Mandiant (Google Cloud)
ListedFrontline breach-investigation heritage now operating as part of Google Cloud, with incident response backed by Google's own threat telemetry.
CrowdStrike Services
ListedIncident response built around the Falcon platform, aimed at fast, global deployment onto an active intrusion.
Kroll Cyber Risk
ListedForensics and incident response practice with particular depth in regulated industries and litigation-sensitive breaches.
Secureworks
ListedEmergency incident response and IR retainers on the Taegis platform, plus proactive services including ransomware readiness assessments.
Arctic Wolf
ListedMid-market-focused managed detection and response, delivered through a named Concierge Security Team rather than a pure self-service console.
Rapid7
ListedManaged Threat Complete bundles MDR and vulnerability management, aimed at larger, multi-vendor security environments.
Trustwave
ListedFusion platform unifying MDR, managed SIEM, and threat hunting, with the SpiderLabs research team behind its intelligence.
Coalition
ListedCyber insurer built around an "active risk management" model — continuous exposure monitoring bundled with the policy itself.
At-Bay
ListedTechnology-driven cyber insurer that underwrites and continuously monitors policyholders' external attack surface.
Chubb
ListedOne of the largest cyber insurance underwriters globally — typically relevant for larger organizations needing higher limits and complex coverage.
Beazley
ListedLong-established cyber insurer with dedicated cyber extortion and ransomware payment coverage.
Rubrik
ListedZero Trust data security platform built on a proprietary immutable file system, widely positioned as strong specifically for ransomware recovery.
Veeam
ListedBackup platform with immutability by design, including WORM-locked retention meant to resist deletion even with compromised admin credentials.
Cohesity
ListedImmutable-by-default backup, including FortKnox, an air-gapped, cloud-managed vault for keeping a clean recovery copy.
Druva
ListedCloud-native backup and cyber resilience delivered as a SaaS service on AWS, without customer-managed backup infrastructure.
Coveware
ListedRansomware-specific incident response with round-the-clock coverage, published pricing practices, and payment facilitation when it's needed.
GroupSense
ListedThreat intelligence and ransomware negotiation, including pre-incident preparation and response playbook development.
Arete
ListedEnd-to-end cyber risk management with a negotiation practice informed by a large database of prior ransomware cases.
Are you a provider?
List your organization in front of enterprise security leaders actively evaluating incident response, MSSP, insurance, and recovery partners.
Frequently asked questions
Is the provider directory free to browse?
Yes, browsing and comparing every listed provider is completely free — no account or email required.
How are providers vetted or selected?
Every entry starts as a real, independently operating company compiled from public information — none are paid placements, and inclusion isn't an endorsement. Providers can additionally apply for or purchase a Featured or Verified Partner tier, which affects placement and badging but never the factual accuracy of a listing. See our Editorial & Listing Policy for the full breakdown.
What's the difference between Listed, Featured, and Verified Partner?
Listed is the free, default tier every genuine provider receives. Featured is a paid tier with higher placement within its category. Verified Partner is our top paid tier, reserved for providers we've done direct diligence on, with priority placement and eligibility for our lead-referral program.
Does a higher tier mean a better provider?
Not necessarily. Tier reflects placement and program eligibility, not a quality ranking — do your own diligence before engaging any provider, regardless of tier.
Can I request a quote from a provider directly?
Yes — providers in the directory can be contacted directly for a quote; no cold outreach or lead-gen form is required to reach them.