Skip to content
Cyber Security Firms

About Cyber Security Firms

Security explained in plain English, the firms that do it well ranked with reasons, and a report on every breach as it lands.

What the site is

Cyber Security Firms has three parts, and each does one job. The resources explain what an attack or a defense actually is, one question per page, with the mechanism drawn out rather than described. The ranked lists name the cyber security firms worth calling, nationally and in the ten metros where people search for them most, with the reasons for every place on the list. The breach reports cover each new incident as it becomes public: what was exposed, how it happened as far as anyone has said, and what to do about it.

The three feed each other. A report on a phishing-led breach links to the page that explains phishing. That page links to the firms that handle incident response. The firm lists link back to the pages that explain what you are buying.

Who checks it

Illustrated portrait of Daniel Reyes

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read Daniel’s full profile →

How the firm lists are built

Every list is put together the same way. Firms are found, checked against what they publish and what third parties say about them, contacted the way a prospective client would contact them, and ranked. Rank one is the best firm overall. Ranks two to four are the best firm for one kind of buyer each: small business, managed detection and response, and compliance work. The rest of the shortlist cleared the same checks. The bullets under a firm are what it did to earn its place, never copy it sent us. The full method is in the editorial policy.

Where the breach reports come from

Reports are built from primary sources: the organization’s own statement, regulator filings and breach notification letters, and verified breach databases. Where the only source is a listing on a criminal group’s leak site, the report says so in the first line and carries a claim label until the organization confirms or disputes it. Every number on a report traces to a source listed at the foot of the page.

What you will not find here

  • No signup wall, no email gate, no paid tier. Every page is open.
  • No fear. Security writing is drowning in it, and it makes people freeze rather than act. Each page says what the risk actually is and what to do about it.
  • No invented testimonials and no fake credentials. If we quote someone, it is a person.
  • No stock photography of hooded figures. The illustrations are drawn for this site, and anything showing how an attack works is a coded diagram with the steps set by hand.

Tell us when we are wrong

Security moves fast and confident people repeat things that are not true. If a page here looks wrong, we would rather fix it than defend it. Get in touch and tell us which page and what looks off.