LMG Security
LMG Security is a founder-led cybersecurity consulting firm offering penetration testing, advisory and compliance (including Virtual CISO), and training services to enterprise, mid-market, SMB, government, and education clients across multiple verticals, supported by an extensive thought-leadership content library and channel referrals.
- Company typePrivate
- Founded2009
- HeadquartersMissoula, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What LMG Security does
LMG Security is a privately held, founder-led cybersecurity professional services firm headquartered in Missoula, Montana, founded in 2009 by Sherri Davidoff. The company delivers three core service lines: (1) Penetration Testing — including network, web application, mobile application, social engineering, red team, and attack detection and response assessments; (2) Advisory and Compliance — spanning Virtual CISO engagements, risk assessments, cloud security reviews for Microsoft 365 and AWS, and incident response plan development against frameworks such as HIPAA, CCPA, GDPR, and the NIST Cybersecurity Framework; and (3) Training and Education — covering ransomware response, cyber first responder, penetration testing for IT pros, executive seminars, tabletop exercises, and a managed KnowBe4 employee awareness offering.
The firm operates as a boutique consultancy rather than a product company, with no proprietary software platform, API, or SDK. Service delivery is performed by GIAC-certified staff (GCFA, GPEN, CISSP, HCISPP) using industry-standard testing methodologies aligned with NIST and CIS Benchmarks. Recent additions such as Continuous Attack Surface Monitoring and Managed KnowBe4 Training represent the firm's first steps into productized, recurring managed services alongside its traditional project-based model.
LMG sells primarily through direct enterprise field sales supported by a quote-based engagement model, supplemented by inbound demand generated through an extensive thought-leadership content library (381 blog posts, 386 videos, 33 tip sheets, and quarterly Top Security Controls Reports), a weekly Cyberside Chats podcast, and speaking/training presence at Black Hat, DEF CON, and regional events. Referral channels through insurance providers, law firms, and network security vendors serve as a secondary distribution layer. Customer evidence spans enterprise, mid-market, SMB, government, and education clients across technology, insurance, biotech, and public-sector verticals. The company has not disclosed external funding, M&A activity, or revenue, and remains under 50 employees.
LMG Security firmographics
Firmographics- Name
- LMG Security
- Legal name
- LMG Security
- Website
- https://lmgsecurity.com
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- LMG Security is a founder-led cybersecurity consulting firm offering penetration testing, advisory and compliance (including Virtual CISO), and training services to enterprise, mid-market, SMB, government, and education clients across multiple verticals, supported by an extensive thought-leadership content library and channel referrals.
- Ownership category
- akta.pro rank
LMG Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (54151), Investigation and Security Services (5616)
- SIC
- Services-Management Services (8741), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where LMG Security is headquartered
LocationHeadquarters
- HQ city
- Missoula
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
LMG Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Operations, Technology or R&D, Others
Revenue model
- Cybersecurity Testing Services: Professional services revenue from penetration testing, vulnerability scanning, web application testing, mobile application tests, social engineering tests, red team testing, and attack detection & response services. These are typically project-based or recurring annual engagements.
- Advisory & Compliance Services: Revenue from Virtual CISO services, risk assessments, compliance guidance (HIPAA, CCPA, NIST CSF), cloud security assessments, and staff augmentation. Delivered as ongoing consulting engagements or one-time assessments.
- Training & Education: Revenue from cybersecurity training classes including ransomware response, cyber first responder, penetration testing for IT pros, executive cybersecurity seminars, and tabletop exercises. Offered as on-demand online classes or in-person sessions at client locations and conferences.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Other | Quote-based custom engagements |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels8 records
LMG Security product offering
Product offeringCore offering
LMG Security is a cybersecurity professional services firm that delivers penetration testing, advisory and compliance consulting, and cybersecurity training to enterprise, mid-market, government, and education clients. Its offerings include penetration tests, vulnerability scans, red team testing, social engineering tests, virtual CISO services, risk assessments, cloud security assessments, and managed employee awareness training. Services are sold through quote-based engagements tailored to client scope and complexity, delivered by GIAC-certified practitioners.
Product overview
LMG Security is a cybersecurity services firm offering a portfolio of technical testing, advisory & compliance, and training services. The core technical testing suite includes Penetration Tests, Vulnerability Scans, Social Engineering Tests, Web Application Pen Tests, Mobile Application Tests, Attack Detection and Response, Red Team Testing, and Continuous Attack Surface Monitoring. On the advisory side, services include Virtual CISO (vCISO), Risk Assessment, Cloud Security Assessment, and Incident Response Plan Development. Training offerings span Managed KnowBe4 Employee Cybersecurity Training, Ransomware Response Course, Cyber First Responder Course, Penetration Testing for IT Pros, Executive Cyber-Security Seminars, and Tabletop Exercises. Complementary knowledge resources include the Cyberside Chats podcast and the quarterly/annual Top Security Controls Reports. The company positions itself as a proactive cybersecurity partner with the tagline 'Achieve Nothing'—aiming for zero breaches and no security incidents for clients.
Differentiator
Problem solved
Functional benefit
Brands
- AchieveNothing™: A trademarked tagline/philosophy representing the company's goal of achieving zero data breaches for clients.
Products and services
- Penetration Tests Expert penetration testing services that identify vulnerabilities in networks, systems, web applications, and mobile devices before hackers can exploit them. Covers annual testing, red team engagements, and targeted security assessments for organizations seeking an accurate understanding of their security posture and actionable recommendations.
- Vulnerability Scans Automated and expert-driven vulnerability scanning services that identify weaknesses across an organization's technology environment, supporting continuous security posture improvement.
- Web Application Pen Tests Comprehensive web application penetration testing to identify security gaps such as credential abuse and exploit attacks before malicious actors can exploit them, addressing web applications as a top target for credential abuse per the 2025 Verizon DBIR.
- Mobile Application Tests Security testing for mobile applications that store sensitive access credentials for bank accounts, email, and cloud apps, ensuring mobile app security before deployment.
- Social Engineering Tests Controlled phishing and phone scam simulations designed to safely train staff to recognize and resist social engineering attacks, reducing human-based security risks within an organization.
- Red Team Testing Advanced adversarial testing where LMG Security's experts simulate real-world attacks to penetrate networks and gain access to sensitive data or impact operations, testing both technical and human defenses.
- Attack Detection and Response Evaluates the effectiveness of an organization's cyber attack detection and response program through controlled simulations and assessments, helping organizations prepare for actual incidents.
- Continuous Attack Surface Monitoring Managed service that continuously scans external attack surfaces to identify exposed or vulnerable assets before attackers can exploit them, including deployment, configuration, routine tune-ups, vulnerability management, and remediation support.
- Virtual CISO Services Fractional CISO (vCISO) services providing experienced cybersecurity leadership for organizations that cannot afford or find full-time qualified security leaders, offering guidance on security programs and compliance.
- Risk Assessment Assessment and prioritization of organizational cybersecurity risks to achieve maximum risk reduction within budget constraints, identifying gaps and recommending improvements.
- Advisory & Compliance Services Comprehensive advisory services spanning vCISO support, compliance guidance, risk assessments, and cloud security reviews to supplement internal resources and reduce breach risk.
- Cloud Security Assessment Assessment of cloud application security configurations across platforms such as Microsoft 365 and AWS, identifying misconfigurations and security gaps to prevent data breaches from cloud configuration errors.
- Incident Response Plan Development Development of customized incident response policies and procedures to help organizations establish formal incident response teams and prepare for effective response to cybersecurity incidents.
- Managed KnowBe4 Employee Cybersecurity Training Managed cybersecurity awareness training program using the KnowBe4 platform to provide on-demand training to employees, featuring short videos and quizzes to keep security top-of-mind.
- Ransomware Response Course Intensive one-day class teaching participants to identify, contain, and respond to ransomware attacks quickly and effectively to minimize damage and organizational downtime.
- Cyber First Responder Course Intensive on-demand one-day training class on incident response and digital forensics, authored by a recognized expert in the field.
- Penetration Testing for IT Pros Hands-on one-day training class that teaches IT professionals to explore and defend IT infrastructure using the same techniques as hackers, helping them identify and address weaknesses proactively.
- Executive Cyber-Security Seminars Security awareness seminars for executives designed to ensure leadership understands how to make smart security choices and support organizational cybersecurity from the top down.
- Tabletop Exercises Simulated incident response exercises led by LMG Security consultants to help organizations evaluate their preparedness, identify gaps in incident handling processes, and practice response procedures. Available on-site or remotely via video conference.
Quantifiable outcome
- Organizations with robust incident response planning and testing save average of $1.49M in data breach costs (IBM 2023)
- +3 more outcomes
Companies that use LMG Security
Customer profileNamed customers8 records
Segments5 records
Ideal customer profiles6 records
LMG Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
LMG Security partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Insurance ProviderscoreLMG teams up with insurance providers who refer clients seeking cybersecurity services. Insurance providers often require cybersecurity assessments as part of coverage requirements.
- Law FirmscoreLMG partners with law firms who refer clients needing cybersecurity assessments, incident response, or compliance guidance. Law firms often work with clients on data breach response.
- Credit Union PartnerscoreStrategic partnership specifically focused on bringing better cybersecurity compliance to credit unions. This partnership addresses the unique regulatory requirements of the credit union industry.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
LMG Security competitors and assessment
Company assessmentDirect peers
- NetSPI: Penetration testing and attack surface management firm offering a platform-enabled approach to vulnerability testing — competes head-to-head with LMG on enterprise penetration testing engagements while combining human expertise with proprietary tooling.
- Coalfire: Cybersecurity advisory, compliance, and technical testing firm offering penetration testing, vCISO, and risk assessment services — directly overlaps LMG's advisory & compliance and testing portfolios with a heavier compliance/audit lean.
- Bishop Fox: Boutique offensive-security firm specializing in penetration testing, red team engagements, and attack surface management — directly competes with LMG in enterprise pen testing with a similar consultancy model and similar brand emphasis on elite technical talent.
- TrustedSec: Offensive cybersecurity consultancy specializing in penetration testing, red teaming, and incident response — a close comparable to LMG in service mix, technical positioning, and target enterprise/mid-market customer segments.
- Tevora: Cybersecurity consulting firm providing penetration testing, advisory, and managed security services — competes with LMG across the same enterprise and mid-market segments with comparable service breadth.
- Schellman: Cybersecurity assessment and compliance firm providing penetration testing alongside SOC 2, ISO, and HITRUST audits — overlaps LMG in penetration testing and compliance advisory with a stronger audit-certification orientation.
Broad incumbents
- Mandiant (Google Cloud): Large-scale incident response, threat intelligence, and cybersecurity consulting firm — overlaps LMG on attack detection/response, IR plan development, and red team engagements at the upper end of the enterprise market.
- NCC Group: Global cybersecurity consultancy with a sizable penetration testing and red team practice — competes with LMG on enterprise testing deals, particularly in regulated industries, with broader geographic and delivery footprint.
- Palo Alto Networks Unit 42: Cybersecurity consulting arm of Palo Alto Networks offering incident response, penetration testing, and threat intelligence — competes with LMG by bundling services with the vendor's broader security platform relationships.
- Optiv: Large cybersecurity solutions integrator and MSSP offering advisory, risk assessment, and managed security services — competes with LMG in enterprise advisory and compliance engagements, particularly where customers want vendor consolidation.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
LMG Security social profiles
Digital presenceLMG Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
LMG Security leadership team
Management profileNumber of profiles
Profiles6 records
LMG Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
LMG Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about LMG Security
What does LMG Security do?
LMG Security is a cybersecurity professional services firm that delivers penetration testing, advisory and compliance consulting, and cybersecurity training to enterprise, mid-market, government, and education clients. Its offerings include penetration tests, vulnerability scans, red team testing, social engineering tests, virtual CISO services, risk assessments, cloud security assessments, and managed employee awareness training. Services are sold through quote-based engagements tailored to client scope and complexity, delivered by GIAC-certified practitioners.
Is LMG Security a public or private company?
LMG Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was LMG Security founded?
LMG Security was founded in 2009. It employs 11 to 50 people.
Where is LMG Security based?
LMG Security is headquartered in Missoula, United States, in the North America region.
How does LMG Security make money?
Three revenue lines are on record. Cybersecurity Testing Services are the primary driver. The others are advisory & Compliance Services and training & Education.
Who are LMG Security's main competitors?
Direct peers on record are NetSPI, Coalfire, Bishop Fox, TrustedSec, Tevora and Schellman. Broad incumbents are Mandiant (Google Cloud), NCC Group, Palo Alto Networks Unit 42 and Optiv.
Does LMG Security have an API?
No public API is recorded for LMG Security.
What industry is LMG Security in?
LMG Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 54151 and its SIC code is 8741.