TrustedSec
TrustedSec is a CREST-accredited penetration testing, red team, and incident response consultancy founded by David Kennedy, creator of the Social-Engineer Toolkit.
Visit Website ↗ + Add to CompareOverview
TrustedSec is an Ohio-based offensive-security and incident-response consultancy founded in 2012 by David Kennedy, a former NSA and Marine Corps signals-intelligence operator who also created the widely-used Social-Engineer Toolkit (SET) and served as a technical advisor to Mr. Robot. The firm built its reputation on hands-on red team engagements, penetration testing, adversarial simulation, and digital forensics/incident response rather than shipping a product — it sells expertise and delivery, not a platform.
That services orientation shows up in its credentialing: TrustedSec holds CREST accreditation for penetration testing, a third-party quality bar that many boutique offensive-security shops don’t pursue, and it has continued to invest in incident-response bench strength, including hiring a former FBI unit chief to lead its IR practice. The firm has grown from its Strongsville, Ohio origins into a larger, purpose-built Fairlawn headquarters, evidence of sustained services demand rather than one-off project work.
For CISOs, TrustedSec is a fit when the need is people-driven: an annual red team exercise, a post-breach forensic investigation, or a mature offensive-security program buildout, not a control that runs continuously in the environment. Its value is judged by the caliber of its consultants and the credibility of its findings, which is harder to benchmark quantitatively than a detection product’s efficacy — but CREST accreditation and over a decade of continuous, name-brand client work are real, checkable signals.
Innovation Matrix Assessment
As a services firm, velocity shows up in practice expansion rather than release cycles: TrustedSec has continued adding capability lines (recent hire of a former FBI unit chief to lead incident response) and open-source tooling contributions from its research team.
Grew from its 2012 Strongsville, Ohio founding into a dedicated 20,000-square-foot Fairlawn headquarters, indicating sustained, scaled services demand rather than a boutique one-project shop.
Momentum is consistent and services-driven: continuous client demand for over a decade, recent CREST accreditation, and senior hires (former FBI unit chief) signal an actively growing incident-response practice rather than stagnation.
TrustedSec doesn't disrupt technology categories since it's a services firm, but its founder's Social-Engineer Toolkit (SET) has been a genuinely influential open-source contribution to the offensive-security tooling ecosystem industry-wide.
CREST accreditation for penetration testing is a real, independent third-party quality bar that not all competitors hold, and the firm's decade-plus track record with named enterprise clients across finance, healthcare, and manufacturing is a genuine efficacy signal for services quality.
Highly relevant: red team testing, penetration testing, and incident response are core, recurring needs for any mature security program, and TrustedSec's dual focus on offense and IR covers both proactive and reactive sides of that need.
Why CISOs Should Care
CISOs building or validating a security program turn to firms like TrustedSec for independent, CREST-accredited penetration testing and adversarial simulation, plus incident-response bench strength when something goes wrong.
What Makes It Different
Differentiated by founder pedigree (David Kennedy, SET creator, Mr. Robot technical advisor) and CREST accreditation, a formal quality bar many boutique offensive-security consultancies skip.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
A credible, independently accredited offensive-security and incident-response consultancy with a decade-plus track record — strong on relevance and delivery credibility, though as a services firm it doesn't carry the product-disruption profile of a technology vendor.
Editorial Note: Claims vs. Verified Findings
Independently verifiable: CREST accreditation is confirmed directly by CREST's own announcement, and David Kennedy's SET authorship and NSA/Marine Corps background are corroborated across multiple independent press sources. Client-satisfaction and engagement-outcome claims on TrustedSec's own site are vendor-sourced and not independently audited in our research.
Sources
Alternatives to TrustedSec
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
ReliaQuest
ReliaQuest operates GreyMatter, a security operations platform that unifies detection, investigation, and response across a customer's existing security…