Mirai Security
Mirai Security is a Vancouver-based cybersecurity consulting firm delivering penetration testing, incident response, cloud security, GRC, and security awareness services to SMEs and enterprises across North America across healthcare, finance, technology, and other regulated verticals.
- Company typePrivate
- Founded2017
- HeadquartersVancouver, Canada
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Mirai Security does
Mirai Security is a private cybersecurity consulting firm headquartered in Vancouver, British Columbia, with a secondary office in Seattle, Washington. Founded in 2017, the firm delivers professional cybersecurity services to small-and-medium enterprises and large organizations across North America, organized around six core practice areas: Application Security, Incident Response, Cloud Security (Azure and AWS), Governance Risk & Compliance (GRC), Security Awareness & Human Risk, and Security Testing / Red Team operations. The company also offers a broader catalog of specialized assessments (Cyber Risk, Data Security & Privacy, ISO 27001 and SOC 2 Gap, Microsoft 365 Security, Azure Cloud Security, Ransomware Readiness), compliance services (CMMC/CPCSC, FedRAMP, PCI-DSS), and preparedness offerings (Tabletop Exercises, Incident Response Plans), serving verticals that include healthcare, mining and manufacturing, logistics, technology, retail and hospitality, and finance and insurance.
The underlying technology is human-delivered expertise rather than a packaged software product. Mirai's consultants hold a dense stack of industry certifications (CISSP, AWS, MS-AZ-500, GIAC GCSA, GRCP, OSWE, SSAP, CIPP-C) and the firm emphasizes practitioners sourced from security research and DevOps backgrounds. Delivery is enabled by a network of technology partnerships with cloud platforms (AWS, Microsoft Azure, HashiCorp), security operations and analytics vendors (Lacework, Elastic, Tenable, ThreatConnect, Obsidian Security), and training platforms (KnowBe4), alongside a vulnerability management platform and outsourced 'Security Department as a Service' offering.
Mirai operates a project- and retainer-based professional services revenue model with quote-based, tailored pricing. Publicly named engagements include a penetration testing program for PayByPhone (technology/payments) and a ransomware response engagement for K2 Fasteners (manufacturing). Multi-year contracts, IR retainers, and managed services form the recurring layer of the book. The company reaches customers through direct enterprise field sales, content-led demand generation via blog and case studies, community event sponsorship (BSides Vancouver, BSidesVI), and is privately held with no disclosed external funding rounds, making it an independently operated boutique in the North American cybersecurity services market.
Mirai Security firmographics
Firmographics- Name
- Mirai Security
- Legal name
- Mirai Security Inc.
- Website
- https://miraisecurity.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Mirai Security is a Vancouver-based cybersecurity consulting firm delivering penetration testing, incident response, cloud security, GRC, and security awareness services to SMEs and enterprises across North America across healthcare, finance, technology, and other regulated verticals.
- Ownership category
- akta.pro rank
Mirai Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Operations Center (SOC) as a Service (BPAEADAB), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
Keywords
Where Mirai Security is headquartered
LocationHeadquarters
- HQ city
- Vancouver
- HQ country
- Canada
- HQ region
- North America
Offices2 records
Markets served
Mirai Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Cybersecurity Consulting Services: Mirai generates revenue through professional services including penetration testing, incident response, GRC consulting, security awareness training, and cloud security assessments. Services are tailored to each organization's unique needs, serving both SMEs and enterprise clients.
- Compliance and Certification Services: The company offers services related to compliance frameworks including SOC 2, ISO 27001, CMMC, CPCSC, PCI-DSS, and FedRAMP assessments and readiness programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise and SME solutions - quote-based pricing |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels4 records
Mirai Security product offering
Product offeringCore offering
Mirai Security provides cybersecurity consulting and professional services, delivering penetration testing, Red Team operations, incident response, cloud security assessments on Azure and AWS, governance/risk/compliance (GRC) advisory, and security awareness training. Services are tailored to each client's needs and delivered by certified practitioners, with the company serving both SMEs exploring security posture and large enterprises requiring specialized expertise.
Product overview
Mirai Security offers a comprehensive portfolio of cybersecurity services organized around six core practice areas: Application Security, Incident Response, Cloud Security, Governance Risk & Compliance (GRC), Security Awareness & Human Risk, and Security Testing/Red Team operations. The company provides specialized assessment services including Cyber Risk Assessment, Data Security and Privacy Assessment, and vulnerability management. Compliance services span CMMC/CPCSC, FedRAMP, PCI-DSS, and ISO 27001/SOC 2 gap assessments. Additional offerings include managed services (Security Department as a Service), advisory services (Cybersecurity Roadmap Workshop), and incident preparedness solutions (Tabletop Exercises, Incident Response Plans, and Zero Down Incident Response Retainers). The portfolio is delivered across cloud platforms (Azure, AWS) and serves clients in healthcare, finance, retail, technology, logistics, mining, and manufacturing sectors across North America.
Differentiator
Problem solved
Functional benefit
Products and services
- Application Security Expert security testing services for applications and infrastructure, including penetration testing and Red Team operations, delivered by testers with backgrounds in computer science, security research, and DevOps.
- Incident Response Industry-certified incident handlers providing urgent response services to help organizations contain, investigate, and recover from cybersecurity incidents, restoring operations and recovering data.
- Cloud Security Certified cloud security specialists securing cloud environments across Azure and AWS without slowing deployment cycles.
- Governance, Risk & Compliance (GRC) Advisory services helping organizations achieve privacy compliance and align with recognized security standards including SOC 2, ISO 27001, and other frameworks.
- Security Awareness & Human Risk Human risk management training and initiatives that develop human firewalls and empower employees to become Security Champions.
- Cyber Risk Assessment Comprehensive process for evaluating potential risks to an organization's information systems and data, quantifying potential impacts and prioritizing mitigation efforts.
- Data Security and Privacy Assessment Assessment to determine which organizational data qualifies as PII, where data is stored and shared, how well it is protected, and measures for robust data security.
- ISO 27001 Gap Assessment Gap assessment to evaluate readiness for ISO 27001 certification, helping organizations implement an information security management system.
- SOC 2 Gap Assessment Gap assessment to align organizations with SOC 2 Trust Services Criteria for managing customer data security.
- Microsoft 365 Security Assessment Assessment of Microsoft 365 environment security controls to identify overlooked security configurations and risks.
- Azure Cloud Security Assessment Assessment of Azure cloud environment security to ensure proper security configurations and compliance.
- Ransomware Readiness Assessment Assessment to evaluate organizational preparedness for ransomware attacks and identify gaps in defense capabilities.
- Cybersecurity Roadmap Workshop Interactive workshop to help organizations understand their cybersecurity journey and develop a strategic security roadmap.
- CMMC/CPCSC Compliance Full-spectrum support for CMMC (Cybersecurity Maturity Model Certification) and CPCSC (Canadian Program for Cyber Security Certification) readiness, from assessments to audit preparation.
- FedRAMP Compliance Support for FedRAMP authorization ensuring cloud services meet U.S. government security requirements for federal agencies.
- PCI-DSS Compliance Compliance services for Payment Card Industry Data Security Standard, helping organizations handle payment card data securely.
- Incident Response Plan Development of incident response plans to prepare organizations for cybersecurity incidents and ensure effective response procedures.
- Cybersecurity Tabletop Exercise Facilitated exercises to test organizational cybersecurity incident response procedures and preparedness.
- Zero Down Incident Response Retainer Retainer service ensuring immediate incident response support when cybersecurity incidents occur, minimizing downtime and impact.
- Security Department as a Service (SDaaS) Outsourced security department providing ongoing security expertise and resources to organizations without an internal security team.
- Vulnerability Management Platform Platform for ongoing vulnerability identification, tracking, and remediation management across organizational assets.
- Shift Security Left / Cloud Infrastructure / DevSecOps Integration of security practices into development pipelines and cloud infrastructure, embedding security throughout the software development lifecycle.
- Cloud Intrusion Readiness Assessment service to evaluate cloud environment preparedness for detecting and responding to intrusion attempts.
- Application Security Assessment Comprehensive security assessment of applications to identify vulnerabilities and security weaknesses.
- Security Awareness Training Training programs to enhance cybersecurity awareness and create a culture of secure practices among employees.
Quantifiable outcome
- Discovered AD vulnerability that six years of pen testing had not found
Companies that use Mirai Security
Customer profileNamed customers3 records
Segments7 records
Ideal customer profiles2 records
Mirai Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Mirai Security partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- Microsoft AzurecoreCertified Microsoft Azure cloud security specialists. Offers Azure Cloud Security Assessment services. Team holds MS-AZ-500 certification.
- AWScoreCertified AWS cloud security specialists. Offers AWS-related security assessments and cloud security services. AWS certification icon displayed on homepage.
- BSides VancouverminorCommunity security event sponsorship and support. Part of company's commitment to supporting the security community through sponsorship and mentorship.
- BSidesVI (Vancouver Island)minorCommunity security event sponsorship. Part of ongoing security community support initiatives.
- RRB (likely a security/reseller partner)minorChannel partner with logo displayed on partners page.
Scale indicators1 record
Recent moves5 records
Expansion highlights5 records
Mirai Security competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US-based boutique cybersecurity consulting firm specializing in offensive security, pen testing, red team, and attack surface management. Highly comparable as a similarly sized, services-led boutique with strong technical reputation.
- GoSecure: Canadian-headquartered cybersecurity firm providing MDR, pen testing, IR, and advisory services across North America. Comparable in scale, service mix, and geography — directly overlapping with Mirai's pen testing, IR, and GRC offerings.
- Herjavec Group: Toronto-based cybersecurity services and MSSP firm founded by Robert Herjavec, offering similar advisory, managed detection, and incident response services. Strong comparable given shared Canadian headquarters, North American market focus, and full-spectrum service portfolio.
Broad incumbents
- NCC Group: Global cybersecurity and software resilience firm with strong pen testing, GRC, and IR practices. Directly comparable in service mix and target customers, but operates at much greater scale across multiple geographies.
- Optiv: Large US-based security solutions integrator and MSSP offering end-to-end advisory, integration, and managed services. Overlaps with Mirai across pen testing, GRC, and IR but at much greater scale and with proprietary platform offerings.
- Secureworks: Global MSSP offering managed detection, vulnerability management, and consulting. Comparable in GRC and security advisory services, but operates a SaaS-like Taegis platform Mirai does not have.
- Trustwave: Global cybersecurity company offering managed security, pen testing, GRC, and database security services. Overlaps with Mirai across the same service taxonomy but operates at significantly larger scale with proprietary technology.
- Mandiant (Google Cloud): Industry-leading incident response and threat intelligence firm (now part of Google Cloud). Comparable via Mirai's IR retainer and security testing practices, though at vastly larger scale and with stronger brand recognition.
Emerging players
- Cybereason: Cybersecurity firm offering MDR and IR services alongside its endpoint detection platform. Comparable via overlapping IR and threat-hunting practices, though primarily a product company rather than a pure services firm.
Regional players
- Scalar Decisions (now part of CDW): Canadian-headquartered IT and security services firm with strong pen testing and advisory practices. Comparable via shared Canadian base and similar service portfolio, though historically broader in IT infrastructure services.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat2 records
Key risks5 records
Key highlights6 records
Customer concentration
Mirai Security social profiles
Digital presenceMirai Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Mirai Security leadership team
Management profileNumber of profiles
Profiles1 record
Mirai Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Mirai Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Mirai Security
What does Mirai Security do?
Mirai Security provides cybersecurity consulting and professional services, delivering penetration testing, Red Team operations, incident response, cloud security assessments on Azure and AWS, governance/risk/compliance (GRC) advisory, and security awareness training. Services are tailored to each client's needs and delivered by certified practitioners, with the company serving both SMEs exploring security posture and large enterprises requiring specialized expertise.
Is Mirai Security a public or private company?
Mirai Security is a private company. It is classified as unknown and is currently operating.
When was Mirai Security founded?
Mirai Security was founded in 2017. It employs 11 to 50 people.
Where is Mirai Security based?
Mirai Security is headquartered in Vancouver, Canada, in the North America region.
How does Mirai Security make money?
Two revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are compliance and Certification Services.
Who are Mirai Security's main competitors?
Direct peers on record are Bishop Fox, GoSecure and Herjavec Group. Broad incumbents are NCC Group, Optiv, Secureworks, Trustwave and Mandiant (Google Cloud). Cybereason is listed as an emerging player. Scalar Decisions (now part of CDW) is listed as a regional player.
Does Mirai Security have an API?
No public API is recorded for Mirai Security.
What industry is Mirai Security in?
Mirai Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519.