Skip to content
Cyber Security Firms

Best Cyber Security Firms in New York

New York is the largest concentration of financial services, media and professional services firms in the country, where the New York Department of Financial Services cybersecurity regulation drives much of the buying. The firms on this list were checked the same way as every list on the site. Rank one is the best overall, ranks two to four are the best for small business, managed detection and compliance work, and the rest cleared the same checks.

10 firms ranked21 evaluatedChecked
  1. 01Best overall
  2. 02Best for small business
  3. 03Best for managed detection
  4. 04Best for compliance
  5. 05+The rest of the shortlist, ranked on the same checks
Rank 01
Kroll logo

Kroll

Best overall

The cyber risk arm of a risk advisory firm headquartered in Lower Manhattan.

Checked
Why they are on this list
  • Headquartered at One World Trade Center on Fulton Street, so the responders a New York board would call sit in the same city as the regulators asking the questions afterwards
  • Listed on the CREST member register with accreditations in incident response, penetration testing and security operations center work, which is three separate assessments rather than one badge
  • Holds ISO 27001, recorded on that same CREST register entry rather than only on its own marketing pages
  • Its CREST listing records more than 3,000 incidents handled a year and more than 100,000 hours of offensive and application security work completed each year
  • Runs digital forensics alongside the investigation, which is what decides whether an incident can be defended in litigation or a regulatory filing rather than only cleaned up
Size
Over 500 staff
Attestations
CREST, ISO 27001
Sectors
Financial services, Legal, Healthcare, Government
Rank 02
Power Consulting logo

Power Consulting

Best for small business

A Manhattan managed IT provider with security as a separate practice.

Checked
Why they are on this list
  • Publishes a per-user range on its own site, putting all-inclusive managed IT with security at $140 to $200 per user per month, so a thirty-person office can budget before it books a sales call
  • Bills one fixed monthly figure per user with unlimited tickets rather than charging security as a separate line, which is the structure a company without a security team can actually manage
  • Operating in New York City since 1991, longer than most of the managed providers now selling security in the metro
  • Runs security as its own practice with its own page covering vulnerability scanning, penetration testing, incident response and virtual CISO work, not as a bullet on an IT support page
  • States that CISSP holders staff the security work and that monitoring runs around the clock, rather than leaving both to a discovery call
Founded
1991
Sectors
Legal, Finance and wealth management, Nonprofit, Education
Rank 03
ITNYC logo

ITNYC

Best for managed detection

A Wall Street managed security provider selling round-the-clock monitoring to New York businesses.

Checked
Why they are on this list
  • Sells 24/7 security operations center monitoring as a named service built on XDR and SIEM with active threat response, rather than forwarding alerts for the customer to triage
  • Offices at 14 Wall Street with stated coverage across all five boroughs, Long Island and New Jersey, so an engineer can reach a trading floor without a flight
  • Includes a virtual CISO and a named compliance officer in the managed security engagement, which is the gap most New York firms hit at their first customer security review
  • Names NYDFS Part 500 alongside SOC 2, ISO 27001, HIPAA, PCI DSS and CMMC in the frameworks it supports, and Part 500 is the one that decides whether a New York financial firm keeps its license
  • Staffs the practice with CISSP and CCIE certified architects and puts continuous vulnerability management and an annual penetration test in the same contract as the monitoring
Rank 04
CyberSecOp logo

CyberSecOp

Best for compliance

A security consultancy with a Manhattan office and a dedicated NYDFS Part 500 practice.

Checked
Why they are on this list
  • Runs a 23 NYCRR 500 practice with its own page covering the risk assessment, the cybersecurity policy, the CISO appointment and the third-party vendor management the regulation actually names
  • Delivers the compliance work through a virtual CISO program that assigns an executive-level CISO to build the NYDFS plan, rather than handing over a gap report and leaving
  • Keeps a staffed New York office at 1250 Broadway with its own Manhattan telephone number alongside the Stamford headquarters, so the compliance and response work is covered from inside the metro
  • Sells managed detection and response from the same firm doing the compliance work, so a control written for Part 500 can be evidenced by the service that runs it
  • States OWASP, ISO 27000 and NIST as the frameworks its practice is built on, which is a checkable claim about method rather than a claim about outcomes
Rank 05

Trail of Bits

An independent security research and engineering firm working on software, cryptography and AI.

Checked
  • Founded in 2012 and based on Park Avenue South, doing code-level security work rather than monitoring or reselling other companies' products
  • Placed second in the DARPA Cyber Grand Challenge in 2016 and was selected with a $1 million semifinal award in the DARPA AI Cyber Challenge, both judged on working code rather than a proposal
  • Named in the Forrester Wave for cybersecurity consulting services in the first quarter of 2024 and in Forrester's 2025 cybersecurity consulting landscape
  • Advises ARPA-H on health research security and assessed frontier model offensive capability for the UK Frontier AI Taskforce, which is public work a buyer can read before hiring
  • Publishes its tooling as open source and started the Empire Hacking meetup in New York, so the standard of the work is visible without an engagement
Founded
2012
Sectors
Technology, Blockchain, Government research
Rank 06

Include Security

A Brooklyn application security firm assessing code, apps and connected devices.

Checked
  • Headquartered in Brooklyn and describing its market as New York, San Francisco and beyond, so a New York software company gets assessors in its own time zone
  • Scopes work by artifact rather than by checklist, listing web applications, mobile apps, IoT devices, server applications, client applications and web services as separate assessment types
  • Does software reverse engineering, fuzzing and dynamic analysis tool creation, which is deeper work than the scan-and-report engagement sold as a penetration test
  • Names automotive, consumer hardware and healthcare among the sectors it assesses, alongside B2B and B2C technology, social networks and streaming services
Also on the shortlist
Rank 07

CyberDuo

Website, CyberDuo
Rank 08

Virtue Security

Website, Virtue Security
Rank 09

Grid32

Website, Grid32
Rank 10

CYBRI

Website, CYBRI

Cyber Security Firms may earn a referral fee if you engage a firm through a link on this site. How that works.

How to Choose a Cyber Security Firm in New York

Start with which of the three New York buying triggers is yours. The first is a regulator: if the Department of Financial Services licenses you, Part 500 sets the program you must have and the certification you file every April, and the firm you hire should have taken other clients through an examination rather than only read the text. The second is a customer: law firms, agencies and software companies in this city now lose deals to a security questionnaire, and the answer is usually a SOC 2 report and a penetration test, not a monitoring contract. The third is an incident already in progress, which needs responders and forensics on the same team.

Then check the things a website will not volunteer. Ask who is watching at three in the morning and what they may do without calling you first, because that single answer separates managed detection from an alert forwarding service. Ask whether the attestations on the site appear on the certifying body's own register. Ask for a starting price for the work you described. And ask what the firm does about the email attacks that start most New York incidents, because that is where a monitoring contract earns its money or does not.

What the Ranks Mean

Rank one is the best firm overall on the checks in the editorial policy. Ranks two to four are the best firm for one kind of buyer each: a small business, an organization buying managed detection, and an organization facing compliance work. The rest of the shortlist cleared the same checks and is ordered on them. A low rank on this list is not a warning; a firm that failed a check is not on it.

Questions about hiring a cyber security firm

What do cyber security firms in New York charge?

Firms on this list publish managed IT with security bundled in at $140 to $200 per user per month, so a thirty-person office can build a budget before it books a call. Penetration tests are scoped projects rather than subscriptions, quoted on the size of the application or network. Incident response is billed hourly, or held on a retainer bought before it is needed.

Do I need a firm with an office in New York?

For monitoring, no. That work is remote and the right firm may be anywhere in the country. For incident response it helps, because someone may need to be in your office with the machines while the rest of the team works remotely. For NYDFS Part 500 work it helps more, since the firm writing your program should have taken other clients through a Department examination.

Who has to comply with NYDFS Part 500?

Part 500, the Department of Financial Services cybersecurity regulation, covers entities licensed or authorized by the Department, which includes banks, insurers, mortgage brokers, money transmitters and many investment firms. Covered entities file an annual certification or acknowledgment with the Department by April 15. A limited exemption exists for the smallest entities, measured on headcount, gross revenue and total assets, but it does not remove the core program obligations.

Does the SHIELD Act apply to my business if I am not a bank?

Probably. The SHIELD Act sets a reasonable safeguards standard for any business holding private information about a New York resident, wherever that business is located. A small business, defined on headcount, revenue or assets, meets the standard with administrative, technical and physical safeguards proportionate to its size and the sensitivity of the data it holds. Naming someone to own the program is the first safeguard the law lists.

Which New York industries drive the demand for security work?

Financial services first, because Part 500 makes security a licensing matter rather than a preference. Then law firms, whose clients now send security questionnaires before an engagement letter. Then healthcare systems under HIPAA, media and advertising businesses with large freelance networks, and software companies facing a SOC 2 report before an enterprise contract closes. Most firms on this list name at least two of those.

What should I ask a New York firm before hiring it?

Ask who answers an alert at three in the morning and what they are allowed to do without waking you. Ask whether the attestations they list appear on the certifying body's own register. Ask for a starting price for the engagement you just described. Ask how many Part 500 examinations they have taken a client through, and what the Department asked for.

How is this list put together?

Every firm is checked on what it actually does, the attestations that can be verified, its track record, a response test where we contact it as a prospective client, and how clear it is about scope and price. Rank one is the best firm overall. Ranks two to four are the best for small business, managed detection and compliance. The editorial policy sets out each check and what fails it.