Fortress Information Security
Orlando-based supply chain and third-party cyber risk management provider that secures a reported 40% of the U.S. power grid and holds a $919 million federal contract for supply chain risk tooling.
Visit Website ↗ + Add to CompareOverview
Fortress Information Security focuses on a specific, high-consequence slice of governance, risk, and compliance: third-party and supply chain cyber risk for regulated critical infrastructure operators, primarily electric utilities, but also transportation, finance, and healthcare. Its platform combines structured vendor risk assessments with continuous AI-assisted monitoring of suppliers, aiming to replace the point-in-time vendor questionnaires that leave utilities blind to supply chain threats between audit cycles, and to help them meet demanding regulatory regimes like NERC CIP.
Founded in 2015 and headquartered in Orlando, Florida, Fortress has grown to roughly 210 employees and works with the top seven investor-owned utilities in the U.S., a customer concentration that reflects how specialized and regulation-driven its market is. In 2022, Goldman Sachs Asset Management made a $125 million strategic investment in the company, part of $144 million raised in total. In 2025, Fortress Government Solutions won a 10-year, $919 million Blanket Purchase Agreement with the GSA for the Supply Chain Risk Illumination Professional Tools and Services (SCRIPTS) program, extending its critical-infrastructure risk model into direct federal government use. A published case study describes one regulated electric utility using Fortress to go from routine NERC CIP violations to zero violations and an audit exemption, cutting remediation timelines for vulnerabilities like Log4Shell and CitrixBleed from 30-90 days down to a matter of days.
For CISOs in regulated critical infrastructure sectors, Fortress is relevant as a compliance-and-risk specialist rather than a general GRC platform: its value proposition is built around the specific regulatory and supply chain risk pressures utilities and similar operators face, evidenced by real audit outcomes rather than generic risk-scoring dashboards.
Innovation Matrix Assessment
Fortress has continued launching new offerings, including a dedicated Foundations Program for NERC CIP compliance, alongside winning a major new 10-year federal contract in 2025, indicating consistent product and go-to-market expansion.
With roughly 210 employees, a decade of operating history, and relationships with the top seven U.S. investor-owned utilities plus a large federal contract vehicle, Fortress demonstrates substantial operational depth in a narrow, high-stakes market.
A $919 million 10-year GSA supply chain risk contract and a $125 million Goldman Sachs Asset Management investment are both large, independently reported, recent signals of accelerating momentum.
Combining structured vendor risk assessments with continuous AI-based supplier monitoring, specifically tailored to NERC CIP and critical infrastructure regulatory regimes, is a meaningfully more specialized approach than generic third-party risk management platforms, though it builds on established GRC and TPRM concepts.
A published case study documenting a regulated utility moving from routine NERC CIP violations to zero violations and an audit exemption, with remediation timelines for Log4Shell and CitrixBleed cut from 30-90 days to days, is concrete, checkable outcome evidence rather than a general marketing claim.
Supply chain and third-party risk to critical infrastructure, especially the power grid, is a top-tier national security and regulatory priority, and Fortress sits squarely inside that concern.
Why CISOs Should Care
Fortress gives regulated critical infrastructure operators a way to move from point-in-time vendor questionnaires to continuous, audit-ready supply chain risk monitoring, directly addressing NERC CIP and similar compliance regimes with documented audit outcomes.
What Makes It Different
Where most GRC and TPRM vendors serve a broad horizontal market, Fortress specializes specifically in critical infrastructure supply chain risk, backed by direct relationships with the largest U.S. utilities and now a major federal government contract.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A specialized, well-capitalized GRC vendor with unusually strong, independently verifiable evidence of impact (a large federal contract, major PE investment, and a documented compliance turnaround at a real utility), making it a standout in the third-party risk management niche.
Editorial Note: Claims vs. Verified Findings
The $919M GSA SCRIPTS contract, the $125M Goldman Sachs Asset Management investment, and the NERC CIP case study outcomes are independently reported via press releases and named case study documents. The '40% of the U.S. power grid' and 'top 7 investor-owned utilities' figures are company-sourced claims not independently re-verified in this research and should be treated as vendor-stated scale claims.
Sources
Alternatives to Fortress Information Security
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…