Kaiju Security
- Company typePrivate
- Founded2021
- HeadquartersEdmonds, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Kaiju Security does
Kaiju Security is a private, boutique offensive security consulting firm headquartered in Seattle, WA, founded in 2021 by Gary DeMercurio (CEO) and Justin Wynn (President) following the settlement of a wrongful-arrest lawsuit stemming from an authorized courthouse security assessment in Iowa. The firm provides adversary simulation and offensive security services operating across digital, physical, and social attack surfaces, structured around six core offerings: Red Team Operations, Penetration Testing, Physical Security testing, Social Engineering assessments, Kaijin Ransomware Attack Simulation, and Breach Data monitoring. A key differentiator is the same-team-delivers-the-service model, in which the experts consulted during scoping are the practitioners who execute the engagement, with no handoff or substitution.
The firm's underlying technology is a combination of proprietary offensive tooling and human-led adversarial methodology rather than a unified software platform. Kaijin is a ransomware assessment tool that evaluates network susceptibility using reverse-engineered attack paths derived from active ransomware campaigns. PolyDrop is a multi-language BYOSI (Bring-Your-Own-Script-Interpreter) exploitation tool, co-developed with the MalwareSupportGroup, that leverages 13 scripting languages to bypass endpoint detection products from Microsoft Defender, CrowdStrike, SentinelOne, Palo Alto Networks, and Fortinet. The firm supplements delivery with a content-led marketing motion via its security blog, conference presence at DEF CON and military events, and active LinkedIn thought leadership.
Kaiju Security generates revenue through project-based professional services engagements sold via a direct, sales-led engagement model with custom pricing that is not publicly disclosed. Target customers include enterprise organizations requiring comprehensive adversary simulation, regulated industries with compliance-driven testing needs (financial institutions, healthcare, government contractors), and financial institutions with elevated physical and cyber risk profiles. The firm currently operates with 1-10 employees, serves only the United States market, has not raised institutional funding, and distributes exclusively through direct website and phone contact rather than channel partners.
Kaiju Security firmographics
Firmographics- Name
- Kaiju Security
- Legal name
- Kaiju Security
- Website
- https://kaiju-security.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
Kaiju Security industry classification
Industry- Product category
- Offensive Security Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Breach & Attack Simulation (BAS) (HDADAHAD)
- akta.pro secondary industry
- Security Analytics & Detection Engineering (HDADAGAE)
Keywords
Where Kaiju Security is headquartered
LocationHeadquarters
- HQ city
- Edmonds
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Kaiju Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Security Consulting Services: Kaiju Security generates revenue through professional security consulting and testing services. The company provides tailored, one-on-one security solutions where the expert team engaged is the same team that delivers the service. Engagements are structured for organizations requiring continuity and precision, covering red team operations, penetration testing, physical security, social engineering, ransomware simulation, and breach data services. Revenue is generated through project-based professional services engagements with organizations requiring offensive security testing and adversarial simulation.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
Kaiju Security product offering
Product offeringCore offering
Kaiju Security is a boutique offensive security firm that provides tailored adversary simulation services across digital, physical, and social attack surfaces. The company delivers red team operations, penetration testing, physical security testing, social engineering assessments, ransomware attack simulation via its proprietary Kaijin tool, and breach data monitoring. Engagements are led by the same expert team from consultation through final deliverable, with no handoffs or substitutions.
Product overview
Kaiju Security provides adversary simulation and offensive security services operating across digital, physical, and social attack surfaces. The company offers a portfolio of six core services: Red Team Operations, Penetration Testing, Physical Security, Social Engineering, Kaijin Ransomware Attack Simulation, and Breach Data. These services are designed to expose risk where domains intersect, addressing how real adversaries move, exploit, and pivot. Kaiju Security emphasizes threat-informed offense through tailored, expert-led engagements without handoffs or substitutions.
Differentiator
Problem solved
Functional benefit
Brands
- Kaijin: Ransomware attack simulation tool that evaluates network susceptibility to ransomware using reverse-engineered attack paths derived from active ransomware campaigns.
Products and services
- Red Team Operations Covert and objective-driven security testing operations executed methodically to avoid detection and escalate deliberately to achieve defined objectives. Designed to help organizations understand how a determined adversary would operate inside their environment, where controls fail, and what goes unnoticed.
- Penetration Testing Fast, coverage-focused vulnerability identification service that establishes a clear security baseline and surfaces immediate risk across an environment. Effective for quick insight, broad visibility, or program enhancement support across enterprise networks and applications.
- Physical Security Testing Adversarial evaluation of physical security including facility access controls, workstation security, network exposure, and employee awareness. Includes training on identifying gaps and actionable recommendations mapped to recognized security frameworks, providing defensible physical security controls and stronger audit readiness.
- Social Engineering Testing and training service that exposes human-driven risk from impersonation, manipulation, and access abuse. Addresses cyber espionage tactics that bypass technical controls and operate undetected, helping organizations act before attacks impact the business.
- Kaijin Ransomware Attack Simulation Ransomware assessment using the proprietary Kaijin tool that evaluates network susceptibility to ransomware via reverse-engineered attack paths derived from active ransomware campaigns. Demonstrates how ransomware executes inside the environment while the client maintains full control and visibility throughout the step-by-step observation.
- Breach Data Dark web and open platform monitoring service that identifies company data exposure, validates exposure scope, and provides clarity on impact to enable informed action and communication from a position of control after a breach.
Quantifiable outcome
- Over 80% compromise rate observed at companies with over 10,000 employees due to social engineering attacks
- +3 more outcomes
Companies that use Kaiju Security
Customer profileSegments3 records
Ideal customer profiles2 records
Kaiju Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
Kaiju Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- MalwareSupportGroupcoreKaiju Security collaborated with the MalwareSupportGroup, a collective of seasoned malware developers, to develop the PolyDrop tool and BYOSI (Bring-Your-Own-Script-Interpreter) exploitation technique. This partnership leveraged MalwareSupportGroup's expertise in understanding EDR bypass methodologies and malware development to create a tool that exposes significant gaps in current antivirus and endpoint detection systems. The collaboration resulted in a novel exploitation technique that is currently undetectable by most mainstream EDR vendors.
Scale indicators1 record
Recent moves5 records
Expansion highlights4 records
Kaiju Security competitors and assessment
Company assessmentDirect peers
- Coalfire: Coalfire provides offensive security services including red teaming, penetration testing, and adversarial simulation alongside its broader cybersecurity advisory portfolio. It competes for the same enterprise pentest and red team budgets as Kaiju.
- Bishop Fox: Bishop Fox is a leading boutique offensive security firm offering red teaming, penetration testing, and adversary simulation services. It is the closest comparable in business model — senior practitioner-led engagements, continuous security research, and tool development — and competes for the same enterprise offensive security buyers.
- Praetorian: Praetorian is an offensive security firm offering red team operations, penetration testing, and attack surface management, with an emphasis on proprietary tooling and continuous security research — closely aligned to Kaiju's positioning.
- Black Hills Information Security: Black Hills Information Security is a boutique offensive security firm combining consulting (pentesting, red teaming) with active community content (webcasts, training). It competes for similar enterprise adversary simulation work and shares a content-led go-to-market motion.
- TrustedSec: TrustedSec is a well-known boutique red team and offensive security consultancy with a similar founder-driven brand, strong community presence, and focus on adversary simulation, social engineering, and penetration testing services for enterprises.
- Silent Break Security: Silent Break Security is a boutique offensive security consultancy offering red teaming, penetration testing, and security research services. Its small-team, senior-practitioner delivery model is structurally similar to Kaiju Security's boutique approach.
Broad incumbents
- NCC Group: NCC Group is a large, established cybersecurity consultancy with a global red team and offensive security practice. It serves the same enterprise buyer with a much broader geographic footprint and delivery capacity, often displacing boutique firms on multi-region mandates.
- Mandiant (Google Cloud): Mandiant, now part of Google Cloud, operates a frontline red team and adversary simulation practice backed by incident response intelligence. It overlaps with Kaiju on enterprise red team services but offers a much wider portfolio including IR, threat intel, and managed defense.
- CrowdStrike: CrowdStrike offers adversary simulation and breach and attack simulation capabilities as part of its Falcon platform, directly competing for offensive security testing budgets and raising the bar on productized, recurring BAS offerings that boutique firms must differentiate against.
Emerging players
- PlexTrac: PlexTrac is a continuous red teaming and security testing management platform that productizes offensive testing workflows. It represents the emerging software-enabled direction the boutique consulting model may need to evolve toward to scale beyond engagement-based revenue.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Kaiju Security social profiles
Digital presenceKaiju Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kaiju Security leadership team
Management profileNumber of profiles
Profiles2 records
Kaiju Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kaiju Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kaiju Security
What does Kaiju Security do?
Kaiju Security is a boutique offensive security firm that provides tailored adversary simulation services across digital, physical, and social attack surfaces. The company delivers red team operations, penetration testing, physical security testing, social engineering assessments, ransomware attack simulation via its proprietary Kaijin tool, and breach data monitoring. Engagements are led by the same expert team from consultation through final deliverable, with no handoffs or substitutions.
Is Kaiju Security a public or private company?
Kaiju Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Kaiju Security founded?
Kaiju Security was founded in 2021. It employs 1 to 10 people.
Where is Kaiju Security based?
Kaiju Security is headquartered in Edmonds, United States, in the North America region.
How does Kaiju Security make money?
One revenue line is on record: professional Security Consulting Services.
Who are Kaiju Security's main competitors?
Direct peers on record are Coalfire, Bishop Fox, Praetorian, Black Hills Information Security, TrustedSec and Silent Break Security. Broad incumbents are NCC Group, Mandiant (Google Cloud) and CrowdStrike. PlexTrac is listed as an emerging player.
Does Kaiju Security have an API?
No public API is recorded for Kaiju Security.
What industry is Kaiju Security in?
Kaiju Security's product category is Offensive Security Services. Its primary akta.pro industry code is HDADAHAD, Breach & Attack Simulation (BAS), with a secondary code of HDADAGAE, Security Analytics & Detection Engineering. Its NAICS code is 5616 and its SIC code is 8700.