Mossé Security
Mossé Security is a Melbourne-based cybersecurity consulting firm founded in 2010 that delivers penetration testing, digital forensics, incident response, GRC, and CISO-as-a-Service to Australian critical-infrastructure organizations in healthcare, finance, defence, energy, and water.
- Company typePrivate
- Founded2010
- HeadquartersMelbourne, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Mossé Security does
Mossé Security is a privately held, Melbourne-based cybersecurity consulting firm founded in 2010 by Benjamin Mossé. The firm delivers professional services — CISO as a Service, Security Assurance (penetration testing across web, network, wireless, and thick-client environments), Digital Investigations (forensics, incident response, malware analysis, OSINT), and Governance, Risk and Compliance — to Australian organizations operating in critical-infrastructure sectors including healthcare, finance, defence, higher education, energy, and water. Engagements are tailored, quote-based, and structured as multi-year contracts, with the firm managing client cybersecurity budgets in the $100K to $2M per annum range.
The firm's technical differentiators rest on proprietary methodologies developed from operational experience: the Offensive Countermeasures framework (a structured set of psychological, economic, misinformation, operational, and prosecutive instruments for engaging adversaries) and the Adversary Management methodology for active defense during incidents. It has codified its accumulated incident response experience — 100+ incidents, 350+ attack simulations, and 53 threat-hunting exercises — into published threat intelligence on adversary groups such as CRIME CHARLIE and CRIME OSCAR, and into an Australian Threat Intelligence Annual Report. The firm's technology stack is people- and methodology-driven rather than software-product-driven, with no AI/ML or software platform referenced.
Mossé Security monetizes through billable consulting hours and project-based engagements, distributed via direct enterprise sales without channel partners. It has built a small affiliated ecosystem: a wholly-owned training arm (Mossé Cyber Security Institute) that certifies its consultants and offers external training, and a wholly-owned business and sales intelligence subsidiary (Deveillance) that augments OSINT capabilities. The company is bootstrapped and founder-owned, with no disclosed external funding, no parent company, and no acquisition history.
Mossé Security firmographics
Firmographics- Name
- Mossé Security
- Legal name
- Mossé Security
- Website
- https://mosse-security.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Mossé Security is a Melbourne-based cybersecurity consulting firm founded in 2010 that delivers penetration testing, digital forensics, incident response, GRC, and CISO-as-a-Service to Australian critical-infrastructure organizations in healthcare, finance, defence, energy, and water.
- Ownership category
- akta.pro rank
Mossé Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Investigation and Personal Background Check Services (561611)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
- akta.pro secondary industries
- Security Risk Assessment, Auditing & Security Consulting Training (BPAKAOAH), Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where Mossé Security is headquartered
LocationHeadquarters
- HQ city
- Melbourne
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
Mossé Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Professional Cybersecurity Services: Mossé Security generates revenue through professional services engagements including CISO as a Service, Security Assurance (penetration testing), Digital Investigations (forensics, incident response, OSINT), and Governance Risk and Compliance consulting. Services are tailored to client needs with bespoke engagement structures.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
Mossé Security product offering
Product offeringCore offering
Mossé Security is a professional cybersecurity services firm that delivers consulting, advisory, and hands-on technical security services to Australian organizations. Its core offerings include CISO as a Service (virtual security leadership), Security Assurance (penetration testing of web, network, wireless, and thick client environments), Digital Investigations (forensics, incident response, malware analysis, and OSINT), and Governance, Risk and Compliance (GRC) consulting.
Product overview
Mossé Security is a cybersecurity consulting firm offering a portfolio of professional services rather than a unified software product. The core service offerings include CISO as a Service (strategic security leadership), Security Assurance (penetration testing across web applications, networks, wireless, and thick clients), Digital Investigations (forensics, incident response, malware analysis, OSINT), and Governance Risk and Compliance (GRC) services. The company also extends its capabilities through two affiliated organizations: Deveillance (business and sales intelligence) and the Mossé Cyber Security Institute (cybersecurity training and education).
Differentiator
Problem solved
Functional benefit
Brands
- Deveillance: Business and sales intelligence platform
- Mossé Cyber Security Institute
Products and services
- CISO as a Service Strategic security leadership service providing dedicated expert guidance through a Virtual CISO who becomes part of the client's team, offering strategic advice and tailored solutions to navigate complex security challenges. Targeted at organizations that need senior security leadership without a full-time executive hire.
- Security Assurance Comprehensive penetration testing and security validation services covering web application, network, wireless network, and thick client penetration testing to assess, validate, and strengthen security measures. Designed for organizations that need to validate defenses against real-world attack techniques.
- Digital Investigations Forensics, incident response, malware analysis, and OSINT investigations services to uncover the root cause of incidents, gather vital intelligence, and preserve critical evidence. Used by organizations responding to active or past cyber incidents and breaches.
- Governance, Risk and Compliance (GRC) Framework creation services including risk assessments, business resilience planning, policies and procedures development, and regulatory compliance support aligned with Australian regulations such as the Privacy Act, SOCI Act, APRA CPS 234, and Notifiable Data Breaches scheme.
Quantifiable outcome
- Responded to 67 separate security breaches and conducted 53 threat hunting exercises between January 2016 and July 2017
- +1 more outcomes
Companies that use Mossé Security
Customer profileSegments6 records
Ideal customer profiles5 records
Mossé Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Mossé Security partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- DeveillancecoreDeveillance is a business and sales intelligence company founded by the team at Mossé Security. It operates as a sister organization used to augment professional cybersecurity services, providing comprehensive business and sales intelligence alongside cybersecurity expertise.
- Mossé Cyber Security Institute (MCSi)coreOne of the largest cybersecurity institutes in the world, founded by Mossé Security. Used to train and certify the company's consultants through hundreds of hours of supervised training annually, ensuring cutting-edge expertise delivery to clients. Also offers training services to external clients including incident simulation exercises.
Scale indicators5 records
Recent moves7 records
Expansion highlights5 records
Mossé Security competitors and assessment
Company assessmentBroad incumbents
- Secureworks: Taegis-powered cybersecurity services firm with incident response, red team, and advisory practices. Closely comparable services-led model targeting similar mid-market and enterprise segments.
- Mandiant (Google Cloud): Global incident response and threat intelligence firm (now within Google Cloud) delivering DFIR, red team, and strategic advisory to enterprises and governments. Overlaps Mossé's Digital Investigations and threat-intel capabilities but at much larger scale.
- Trustwave: Global cybersecurity services and MDR provider offering penetration testing, incident response, and consulting. Comparable services portfolio aimed at enterprise and government customers.
- CrowdStrike Services: Endpoint-platform leader whose services arm (incident response, proactive services, advisory) competes directly with Mossé's CISO-as-a-Service and Digital Investigations offerings, augmented by a global installed base.
- Palo Alto Networks Unit 42: Threat intelligence and incident response consulting arm of Palo Alto Networks. Provides DFIR, risk assessment, and red team services overlapping with Mossé's offensive-security and advisory practice.
Direct peers
- Sekuro: Australian cybersecurity consultancy offering advisory, offensive security, and managed detection services to enterprise and government. Comparable consultative service model targeting regulated verticals in Australia.
- NCC Group: UK-listed pure-play cybersecurity consulting firm delivering penetration testing, incident response, and threat intelligence globally. Closest international analogue in business model: services-led, framework-driven, vertically specialised.
- CyberCX: Australia's largest dedicated cybersecurity services firm, also headquartered in Melbourne-like operations and serving critical-infrastructure and government clients. Directly comparable vertical focus, service portfolio, and geography.
- Tesserent (Thales Australia Cyber Consultancy): Australia-based cybersecurity consulting and managed services firm (now part of Thales) serving federal government, defence, and critical-infrastructure customers. Closest direct Australian competitor in scale, vertical focus, and service mix.
- Loop Secure (formerly Hivint / Sense of Security): Australian cybersecurity consultancy focused on advisory, GRC, and offensive security for critical-infrastructure and enterprise clients. Direct mid-sized Australian competitor with overlapping vertical specialisations.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Mossé Security social profiles
Digital presenceMossé Security compliance and trust
Trust signalCompliance6 records
Mossé Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mossé Security leadership team
Management profileNumber of profiles
Profiles1 record
Mossé Security subsidiaries and ownership
Company hierarchySubsidiaries2 records
Mossé Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mossé Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mossé Security
What does Mossé Security do?
Mossé Security is a professional cybersecurity services firm that delivers consulting, advisory, and hands-on technical security services to Australian organizations. Its core offerings include CISO as a Service (virtual security leadership), Security Assurance (penetration testing of web, network, wireless, and thick client environments), Digital Investigations (forensics, incident response, malware analysis, and OSINT), and Governance, Risk and Compliance (GRC) consulting.
Is Mossé Security a public or private company?
Mossé Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Mossé Security founded?
Mossé Security was founded in 2010. It employs 11 to 50 people.
Where is Mossé Security based?
Mossé Security is headquartered in Melbourne, Australia, in the Oceania region.
How does Mossé Security make money?
One revenue line is on record: professional Cybersecurity Services.
Who are Mossé Security's main competitors?
Broad incumbents on record are Secureworks, Mandiant (Google Cloud), Trustwave, CrowdStrike Services and Palo Alto Networks Unit 42. Direct peers are Sekuro, NCC Group, CyberCX, Tesserent (Thales Australia Cyber Consultancy) and Loop Secure (formerly Hivint / Sense of Security).
Does Mossé Security have an API?
No public API is recorded for Mossé Security.
What industry is Mossé Security in?
Mossé Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPABAMAE, Security Consulting, Risk Assessment & Security Program Design, with a secondary code of BPAKAOAH, Security Risk Assessment, Auditing & Security Consulting Training. Its NAICS code is 561611 and its SIC code is 8700.