Guardian360
Dutch, self-funded external attack surface management platform combining continuous asset discovery, vulnerability scanning, and NCSC threat-intel feeds for European compliance.
Visit Website ↗ + Add to CompareOverview
Guardian360 is a Utrecht, Netherlands-based external attack surface management (EASM) vendor built and hosted entirely within the Netherlands, a deliberate choice aimed at customers with EU data-residency and sovereignty requirements. Its Lighthouse platform continuously discovers and monitors internet-facing assets, layers in internal and external vulnerability scanning, and pipes findings from the Dutch National Cyber Security Centre (NCSC) and other European threat-intel sources directly into its risk scoring, then maps results against 25-plus compliance frameworks including ISO 27001, NIS2, and DORA.
Founded in 2015 and still 100% privately owned with no venture capital raised, Guardian360 sells exclusively through a partner channel rather than direct enterprise sales, a distribution model more common among smaller regional security vendors than EASM competitors. The company’s stated philosophy is to prioritize exploitability and real-world risk over raw vulnerability counts — asking what is actually reachable and dangerous right now rather than generating exhaustive scan reports that security teams have to triage themselves.
Guardian360 competes in an EASM category increasingly crowded by larger, venture-backed players and by attack-surface features bundled into broader XSPM and vulnerability management suites. Its differentiator is a Dutch/EU-sovereign hosting and data model tied directly into NCSC threat feeds, which appeals specifically to European public-sector and regulated customers, but its bootstrapped, partner-only, roughly 10-person operation is small relative to well-funded EASM competitors with global reach.
Innovation Matrix Assessment
As a small, self-funded team, Guardian360's product cadence is steady rather than fast; the vendor's own materials describe continuous platform refinement but no independently confirmed release velocity or AI-driven feature rollout was found.
Guardian360 has operated continuously since 2015, holds ISO 27001 certification, and runs its platform entirely on Dutch-hosted infrastructure, giving it a stable if small operational footprint appropriate to its roughly 10-person scale.
With no venture funding and no publicly disclosed revenue or customer-growth figures, there is limited independent evidence of accelerating momentum; the company appears to be a steady, long-running bootstrapped operation rather than one in a visible growth spike.
The direct pipeline from Dutch NCSC threat intelligence into exploitability-focused risk scoring is a genuine differentiator versus generic vulnerability-count scanners, but EASM as a category is now well established rather than architecturally novel.
Mapping findings against 25-plus frameworks (ISO 27001, NIS2, DORA) and integrating NCSC feeds are independently verifiable platform capabilities, but no third-party penetration-test results, breach-prevention case studies, or lab evaluations were found to substantiate detection accuracy claims.
NIS2 and DORA are actively reshaping compliance obligations for European organizations right now, making a Dutch/EU-sovereign EASM platform with built-in framework mapping directly relevant to the compliance pressure regulated European buyers currently face.
Why CISOs Should Care
European CISOs under NIS2 or DORA pressure who need EU-sovereign attack surface visibility with compliance mapping built in, rather than a US-hosted platform, get a purpose-built option in Guardian360.
What Makes It Different
Guardian360 hosts entirely within the Netherlands and pipes NCSC threat intelligence directly into its exploitability scoring, and sells exclusively through partners rather than direct sales, unlike most venture-backed EASM competitors.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A durable, values-driven Dutch EASM vendor whose EU-sovereignty and NCSC integration are real and differentiated for European compliance buyers, but whose bootstrapped, partner-only, small-team model caps its scale and independent verification relative to larger-funded EASM competitors.
Editorial Note: Claims vs. Verified Findings
Independently verifiable: 2015 founding, Utrecht HQ, self-funded/no-VC status, and ISO 27001 certification are corroborated by Dutch business registry and trade sources. Vendor-sourced and unverified: specific claims about NCSC feed integration depth, the 25-plus framework count, and platform accuracy are drawn from Guardian360's own site and could not be independently cross-checked.
Sources
Alternatives to Guardian360
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…