Skip to content
Cyber Security Firms
Ranked and checked

The best cyber security firms in the United States

The US cyber security market runs from four-figure managed detection contracts for a fifty-person company to national incident response retainers, and most firms say they do all of it. These ten were ranked on the checks we run on every firm. Rank one is the best overall, ranks two to four are the best for small business, managed detection and compliance work, and the rest cleared the same checks.

Checked . Nobody pays to be assessed.

  1. 01Best overall
  2. 02Best for small business
  3. 03Best for managed detection
  4. 04Best for compliance
  5. 05+The rest of the shortlist, ranked on the same checks
Rank 01
CrowdStrike logo

CrowdStrike

Best overall

The Falcon platform plus a staffed managed detection service, at national scale.

Checked
Why they are on this list
  • Falcon is one sensor covering endpoint, cloud workloads and identity, so a detection in one place is correlated with the others rather than living in a separate console
  • Falcon Complete is a staffed managed detection and response service run on the same platform, which is the part most buyers actually want from a vendor this size
  • Runs a dedicated incident response practice that is retained by large organizations before an incident, not only called after one
  • Publicly listed on the Nasdaq, so financials, leadership and material incidents are on the record rather than taken on trust
  • Publishes an annual Global Threat Report with named adversary groups and dwell-time figures, which is where much of the field's benchmark data comes from
Founded
2011
Size
Over 5,000 staff
Attestations
FedRAMP authorized
Sectors
Enterprise, Public sector, Financial services
Rank 02
Huntress logo

Huntress

Best for small business

Managed endpoint and identity protection built for small businesses and the IT providers that serve them.

Checked
Why they are on this list
  • Sells almost entirely to small and mid-sized organizations, mostly through the managed IT providers they already use, so the product is priced and packaged for a company without a security team
  • A staffed security operations center reviews detections around the clock and writes the remediation steps in plain language, rather than forwarding raw alerts
  • Started with a persistent-foothold detection that catches attackers who are already inside, which is the failure mode small businesses most often discover late
  • Publishes pricing tiers and a per-endpoint model, so a fifty-seat company can budget without a sales call
  • Adds identity threat detection for Microsoft 365 accounts, which is where most small business compromises now start
Founded
2015
Size
500 to 1,000 staff
Sectors
Small business, Managed service providers, Healthcare, Education
Rank 03
Arctic Wolf logo

Arctic Wolf

Best for managed detection

Security operations as a service, with a named concierge team on every account.

Checked
Why they are on this list
  • Sells the operations center rather than a product, so the buyer gets monitoring across endpoint, network, cloud and identity without standardizing on one vendor's agent
  • Assigns a named concierge security team to each customer, which is the difference between a ticket queue and someone who knows the environment
  • Runs incident response as a retainer and as an emergency service, with response commitments written into the contract
  • Built for the mid-market: the typical customer is too large for a reseller package and too small to staff a 24-hour team
  • Includes managed risk scanning and awareness training in the same subscription rather than as separate line items
Founded
2012
Size
Over 2,000 staff
Sectors
Mid-market, Healthcare, Manufacturing, Local government
Rank 04

Coalfire

Best for compliance

Assessors on staff for the frameworks that regulators and customers actually ask about.

Checked
Why they are on this list
  • Accredited to assess against PCI DSS, FedRAMP and HITRUST in-house, so the same firm can advise on a gap and then perform the assessment that closes it
  • One of the assessment organizations most large cloud providers use for FedRAMP authorizations, which is the hardest US compliance regime to get through
  • Runs a penetration testing and offensive security practice alongside compliance, so a finding gets tested rather than only documented
  • Publishes assessment methodology and scoping guidance, which makes it easier to compare a quote against the work being proposed
  • Twenty-five years in operation, most of it in regulated industries, with a named practice for each framework rather than a generalist team
Founded
2001
Size
1,000 to 2,000 staff
Attestations
PCI Qualified Security Assessor, FedRAMP Third Party Assessment Organization, HITRUST assessor
Sectors
Cloud providers, Healthcare, Financial services, Federal contractors
Rank 05

Palo Alto Networks Unit 42

The incident response and threat intelligence arm of the largest US security vendor.

Checked
  • Incident response retainers with a response commitment, backed by a team that handles ransomware negotiations and recovery as well as the investigation
  • Threat intelligence published under named actor groups, so a customer can read what the responders have actually seen this quarter
  • Runs on the parent company's Cortex platform, so an engagement can move from investigation to managed detection without a tooling change
  • Publishes an annual incident response report with median dwell times and initial access statistics drawn from its own cases
Founded
2005
Size
Over 10,000 staff (parent company)
Sectors
Enterprise, Public sector, Financial services
Rank 06

Mandiant

The incident response firm that named the field's biggest intrusions, now part of Google Cloud.

Checked
  • Has handled a large share of the headline intrusions of the last fifteen years, and its annual M-Trends report is the reference for dwell-time and initial-access statistics
  • Acquired by Google in 2022, so the intelligence now sits alongside Google's own telemetry and the Chronicle security operations platform
  • Publishes named threat actor research that the rest of the industry cites, which is a reasonable proxy for what the response team actually knows
  • Offers retainers, on-demand response and a managed defense service, so an organization can start with a retainer and grow into monitoring
Founded
2004
Size
Over 2,000 staff
Sectors
Enterprise, Government, Critical infrastructure
Also on the shortlist
Rank 07

Rapid7

Website, Rapid7
Rank 08

Optiv

Website, Optiv
Rank 09

Trustwave

Website, Trustwave
Rank 10

Secureworks

Website, Secureworks

Cyber Security Firms may earn a referral fee if you engage a firm through a link on this site. How that works.

How to Choose a Cyber Security Firm

Start with the problem, not the vendor. A company that has never had monitoring needs managed detection and response before it needs a penetration test, because a test finds holes and monitoring finds the person already using one. A company facing a customer's SOC 2 questionnaire needs an assessor, and a company that has just found ransomware on a server needs an incident response retainer it should have bought last year.

Then check three things that the firm's own website will not volunteer. First, who is on the other end of an alert at night, and what they are allowed to do without a phone call. Second, whether the attestations the firm lists can be found on the certifying body's own register. Third, whether the firm will give a starting price for the engagement you described before a discovery call.

What the Ranks Mean

Rank one is the best firm overall on the checks in the editorial policy. Ranks two to four are the best firm for one kind of buyer each: a small business, an organization buying managed detection, and an organization facing compliance work. The rest of the shortlist cleared the same checks and is ordered on them. A low rank on this list is not a warning; a firm that failed a check is not on it.

Questions about hiring a cyber security firm

What does a cyber security firm actually do for a small business?

Most small businesses buy one of two things: monitoring, where a firm watches your computers, accounts and email around the clock and steps in when something is wrong, or a project, such as a security assessment, a penetration test or help meeting a compliance requirement a customer has asked for. Managed detection and response is the monitoring product, and for a company without a security team it is usually the right first purchase.

How much do cyber security firms charge?

Managed detection for a small business is typically priced per device or per user per month, and often lands in the low thousands of dollars a year for a fifty-person company. Penetration tests are scoped projects and commonly run from a few thousand dollars for a small external test to tens of thousands for a large application. Incident response is billed hourly or on a retainer. Any firm that will not give a starting range before a call is telling you something.

What is the difference between managed detection and response and a managed security service provider?

A managed security service provider historically managed your security tools and forwarded alerts. Managed detection and response means the firm investigates the alerts itself and takes action, such as isolating a machine, before telling you. In practice most firms now sell the second thing and many still call it the first. Ask who acts on an alert at three in the morning, and what they are allowed to do without waking you.

Do I need a firm in my own city?

For monitoring, no. The work is remote and the right firm may be anywhere in the country. For incident response, compliance work and anything involving your physical premises or staff, a firm with people nearby is worth more than it sounds, which is why this site keeps one list per metro alongside the national list.

How is this list put together?

Every firm is checked on what it actually does, the attestations that can be verified, its track record, a response test where we contact it as a prospective client, and how clear it is about scope and price. Rank one is the best firm overall. Ranks two to four are the best for small business, managed detection and compliance. The editorial policy sets out each check and what fails it.