RSA
Bedford, Massachusetts-based identity security vendor best known for SecurID hardware and software tokens, now an independent private company offering multi-factor authentication, access management, and identity governance.
Visit Website ↗ + Add to CompareOverview
RSA is one of the oldest brand names in commercial cybersecurity, originally built around public-key cryptography (the RSA algorithm, named for founders Rivest, Shamir, and Adleman in 1982) and later best known for SecurID, the hardware and software one-time-password token widely deployed for enterprise multi-factor authentication starting in the 1990s and 2000s. Note: this profile covers RSA’s identity security business (SecurID and related access management and identity governance products); its former GRC platform, Archer, was spun out as a separate independent company in 2022 and is profiled separately on this site.
RSA has changed hands repeatedly over the past two decades: acquired by EMC in 2006, folded into Dell after Dell’s EMC acquisition in 2016, then spun out again in 2020 when a consortium led by Symphony Technology Group (STG), together with Ontario Teachers’ Pension Plan and AlpInvest Partners, bought RSA as an independent company. It is now RSA Security LLC, headquartered in Bedford, Massachusetts, with more than 2,700 employees and Greg Nelson serving as CEO. The 2011 breach of RSA’s own SecurID seed database — attributed to a nation-state actor and used in follow-on attacks against RSA customers including defense contractors — remains a significant, well-documented episode in the company’s history and a reminder that even foundational identity vendors are high-value targets themselves.
Post-spinout, RSA has focused on modernizing SecurID with passwordless and risk-based authentication options alongside its legacy hardware token base, competing against newer, cloud-native identity vendors that do not carry RSA’s decades of on-premises deployment and hardware-token legacy architecture. Its relevance today rests heavily on its enormous embedded base of existing SecurID customers rather than being the newest or fastest-growing identity platform on the market.
Innovation Matrix Assessment
Has added passwordless and risk-based authentication options on top of its legacy SecurID token base since the 2020 spinout, but as a large, mature identity incumbent its pace of new capability delivery lags cloud-native identity challengers.
SecurID multi-factor authentication is a proven, widely deployed operational control for enterprise and government access; its hardware token option is also useful specifically where phone-based MFA is impractical or restricted (e.g., classified or air-gapped environments).
RSA has been sold and restructured repeatedly (EMC in 2006, Dell/EMC merger 2016, STG-led buyout in 2020, Archer spinout in 2022), reflecting an incumbent working through ownership and portfolio changes rather than a company on a clear growth trajectory; no recent independent revenue-growth figures were found.
A 40+ year old, large-scale identity incumbent whose core SecurID product architecture predates the cloud-native identity category by decades; per this site's convention, scaled legacy incumbents of this size are scored as low-disruption regardless of continued relevance.
Decades of large-scale enterprise and government deployment provide strong indirect evidence the core authentication technology works reliably at scale, though the well-documented 2011 SecurID seed-database breach is a serious, independently confirmed historical incident that also demonstrates real consequences when a foundational identity vendor is itself compromised.
Multi-factor authentication remains a baseline security requirement, and RSA's enormous embedded SecurID customer base keeps it relevant, but newer cloud-native and passwordless-first identity platforms are increasingly the default choice for new deployments.
Why CISOs Should Care
For organizations with an existing large SecurID hardware/software token deployment, particularly in regulated, government, or air-gapped environments, RSA offers continuity and a modernization path without a full identity platform migration.
What Makes It Different
An enormous embedded base of hardware-token deployments across government and regulated industries gives RSA a switching-cost advantage that newer cloud-native identity vendors don't have to displace, for better or worse.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
A legacy identity incumbent with real ongoing relevance through its massive SecurID installed base, but limited disruption potential and a history that includes one of the industry's most consequential vendor breaches; a safe continuity choice rather than a forward-looking bet.
Editorial Note: Claims vs. Verified Findings
RSA's ownership history (EMC, Dell, STG-led 2020 buyout, 2022 Archer spinout) and the 2011 SecurID breach are independently and extensively reported in industry and mainstream press. Current-generation product performance and passwordless-authentication claims found in RSA's own marketing are vendor-sourced and not independently benchmarked in this research.
Sources
Alternatives to RSA
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.