Skip to content

Komodo Consulting

Herzliya, Israel-based penetration testing and TIBER-EU-aligned red team firm serving Fortune 500 clients across banking, energy, healthcare and critical infrastructure.

Visit Website ↗ + Add to Compare
47/100Emerging / Unranked

Overview

Komodo Consulting, also marketed as KomodoSec, is a cybersecurity consulting firm founded in 2011 by Boaz Shunami and Yossi Shenhav and headquartered in Herzliya, Israel, with a London presence covering its European and UK client base. The firm has built a 14-year track record doing offensive security work — penetration testing and red team exercises — for Fortune 500 clients across banking, insurance, automotive, energy, telecommunications, critical infrastructure and healthcare.

Its service portfolio spans full black-box and white-box penetration testing of networks, web applications and mobile apps; cloud security assessments across AWS, GCP and Azure; application security consulting; cyber threat intelligence; and incident response. Notably, Komodo runs red team exercises modeled on the TIBER-EU framework — the European threat-led penetration testing standard used to validate financial institutions’ resilience against realistic, intelligence-driven attack scenarios — which signals a more rigorous, regulator-aligned methodology than generic red teaming.

For CISOs, particularly at European financial institutions facing TIBER-EU or DORA-related testing obligations, Komodo is a boutique alternative to the large consultancies for threat-led red team engagements, with the trade-off that as a small, privately held firm (no public funding history was found) its capacity and bench depth are inherently more limited than a big-four-style provider.

Innovation Matrix Assessment

Innovation Velocity 5/10

Adopting the TIBER-EU threat-led red team methodology shows the firm keeping pace with evolving European financial-sector testing regulation, though this is methodology adoption rather than proprietary technology development.

Operational Value 6/10

Fourteen years of continuous operation serving Fortune 500 clients across multiple regulated verticals is a solid, if not exceptional, operational track record for a boutique offensive-security consultancy.

Market Momentum 4/10

Employee counts reported by third-party data providers are small (roughly a few dozen), and no funding rounds or major expansion announcements were found, suggesting steady rather than fast-growing momentum.

Category Disruption 3/10

Penetration testing and red teaming are well-established service categories; Komodo's differentiation is methodology rigor (TIBER-EU alignment) rather than a novel technical approach or product.

Real-World Efficacy 4/10

Serving named-industry Fortune 500 clients implies a level of vendor vetting, but client confidentiality in offensive-security engagements means no publicly named case study or quantified outcome could be verified for this profile.

Enduring Relevance 6/10

Threat-led penetration testing is a growing regulatory requirement for European financial institutions (TIBER-EU, and the related DORA framework), keeping demand for firms with this specific capability consistently relevant.

Why CISOs Should Care

Provides a boutique option for TIBER-EU-aligned, threat-led red team testing that is increasingly required or expected of European financial institutions and other regulated entities.

What Makes It Different

Explicit alignment with the TIBER-EU threat-led penetration testing framework, a more rigorous and regulator-recognized methodology than generic penetration testing offered by many smaller firms.

The Matrix Verdict

47/100 — EMERGING / UNRANKED

A credible, long-tenured boutique offensive-security firm with a genuine regulatory-methodology edge (TIBER-EU); appropriate for organizations seeking a smaller, specialized red team partner rather than a large multi-service consultancy.

Editorial Note: Claims vs. Verified Findings

Client-industry claims (Fortune 500 across banking, insurance, automotive, energy, healthcare) are self-reported by Komodo with no publicly named clients, consistent with standard confidentiality practices in penetration testing engagements; this should be read as an unverified but plausible claim rather than independently confirmed. TIBER-EU framework alignment is independently verifiable as a defined, published European testing standard.

Sources