managed services for ongoing security monitoring and detection, billed monthly in advance.
- Security Information and Event Management (SIEM): Managed SIEM services with seat licenses, billed monthly with true-up provisions for count changes.
- Security Awareness Training (SAT): Monthly billed security awareness training services with seat licensing.
- Virtual CISO (vCISO) Services: Annual subscription vCISO service providing ongoing security program management, billed monthly in advance with risk assessments, business requirements analysis, and security roadmap development.
- Digital Forensics & Incident Response: Forensic investigation and incident response services, typically project-based engagements with time and materials billing for follow-up activities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Project-Based Engagements - Progressive Billing |
| One time/ perpetual license | Multi-year contract | Project-Based Engagements - Full Payment Upon Signing |
| Subscription | Monthly | Managed Services (MDR, SIEM, SAT, vCISO) |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
Parameter Security product offering
Product offeringCore offering
Parameter Security is a cybersecurity professional services firm that delivers ethical hacking, penetration testing, vulnerability assessments, web application assessments, and PCI-DSS compliance services. The company also provides digital forensics and incident response (DFIR), virtual CISO (vCISO) advisory, managed detection and response (MDR), managed SIEM, and security awareness training to organizations across regulated industries.
Product overview
Parameter Security is a cybersecurity professional services firm offering a portfolio of assessment, advisory, and digital forensics services. The core offerings include Assessment Services (penetration testing, vulnerability assessments, web application assessments, readiness assessments), Advisory Services (vCISO, risk assessment, incident handling, BCP/DRP planning), PCI Compliance Services (QSA assessments, ROC, SAQ, AOC, managed scanning), and Digital Forensics & Incident Response (DFIR). Services are delivered through experienced security consultants and can be bundled (e.g., PCI Bundle combining compliance checks with penetration assessments, managed scanning, and training) or purchased as standalone engagements. The company has been operating since 2007 and serves clients nationally from its St. Louis headquarters.
Differentiator
Problem solved
Functional benefit
Brands
- ShowMeCon: A regional security conference founded by Parameter Security which, pre-COVID, was becoming the largest security conference in the region.
Products and services
- Assessment Services
- Advisory Services
- PCI Compliance Services PCI Qualified Security Assessor (QSA) services including Report on Compliance (ROC), Self-Assessment Questionnaire (SAQ), Attestation of Compliance (AOC), managed ASV scanning, vulnerability scanning, security awareness training, and phishing assessments bundled as the PCI Bundle. Targeted at merchants, payment processors, and financial institutions requiring PCI-DSS certification.
- Digital Forensics & Incident Response (DFIR) Digital forensics and incident response services including breach investigations, expert witness testimony, threat hunting, ransomware investigations, and litigation support for organizations facing security incidents or involved in legal proceedings.
- Virtual Chief Information Security Officer (vCISO) Fractional vCISO advisory service providing risk assessment, business impact analysis, regulatory compliance guidance, incident response planning, disaster recovery planning, policy creation, and board-level reporting to help organizations mature their security programs. Targeted at mid-market and regulated organizations lacking dedicated internal CISO leadership.
Quantifiable outcome
- 279 days average time for businesses to detect an incident (industry benchmark cited)
- +3 more outcomes
Companies that use Parameter Security
Customer profileSegments4 records
Ideal customer profiles4 records
Parameter Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Parameter Security partnerships and signals
Strategic signalScale indicators4 records
Recent moves6 records
Expansion highlights6 records
Parameter Security competitors and assessment
Company assessmentDirect peers
- RSI Security: Cybersecurity services firm offering pen testing, compliance assessments (PCI, HIPAA, SOC 2), and advisory services. Comparable boutique competitor serving similar regulated mid-market and enterprise clients.
- NetSPI: Penetration testing and attack surface management provider with both human-delivered and platform-enabled services. Comparable to Parameter in core pen testing/vulnerability assessment services, but larger and more productized.
- A-LIGN: Compliance-focused cybersecurity firm providing PCI QSA, SOC 2, HITRUST, and ISO assessments combined with pen testing. Highly comparable to Parameter's PCI-led, compliance-driven assessment business.
- NCC Group: Global cybersecurity consultancy providing penetration testing, vulnerability assessment, PCI QSA services, and incident response. Overlaps with Parameter's services mix and international client reach, though materially larger.
- TrustedSec: Boutique cybersecurity consulting firm specializing in penetration testing, vulnerability assessments, red teaming, and incident response — closely matching Parameter's ethical-hacking core. Similar size and sales-led GTM targeting enterprise and mid-market compliance buyers.
- Bishop Fox: Boutique offensive security consultancy focused on penetration testing, red teaming, and attack surface management. Directly comparable to Parameter in service mix, target buyer (enterprise), and consulting-led delivery model.
- Coalfire: PCI QSA company offering compliance assessments (PCI, HITRUST, FedRAMP), pen testing, and advisory — directly overlapping Parameter's PCI Bundle and broader assessment portfolio. A more scaled direct competitor in compliance services.
Broad incumbents
- Trustwave: Large MSSP and PCI QSA company delivering managed security services, pen testing, DFIR, and compliance consulting. Competes with Parameter for mid-market and enterprise compliance work, but at much greater scale and with broader portfolio.
- Secureworks: Global MSSP delivering managed detection and response, vulnerability management, and incident response. Overlaps with Parameter's MDR and DFIR offerings, though at significantly larger scale and with proprietary Taegis platform.
- Optiv: Large cybersecurity solutions integrator and MSSP offering advisory, pen testing, and managed services. Targets the same mid-market to enterprise buyer as Parameter, with a much wider service catalog and partner ecosystem.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Parameter Security social profiles
Digital presenceParameter Security compliance and trust
Trust signalCompliance2 records
Parameter Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Parameter Security leadership team
Management profileNumber of profiles
Profiles3 records
Parameter Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Parameter Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Parameter Security
What does Parameter Security do?
Parameter Security is a cybersecurity professional services firm that delivers ethical hacking, penetration testing, vulnerability assessments, web application assessments, and PCI-DSS compliance services. The company also provides digital forensics and incident response (DFIR), virtual CISO (vCISO) advisory, managed detection and response (MDR), managed SIEM, and security awareness training to organizations across regulated industries.
Is Parameter Security a public or private company?
Parameter Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Parameter Security founded?
Parameter Security was founded in 2007. It employs 11 to 50 people.
Where is Parameter Security based?
Parameter Security is headquartered in Saint Peters, United States, in the North America region.
How does Parameter Security make money?
Six revenue lines are on record. Project-Based Assessment Services are the primary driver. The others are managed Detection & Response (MDR), security Information and Event Management (SIEM), security Awareness Training (SAT), virtual CISO (vCISO) Services and digital Forensics & Incident Response.
Who are Parameter Security's main competitors?
Direct peers on record are RSI Security, NetSPI, A-LIGN, NCC Group, TrustedSec, Bishop Fox and Coalfire. Broad incumbents are Trustwave, Secureworks and Optiv.
Does Parameter Security have an API?
No public API is recorded for Parameter Security.
What industry is Parameter Security in?
Parameter Security's product category is Cybersecurity Professional Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519 and its SIC code is 7370.