THINGSRECON
ThingsRecon is a Netherlands-based cybersecurity SaaS platform that runs agentless external scans to map organizations' external attack surface and digital supply chain, scoring risks via its patent-pending Digital Proximity metric for enterprise security teams, compliance leaders, and national cyber agencies.
- Company typePrivate
- Founded-
- HeadquartersAmsterdam, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What THINGSRECON does
ThingsRecon B.V. is a Netherlands-headquartered (Amsterdam) cybersecurity software company that has built a category it calls Supply Chain Intelligence, sitting between traditional Third-Party Risk Management (TPRM), External Attack Surface Management (EASM), vulnerability management, and GRC tooling. Its platform runs continuous, agentless, outside-in scans to discover internet-exposed assets (domains, IPs, APIs, shadow applications, certificates, scripts, and supplier connections) and then scores each finding using a proprietary, patent-pending Digital Proximity metric that measures how close an exposed asset or supplier sits to a customer's core systems, rather than relying on vendor-declared questionnaires or external security ratings. The platform layers AI-driven contextual intelligence (150+ signals per supplier node across technical, business, financial, and geopolitical dimensions) and a natural-language conversational interface (Ask Steph) over a living map of the digital supply chain. Three product surfaces are delivered: Attack Surface Discovery (the enterprise EASM-adjacent core), Supply Chain Intelligence (digital supply chain mapping and proximity scoring), and Global Security Intelligence / Securing Nations (a Critical National Infrastructure offering targeting national cyber agencies with 12-36 month resilience programs). The company monetizes through annual enterprise SaaS subscriptions with a freemium entry point (a free proximity snapshot) and sells primarily via direct enterprise field sales with an MSSP/reseller overlay; the platform integrates natively with 14+ enterprise systems including ServiceNow, Jira, RSA Archer, OneTrust, SAP Ariba, Coupa, BMC Remedy, Workday, Dynamics 365, Power BI, and Snowflake.
THINGSRECON firmographics
Firmographics- Name
- THINGSRECON
- Legal name
- ThingsRecon B.V.
- Website
- https://thingsrecon.com
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- ThingsRecon is a Netherlands-based cybersecurity SaaS platform that runs agentless external scans to map organizations' external attack surface and digital supply chain, scoring risks via its patent-pending Digital Proximity metric for enterprise security teams, compliance leaders, and national cyber agencies.
- Ownership category
- akta.pro rank
THINGSRECON industry classification
Industry- Product category
- External Attack Surface Management (Supply Chain Intelligence)
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Third-Party & Supply Chain Exposure Monitoring (HDADAHAJ)
Keywords
Where THINGSRECON is headquartered
LocationHeadquarters
- HQ city
- Amsterdam
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
THINGSRECON business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: Cloud-based platform subscription model providing continuous external attack surface discovery and supply chain intelligence. Pricing based on organizational scope and monitoring requirements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | One-time | Free Proximity Snapshot |
| Subscription | Annual | Enterprise Platform |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
THINGSRECON product offering
Product offeringCore offering
ThingsRecon is a SaaS supply chain intelligence platform that continuously maps external attack surfaces and digital supply chain connections using agentless, outside-in scanning. It discovers domains, IPs, APIs, certificates, scripts, and hidden supplier connections, then prioritizes them with the proprietary Digital Proximity metric that measures how close each internet-exposed asset sits to an organization's critical systems, producing actionable, evidence-based remediation guidance.
Product overview
ThingsRecon is a supply chain intelligence platform providing two core products: Attack Surface Discovery and Supply Chain Intelligence. Attack Surface Discovery provides external attack surface management through agentless scanning of domains, IPs, APIs, and supplier connections. Supply Chain Intelligence maps the full digital supply chain including hidden dependencies and measures exposure through the proprietary Digital Proximity metric. A third offering, Global Security Intelligence (CNI Security), extends the platform for nation-scale critical infrastructure protection with three-phase resilience programs for government agencies. The platform integrates with existing ITSM, GRC, ERP, and analytics tools via API and webhooks.
Differentiator
Problem solved
Functional benefit
Brands
- Digital Proximity: A patent-pending security metric measuring how closely an internet-exposed asset sits to sensitive systems, data, identities, or suppliers. It is a proprietary measure developed by ThingsRecon.
- All Things Cyber
- Securing Nations
Products and services
- Attack Surface Discovery External attack surface management product that discovers domains, IPs, APIs, shadow applications, and supplier connections through agentless, outside-in scanning, then assigns risk scores, Digital Proximity ratings, and continuous monitoring alerts for new assets and remediated issues. Targeted at enterprise security teams that need a living map of their internet-exposed footprint without deploying agents or uploading vendor registers.
- Supply Chain Intelligence Platform module that discovers and maps the full digital supply chain including subprocessors, hidden dependencies, infrastructure concentrations, and supplier relationships, scoring each connection via the proprietary Digital Proximity metric to measure how deeply each supplier is embedded in the customer environment. Designed for security, GRC, and procurement teams that need evidence-based third-party risk data beyond declared vendor lists.
- Global Security Intelligence (CNI Security) Nation-scale visibility and resilience platform for Critical National Infrastructure protection, offering country-level digital ecosystem mapping, supply chain dependency analysis, and active threat intelligence overlay through a 12-36 month resilience program methodology. Sold to government ministries, national cyber agencies, and critical infrastructure regulators operating programs across the Balkans and broader Europe.
Quantifiable outcome
- Discovers 3x more active supplier connections than official vendor lists
- +5 more outcomes
Companies that use THINGSRECON
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles5 records
THINGSRECON technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration14 records
AI capability7 records
Feature5 records
THINGSRECON partnerships and signals
Strategic signalPartnerships
15 partnerships are on record, tiered core and supporting.
- ServiceNowcoreNative integration with ServiceNow for ITSM workflows. Attack surface findings and supply chain intelligence can flow into ServiceNow ticketing and incident management.
- Jira Service ManagementcoreIntegration with Atlassian Jira Service Management for security findings and remediation workflow management.
- Jira SoftwarecoreIntegration with Atlassian Jira Software for development and security team collaboration on vulnerability remediation.
- RSA ArchercoreIntegration with RSA Archer GRC platform for supply chain risk data and compliance evidence workflows.
- OneTrustcoreIntegration with OneTrust privacy and governance platform for third-party risk data and compliance automation.
- SAP AribacoreIntegration with SAP Ariba procurement platform for supplier risk data during procurement lifecycle.
- Microsoft Power BIsupportingIntegration with Microsoft Power BI for data analytics and custom dashboard visualization of attack surface findings.
- SnowflakesupportingIntegration with Snowflake data platform for advanced analytics and data warehousing of supply chain intelligence.
- BMC Remedy/HelixcoreIntegration with BMC Remedy/Helix ITSM platform for incident and change management workflows.
- ZendesksupportingIntegration with Zendesk support platform for customer service and ticketing integration.
- FreshservicesupportingIntegration with Freshservice ITSM platform for security and incident management workflows.
- CoupacoreIntegration with Coupa procurement platform for supply chain risk data during vendor management.
- WorkdaysupportingIntegration with Workday for HR and finance data related to supplier risk context.
- Dynamics 365 Supply Chain ManagementsupportingIntegration with Microsoft Dynamics 365 for supply chain management and procurement workflows.
- BAE Systems Digital IntelligencecoreDavid Smith, Regional Lead Consultant at BAE Systems, appears on All Things Cyber podcast discussing CNI security. BAE Systems works with governments on national cyber resilience programs.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
THINGSRECON competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike: Endpoint and extended detection platform offering Falcon Surface for external attack surface management. Larger incumbent operating broadly across security operations, including externally exposed assets and supplier-related exposure signals relevant to ThingsRecon.
- Tenable: Large vulnerability management platform that has absorbed CyCognito to expand into external attack surface and third-party risk. Broader incumbent whose portfolio increasingly overlaps ThingsRecon's discovery and supply chain intelligence scope.
- Microsoft Defender External Attack Surface Management: Microsoft's EASM capability bundled into the Defender and Security Copilot ecosystem. Broad incumbent offering discovery and supplier-aware inventory to a large enterprise base that overlaps ThingsRecon's buyer profile.
Emerging players
- Reflectiz: Emerging player focused on web supply chain and third-party script risk from the outside-in. Compares to ThingsRecon's narrower view on supplier-controlled scripts and APIs that touch core systems.
Direct peers
- CyCognito (Tenable): External attack surface management platform (now part of Tenable) that maps an organization's digital footprint across subsidiaries, suppliers, and exposed assets. Highly comparable to ThingsRecon's discovery-then-prioritize flow.
- SecurityScorecard: Third-party risk and cybersecurity ratings platform that scores vendor security posture. Directly comparable because it operates in the same TPRM-plus-attack-surface category that ThingsRecon positions against and serves overlapping buyer personas (CISOs, TPRM leaders).
- Censys: External attack surface and internet intelligence platform that continuously discovers exposed assets and infrastructure. Directly comparable to ThingsRecon's Attack Surface Discovery product, with overlapping methodologies for outside-in scanning.
- UpGuard: Third-party risk and attack surface management platform combining vendor risk ratings with external asset discovery. Closely aligned with ThingsRecon's dual-product positioning across TPRM and external asset/supplier graph visibility.
- RiskRecon (Mastercard): Data-driven third-party cyber risk scoring platform acquired by Mastercard. Directly comparable because it prioritizes third-party risk via continuous external telemetry, sharing ThingsRecon's evidence-based rather than self-attested approach.
- BitSight: Security ratings and third-party risk management vendor providing continuous monitoring of vendor cyber posture. Directly comparable to ThingsRecon's supply-chain-risk prioritization offering, with overlapping enterprise customer base and regulatory-driven use cases.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
THINGSRECON social profiles
Digital presenceTHINGSRECON compliance and trust
Trust signalCompliance6 records
THINGSRECON financial estimates
Financial estimateRevenue estimate
Valuation estimate
THINGSRECON leadership team
Management profileNumber of profiles
Profiles3 records
THINGSRECON funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
THINGSRECON M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about THINGSRECON
What does THINGSRECON do?
ThingsRecon is a SaaS supply chain intelligence platform that continuously maps external attack surfaces and digital supply chain connections using agentless, outside-in scanning. It discovers domains, IPs, APIs, certificates, scripts, and hidden supplier connections, then prioritizes them with the proprietary Digital Proximity metric that measures how close each internet-exposed asset sits to an organization's critical systems, producing actionable, evidence-based remediation guidance.
Is THINGSRECON a public or private company?
THINGSRECON is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was THINGSRECON founded?
THINGSRECON was founded in -1. It employs 11 to 50 people.
Where is THINGSRECON based?
THINGSRECON is headquartered in Amsterdam, Netherlands, in the Europe region.
How does THINGSRECON make money?
One revenue line is on record: saaS Subscription.
Who are THINGSRECON's main competitors?
Broad incumbents on record are CrowdStrike, Tenable and Microsoft Defender External Attack Surface Management. Reflectiz is listed as an emerging player. Direct peers are CyCognito (Tenable), SecurityScorecard, Censys, UpGuard, RiskRecon (Mastercard) and BitSight.
Does THINGSRECON have an API?
Yes. ThingsRecon offers API integration capabilities allowing customers to plug discovery intelligence directly into their existing security stack via API, webhook, or native integration. The platform exports data for integration with GRC, SIEM, EASM workflows, and ticketing systems. Specific API documentation URL not provided in source materials.
What industry is THINGSRECON in?
THINGSRECON's product category is External Attack Surface Management (Supply Chain Intelligence). Its primary akta.pro industry code is HDADAHAJ, Third-Party & Supply Chain Exposure Monitoring. Its NAICS code is 518 and its SIC code is 7370.