5 firms name this framework on its website
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Arista Cyber
Industrial cybersecurity firm for OT and ICS: risk assessments, gap analysis, IEC 62443 zone and conduit design, vulnerability assessments and incident response planning for energy and industrial operators.
- OT and ICS
- GRC advisory
- Vulnerability mgmt
- IR and forensics
- IEC 62443
- NERC CIP
- NIST CSF
CyberHunter Solutions
Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Cloud security
- NIST CSF
- CIS Controls
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
PlutoSec
Etobicoke firm covering penetration testing, red team, compliance readiness (ISO 27001, SOC 2, PCI DSS, HIPAA), cloud security, managed SOC/MDR, secure development and incident response.
- Pen testing
- Red team
- GRC advisory
- Audit and certification
- Cloud security
- +3
- ISO 27001
- SOC 2
- PCI DSS
- NIST CSF
- ITSG-33
- +2
Learn more
// more
Other frameworks
A firm appears here only when its own website names the framework. That is not a statement that it is certified, accredited, or qualified for it. Confirm with the firm. How the directory works.