EC-Council Global Services
EC-Council Global Services is the cybersecurity consulting and managed services arm of EC-Council, delivering penetration testing, SOC, compliance advisory, and training to enterprise and government clients across BFSI, insurance, and regulated industries from its Kuala Lumpur base.
- Company typePrivate
- Founded-
- HeadquartersKuala Lumpur, Malaysia
- Headcount51–100
- GTM typeB2B
- OfferingServices
What EC-Council Global Services does
EC-Council Global Services (EGS) is the cybersecurity consulting and managed services division of EC-Council (International Council of E-Commerce Consultants), the world's largest cybersecurity technical certification body. Headquartered in Kuala Lumpur, Malaysia, EGS delivers professional cybersecurity services to enterprise and government clients, organized around the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) and a proprietary four-phased InfoSec methodology (assess, block, correct, defend). Its core offerings span Vulnerability Assessment and Penetration Testing (including remote, intelligence-led, and compromise assessment variants), Security Strategy and Transformation, Managed Security Services, a 24x7 Security Operations Centre, Incident Response and Digital Forensics, Cloud and Data Centre security, and advisory on ISO 27001, PCI DSS, RMiT, GDPR, HIPAA, and NIST frameworks. EGS also runs the proprietary OhPhish phishing simulation platform and delivers enterprise security training and certification programs.
The firm serves financial services, insurance, government, technology, industrial, aviation/telecom, and healthcare clients across more than a dozen countries, with claimed reach across 140 countries through its parent's network and over 380,000 certified professionals worldwide. It holds ISO 27001 SOC certification, CREST certification for pentesting and incident response, and approved vendor status with Malaysia's NACSA and CyberSecurity Malaysia as well as Singapore's CSA. Distribution combines direct enterprise sales with an Affiliate/Channel Partner Program, supported by digital marketing, whitepapers, and the EC-Council Cybersecurity Exchange blog.
Revenue is generated primarily through custom-quoted project engagements and multi-year managed services contracts. No revenue, headcount growth, or ownership figures are publicly disclosed; the firm operates as an unlisted division of a privately held parent, with no venture funding rounds on record.
EC-Council Global Services firmographics
Firmographics- Name
- EC-Council Global Services
- Legal name
- EC-Council Global Services
- Website
- https://egs.eccouncil.org
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- EC-Council Global Services is the cybersecurity consulting and managed services arm of EC-Council, delivering penetration testing, SOC, compliance advisory, and training to enterprise and government clients across BFSI, insurance, and regulated industries from its Kuala Lumpur base.
- Ownership category
- akta.pro rank
EC-Council Global Services industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
Keywords
Where EC-Council Global Services is headquartered
LocationHeadquarters
- HQ city
- Kuala Lumpur
- HQ country
- Malaysia
- HQ region
- Asia
Offices2 records
Markets served
EC-Council Global Services business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Cybersecurity Consulting and Advisory Services: Professional services revenue from providing cybersecurity consulting engagements including vulnerability assessment, penetration testing, security strategy, risk management advisory, compliance advisory (ISO 27001, PCI DSS, GDPR), and other technical cybersecurity assessments. Typically project-based or retainer engagements.
- Managed Security Services: Recurring managed security services including 24x7 Security Operations Center (SOC) monitoring, managed SIEM, and ongoing vulnerability management. Revenue from continuous monitoring contracts.
- Cybersecurity Training and Certification: Enterprise security professional certification and training services, security awareness training, and phishing simulation services. Includes classroom training, examinations, and certification programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagements |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels4 records
EC-Council Global Services product offering
Product offeringCore offering
EC-Council Global Services (EGS) provides enterprise cybersecurity consulting, advisory, and managed security services covering vulnerability assessment, penetration testing, security strategy, cloud security, compliance advisory (ISO 27001, PCI DSS, GDPR, RMiT), 24x7 Security Operations Centre monitoring, digital forensics, incident response, and enterprise security training. Services are organized around the NIST Cybersecurity Framework functions of Identify, Protect, Detect, Respond, and Recover, and delivered by certified consultants (CEH, CISSP, CISM, CISA, PCI-QSA) using EC-Council's proprietary Licensed Penetration Testing methodology.
Product overview
EC-Council Global Services (EGS) is a division of EC-Council offering cybersecurity consulting and advisory services organized around a portfolio of over 20 specialized service offerings. The services follow NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) and include assessment services (VAPT, Cybersecurity Posture Assessment, IT Risk Assessment), strategic advisory (Security Strategy, ISO 27001, IT Governance), managed services (SOC, Managed Security Services), technical testing (Remote Penetration Testing, Intelligence-Led Pentesting, Compromise Assessment, Secure Code Review), incident response (Digital Forensics, Incident Response), and training (Enterprise Security Professional Certification, Security Awareness Training, Cybersecurity Skill Development). EGS also operates the proprietary OhPhish platform for phishing simulations. The company operates across 140 countries with 150+ clients and 100+ consultants, delivering services through a four-phased InfoSec methodology aligned with NIST standards.
Differentiator
Problem solved
Functional benefit
Products and services
- Vulnerability Assessment and Penetration Testing (VAPT) Security assessment service covering network infrastructure, web applications, and mobile applications to identify and gauge security vulnerabilities through external and internal threat analysis, targeted at enterprise IT environments.
- Security Strategy and Transformation Advisory service establishing security strategies aligned with client business strategies to ensure information systems are protected from intrusion and cyber threats, for organizations transforming their cybersecurity posture.
- Business Continuity Management / Disaster Recovery Plan Frameworks governing business management requirements and regulatory processes enabling organizations to respond quickly during emergencies and ensure critical business functions continue without disruption.
- Cloud Security Services Holistic cloud security services including cloud migration assessment, security compliance evaluation (PCI-DSS, SOX, HIPAA), data privacy standards, and security posture assessment for organizations using or migrating to cloud environments.
- Information Security Risk Management Advisory Advisory service helping organizations identify, assess, and mitigate information security risks through mature risk-based approaches and robust risk management processes.
- Data Centre Risk Assessment Comprehensive assessment of data center facilities including critical infrastructures, mechanical and electrical systems, and operations to identify risks and determine resilience levels.
- Risk Management in Technology (RMiT) Specialized compliance framework for Malaysian financial institutions aligned with Bank Negara Malaysia's RMiT regulation (BNM/RH/ED 028-11) covering vulnerability management, privileged remote access, and identity access management.
- Cybersecurity Posture and Maturity Assessment Assessment evaluating an organization's network security effectiveness and information security resources, including review of Information Security Management System maturity to develop tactical and strategic improvement directions.
- Cybersecurity Gap Analysis and Roadmap Development Continuous process enabling organizations to identify gaps in cybersecurity posture against ideal states and develop roadmaps to achieve target security maturity levels aligned with ISO, NIST, and CST standards.
- Secure Software Development Lifecycle Structured security integration across software development phases including requirement analysis, design analysis, implementation, testing, release, and delivery to prevent security flaws from the development stage.
- ISO 27001 Advisory Comprehensive advisory helping organizations establish, implement, operate, monitor, and certify an Information Security Management System aligned with ISO 27001:2013 standards.
- Data Governance Framework ensuring high data quality throughout the data lifecycle addressing confidentiality, integrity, availability, accessibility, and non-repudiation of organizational data.
- Managed Security Services Outsourced management of security devices and systems including firewalls, intrusion detection/prevention systems, antivirus software, and VPNs to address organizational security challenges on a recurring basis.
- Staff Augmentation Temporary staffing service providing qualified and experienced cybersecurity experts to support specific projects or regular cybersecurity needs without full-time hiring commitment.
- Third-Party Risk Management Vendor management framework ensuring best-in-class vendor management processes across service providers to mitigate risks related to cybersecurity threats, reputational damage, and financial loss from third-party actions.
- Security Operations Centre (SOC) 24x7 computing facility for monitoring and analyzing cyber threats with three-tier approach (detect, react, predict) including SIEM infrastructure management and incident response capabilities, ISO 27001 certified.
- Vulnerability Management End-to-end approach identifying, evaluating, and remediating security vulnerabilities before exploitation through periodic assessments, checks, and mitigations to minimize organizational attack surfaces.
- Remote Penetration Testing Remote-based penetration testing services assessing distributed network security and WFH team environments through black box, white box, and gray box testing methodologies using industry-proven standards (OWASP, CREST, OSSTMM).
- Intelligence-Led Pentesting Services Penetration testing augmented with threat intelligence to craft attack scenarios mimicking advanced persistent threat actors, providing holistic overview of cybersecurity defenses rather than piecemeal results.
- Compromise Assessment Comprehensive technical assessment of organizational infrastructure, endpoints, and servers to identify indicators of compromise or evidence of ongoing and historical malicious activities.
- Secure Code Review Source code security review process identifying weak security gaps in application source code and remediating security flaws, with mandatory review before product launch per compliance requirements.
- Digital Forensics Digital crime investigation service involving collection, preservation, and analysis of digital evidence using advanced techniques including correlation, aggregation, corroboration, and systematic interpretation.
- Incident Response Structured framework helping organizations mitigate cybersecurity incident damages, reduce business disruption costs through defined policies, processes, and supported response teams.
- Enterprise Security Professional Certification & Training Professional certification and training programs equipping employees with necessary knowledge and skills to secure organizational networks against cybercriminals and evolving threats.
- Security Awareness Training Formal employee training and education process on information security importance and protection, including phishing, smishing, and vishing simulations through integrated e-Learning and gamification modules.
- Cybersecurity Professional Skill Development Training Training programs addressing cybersecurity skills shortages by providing employees with skills relevant to their job functions to fortify human firewall against cyberattacks.
- OhPhish Platform Proprietary phishing simulation platform providing phishing, SMiShing, and vishing simulations integrated with e-Learning and gamification modules on a learning management system (LMS) to test and train employees against social engineering attacks.
- IT Governance Advisory service ensuring IT investments yield fruitful results and mitigate IT-associated risks through alignment of IT governance with business strategy using industry best practices.
- IT Risk Assessment Methodology reviewing possible threats and risks posed to organizations to identify, assess, and modify security posture for enhanced operations and attacker defense.
- PCI DSS Advisory Advisory services helping organizations understand and implement Payment Card Industry Data Security Standards to protect online banking transactions and prevent cardholder information loss.
- Identity Access Management Service ensuring right personnel access right resources the right way for the right reason, addressing security challenges from SaaS, PaaS, Cloud, and BYOD adoption.
- Data Privacy Services Advisory services covering HIPAA compliance for healthcare, PCI compliance, third-party due diligence, DLP, data classification, encryption, data governance, and BS 10012 compliance.
- Vendor Risk Management Sustainable and scalable vendor management framework ensuring best-in-class vendor management processes including vendor selection, assessment, risk profiling, and SLA monitoring.
Companies that use EC-Council Global Services
Customer profileNamed customers13 records
Segments7 records
Ideal customer profiles4 records
EC-Council Global Services technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
EC-Council Global Services partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core.
- EGS Partner Program - Affiliate PartnerscoreThe affiliate partner serves as the client acquisition and relationship manager. EGS works with the client on their particular needs, solutions specifications, and delivery expectations. The affiliate represents the account but EGS fronts the delivery from inception till end of the project.
- EGS Partner Program - Channel PartnerscoreThe channel partner serves as the account titleholder. The partner works with the client on their particular needs, solutions specifications, and delivery expectations. The affiliate owns the account and EGS helps support the delivery and implementation of the required services.
- EC-Council (Parent Organization)coreEC-Council Global Services is a division of EC-Council (International Council of E-Commerce Consultants), the world's largest cyber-security technical certification body. EGS leverages EC-Council's proprietary methodologies, certification programs, and global network of 380,000+ certified professionals.
- National Cyber Security Agency (NACSA)coreEGS is an approved vendor for Managed Security Services and Penetration Testing services, recognized by Malaysia's national cybersecurity agency.
- Cyber Security Agency of Singapore (CSA)coreEGS holds approved vendor status with Singapore's national cybersecurity agency for cybersecurity services.
- CyberSecurity MalaysiacoreEGS is an approved vendor for Managed Security Services and Penetration Testing, and has received multiple awards from CyberSecurity Malaysia including CSM-ACE Cyber Security Company recognition.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
EC-Council Global Services competitors and assessment
Company assessmentDirect peers
- Trustwave: MSSP and cybersecurity consulting firm offering managed detection, incident response, and compliance advisory. Comparable to EGS's managed SOC, vulnerability management, and PCI DSS / ISO 27001 advisory offerings.
- Bishop Fox: Offensive security firm specializing in penetration testing, red teaming, and security assessments. Closely comparable to EGS's VAPT and intelligence-led pentesting practices serving enterprise and financial clients.
- Optiv Security: Cybersecurity solutions integrator and advisory firm delivering managed security, risk and compliance services, and technical testing. Comparable as a broad cyber consulting and MSSP serving mid-to-large enterprise clients.
- Kudelski Security: Cybersecurity services and solutions firm with managed detection, incident response, and advisory practices. Comparable to EGS's mix of consulting, managed SOC, and compliance advisory work for regulated industries.
- IOActive: Cybersecurity consultancy specializing in penetration testing, security assessments, and hardware/IoT security. Comparable to EGS's offensive security, VAPT, and intelligence-led assessment offerings.
- NCC Group: Global cybersecurity consulting and managed services firm with deep penetration testing, incident response, and managed detection capabilities. Comparable as a services-led cyber advisory serving regulated financial and enterprise clients.
- Mandiant (Google Cloud): Global cybersecurity consulting and incident response firm with managed defense services. Closely comparable to EGS's incident response, digital forensics, threat intelligence-led testing, and managed detection offerings.
Broad incumbents
- Accenture Security: Global professional services firm's cybersecurity practice offering managed security, cyber defense, and compliance advisory at massive scale. Comparable in service breadth but with vastly greater geographic and resource footprint than EGS.
- Deloitte Cyber: Big 4 cyber risk advisory practice offering strategy, managed security, incident response, and compliance. Comparable to EGS's enterprise advisory and managed services but as part of a global multi-practice firm.
- Palo Alto Networks Unit 42: Threat intelligence and incident response consulting arm of Palo Alto Networks, offering managed detection and advisory services. Comparable as a high-end MSSP/IR practice but operating within a much larger security platform vendor.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights5 records
Customer concentration
EC-Council Global Services social profiles
Digital presenceEC-Council Global Services compliance and trust
Trust signalCompliance14 records
EC-Council Global Services financial estimates
Financial estimateRevenue estimate
Valuation estimate
EC-Council Global Services leadership team
Management profileNumber of profiles
EC-Council Global Services funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
EC-Council Global Services M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about EC-Council Global Services
What does EC-Council Global Services do?
EC-Council Global Services (EGS) provides enterprise cybersecurity consulting, advisory, and managed security services covering vulnerability assessment, penetration testing, security strategy, cloud security, compliance advisory (ISO 27001, PCI DSS, GDPR, RMiT), 24x7 Security Operations Centre monitoring, digital forensics, incident response, and enterprise security training. Services are organized around the NIST Cybersecurity Framework functions of Identify, Protect, Detect, Respond, and Recover, and delivered by certified consultants (CEH, CISSP, CISM, CISA, PCI-QSA) using EC-Council's proprietary Licensed Penetration Testing methodology.
When was EC-Council Global Services founded?
EC-Council Global Services was founded in -1. It employs 51 to 100 people.
Where is EC-Council Global Services based?
EC-Council Global Services is headquartered in Kuala Lumpur, Malaysia, in the Asia region.
How does EC-Council Global Services make money?
Three revenue lines are on record. Cybersecurity Consulting and Advisory Services are the primary driver. The others are managed Security Services and cybersecurity Training and Certification.
Who are EC-Council Global Services's main competitors?
Direct peers on record are Trustwave, Bishop Fox, Optiv Security, Kudelski Security, IOActive, NCC Group and Mandiant (Google Cloud). Broad incumbents are Accenture Security, Deloitte Cyber and Palo Alto Networks Unit 42.
Does EC-Council Global Services have an API?
No public API is recorded for EC-Council Global Services.
What industry is EC-Council Global Services in?
EC-Council Global Services's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519 and its SIC code is 7373.