Latka logo

Top 25 Breach and Attack Simulation (BAS) Software SaaS Companies in May 2026

As of May 2026, there are 25 SaaS companies in Breach and Attack Simulation (BAS) Software. They have combined revenues of $294M and employ 1.9K people. They have raised $458.4M and serve 12.2K customers combined.

Breach and Attack Simulation (BAS) software is a cybersecurity tool designed to proactively assess and enhance an organization's security posture by simulating real-world cyberattacks. It automates the process of testing security measures, enabling organizations to identify vulnerabilities and validate the effectiveness of their defenses. Key use cases include continuous monitoring of security readiness, validating security controls, and complementing traditional penetration testing efforts. Typically, BAS solutions provide features such as automated attack simulations, detailed reporting on vulnerabilities, and guidance on remediation strategies. They cater to a variety of organizations focusing on cybersecurity, including IT departments, security operations teams, and compliance professionals. By facilitating routine testing, BAS software helps organizations prepare for potential breaches, thereby strengthening their overall cybersecurity framework.

Companies
25
Revenue
$294M
Funding
$458.4M
Employees
1.9K

Filters

Sorting: Highest -> Lowest

Filters

Top Breach and Attack Simulation (BAS) Software Companies

Showing 10 of 9 companies ranked by annual revenue.

1
Boxphish

Leeds, England, United Kingdom

Boxphish is a low-touch cyber security awareness training platform that arms organisations—and their people—with the tools and knowledge needed to reduce the risk of cyber attacks. This is achieved by combining real-world phishing simulations, quality training content and actionable analytics into a single platform.

Revenue
$4.2M
Customers
-
Year founded
2018
Funding
-
Team size
38
Growth
-
2
Grit Solutions S.L.

Ciudad Real, Spain

Zepo is designed to run simulated phishing attacks to test the susceptibility of your employees to cyber attacks. By providing a safe and controlled environment for employees to practice detecting and responding to phishing attempts.

Revenue
$3.2M
Customers
-
Year founded
-
Funding
-
Team size
29
Growth
-
3
Hook Security Inc

Greenville, South Carolina, United States

Hook Security is a psychological and behavioral science startup designed to help companies establish policies for email and provide on-demand fake social engineering cyber attacks on employees with micro-learning and training. Despite being a young company, Hook Security comes with experience, with founder, Adam Anderson's immense background in cybersecurity and technology. Adam's 15 years of entrepreneurial startup experience and his knowledge of Enterprise Cyber Defense gives him a window into what's wrong with communication between large and small companies. Hook Security started with the goal of helping vulnerable companies from being hooked by cyber predators. Our mission is to safeguard companies from social engineering threats in order to build an active line of defense with on-demand employee awareness training. #DontGetHooked

Revenue
$3.2M
Customers
-
Year founded
2019
Funding
$1.4M
Team size
26
Growth
36.01%
4
PhishingBox

Lexington, Kentucky, United States

Provider of a social engineering testing software for companies. The company offers a web-based system for auditors and security consultants to conduct social engineering testing via spear-phishing.

Revenue
$2.8M
Customers
-
Year founded
2005
Funding
-
Team size
23
Growth
65.61%
5
malanta.ai

Ramat Gan, Israel

AI .Attackers - faster, smarter, self-learners, and more relentless than ever. These adversaries are leveraging AI to automate reconnaissance, craft hyper-personalized attacks, perform real tasks, and exploit digital exposures at a scale and speed that traditional defenses can't match. To combat this new wave...

Revenue
$2.2M
Customers
-
Year founded
2024
Funding
-
Team size
20
Growth
-
6
PhishFirewall

Huntsville, Alabama, United States

Advanced AI-driven CyberSecurity Awareness Education, Threat Emulation, and Human Security Analytics Platform. Phish Your Users Condition Your Users Stop Malware Better Psychology = Better Results Stopping phish clicks and driving sub 1% rates, requires an acute understanding of psychology and how it affects human behavior. PhishFirewall uses the science of learning and behavioral modification to empower your workforce to be more security aware and stop clicking!

Revenue
$1.5M
Customers
-
Year founded
2019
Funding
-
Team size
14
Growth
-
7
PhishX

Sao Paulo, Sao Paulo, Brazil

PhishX | Cybersecurity for People PhishX is a cybersecurity platform focused on people. PhishX conducts awareness campaigns automated, continuous and effectively through phishing simulations, passing knowledge via microlearning and online monitoring of results, reducing the risk of digital fraud. phishx.io @PhishX

Revenue
$1.4M
Customers
4K
Year founded
2014
Funding
-
Team size
20
Growth
61.5%
8
Retrospect Labs

Perth, Western Australia, Australia

Retrospect Labs is a company that specialises in cyber security exercises, delivered through a SaaS platform.

Revenue
$1.4M
Customers
-
Year founded
2019
Funding
$32.3K
Team size
14
Growth
56.96%
9
OutKept

Ghent, Flemish Region, Belgium

OutKept offers phishing prevention for organisations. We execute the highest quality phishing simulation campaigns, supported by a community of ethical phishers, to build awareness, and maintain alertness. Via our platform ethical phishers help organisations who seek to protect themselves, in a safe and confidential way. Our phishing simulations benefit organisations in 3 ways: - Increase general awareness and knowledge of phishing - Train people to have the right reflexes when encountering phishing mails - Boosting alertness to phishing attempts continuously Phishing awareness takes time to build. Therefore we offer our simulation campaigns in an as-a-service formula: Low fees per user, and regular phishing simulation mails for protection all year round. Our phishing mails are ethically sourced: We do not use a fixed set of phishing mail templates, but leverage a community of ethical phishers who are rewarded through a bounty system, to ensure we stimulate the use of the most contemporary techniques and simulate the most dangerous attacks. Our platform acts as a wall and filter between organisations and ethical social engineers: we protect data and anonimity, while allowing for the highest quality simulations. The platform allows organisations to test and improve on awareness and phishing vulnerability without the risk of suffering any actual damages.

Revenue
$1.2M
Customers
-
Year founded
2020
Funding
-
Team size
11
Growth
-

Inclusion Criteria

- The product must automate the simulation of real-world cyberattacks. - It should provide detailed reports on vulnerabilities and security posture. - The software must facilitate ongoing monitoring and assessment of security controls. - It needs to support various attack scenarios to test different components of the security infrastructure. - Not just focused on compliance; must also improve proactive threat detection and response capabilities.