Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
ThreatSec Limited is a cybersecurity testing consultancy registered in England and Wales. It is not positioned as a security product vendor; instead, it evaluates clients’ information assets by simulating real-world cyberattacks, identifying and demonstrating business risk. The website states that its consultants have delivered assessments for global organizations across sectors such as finance, energy, automotive, gaming, government, travel, and technology.
In terms of defensive coverage, ThreatSec offers a broad range of testing services: internet-facing and internal application security testing, mobile application and API testing, enterprise mobile security policy reviews, infrastructure testing for servers/laptops/kiosks/network devices, wireless security, phishing assessments, bypassing physical security controls, and a broad security check-up. Its “Goal orientated testing” focuses on bypassing prevention and detection controls to validate predefined objectives, such as stealing intellectual property or customer data, or gaining access to critical systems. This is closer to red teaming or objective-led penetration testing.
Its service process is relatively clear: after a client contacts the company via the website, both sides discuss requirements, schedule, testing approach, feedback format, and deliverables. ThreatSec then provides a work plan specifying deliverables, prerequisites, and costs. Once the client signs off, they prepare required accounts, target information, on-site access, or other conditions. During testing, findings are updated according to the client’s preferred cadence. A formal report is delivered at the end, followed by a debrief meeting with relevant stakeholders to discuss issues and remediation recommendations. The website does not show capabilities for continuous monitoring, an alerting platform, or SIEM/SOAR integrations.
No public packages or unit pricing are provided; pricing appears to be quoted based on project scope. Information on compliance certifications, testing methodology standards, staff qualifications, and whether reports can satisfy specific audit requirements is not disclosed. These are key points to confirm before procurement.
Its strengths are broad scenario coverage and practical, real-world orientation. Case examples include ATM testing, smart card authentication bypass, unauthorized access to medical documents, unlimited international payments, lateral movement in a DMZ, and physical security at live event venues. The downside is that the website is relatively sparse, with little detail on certifications, service levels, China support, or payment methods. It is better suited to mid-sized and large organizations with clear security validation goals that want in-depth human-led testing and demonstrable business-risk evidence. If you only need a low-cost automated scanning tool, it may not be the best match.
Access from mainland China, payment options, and local service capabilities are unclear. Cross-border contracts, time-zone communication, and compliance requirements for on-site testing should be confirmed in advance. Domestic alternatives include QiAnXin, NSFOCUS, Venustech, and DBAPPSecurity; comparable international providers include NCC Group, Bishop Fox, and Mandiant.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on threatsec.com official site.
threatsec.com is an Unknown Security (Pen Testing) provider. TG4G tracks its product information, an overall rating of 6.0/10, and a China-accessibility score of Limited (proxy recommended). Click "Visit Official Site" to reach threatsec.com directly.