🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
Independent Directory

Find the right people before you need them.

A working reference of incident response firms, MSSPs, cyber insurers, backup & recovery vendors, and ransomware negotiators — the kind of list you want compiled before an incident, not during one.

Every entry here is a real, independently operating company, compiled from public information. None are paid placements, and inclusion isn't an endorsement — see our editorial & listing policy for what a "Listed" badge means and do your own diligence before engaging anyone.

Mandiant (Google Cloud)

Listed
Incident Response

Frontline breach-investigation heritage now operating as part of Google Cloud, with incident response backed by Google's own threat telemetry.

ForensicsThreat intelligencePart of Google Cloud

CrowdStrike Services

Listed
Incident Response

Incident response built around the Falcon platform, aimed at fast, global deployment onto an active intrusion.

Falcon platformGlobal deployment

Kroll Cyber Risk

Listed
Incident Response

Forensics and incident response practice with particular depth in regulated industries and litigation-sensitive breaches.

ForensicsRegulated sectors

Secureworks

Listed
Incident Response

Emergency incident response and IR retainers on the Taegis platform, plus proactive services including ransomware readiness assessments.

Taegis platformRetainersReadiness assessments
SCAN

Arctic Wolf

Listed
MSSP

Mid-market-focused managed detection and response, delivered through a named Concierge Security Team rather than a pure self-service console.

MDRConcierge modelMid-market
SCAN

Rapid7

Listed
MSSP

Managed Threat Complete bundles MDR and vulnerability management, aimed at larger, multi-vendor security environments.

MDRVulnerability management
SCAN

Trustwave

Listed
MSSP

Fusion platform unifying MDR, managed SIEM, and threat hunting, with the SpiderLabs research team behind its intelligence.

MDRManaged SIEMSpiderLabs research

Coalition

Listed
Cyber Insurance

Cyber insurer built around an "active risk management" model — continuous exposure monitoring bundled with the policy itself.

Active risk monitoringTech-driven underwriting

At-Bay

Listed
Cyber Insurance

Technology-driven cyber insurer that underwrites and continuously monitors policyholders' external attack surface.

Tech-driven underwritingContinuous monitoring

Chubb

Listed
Cyber Insurance

One of the largest cyber insurance underwriters globally — typically relevant for larger organizations needing higher limits and complex coverage.

High limitsLarge enterprise

Beazley

Listed
Cyber Insurance

Long-established cyber insurer with dedicated cyber extortion and ransomware payment coverage.

Cyber extortion coverageEstablished carrier
1>AF#A#D%}DDBB
/B*0>0%<01<<FC
#0ABAFEAE0*#B<
#CF>1<D$$D%0{<
ACD%#%A1}}DEC/
}>#A}>#E>$}100
$>%<}1FB><AC>0
{E}EA*A*A{/E0C
<D1}%10E$}{0C}

Rubrik

Listed
Backup & Recovery

Zero Trust data security platform built on a proprietary immutable file system, widely positioned as strong specifically for ransomware recovery.

Immutable storageZero Trust architecture
BABEB}1C%#*F*{
/$#E}AF%01A#}0
E$D1$}>#}}CE<>
*0F{<D#%A$E}B%
>$/##{1EC%$/AE
$#FE%%F0E0%1D$
**DC>DEFBAFD$E
}F///{%<>A*{$D
1A*/<F1{FE1%>/

Veeam

Listed
Backup & Recovery

Backup platform with immutability by design, including WORM-locked retention meant to resist deletion even with compromised admin credentials.

Immutable by designWORM retention
%DC#B}E*<C%%BA
>C/{1*B>F>*0>E
C$>1{1%/>/{0{$
E$%*B00$B%F}C1
B#B$/0AEBFB<C/
C$#{A*%%<FE%#*
#$<}*#>*E#1C#0
C%{>#>%1*E0E>*
ADEF#}$>$D>CAA

Cohesity

Listed
Backup & Recovery

Immutable-by-default backup, including FortKnox, an air-gapped, cloud-managed vault for keeping a clean recovery copy.

Immutable by defaultAir-gapped vault
{FB%D$1F>*C*C%
><{A0/1}D%F00F
%{F}*/}AA>B%{D
C>>ED{><{#{{<1
/*>%}#DB$1D{FC
%#FF*<1CF/C%BA
}%}D0{}}E1D<F<
AED*10%00>BCEB
C%BA*{$%<<%**}

Druva

Listed
Backup & Recovery

Cloud-native backup and cyber resilience delivered as a SaaS service on AWS, without customer-managed backup infrastructure.

Cloud-nativeSaaS delivery

Coveware

Listed
Negotiation

Ransomware-specific incident response with round-the-clock coverage, published pricing practices, and payment facilitation when it's needed.

24/7 coverageTransparent pricing

GroupSense

Listed
Negotiation

Threat intelligence and ransomware negotiation, including pre-incident preparation and response playbook development.

Threat intelligencePlaybook prep

Arete

Listed
Negotiation

End-to-end cyber risk management with a negotiation practice informed by a large database of prior ransomware cases.

Case-data drivenEnd-to-end IR

Are you a provider?

List your organization in front of enterprise security leaders actively evaluating incident response, MSSP, insurance, and recovery partners.

Frequently asked questions

Is the provider directory free to browse?

Yes, browsing and comparing every listed provider is completely free — no account or email required.

How are providers vetted or selected?

Every entry starts as a real, independently operating company compiled from public information — none are paid placements, and inclusion isn't an endorsement. Providers can additionally apply for or purchase a Featured or Verified Partner tier, which affects placement and badging but never the factual accuracy of a listing. See our Editorial & Listing Policy for the full breakdown.

What's the difference between Listed, Featured, and Verified Partner?

Listed is the free, default tier every genuine provider receives. Featured is a paid tier with higher placement within its category. Verified Partner is our top paid tier, reserved for providers we've done direct diligence on, with priority placement and eligibility for our lead-referral program.

Does a higher tier mean a better provider?

Not necessarily. Tier reflects placement and program eligibility, not a quality ranking — do your own diligence before engaging any provider, regardless of tier.

Can I request a quote from a provider directly?

Yes — providers in the directory can be contacted directly for a quote; no cold outreach or lead-gen form is required to reach them.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy