S-RM
S-RM is a global cyber security and corporate intelligence consultancy offering 24/7 incident response, managed cyber security services, digital forensics, and offensive security, majority-owned by insurer AXA XL.
Visit Website ↗ + Add to CompareOverview
S-RM (originally incorporated as Salamanca Risk Management in 2005) grew from corporate intelligence and risk consulting into a full cyber security practice, now offering 24/7 incident response, managed cyber security services, cyber advisory, digital forensics, and offensive security testing alongside its original corporate intelligence, due diligence, and crisis response lines. That dual heritage — corporate/geopolitical intelligence plus technical cyber response — gives it a broader risk lens than pure-play technical SOC vendors.
Insurer AXA XL holds roughly 49% of S-RM and has announced plans to acquire the remaining stake, tying S-RM increasingly closely to the cyber insurance ecosystem — a structurally significant relationship, since insurer-affiliated incident responders often get early, high-volume visibility into real-world breach patterns across many policyholders.
For CISOs, S-RM’s practical relevance is strongest during and after an actual incident — its 24/7 IR team and forensics capability — and as a strategic advisory resource that blends cyber, corporate intelligence, and crisis response expertise, rather than as an ongoing SOC monitoring platform vendor.
Innovation Matrix Assessment
As a services-led consultancy rather than a product company, its pace of change is reflected in service line expansion (offensive security, managed services) rather than rapid software release cycles.
24/7 incident response combined with broader corporate intelligence and digital forensics capability gives customer security teams a genuinely wider risk-response resource than a narrow technical IR shop.
Growing integration with AXA XL, including a majority ownership stake and plans for full acquisition, signals strong strategic demand for S-RM's capability from a major global insurer.
A conventional, if broad, incident response and risk consultancy model rather than a technology-driven reinvention of SOC or detection capability.
Two decades of operating history and deepening ties to a major cyber insurer (which has direct visibility into claims outcomes) are a reasonable, if indirect, signal of demonstrated real-world incident response capability.
Insurer-integrated incident response and broader corporate risk intelligence remain strategically relevant as cyber insurance increasingly shapes how breaches are managed and priced.
Why CISOs Should Care
CISOs get access to a 24/7 incident response team with insurer-backed scale and cross-portfolio breach pattern visibility via its AXA XL ownership relationship, plus broader corporate intelligence and crisis response capability beyond pure technical response.
What Makes It Different
S-RM's dual heritage in corporate/geopolitical risk intelligence and technical cyber incident response, combined with deepening integration into AXA XL's insurance ecosystem, differentiates it from both pure-play IR boutiques and pure cyber insurers.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A well-established, insurer-integrated incident response and intelligence consultancy whose broad risk lens and claims-data visibility via AXA XL are genuine differentiators, functioning as a services firm rather than a technology platform vendor.
Editorial Note: Claims vs. Verified Findings
Incorporation date and company number are confirmed via the UK's Companies House register; the approximately 49% AXA XL ownership stake and plans for full acquisition are stated on S-RM's own site, and independent confirmation of the precise ownership percentage and timeline was not found beyond that source.
Sources
Alternatives to S-RM
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…