InnoSec
STORM platform quantifies cyber risk in business-impact terms for enterprises, insurers, and M&A due diligence, recognized as a Gartner Cool Vendor in 2018.
Visit Website ↗ + Add to CompareOverview
InnoSec builds STORM, a cyber risk management platform that lets large enterprises, government entities, M&A teams, and cyber insurers assess, quantify, and prioritize security posture and spending from a business-impact rather than purely technical perspective. STORM calculates cyber risk levels and business impact according to asset value, helps prioritize and budget security initiatives against cost and risk reduction, supports cyber incident management, and automates elements of compliance reporting for frameworks like GDPR.
Founded in 2015 and based in Hod Hasharon, Israel, InnoSec was named a Gartner “Cool Vendor” in Privacy Management in 2018, an independent analyst recognition rather than a self-reported claim, though that recognition is now several years old. STORM is offered both on-premise and as SaaS, giving it flexibility for regulated customers such as government and insurance entities that may resist pure cloud delivery.
InnoSec occupies a similar cyber risk quantification and management niche to RiskQ and other GRC-adjacent vendors, competing on its specific asset-value-based risk calculation approach and its target base of insurers and M&A due-diligence users; no recent funding or customer-scale data was found beyond the company’s own materials and older analyst mentions.
Innovation Matrix Assessment
No recent (post-2018) product news or funding announcements were found beyond the company's core STORM platform description, suggesting a slower current pace of visible innovation.
STORM covers asset-value-based risk calculation, initiative prioritization and budgeting, incident management, and automated compliance reporting, a reasonably full GRC workflow, offered both on-premise and as SaaS.
No recent funding rounds or major customer announcements were found; its most notable independent recognition, a Gartner Cool Vendor naming, dates to 2018.
Asset-value-based cyber risk quantification for insurers and M&A due diligence is a differentiated angle within GRC, though InnoSec is one of several vendors pursuing similar cyber risk quantification approaches.
The 2018 Gartner Cool Vendor recognition is an independent, non-vendor-sourced signal of product quality, but is now dated and no more recent independent validation was found.
Cyber risk quantification for insurance and M&A due diligence remains a real use case, though InnoSec's visibility and independent validation have not kept pace with more recently funded competitors in the space.
Why CISOs Should Care
Useful for organizations, particularly insurers and M&A teams, that need to translate technical risk posture into asset-value-based business impact for underwriting or deal decisions.
What Makes It Different
Targets insurance and M&A due-diligence use cases specifically, alongside general enterprise risk management, a narrower go-to-market focus than many GRC platforms.
The Matrix Verdict
42/100 — EMERGING / UNRANKED
A capable, independently recognized (if dated) cyber risk quantification platform with a differentiated insurance/M&A angle, but limited visible recent momentum or new independent validation.
Editorial Note: Claims vs. Verified Findings
The Gartner Cool Vendor recognition (2018) is an independently verifiable analyst designation; feature descriptions and platform capabilities are drawn from the company's own site with no independent case studies found.
Sources
Alternatives to InnoSec
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…