OSI Security Devices
OSI Security is a Sydney-based boutique penetration testing and security consulting firm, serving Australian and New Zealand government agencies, ASX-listed corporates, and mid-market enterprises with managed and ad-hoc offensive security services since 2010.
- Company typePrivate
- Founded1986
- HeadquartersChula Vista, United States
- Headcount—
- GTM typeB2B
- OfferingServices
What OSI Security Devices does
OSI Security is a Sydney-based, privately held penetration testing and security consulting boutique founded in June 2010 by information security researcher Patrick Webster. The firm delivers managed monthly and quarterly penetration testing engagements, ad-hoc day-rate testing, bug-bounty-format testing, and specialized services including web application security testing, source code review, email security review, wireless auditing, firewall configuration review, forensics, and system hardening. Service delivery relies on industry-standard offensive-security tooling (Metasploit Pro, Tenable Nessus, Acunetix, Nexpose, PortSwigger BurpSuite, HP Fortify, Secunia, Elcomsoft) and is supported by a small distributed team of four people operating without a designated workplace.
The firm's customer base spans Australian and New Zealand government agencies (it is an approved supplier on the NSW Government ICT Services panel SCM0020 and on equivalent Victorian, Queensland, and New Zealand government panels), ASX-listed corporates, financial services, critical infrastructure, healthcare, and retail/ecommerce organizations. OSI Security has performed over 1,000 penetration tests cumulatively and references protecting more than $4 million in client assets. The business also operates WICAR.org, a free public service modeled on the EICAR anti-virus test file that allows organizations to safely evaluate anti-malware, firewall, IDS/IPS, and SSL inspection products.
OSI Security monetizes through subscription managed services (A$2,000 per month or A$3,000 per quarter for the first IP, plus A$100 per additional IP), ad-hoc engagements at A$2,200 per day, bug-bounty outcomes-based pricing, and standalone specialized projects. Sales are driven primarily through website quote requests, content marketing via its security blog and published vulnerability advisories, and direct outreach under government panel frameworks. The firm has been bootstrapped from inception under the Australian Federal Government's New Enterprise Incentive Scheme and shows no evidence of external institutional investment, M&A activity, or parent-company ownership.
OSI Security Devices firmographics
Firmographics- Name
- OSI Security Devices
- Legal name
- OSI Security
- Website
- https://www.osisecurity.com/
- Company type
- Private
- Founded year
- 1986
- Operating status
- Operating
- Short description
- OSI Security is a Sydney-based boutique penetration testing and security consulting firm, serving Australian and New Zealand government agencies, ASX-listed corporates, and mid-market enterprises with managed and ad-hoc offensive security services since 2010.
- Ownership category
- akta.pro rank
OSI Security Devices industry classification
Industry- Product category
- Penetration Testing & Cybersecurity Consulting
- NAICS
- Testing Laboratories and Services (541380)
- SIC
- Services-Testing Laboratories (8734), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where OSI Security Devices is headquartered
LocationHeadquarters
- HQ city
- Chula Vista
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
OSI Security Devices business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Managed Penetration Testing Services: Recurring revenue through monthly ($2000 for first IP, $100 each additional) and quarterly ($3000 for first IP, $100 each additional) managed penetration testing services. Includes external, internal, web application, and wireless security testing.
- Ad-hoc Penetration Testing: One-time engagement penetration testing priced at $2200 per day, as well as bug bounty format testing where clients pay only for vulnerabilities found.
- Specialized Security Services: Additional services including email security reviews, remote support, managed security services, source code review, firewall configuration auditing, WiFi access point auditing, forensics, data recovery, and system hardening.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Monthly Managed Service - $2000 for first IP address, $100 per additional IP |
| Subscription | Quarterly | Quarterly Managed Service - $3000 for first IP address, $100 per additional IP |
| One time/ perpetual license | Pay-as-you-go | Annual or Ad-hoc - $2200 per day |
| Outcome based/ performace | Pay-as-you-go | Bug Bounty Format - Free to start, pay only for findings |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
OSI Security Devices product offering
Product offeringCore offering
OSI Security Devices (operating as OSI Security per the supplied website content) delivers boutique penetration testing and web application security consulting to Australian and New Zealand organizations. Core services are managed monthly and quarterly penetration testing engagements with elastic per-IP pricing, complemented by ad-hoc penetration testing, bug bounty-style testing, web application security testing, source code review, email security review, wireless auditing, forensics, and system hardening. The firm also operates WICAR.org, a free public service for safely testing anti-malware defenses.
Product overview
OSI Security provides penetration testing and security consulting services, not a unified software product. The core offerings are managed penetration testing services (delivered monthly or quarterly with elastic pricing based on IP addresses), complemented by specialized testing services including external/internal penetration testing, web application security testing, source code review, email security review, bug bounty programs, wireless auditing, forensics, and system hardening. The company also developed WICAR.org as a free public service for anti-malware testing. Services utilize industry-standard security tools including Metasploit Pro, Tenable Nessus, Acunetix, PortSwigger BurpSuite, and HP Fortify. The company operates as a remote-first organization without a designated workplace.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Monthly Penetration Testing Service Recurring monthly penetration testing engagement covering external, internal, web application, and wireless security testing with elastic pricing that scales with the number of IP addresses.
- Managed Quarterly Penetration Testing Service Recurring quarterly penetration testing engagement providing comprehensive security assessment on a periodic basis with detailed reporting and remediation recommendations.
- External Penetration Testing Testing of externally facing systems and infrastructure to identify vulnerabilities that could be exploited from the internet.
- Web Application Security Testing Security assessment of web applications to identify vulnerabilities such as XSS, SQL injection, and other OWASP Top 10 issues.
- Source Code Review Security review of application source code to identify vulnerabilities before deployment.
- Email Security Review Assessment of email security configurations, including testing for email interception and direct object reference vulnerabilities.
- Bug Bounty Penetration Test Bug bounty style penetration testing where clients pay only for valid vulnerabilities discovered; free to start.
- WiFi Access Point and Client Auditing Wireless network security assessment including testing of access points and connected clients for vulnerabilities.
- Forensics and Data Recovery Incident response forensics and data recovery services following security incidents.
- System Hardening and Configuration Security hardening services for systems and configurations to reduce attack surface.
- Firewall Configuration and Rulesets Assessment and review of firewall configurations and rule sets for security effectiveness.
- Remote Support Remote security support services for clients needing assistance with security issues.
- WICAR.org Anti-Malware Testing Service Free public web service for testing anti-malware defenses, including firewalls, IDS/IPS, content filters, SSL inspection products, and desktop anti-virus solutions, modeled on the EICAR anti-virus test file standard.
Quantifiable outcome
- Performed over 1,000 penetration tests spanning nearly 2 decades
- +2 more outcomes
Companies that use OSI Security Devices
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles3 records
OSI Security Devices technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
OSI Security Devices partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered minor.
- Australian Computer Museum Society IncorporatedminorOSI Security is proud to support this charity, development project and industry group. This is a community support initiative rather than a commercial partnership.
- Hackers Helping HackersminorOSI Security supports this community initiative that helps hackers and security researchers.
- 2600-AU AustraliaminorOSI Security supports the Australian chapter of 2600, an international hacker community organization.
Scale indicators5 records
Recent moves5 records
Expansion highlights5 records
OSI Security Devices competitors and assessment
Company assessmentMarket position
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
OSI Security Devices social profiles
Digital presenceOSI Security Devices compliance and trust
Trust signalCompliance6 records
OSI Security Devices financial estimates
Financial estimateRevenue estimate
Valuation estimate
OSI Security Devices leadership team
Management profileNumber of profiles
Profiles4 records
OSI Security Devices funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OSI Security Devices M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OSI Security Devices
What does OSI Security Devices do?
OSI Security Devices (operating as OSI Security per the supplied website content) delivers boutique penetration testing and web application security consulting to Australian and New Zealand organizations. Core services are managed monthly and quarterly penetration testing engagements with elastic per-IP pricing, complemented by ad-hoc penetration testing, bug bounty-style testing, web application security testing, source code review, email security review, wireless auditing, forensics, and system hardening. The firm also operates WICAR.org, a free public service for safely testing anti-malware defenses.
Is OSI Security Devices a public or private company?
OSI Security Devices is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was OSI Security Devices founded?
OSI Security Devices was founded in 1986.
Where is OSI Security Devices based?
OSI Security Devices is headquartered in Chula Vista, United States, in the North America region.
How does OSI Security Devices make money?
Three revenue lines are on record. Managed Penetration Testing Services are the primary driver. The others are ad-hoc Penetration Testing and specialized Security Services.
Does OSI Security Devices have an API?
No public API is recorded for OSI Security Devices.
What industry is OSI Security Devices in?
OSI Security Devices's product category is Penetration Testing & Cybersecurity Consulting. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 541380 and its SIC code is 8734.