Independent Security Evaluators
Independent Security Evaluators is a privately held Baltimore-based cybersecurity consultancy founded in 2005 that delivers manual penetration testing, vulnerability assessments, and vendor risk management software to Fortune 100 enterprises across technology, entertainment, and regulated industries.
- Company typePrivate
- Founded2005
- HeadquartersBaltimore, MD, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Independent Security Evaluators does
Independent Security Evaluators (ISE) is a privately held cybersecurity consulting firm founded in 2005 and headquartered in Baltimore, Maryland, with a second office in San Diego. The company was formed out of an academic security research team and built its reputation through pioneering disclosures — including being the first to hack the iPhone and the first to hack Android OS in 2007 — and a sustained publication cadence across medical devices, IoT, cars, password managers, and blockchain.
ISE monetizes through two complementary lines. The primary line is professional services delivered by a roughly 43-person team of security researchers and consultants, offering penetration testing, vulnerability and application assessments, cloud security assessments, network penetration testing, vulnerability scanning, secure design analysis, independent verification and validation, IT consulting, and security training (including Hackalong workshops). The second line is START VRM, a SaaS vendor risk management platform that productizes ISE's assessment methodology into subscription software for third-party onboarding, assessments, and remediation tracking.
The firm serves a Fortune 100-leaning enterprise base spanning technology (Google, Amazon, Microsoft, Apple, Qualcomm, Salesforce), entertainment (Netflix, Disney), insurance, media, and consumer electronics. Go-to-market is consultative and enterprise-led, supplemented by an unusually strong content engine — the Hackers Blog, Industry Blog, Tech Done Different podcast, VRM/TPRM articles, and Ted Harrington's book "Hackable" — and by sustained presence at DEF CON, Black Hat, and RSA, including organizing the IoT Village hacking event. Pricing is quote-based across both services and software, with no publicly disclosed tiers.
Independent Security Evaluators firmographics
Firmographics- Name
- Independent Security Evaluators
- Legal name
- Independent Security Evaluators
- Website
- https://ise.io
- Company type
- Private
- Founded year
- 2005
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Independent Security Evaluators is a privately held Baltimore-based cybersecurity consultancy founded in 2005 that delivers manual penetration testing, vulnerability assessments, and vendor risk management software to Fortune 100 enterprises across technology, entertainment, and regulated industries.
- Ownership category
- akta.pro rank
Independent Security Evaluators industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Other Scientific and Technical Consulting Services (54169), Computer Systems Design and Related Services (54151), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- IT Risk Management (ITRM) (HDADAIAD), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Independent Security Evaluators is headquartered
LocationHeadquarters
- HQ city
- Baltimore, MD
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Independent Security Evaluators business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Security Consulting & Assessments: Professional services revenue generated from penetration testing, vulnerability assessments, application security assessments, cloud security assessments, network penetration testing, vulnerability scanning, security consulting, secure design analysis, IT consulting, and security training engagements. These are typically project-based or retainer engagements with enterprise clients.
- START VRM Software: SaaS-based vendor risk management platform (START) offering subscription-based software for third-party risk management. Customers can subscribe to the platform for vendor onboarding, assessments, risk identification, and remediation tracking.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Independent Security Evaluators product offering
Product offeringCore offering
ISE provides manual, human-driven cybersecurity consulting services — including penetration testing, vulnerability and application security assessments, cloud security assessments, network penetration testing, vulnerability scanning, security consulting, secure design analysis, independent verification and validation, IT consulting, and security training (Hackalong workshops). Alongside its services, ISE sells START VRM, a SaaS platform that automates vendor onboarding, third-party risk assessments, risk identification, and remediation tracking for enterprise customers.
Product overview
Independent Security Evaluators offers a cybersecurity consulting firm with two main offerings: START VRM (a vendor risk management software platform) and professional security services including penetration testing, vulnerability assessments, application security, cloud security, secure design analysis, IT consulting, and security training. START VRM is the core software product enabling organizations to automate and manage their third-party risk management programs through vendor onboarding, streamlined assessments, risk identification, and remediation workflows. The professional services complement the software by providing hands-on security testing, consulting, and training capabilities. The company also conducts security research and publishes findings through its blog, podcast (Tech Done Different), and industry talks, and organizes the IoT Village hacking event.
Differentiator
Problem solved
Functional benefit
Products and services
- START VRM SaaS vendor risk management platform that enables organizations to manage third-party and vendor risks through vendor onboarding, streamlined assessments, risk identification, and remediation tracking, built on ISE's adversarial security assessment methodology.
- Vulnerability Assessments Human-driven security assessment services that find and fix exploitable security vulnerabilities in enterprise applications and systems beyond what automated scans can identify.
Quantifiable outcome
- Research shows it's 25 times more effort to fix a design issue discovered after deployment
Companies that use Independent Security Evaluators
Customer profileNamed customers9 records
Segments5 records
Ideal customer profiles3 records
Independent Security Evaluators technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Independent Security Evaluators partnerships and signals
Strategic signalScale indicators2 records
Recent moves6 records
Expansion highlights5 records
Independent Security Evaluators competitors and assessment
Company assessmentDirect peers
- Coalfire: Cybersecurity advisory and assessment firm offering penetration testing, application/cloud security, and GRC services to enterprise and regulated industries. Comparable in service breadth and enterprise-targeting GTM, though larger in scale.
- Kudelski Security: Cybersecurity services and consulting provider offering penetration testing, application security, and managed security. Comparable boutique-to-mid-market enterprise security consulting with a research-driven heritage.
- Trail of Bits: Security research and consulting firm known for cutting-edge research across cryptography, blockchain, and software assurance. Highly comparable to ISE's research-driven brand and target customers in tech and crypto.
- Bishop Fox: Boutique offensive-security consulting firm offering penetration testing, red teaming, and security research. Closely comparable to ISE in services mix, target buyers, and prestige-driven positioning among Fortune 500 tech and media clients.
- Bitsight: Security ratings and third-party risk management platform. Comparable to START VRM in the TPRM workflow category, serving enterprise procurement and security teams.
- SecurityScorecard: SaaS vendor risk management and security ratings platform. Direct competitor to START VRM in the TPRM/VRM category, with a much larger customer base and capital base.
- Panorays: Third-party security risk management SaaS platform. Closely comparable to START VRM in functionality (vendor assessments, risk identification, remediation tracking) and enterprise buyer profile.
Broad incumbents
- NCC Group: Global cybersecurity consulting and software resilience firm with deep penetration testing and research capabilities (Origin). Comparable in service mix but with a much broader geographic footprint and product portfolio.
- Mandiant (Google Cloud): Enterprise security consulting and incident response firm, now part of Google Cloud. Overlaps with ISE's adversary-centric consulting and serves many of the same large technology and Fortune 100 buyers, but at significantly greater scale.
- Rapid7: Public cybersecurity vendor offering security testing, vulnerability management, and managed detection services. Overlaps with ISE's vulnerability assessment and penetration testing services as part of a broader product portfolio.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Independent Security Evaluators social profiles
Digital presenceIndependent Security Evaluators financial estimates
Financial estimateRevenue estimate
Valuation estimate
Independent Security Evaluators leadership team
Management profileNumber of profiles
Profiles1 record
Independent Security Evaluators funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Independent Security Evaluators M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Independent Security Evaluators
What does Independent Security Evaluators do?
ISE provides manual, human-driven cybersecurity consulting services — including penetration testing, vulnerability and application security assessments, cloud security assessments, network penetration testing, vulnerability scanning, security consulting, secure design analysis, independent verification and validation, IT consulting, and security training (Hackalong workshops). Alongside its services, ISE sells START VRM, a SaaS platform that automates vendor onboarding, third-party risk assessments, risk identification, and remediation tracking for enterprise customers.
Is Independent Security Evaluators a public or private company?
Independent Security Evaluators is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Independent Security Evaluators founded?
Independent Security Evaluators was founded in 2005. It employs 11 to 50 people.
Where is Independent Security Evaluators based?
Independent Security Evaluators is headquartered in Baltimore, MD, United States, in the North America region.
How does Independent Security Evaluators make money?
Two revenue lines are on record. Security Consulting & Assessments are the primary driver. The others are START VRM Software.
Who are Independent Security Evaluators's main competitors?
Direct peers on record are Coalfire, Kudelski Security, Trail of Bits, Bishop Fox, Bitsight, SecurityScorecard and Panorays. Broad incumbents are NCC Group, Mandiant (Google Cloud) and Rapid7.
Does Independent Security Evaluators have an API?
No public API is recorded for Independent Security Evaluators.
What industry is Independent Security Evaluators in?
Independent Security Evaluators's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of HDADAIAD, IT Risk Management (ITRM). Its NAICS code is 54169 and its SIC code is 7371.