Latka logo

Top 8 Breach and Attack Simulation Software Companies With $10M–$100M Revenue (September 2026)

As of September 2026, Latka tracks 8 breach and attack simulation software companies with $10M–$100M in annual revenue. They have combined revenues of $138.2M and employ 995 people. They have raised $154.5M and serve 8.2K customers combined.

Every company below sells breach and attack simulation software to other businesses and is ranked by its most recent annual revenue. Revenue, funding, headcount and customer figures come from CEO interviews on the Latka podcast, public company filings, and Latka estimates where a company has not disclosed a number.

What Breach and Attack Simulation Software Companies do

Breach and Attack Simulation (BAS) software is a cybersecurity tool designed to proactively assess and enhance an organization's security posture by simulating real-world cyberattacks. It automates the process of testing security measures, enabling organizations to identify vulnerabilities and validate the effectiveness of their defenses. Key use cases include continuous monitoring of security readiness, validating security controls, and complementing traditional penetration testing efforts. Typically, BAS solutions provide features such as automated attack simulations, detailed reporting on vulnerabilities, and guidance on remediation strategies. They cater to a variety of organizations focusing on cybersecurity, including IT departments, security operations teams, and compliance professionals. By facilitating routine testing, BAS software helps organizations prepare for potential breaches, thereby strengthening their overall cybersecurity framework.

Companies
8
Revenue
$138.2M
Funding
$154.5M
Employees
995

Filters

Sorting: Highest -> Lowest

Filters

Top Breach and Attack Simulation Software Companies With $10M–$100M Revenue

Showing 8 of 8 companies ranked by annual revenue.

1Yogosha logo
Yogosha

Paris, France

Yogosha is a french bug bounty platform.

Revenue
$27M
Customers
100
Year founded
2015
Funding
$2.2M
Team size
210
2SafeBreach logo
SafeBreach

Sunnyvale, California, United States

Provider of a cyber-security platform intended to stimulate hacks on companies' systems to help them identify holes. The company's platform constantly runs breach simulations such as brute force and exploits malware on a client's network to theoretically and proactively locate and remediate security issues, enabling users to analyze the impact of attacks on a company's systems and the efficacy of its defenses.

Revenue
$21M
Year founded
2014
Funding
$53M
Team size
135
3Filigran logo
Filigran

Asnieres-sur-seine, France

Filigran provides open-source cybersecurity solutions covering threat intelligence management, breach and attack simulation, and cyber risk management.

Revenue
$19.7M
Team size
147
4BreachLock Inc. logo
BreachLock Inc.

New York, New York, United States

Built by industry leaders, BreachLock enables you to find and fix your next Cyber Breach before it happens.

Revenue
$17.3M
Year founded
2018
Funding
$3.1M
Team size
122
5Intruder logo
Intruder

London, England, United Kingdom

Provider of a cloud-based security monitoring platform intended to secure internet-facing infrastructure. The company's security monitoring platform focuses on vulnerabilities and prioritizing the most critical threats by breaching the systems, enabling clients to identify loopholes in network security and improve its vulnerability before hackers expose them.

Revenue
$16.1M
Customers
3K
Year founded
2015
Funding
$1.2M
Team size
67
6RangeForce logo
RangeForce

Norfolk, Virginia, United States

cyber security training and exercises

Revenue
$15M
Customers
100
Year founded
2019
Team size
68
7LetsDefend logo
LetsDefend

Herndon, Virginia, United States

LetsDefend is a hands-on Blue Team training platform that enables people to gain practical experience by investigating real cyber attacks inside a simulated SOC.

Revenue
$11.2M
Year founded
2020
Team size
102
8IronScales logo
IronScales

Atlanta, Georgia, United States

Developer of an automated platform intended to address the challenges of email phishing. The company's platform uses a combination of machine learning and human intelligence to offer phishing simulation training, detection, incidence responses and automated intelligence sharing, enabling organizations to protect themselves from the threat of phishing and make emails secure.

Revenue
$10.9M
Customers
5K
Year founded
2013
Funding
$95M
Team size
144

Frequently asked questions about Breach and Attack Simulation Software Companies With $10M–$100M Revenue

How many breach and attack simulation software companies with $10M–$100M in annual revenue are there?

Latka tracks 8 breach and attack simulation software companies with $10M–$100M in annual revenue. Together they generate $138.2M in annual revenue and employ 995 people.

Which breach and attack simulation software company with $10M–$100M in annual revenue is the largest?

Yogosha is the largest, with $27M in annual revenue, founded in 2015.

How much revenue does a typical breach and attack simulation software company with $10M–$100M in annual revenue make?

The average breach and attack simulation software company in this list makes $17.3M a year, across 8 companies with reported revenue. They serve 8.2K customers combined.

Who are the leading Breach and Attack Simulation software vendors with $10M–$100M in annual revenue?

Ranked by annual revenue, the leaders are Yogosha, SafeBreach, Filigran, BreachLock Inc. and Intruder.

How much funding have breach and attack simulation software companies with $10M–$100M in annual revenue raised?

The 8 breach and attack simulation software companies with $10M–$100M in annual revenue tracked here have raised $154.5M in disclosed funding between them.

Related Security Software categories

Inclusion Criteria

- The product must automate the simulation of real-world cyberattacks. - It should provide detailed reports on vulnerabilities and security posture. - The software must facilitate ongoing monitoring and assessment of security controls. - It needs to support various attack scenarios to test different components of the security infrastructure. - Not just focused on compliance; must also improve proactive threat detection and response capabilities.