ORIZON S.R.L.
Orizon S.r.l. is an Italian cybersecurity firm (division of Syneto Group) that sells an integrated platform of six AI-enabled services covering external attack surface management, internal asset discovery, penetration testing, managed SOC, security awareness and dark web intelligence, targeting European mid-market organizations facing NIS2 compliance obligations.
- Company typePrivate
- Founded2022
- HeadquartersBrescia, Italy
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What ORIZON S.R.L. does
Orizon S.r.l. is an Italian cybersecurity company and a wholly-owned division of Syneto Group, headquartered in Brescia with a Spanish subsidiary established in Madrid in 2025. It provides an integrated platform of six services for European mid-market organizations: RECON (external attack surface management and internal asset discovery), Fireline (AI-orchestrated penetration testing), Oversight (24/7 managed SOC), Aware (AI-driven security awareness and phishing simulation), Darkfield (dark web intelligence), and Orizon AI (on-premise sovereign AI). The platform is built around 143 security controls mapped to 7 compliance frameworks (NIS2, ISO 27001, NIST CSF, SOC 2, GDPR, ACN, CIS Controls) and emphasizes EU data sovereignty as a default posture rather than a configuration option.
The technical architecture combines multi-source CVE correlation (8 sources), agentless internal scanning via a Scout probe, dual AI models (one simulating attacker behavior, one mapping findings to compliance frameworks) orchestrating 67+ security tools, and ML-driven anomaly detection with auto-correlated Attack Stories mapped to MITRE ATT&CK. The company has obtained ISO 9001, ISO/IEC 27001 and ISO/IEC 27017 certifications and operates a REST API with webhooks and native integrations to Slack, Jira, ServiceNow, Splunk HEC and Azure Sentinel.
Orizon monetizes through a hybrid pricing model: token-based consumption for external scans (EUR 90 per domain, with volume discounts up to 42% on annual tiers), per-asset annual subscriptions for internal discovery (EUR 9.80-16.80 per asset), annual pentest subscriptions (EUR 6,300/year for 3 pentests), and contact-sales pricing for managed SOC, Aware and Orizon AI. Its go-to-market combines a self-serve product-led growth funnel (3 free scans, no credit card) with a 100% channel partner program targeting European MSPs, MSSPs and cybersecurity consultancies, supplemented by enterprise direct sales for 1,000+ scan deployments and multi-year agreements.
ORIZON S.R.L. firmographics
Firmographics- Name
- ORIZON S.R.L.
- Legal name
- Orizon S.r.l.
- Website
- https://orizon.one
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Orizon S.r.l. is an Italian cybersecurity firm (division of Syneto Group) that sells an integrated platform of six AI-enabled services covering external attack surface management, internal asset discovery, penetration testing, managed SOC, security awareness and dark web intelligence, targeting European mid-market organizations facing NIS2 compliance obligations.
- Ownership category
- akta.pro rank
ORIZON S.R.L. industry classification
Industry- Product category
- Cybersecurity Platform (Attack Surface Management & Compliance Automation)
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- SOAR & Security Automation (HDADAGAB)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Network Security Services (Firewall/VPN/ZTNA/SASE Integration) (BPAEAEAG)
Keywords
Where ORIZON S.R.L. is headquartered
LocationHeadquarters
- HQ city
- Brescia
- HQ country
- Italy
- HQ region
- Europe
Offices2 records
Markets served
ORIZON S.R.L. business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- RECON Essentials - External Scanning: Token-based consumption model where 1 token = EUR 1.00. External attack surface scans cost 90 tokens (EUR 90) per domain. Tokens valid 12 months from purchase. Subscription tiers offer volume discounts (30-42% savings) with token pools valid for 12 months.
- RECON Internal - Internal Asset Discovery: Per-asset annual subscription pricing. Starter at EUR 16.80/asset/year, Professional at EUR 14/asset (100 assets), Business at EUR 11.20/asset (500 assets), Enterprise at EUR 9.80/asset (1,000 assets).
- Fireline - Penetration Testing: One-time pentest report at EUR 2,800 or annual subscription at EUR 6,300/year (3 pentests). Each engagement includes 143 controls tested, 7 framework mappings, 4 automated report types, 48-hour delivery, and re-test of remediated findings.
- Oversight - Managed SOC: 24/7 SOC monitoring, behavioral detection, ML anomaly identification, automated incident response. Contact sales for pricing (from EUR 3K/month based on comparison table).
- Aware - Security Awareness Training: AI-powered phishing simulations and security awareness training. NIS2 Article 20 compliance built-in. Pricing available on request.
- Partner Program - Channel Revenue: Partners (MSPs, consultancies, resellers) receive competitive margins on services sold. Recurring revenue on annual contracts for partners. NIS2 affects 160,000+ European companies creating partner opportunity.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Pay-as-you-go | RECON Essentials Pay-As-You-Go - EUR 90/domain |
| Subscription | Annual | RECON Essentials Starter - EUR 630 (Save 30%) |
| Subscription | Annual | RECON Essentials Professional - EUR 1,487.50 (Save 34%) |
| Subscription | Annual | RECON Essentials Business - EUR 2,800 (Save 38%) |
| Subscription | Annual | RECON Essentials Enterprise - EUR 5,250 (Save 42%) |
| Subscription | Annual | RECON Internal Starter - EUR 16.80/asset/year |
| Subscription | Annual | RECON Internal Professional - EUR 1,400/year |
| Subscription | Annual | RECON Internal Business - EUR 5,600/year |
| Subscription | Annual | RECON Internal Enterprise - EUR 9,800/year |
| One time/ perpetual license | Pay-as-you-go | Fireline One-Shot - EUR 2,800/report |
| Subscription | Annual | Fireline Annual - EUR 6,300/year (Save 25%) |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
ORIZON S.R.L. product offering
Product offeringCore offering
Orizon sells a unified European cybersecurity platform combining external attack surface management (RECON Essentials), internal asset discovery (RECON Internal), AI-powered penetration testing (Fireline), 24/7 managed SOC (Oversight), AI-driven phishing simulations and security awareness training (Aware), dark web intelligence (Darkfield), and on-premise sovereign AI (Orizon AI). The platform automates compliance reporting across 143 controls and 7 frameworks including NIS2, ISO 27001, NIST CSF, SOC 2, GDPR, ACN, and CIS Controls, and is sold to European mid-market organizations via a self-serve platform, 100% channel partner program, and enterprise direct sales.
Product overview
Orizon is a unified European cybersecurity platform offering six integrated services built around attack surface management, penetration testing, SOC monitoring, security awareness, and dark web intelligence. The platform architecture centers on RECON (Essentials for external attack surface management, Internal for internal network discovery) combined with Fireline (AI-powered penetration testing). Oversight provides 24/7 managed SOC monitoring, Aware delivers AI-powered security training, and Darkfield monitors dark web threats. Orizon AI enables on-premise sovereign AI. All services are integrated into a single platform with unified reporting, 143 security controls, and mapping to 7 compliance frameworks (NIS2, ISO 27001, NIST CSF, SOC 2, GDPR, ACN, CIS Controls). Pricing is token-based: RECON scans from EUR 90/domain, RECON Internal from EUR 16.80/asset/year, Fireline from EUR 2,800/report.
Differentiator
Problem solved
Functional benefit
Brands
- RECON: External Attack Surface Management (EASM) and Internal Asset Discovery platform that maps external attack surfaces and internal networks.
- Fireline
- Oversight
- Aware
- Darkfield
- Orizon AI
Products and services
- RECON Essentials External Attack Surface Management (EASM) platform that maps an organization's external perimeter, discovering subdomains, open ports, exposed services, misconfigurations, CVEs, and technology stack via a 6-phase scanning pipeline completing in under 60 seconds. Sells to security teams and IT leaders needing continuous external visibility and audit-ready reports.
- RECON Internal Internal Asset Discovery service identifying shadow IT, misconfigurations, and unauthorized access within internal networks via agentless Scout probe scanning. Classifies assets into 9 categories, performs CMDB reconciliation, and maps network topology. Sells to security teams needing NIS2 asset mapping and continuous internal monitoring.
- Fireline AI-powered Penetration Testing as a Service using dual-model AI (Attack Model + Analysis Model) that orchestrates 67+ security tools into complete attack chains, simulating real attacker behavior across 143 controls and 7 compliance frameworks. Delivers 4 automated report types within 48 hours. Sells to organizations needing automated, affordable pentest coverage.
- Oversight 24/7 Managed Detection and Response (MDR) SOC providing threat detection, investigation, and response with certified analysts, behavioral/ML anomaly detection, Attack Stories (correlated incident narratives mapped to MITRE ATT&CK), and 500+ security tool integrations. Sub-5-minute mean time to detect and sub-30-minute automated containment. Built-in NIS2 incident reporting.
- Aware AI-powered security awareness training platform with adaptive phishing simulations, ML-powered personalized training paths, behavioral analytics, gamification, micro-learning, and NIS2 Article 20 compliance reporting across 25+ languages. Reduces phishing click rates by 60% within 3 months.
- Darkfield Dark web intelligence service monitoring 200+ ransomware groups, detecting leaked credentials across dark web databases, tracking threat actors with MITRE ATT&CK mapping, and providing ransomware victim tracking intelligence.
- Orizon AI On-premise sovereign AI product for enterprise customers requiring full data sovereignty. Runs entirely on customer infrastructure with 100% data sovereignty, EU AI Act compliant, GDPR guaranteed, and supports custom model training on customer data.
Quantifiable outcome
- Compliance audit time reduced from 6-12 months to 48 hours
- +5 more outcomes
Companies that use ORIZON S.R.L.
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
ORIZON S.R.L. technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability12 records
Feature9 records
ORIZON S.R.L. partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core and flagship.
- European Channel Partners (MSPs, Consultancies, Resellers)coreGrowing network of European cybersecurity partners including MSPs, MSSPs, IT consultancies, system integrators, and cybersecurity resellers. 100% channel model - Orizon never competes with partners. Partners receive technical certification, dedicated partner dashboard, multi-client management, co-selling support, and competitive margins. 160,000+ NIS2-in-scope European companies create massive market opportunity.
- Syneto Group (Parent Company)flagshipOrizon is the cybersecurity division of Syneto, an Italian technology group founded in 2012 and headquartered in Brescia. Syneto built hyperconverged infrastructure trusted by hundreds of European organizations for data protection, business continuity, and disaster recovery. Orizon created in 2022 to address proactive security needs discovered through infrastructure protection work.
Scale indicators10 records
Recent moves8 records
Expansion highlights5 records
ORIZON S.R.L. competitors and assessment
Company assessmentDirect peers
- Detectify: Detectify is an external attack surface management (EASM) platform focused on continuous discovery of internet-exposed assets and vulnerabilities. It competes head-on with Orizon's RECON Essentials product line in the European mid-market.
- Outpost24: Outpost24 is a European-headquartered cybersecurity company offering attack surface management, vulnerability management, and threat intelligence. It is a direct EASM peer with similar geographic focus on the European mid-market.
- Rapid7: Rapid7 offers an integrated platform spanning vulnerability management (InsightVM), managed SOC (InsightIDR / MDR), penetration testing services, and security awareness — closely mirroring Orizon's six-service breadth from a single vendor.
- Sekoia.io: Sekoia.io is a European SOC/SOAR platform offering managed detection and response and threat intelligence with EU data sovereignty. It directly competes with Orizon's Oversight SOC service in the European sovereign SOC category.
- HackerOne: HackerOne is a leading pentest-as-a-service and bug bounty platform, providing access to ethical hackers for security testing. It overlaps with Orizon's Fireline AI-driven penetration testing, though HackerOne's model is human-augmented rather than fully automated.
- Tenable: Tenable is a major provider of vulnerability management and external attack surface management (Tenable.asm / Nessus). It directly overlaps with Orizon's RECON Essentials EASM and CVE-driven risk scoring, though Tenable operates at a much larger scale.
- Pentera: Pentera is the leading automated penetration testing platform, with AI-driven attack simulation across enterprise environments. It is the most direct competitor to Orizon's Fireline service in the automated, continuous pentest category.
Broad incumbents
- CrowdStrike: CrowdStrike is a major endpoint and cloud security incumbent with an expanding attack surface management and identity protection portfolio. Orizon explicitly compares itself against CrowdStrike on EASM, ASM, and integrated reporting features.
- Qualys: Qualys is an established cloud-based vulnerability management and attack surface management platform. Orizon's comparison table positions against Qualys on EASM breadth and compliance framework coverage.
- WithSecure: WithSecure (formerly F-Secure) is a European cybersecurity vendor offering managed detection and response, vulnerability management, and security consulting. It overlaps with Orizon's European-focused, sovereign-architecture positioning across multiple product categories.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
ORIZON S.R.L. social profiles
Digital presenceORIZON S.R.L. compliance and trust
Trust signalCompliance6 records
ORIZON S.R.L. financial estimates
Financial estimateRevenue estimate
Valuation estimate
ORIZON S.R.L. leadership team
Management profileNumber of profiles
ORIZON S.R.L. subsidiaries and ownership
Company hierarchySubsidiaries1 record
ORIZON S.R.L. funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ORIZON S.R.L. M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ORIZON S.R.L.
What does ORIZON S.R.L. do?
Orizon sells a unified European cybersecurity platform combining external attack surface management (RECON Essentials), internal asset discovery (RECON Internal), AI-powered penetration testing (Fireline), 24/7 managed SOC (Oversight), AI-driven phishing simulations and security awareness training (Aware), dark web intelligence (Darkfield), and on-premise sovereign AI (Orizon AI). The platform automates compliance reporting across 143 controls and 7 frameworks including NIS2, ISO 27001, NIST CSF, SOC 2, GDPR, ACN, and CIS Controls, and is sold to European mid-market organizations via a self-serve platform, 100% channel partner program, and enterprise direct sales.
Is ORIZON S.R.L. a public or private company?
ORIZON S.R.L. is a private company. It is classified as corporate owned and is currently operating.
When was ORIZON S.R.L. founded?
ORIZON S.R.L. was founded in 2022. It employs 11 to 50 people.
Where is ORIZON S.R.L. based?
ORIZON S.R.L. is headquartered in Brescia, Italy, in the Europe region.
How does ORIZON S.R.L. make money?
Six revenue lines are on record. RECON Essentials - External Scanning is the primary driver. The others are RECON Internal - Internal Asset Discovery, fireline - Penetration Testing, oversight - Managed SOC, aware - Security Awareness Training and partner Program - Channel Revenue.
Who are ORIZON S.R.L.'s main competitors?
Direct peers on record are Detectify, Outpost24, Rapid7, Sekoia.io, HackerOne, Tenable and Pentera. Broad incumbents are CrowdStrike, Qualys and WithSecure.
Does ORIZON S.R.L. have an API?
Yes. REST API with scope-based Personal Access Tokens, async delivery for reports, per-user scan token quotas. Supports webhook integrations for scan.completed, finding.critical, probe.offline, schedule.failed events. API tokens scoped and revocable. Developer documentation is at recon.orizon.one.
What industry is ORIZON S.R.L. in?
ORIZON S.R.L.'s product category is Cybersecurity Platform (Attack Surface Management & Compliance Automation). Its primary akta.pro industry code is HDADAGAB, SOAR & Security Automation, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 5415 and its SIC code is 7373.