Agile Information Security
Agile Information Security is a London-headquartered boutique cybersecurity consultancy, founded in 2013, that delivers manual penetration testing, code review, reverse engineering, secure architecture, product security, and incident response services to enterprise, government, defense, and startup clients across three continents.
- Company typePrivate
- Founded2013
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Agile Information Security does
Agile Information Security is a London-headquartered cybersecurity consultancy founded in 2013 that delivers offensive security services to enterprise, government, defense, and startup clients across three continents. The firm operates through six core service lines: Security Code Review (white-box source analysis combining automated tools with manual checks), Penetration Testing (black box, white box, infrastructure, red team, and fuzzing engagements), Reverse Engineering (across x86, x64, ARM, MIPS, SH-4, and multiple languages), Secure Architecture & Threat Modelling, Product Security, and Incident Response & Network Monitoring. Its competitive positioning rests on a small team of senior consultants who hold CISSP and OSCP certifications, are qualified to perform ISO 27001 audits, have collectively disclosed over 200 vulnerabilities in commercial software (Cisco, Adobe, IBM, Apple, VLC, etc.), and have won prizes at Pwn2Own competitions.
The business model is professional services on a quote-based, project-by-project pricing structure with multi-year contracts. The company employs five people across offices in London (headquarters), Portugal, and Thailand, and distributes exclusively through direct enterprise sales with no channel partners. Marketing is driven by public vulnerability research, responsible disclosure, and competition participation rather than traditional channels. The firm serves a horizontally diversified client base spanning international banks, large multinational corporations, government entities, law enforcement, military, and startups, with geographic restrictions on reverse engineering services limited to NATO-country clients due to legal constraints. There is no disclosed external funding, no parent company, and no evidence of inorganic growth activity, indicating a founder-operated, organically funded boutique consultancy.
Agile Information Security firmographics
Firmographics- Name
- Agile Information Security
- Legal name
- Agile Information Security
- Website
- https://agileinfosec.co.uk
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Agile Information Security is a London-headquartered boutique cybersecurity consultancy, founded in 2013, that delivers manual penetration testing, code review, reverse engineering, secure architecture, product security, and incident response services to enterprise, government, defense, and startup clients across three continents.
- Ownership category
- akta.pro rank
Agile Information Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (54151), Other Scientific and Technical Consulting Services (54169), Computer Systems Design Services (541512)
- SIC
- Services-Computer Programming Services (7371), Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- Enterprise Security Strategy & Program Advisory (BPAKADAA), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
Keywords
Where Agile Information Security is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices3 records
Markets served
Agile Information Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Security Consulting Services: Project-based consulting engagements including penetration testing, security code review, reverse engineering, secure architecture design, product security, and incident response services. Services are priced quote-based and customized to client requirements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements - pricing varies by service type and scope |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels2 records
Agile Information Security product offering
Product offeringCore offering
Agile Information Security is a boutique cybersecurity consultancy that delivers offensive security services including penetration testing, security code review, reverse engineering, secure architecture design, product security assessments, and incident response. Services are delivered as project-based consulting engagements by a small team of consultants recognized for vulnerability research and competition wins (e.g., Pwn2Own), targeting enterprises, banks, government and defense organizations, and startups.
Product overview
Agile Information Security is a cybersecurity consultancy offering a portfolio of professional services rather than a unified software product. The core service offerings include Security Code Review (white-box code analysis), Penetration Testing (covering black box, white box, infrastructure, red teaming, and fuzzing), Reverse Engineering, Secure Architecture & Threat Modelling, Product Security, and Incident Response & Network Monitoring. These services are delivered by expert consultants who conduct vulnerability research, participate in hacking competitions like Pwn2Own, and provide technical security training courses. The company operates as a services firm rather than a product platform, with no modules or add-ons available for self-service use.
Differentiator
Problem solved
Functional benefit
Products and services
- Security Code Review A comprehensive white-box review of source code to identify security vulnerabilities, using both automated tools and manual analysis techniques. Handles any programming language from low-level C to top-of-stack Ruby, with code kept encrypted and deleted after engagement. Targeted at organizations needing deeper vulnerability coverage than penetration testing alone, including startups, multinationals, and government entities.
- Penetration Testing Hands-on manual penetration testing of web applications, infrastructure, networks, hardware, embedded devices, and thick clients, simulating real attacker techniques. Variants include Black Box, White Box, Infrastructure, Red Teaming, and Fuzzing. Delivered with a detailed report of findings and remediation guidance for organizations needing simulated hacker-style attacks on their systems.
- Reverse Engineering Reverse engineering of software and hardware for interoperation, algorithm identification, and vulnerability research. Covers multiple architectures including x86, x64, ARM, MIPS, SH-4 and languages including C, C++, C#, Java, Python, Ruby, Go, and Rust. Available only to clients based in NATO countries due to legal restrictions.
- Secure Architecture & Threat Modelling Consulting service to help clients design and develop products with security built in from the start, including analysis of data flows, components, authentication, authorization, data storage, and encryption, plus threat modelling for products already in production. Recommended for organizations developing commercial, government, law enforcement, or military products.
- Product Security A holistic service combining penetration testing, fuzzing, vulnerability research, reverse engineering, hardware security, and secure architecture expertise to uncover vulnerabilities and bad practices in client products. Covers mobile phones, embedded servers, applications, and cloud infrastructure for large and small organizations.
- Incident Response & Network Monitoring Incident response services for organizations that have experienced a security breach, including securing networks, kicking out attackers, determining breach causes, establishing damage, monitoring for re-entry, and preventing future intrusions. Also includes developing network monitoring, logging, and SIEM capabilities with knowledge transfer and training.
Quantifiable outcome
- Finds at least 50% more vulnerabilities than penetration testing alone when combining security code review with penetration testing
- +1 more outcomes
Companies that use Agile Information Security
Customer profileNamed customers5 records
Segments3 records
Ideal customer profiles3 records
Agile Information Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Agile Information Security partnerships and signals
Strategic signalScale indicators5 records
Recent moves4 records
Expansion highlights4 records
Agile Information Security competitors and assessment
Company assessmentBroad incumbents
- Trustwave (Singtel): Global cybersecurity firm offering penetration testing, managed security services, and consulting. Larger incumbent overlapping with Agile's service portfolio but operating at much greater scale.
- WithSecure (formerly F-Secure / MWR): European cybersecurity firm offering offensive security, incident response, and managed security following the MWR Cyber acquisition. Direct overlap in penetration testing and product security services.
- NCC Group: UK-headquartered cybersecurity consulting firm offering penetration testing, code review, and managed security services to enterprise clients across multiple regions. Directly comparable services portfolio but operates at significantly greater scale than Agile.
- Synopsys Software Integrity Group: Enterprise application security testing and consulting provider with code review, static/dynamic analysis, and threat modeling services. Incumbent in the secure code review and AppSec space.
Emerging players
- PortSwigger (Burp Suite): Developer of Burp Suite, the leading web application penetration testing platform. Adjacent to Agile's pentesting service lines; could enable productization and tooling-driven efficiency gains.
- HackerOne: Bug bounty and vulnerability disclosure platform that crowdsources offensive security testing. Represents an alternative model to Agile's manual consultancy, competing for security testing budgets.
Direct peers
- Bishop Fox: US-based offensive security consultancy specializing in penetration testing, red teaming, and product security assessments. Closely aligned with Agile's core offerings and recognized research reputation.
- Secarma: UK cybersecurity services firm offering penetration testing, application security, and incident response. Comparable boutique UK player with similar service mix and enterprise/government client focus.
- NetSPI: Enterprise penetration testing and vulnerability management firm with hybrid manual/automated approach. Comparable boutique-style offensive security services model targeting enterprise clients.
- Pen Test Partners: UK-based boutique cybersecurity consultancy specializing in penetration testing, red teaming, and security code review. Closely comparable niche player serving enterprises with similar manual offensive security methodologies.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Agile Information Security social profiles
Digital presenceAgile Information Security compliance and trust
Trust signalCompliance3 records
Agile Information Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Agile Information Security leadership team
Management profileNumber of profiles
Agile Information Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Agile Information Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Agile Information Security
What does Agile Information Security do?
Agile Information Security is a boutique cybersecurity consultancy that delivers offensive security services including penetration testing, security code review, reverse engineering, secure architecture design, product security assessments, and incident response. Services are delivered as project-based consulting engagements by a small team of consultants recognized for vulnerability research and competition wins (e.g., Pwn2Own), targeting enterprises, banks, government and defense organizations, and startups.
Is Agile Information Security a public or private company?
Agile Information Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Agile Information Security founded?
Agile Information Security was founded in 2013. It employs 1 to 10 people.
Where is Agile Information Security based?
Agile Information Security is headquartered in London, United Kingdom, in the Europe region.
How does Agile Information Security make money?
One revenue line is on record: professional Security Consulting Services.
Who are Agile Information Security's main competitors?
Broad incumbents on record are Trustwave (Singtel), WithSecure (formerly F-Secure / MWR), NCC Group and Synopsys Software Integrity Group. Emerging players are PortSwigger (Burp Suite) and HackerOne. Direct peers are Bishop Fox, Secarma, NetSPI and Pen Test Partners.
Does Agile Information Security have an API?
No public API is recorded for Agile Information Security.
What industry is Agile Information Security in?
Agile Information Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKADAA, Enterprise Security Strategy & Program Advisory. Its NAICS code is 54151 and its SIC code is 7371.