GRIMM
GRIMM is a private cybersecurity research and consulting firm specializing in cyber-physical systems, ICS/OT, and automotive security, serving federal defense, critical infrastructure, and automotive clients with vulnerability assessments, red-team services, and physical training hardware.
- Company typePrivate
- Founded-
- HeadquartersCedar Springs, United States
- Headcount—
- GTM typeB2B
- OfferingServices
What GRIMM does
GRIMM (legal entity SMFS, Inc.) is a private cybersecurity research and consulting firm headquartered in Cedar Springs, Michigan, with an additional facility announced in Virginia in February 2020. The company specializes in cyber-physical systems (CyPhy), embedded systems, Industrial Control Systems/Operational Technology (ICS/OT), and automotive/connected mobility security — niches where traditional IT cybersecurity firms have limited depth. Its team comprises former U.S. Department of Defense and government cybersecurity researchers, and it is led by CEO John Adams and CEO Jennifer Tisdale (the latter appointed in February 2022), with founder Bryson Bort also associated with the company and the co-founding of the ICS Village non-profit.
GRIMM operates two interlocking business lines. The first is professional services: red team/penetration testing, threat hunting, cyber threat intelligence, application security, security management, threat modeling, tabletop exercises, tailored software development, and end-to-end vulnerability assessments of embedded systems for federal defense, critical infrastructure, automotive, healthcare, financial services, and other verticals. The second is a product line of physical training environments and open-source tooling — including CanCat and CANT for CAN bus analysis, the INCITE, KITE, and LITE ICS training kits, the TinyTown miniature 3D city, CyberHive wall display, car-hacking workbenches, and customizable Capture-the-Flag challenges — distributed partly through the Coursestorm learning platform.
GRIMM monetizes primarily through quote-based professional services engagements with enterprise and government clients, supplemented by hardware product sales of training environments and an online training catalog. The company pursues an enterprise field sales motion with a "Contact a Consultant" website CTA, complemented by event-driven community marketing through partnerships with Auto-ISAC, ICS Village, the CyberTruck Challenge, and others. It has also received research recognition via a 2020 DARPA award for Assured MicroPatching (AMP), and in 2023 formed alliances with Ampere (ICS security) and CYBER RANGES to extend reach in critical infrastructure and training delivery. Ownership appears founder/management-held, with no disclosed external venture funding.
GRIMM firmographics
Firmographics- Name
- GRIMM
- Legal name
- SMFS, Inc.
- Website
- https://grimmcyber.com
- Company type
- Private
- Operating status
- Operating
- Short description
- GRIMM is a private cybersecurity research and consulting firm specializing in cyber-physical systems, ICS/OT, and automotive security, serving federal defense, critical infrastructure, and automotive clients with vulnerability assessments, red-team services, and physical training hardware.
- Ownership category
- akta.pro rank
GRIMM industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Investigation and Security Services (5616), Security Systems Services (56162)
- SIC
- Services-Detective, Guard & Armored Car Services (7381), Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Threat Intelligence, Hunting & Adversary Emulation (BPAKAHAE), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Penetration Testing & Red Teaming (BPAKADAE), Deception Technology & Threat Hunting (HDADAGAI)
Keywords
Where GRIMM is headquartered
LocationHeadquarters
- HQ city
- Cedar Springs
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
GRIMM business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Supply Chain, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consulting Services: Professional services including red team/penetration testing, threat modeling, security assessments, and tailored software development for enterprise and government clients.
- Technical Training and Education: Off-the-shelf and custom training courses covering application security, automotive cybersecurity, ICS security, and penetration testing. Delivered through classroom, virtual, and hands-on formats.
- Cyber Range Products: Sale of physical training products including ICS Cyber Range walls, TinyTown miniature cities, INCITE training kits, KITE training environments, and car-hacking workbenches with accompanying VMs and training materials.
- Managed Security Services: Ongoing security management solutions and threat hunting services for clients requiring continuous security monitoring and support.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
GRIMM product offering
Product offeringCore offering
GRIMM provides cybersecurity research, consulting, and testing services such as red team/penetration testing, threat hunting, threat modeling, cyber threat intelligence, application security, security management, and tailored software, alongside technical training and physical cyber-range products. The company specializes in cyber-physical systems, ICS/OT, and automotive cybersecurity for federal, critical infrastructure, and enterprise clients.
Product overview
GRIMM offers a cybersecurity R&D portfolio consisting of physical training hardware products and professional security services. The product line includes hands-on ICS training kits (LITE, INCITE, KITE), cyber-physical training environments (TinyTown, CyberHive), car-hacking workbenches, and Capture-the-Flag challenges. GRIMM also provides CyPhy™ cyber-physical systems security assessments, along with services including Red Team/Penetration Testing, Threat Hunting, Cyber Threat Intelligence, Application Security, Security Management, Technical Training and Education, Threat Modeling, Tabletop Exercises, and Tailored Software Development. The company also develops open-source tools like CanCat (CAN bus reverse-engineering) and CANT for automotive security research.
Differentiator
Problem solved
Functional benefit
Brands
- CyPhy™: Cyber-Physical Systems Security team that performs vulnerability assessments and provides technical solutions for embedded systems across sectors including Critical Infrastructure, Manufacturing, Energy, Financial Services, Healthcare, and Water.
Products and services
- Little ICS Training Environment (LITE) Compact ICS training kit providing hands-on PLC programming and networking experience using basic inputs and outputs to familiarize students with PLC programming and communication. Sold as a physical training product to enterprise and education customers.
- Industrial Control Innovative Training Environment (INCITE) Comprehensive ICS training solution with rugged training kits featuring PLC, HMI, and network security learning capabilities including ICS protocols, active scanning, and network manipulation. Sold to enterprise and education customers.
- TinyTown 2'x3' 3D-printed miniature city with individually illuminated cyber-physical assets for hands-on visual learning objectives in cybersecurity training. Sold as a physical training product.
- CyberHive Large custom 5'x6' wall-on-wheels display of ICS networks found in OT environments with configured assets simulating real-world scenarios such as water tank operations. Sold as a physical training product.
- Kickstart ICS Training Environment (KITE) Introductory ICS and OT cybersecurity course with hands-on hardware experience designed to introduce students to ICS, OT, and Critical Infrastructure Cybersecurity concepts. Sold as a training product.
- Capture-the-Flag Challenges (CTF) Customizable cybersecurity challenges for various skill levels and learning objectives, delivered as VMs run on customer-provided servers. Sold as a training product.
- Car-Hacking Workbenches Automotive cybersecurity training environments using actual vehicle hardware to provide hands-on training experience in understanding cybersecurity implications for advanced transportation mobility. Sold as a physical training product.
- CyPhy Cyber-Physical Systems Security Assessments Cyber-physical systems security service performing vulnerability assessments and providing technical solutions for embedded systems across Critical Infrastructure sectors including Manufacturing, Energy, Financial Services, Healthcare, and Water. Delivered to enterprise and government clients.
- Red Team / Penetration Testing Security testing services using blackbox/whitebox testing approaches to evaluate areas of threats and weaknesses in client systems. Delivered to enterprise and government clients.
- Threat Hunting Proactive security service to discover entry-points and identify threats before they can be exploited. Delivered to enterprise and government clients.
- Cyber Threat Intelligence Intelligence services helping organizations understand and respond to cyber threats targeting their environments. Delivered to enterprise and government clients.
- Application Security Security assessment and consulting services for applications and software systems. Delivered to enterprise and government clients.
- Security Management Solutions Solutions helping organizations manage their overall cybersecurity posture and risk. Delivered to enterprise and government clients.
- Tailored Software Custom software development services for cybersecurity-specific needs and requirements. Delivered to enterprise and government clients.
- Technical Training and Education Off-the-shelf and custom training courses teaching how to think like an attacker, designed for developers, engineers, penetration testers, and security professionals. Delivered through classroom, virtual, and hands-on formats.
- Threat Modeling Structured approach to identify and prioritize potential threats to systems and determine appropriate countermeasures. Delivered to enterprise and government clients.
- Tabletop Exercises Facilitated exercises helping organizations practice and improve their incident response procedures. Delivered to enterprise and government clients.
- Advanced Transportation Mobility Specialized security services for connected and autonomous vehicles, automotive systems, and transportation sector cybersecurity. Delivered to enterprise and government clients.
Companies that use GRIMM
Customer profileNamed customers3 records
Segments6 records
Ideal customer profiles3 records
GRIMM technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
GRIMM partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core, secondary and minor.
- CYBER RANGEScoreGRIMM and CYBER RANGES formed an alliance to make advanced cybersecurity solutions more accessible. This partnership combines GRIMM's cybersecurity expertise with CYBER RANGES' platforms to deliver comprehensive security training and solutions.
- AmperecoreGRIMM announced an alliance with Ampere, a security consulting firm specializing in Industrial Control Systems (ICS). Together they pledge to secure critical infrastructure around the globe through combined expertise in ICS security.
- Walsh CollegesecondaryPartnership between GRIMM and Walsh College focused on automotive cybersecurity education and workforce development. Combines academic resources with industry expertise.
- Auto-ISACcoreGRIMM partnered with Auto-ISAC on the National Highway Traffic Safety Administration (NHTSA) initiative for Automotive Cybersecurity Training (ACT) pilot program. GRIMM developed advanced automotive security training that kicked off in April 2022 for Auto-ISAC members. This formal education program establishes a global standard for automotive cybersecurity training and education.
- Square One (Michigan Educational Non-Profit)secondaryGRIMM announced a cyber partnership with Michigan educational non-profit Square One focused on developing new high school curriculum for automotive cybersecurity, preparing students for careers in the field.
- ICS VillagecoreICS Village is a non-profit organization focused on Control System security and awareness, co-founded by GRIMM Founder Bryson Bort in 2017. The organization provides interactive learning experiences with real ICS equipment including PLCs, HMIs, RTUs, and robotic arms.
- Black Girls CODEminorAll proceeds from GRIMM's Swag Shop are donated to Black Girls CODE, a charity focused on increasing the number of women of color in technology by empowering girls ages 7-17 with computer science and technology skills.
- U.S. Army Ground Vehicle Systems CentercoreCollaborative vehicle cyber security demonstration with U.S. Army Ground Vehicle Systems Center, Michigan Economic Development Corporation (MEDC), and Michigan State Police announced October 2022.
Scale indicators2 records
Recent moves7 records
Expansion highlights5 records
GRIMM competitors and assessment
Company assessmentDirect peers
- Dragos: Dragos is a leading ICS/OT cybersecurity vendor focused on industrial asset identification, threat detection, and incident response. It directly competes with GRIMM in critical infrastructure cyber-physical assessments while offering a more mature software platform.
- Nozomi Networks: Nozomi Networks delivers OT and IoT visibility, vulnerability management, and threat detection for critical infrastructure. It competes with GRIMM's CyPhy practice and has a strong presence in the same manufacturing, energy, and water segments.
- Atredis Partners: Atredis Partners is a boutique security research and consulting firm with deep embedded systems, IoT, and hardware expertise — closely matching GRIMM's cyber-physical and automotive security research profile at a similar scale.
- Bishop Fox: Bishop Fox is an offensive security firm providing penetration testing, red teaming, and attack surface management. Directly comparable to GRIMM's red team and security assessment services across enterprise clients.
- IOActive: IOActive is a security research and consulting firm specializing in penetration testing, hardware/embedded security, automotive cybersecurity, and IoT — closely paralleling GRIMM's cyber-physical and red team services for enterprise and government clients.
- Pen Test Partners: Pen Test Partners is a UK-based penetration testing consultancy with strong IoT, connected vehicle, and industrial security practices. Highly comparable to GRIMM's red team and automotive cybersecurity offerings, though primarily serving EMEA clients.
- Claroty: Claroty provides cybersecurity for industrial, healthcare, and commercial environments via its OT visibility and segmentation platform. Overlaps with GRIMM's critical infrastructure and medical device security verticals, with a more productized approach.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity consulting and software firm offering penetration testing, threat intelligence, and managed detection services. Overlaps broadly with GRIMM's service portfolio but at significantly larger scale and geographic reach.
- Mandiant (Google Cloud): Mandiant is a leading incident response, threat intelligence, and security consulting firm (now part of Google Cloud). It competes with GRIMM on threat hunting, threat intelligence, and red team engagements at the enterprise tier.
Emerging players
- Cylera: Cylera specializes in healthcare IoT and medical device cybersecurity — directly overlapping with GRIMM's Medical Devices & Healthcare vertical but offering a software platform rather than services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
GRIMM social profiles
Digital presenceGRIMM financial estimates
Financial estimateRevenue estimate
Valuation estimate
GRIMM leadership team
Management profileNumber of profiles
Profiles5 records
GRIMM funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GRIMM M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GRIMM
What does GRIMM do?
GRIMM provides cybersecurity research, consulting, and testing services such as red team/penetration testing, threat hunting, threat modeling, cyber threat intelligence, application security, security management, and tailored software, alongside technical training and physical cyber-range products. The company specializes in cyber-physical systems, ICS/OT, and automotive cybersecurity for federal, critical infrastructure, and enterprise clients.
Is GRIMM a public or private company?
GRIMM is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was GRIMM founded?
GRIMM was founded in -1.
Where is GRIMM based?
GRIMM is headquartered in Cedar Springs, United States, in the North America region.
How does GRIMM make money?
Four revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are technical Training and Education, cyber Range Products and managed Security Services.
Who are GRIMM's main competitors?
Direct peers on record are Dragos, Nozomi Networks, Atredis Partners, Bishop Fox, IOActive, Pen Test Partners and Claroty. Broad incumbents are NCC Group and Mandiant (Google Cloud). Cylera is listed as an emerging player.
Does GRIMM have an API?
No public API is recorded for GRIMM.
What industry is GRIMM in?
GRIMM's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAE, Threat Intelligence, Hunting & Adversary Emulation. Its NAICS code is 5616 and its SIC code is 7381.