Cybersecurity Companies

Categories · Certification

ISO 27001

Companies that list an ISO/IEC 27001 information-security management certificate. As listed — we do not audit the certificate.

47 companies. Search a country or city. Tick features, then apply once. Organic order is not for sale.

Indexorganic · newest first · page 2/2
CompanyWhat they sellFocus / ratingStatus

Tenable

Columbia, US · Product vendor

Exposure management and vulnerability scanning across IT, cloud, and OT.

Threat & vulnerability · Cyber-physical

Rapid7

Boston, US · Product vendor

SIEM, vulnerability management, and detection from InsightVM and InsightIDR.

Security operations · Threat & vulnerability

Semgrep

Detroit, US · Product vendor

Open-source SAST and a commercial code security platform.

Application security

Netskope

Santa Clara, US · Product vendor

SSE, CASB, and data protection delivered from a security cloud.

Network security · Data protection

SecurityScorecard

New York, US · Product vendor

Security ratings and vendor-risk monitoring.

GRC · Attack surface

Wiz

New York, US · Product vendor

Cloud security graph for code-to-cloud risk.

Cloud security · Application security
Promoted

Censys

Ann Arbor, US · Research / intel

Internet-wide attack surface and exposure intelligence.

Attack surface · Threat & vulnerability

Aqua Security

Boston, US · Product vendor

Cloud-native application protection from code to runtime.

Cloud security · Application security

Cloudflare

San Francisco, US · Product vendor

CDN, WAF, Zero Trust, and bot management on a global edge.

Network security · Application security

Microsoft Security

Redmond, US · Product vendor

Defender, Entra, Sentinel, and Purview across the Microsoft estate.

Endpoint security · Identity

Cisco Security

San Jose, US · Product vendor

Network, email, and SASE security from the campus to the cloud.

Network security · Email & messaging

Qualys

Foster City, US · Product vendor

VMDR, cloud posture, and compliance scanning as a service.

Threat & vulnerability · Cloud security

Splunk

San Francisco, US · Product vendor

SIEM, observability, and security analytics now under Cisco.

Security operations

Mimecast

London, GB · Product vendor

Email security, continuity, and human-risk training.

Email & messaging · Human risk

Orca Security

Portland, US · Product vendor

Agentless CNAPP for AWS, Azure, and GCP.

Cloud security · Threat & vulnerability
5.0(1)
Promoted

SailPoint

Austin, US · Product vendor

Identity governance and administration for large directories.

Identity · GRC

BeyondTrust

Johns Creek, US · Product vendor

Privileged access, remote support, and endpoint privilege.

Identity

Sophos

Oxford, GB · Product vendor

Endpoint, firewall, and managed detection for mid-market.

Endpoint security · Network security

Trend Micro

Tokyo, JP · Product vendor

Endpoint, email, and cloud security from Tokyo.

Endpoint security · Email & messaging

Mandiant

Reston, US · Consultancy / pentest

Incident response, threat intel, and Mandiant Advantage — now Google Cloud.

Security operations · Threat & vulnerability

Rubrik

Palo Alto, US · Product vendor

Cyber-recovery, backup, and data security posture.

Data protection · Security operations

HashiCorp

San Francisco, US · Product vendor

Vault secrets, Terraform, and identity-based security for infrastructure.

Identity · Cloud security

CrowdStrike

Austin, US · Product vendor

Cloud-native endpoint detection, identity, and threat intel.

Endpoint security · Security operations
4.0(1)
Verified
PreviousPage 2 of 2
FAQ
What does ISO 27001 mean on this index?

Companies that list ISO 27001. Company attestations (ISO 27001, SOC 2) are held by the firm. Practitioner credentials (OSCP, GPEN) are held by people on staff. We do not audit certificates or invigilate exams.

Is the order paid?

No. Organic order is recency. Promoted shelves are labeled and separate. That is the opposite of buying a rank.

How do I get listed under ISO 27001?

Submit a company and tick the certifications you actually hold. We review before anything is public. Paid plans buy a labeled shelf, not a silent bump in this list.

Why is a staff exam on a company directory?

Buyers shortlist pentest and training firms by who sits on the engagement. OSCP and GPEN are company filters here, not a people directory.