Skip to content

Brier & Thorn

San Diego-based, ISO 27001-certified vendor-neutral MSSP offering managed detection and response, threat intelligence, and SecOps-as-a-Service across North and Latin America.

Visit Website ↗ + Add to Compare
48/100Emerging / Unranked

Overview

Brier & Thorn is a managed security service provider (MSSP) offering a vendor-neutral security operations center covering managed detection and response (MDR), penetration testing, incident response and forensics, risk assessments, and information security management system (ISMS) program development. Its “SecOps-as-a-Service” offering packages outsourced security operations functions — tooling, monitoring, and analyst expertise — for organizations that don’t want to build and staff a SOC internally, backed by threat intelligence feeds the company says keep detection logic current against emerging threats.

Founded around 2010 and headquartered in San Diego, California, with an operating entity in Mexico supporting Latin American clients, Brier & Thorn is ISO 27001 certified — an independently auditable standard for information security management that provides real third-party verification of its internal security processes, distinct from unverifiable marketing claims. The company has also formed technology partnerships, including a 2022 agreement with BlastWave to resell BlastShield OT/ICS network security in North and Latin America and a services partnership with Tego Cyber for threat intelligence.

Brier & Thorn’s vendor-neutral SOC model is a well-established MSSP pattern rather than a novel technology, and its cross-border North America/Latin America footprint is its main practical differentiator versus similarly sized US-only MSSPs. No independent, named case study quantifying detection or response-time outcomes was found; assessment of its actual SOC performance depends largely on the company’s own materials and its ISO 27001 certification as a process-maturity signal.

Innovation Matrix Assessment

Innovation Velocity 5/10

The company has added a formal SecOps-as-a-Service package and struck OT-focused (BlastWave) and threat-intelligence (Tego Cyber) partnerships in recent years, showing steady but incremental capability expansion.

Operational Value 6/10

Fifteen years of operation, ISO 27001 certification, and a cross-border US/Mexico operating structure indicate real operational maturity for an MSSP of its size.

Market Momentum 4/10

Growth signals are limited to partnership announcements (BlastWave, Tego Cyber) rather than disclosed funding rounds or headcount/revenue growth figures, making momentum harder to size than for a VC-backed peer.

Category Disruption 3/10

A vendor-neutral, outsourced SOC/MDR model is a well-established MSSP category pattern; Brier & Thorn's North America/Latin America cross-border reach is a practical differentiator but not a technological one.

Real-World Efficacy 5/10

ISO 27001 certification is a genuine, independently audited process-maturity signal; specific detection/response performance metrics or a named customer outcome study were not found and are not independently verifiable from public sources.

Enduring Relevance 6/10

Outsourced MDR/SecOps remains a real need for organizations without in-house SOC capacity, and a cross-border US/Latin America footprint is a relevant differentiator for multinational mid-market companies with operations in both regions.

Why CISOs Should Care

CISOs at mid-market organizations with operations spanning the US and Latin America get a single vendor-neutral MSSP partner with ISO 27001-certified processes rather than needing separate regional security operations providers.

What Makes It Different

Cross-border US/Latin America SOC coverage combined with a vendor-neutral tooling stance differentiates Brier & Thorn from single-region or single-vendor-aligned MSSP competitors.

The Matrix Verdict

48/100 — EMERGING / UNRANKED

A steady, ISO 27001-certified vendor-neutral MSSP with a genuine cross-border US/Latin America niche; solid and credible but operating in a mature category without independently documented performance differentiation.

Editorial Note: Claims vs. Verified Findings

Independently verifiable: San Diego headquarters, ISO 27001 certification claim, and the BlastWave/Tego Cyber partnerships are corroborated by press releases (PR Newswire, Barchart) and the company's own certifications page. Vendor-sourced and unverified: specific SOC detection/response performance claims and client outcomes come from Brier & Thorn's own materials and were not independently confirmed.

Sources