S-RM
S-RM is a global cyber security and corporate intelligence consultancy offering 24/7 incident response, managed cyber security services, digital forensics, and offensive security, majority-owned by insurer AXA XL.
Visit Website ↗ + Add to CompareOverview
S-RM (originally incorporated as Salamanca Risk Management in 2005) grew from corporate intelligence and risk consulting into a full cyber security practice, now offering 24/7 incident response, managed cyber security services, cyber advisory, digital forensics, and offensive security testing alongside its original corporate intelligence, due diligence, and crisis response lines. That dual heritage — corporate/geopolitical intelligence plus technical cyber response — gives it a broader risk lens than pure-play technical SOC vendors.
Insurer AXA XL holds roughly 49% of S-RM and has announced plans to acquire the remaining stake, tying S-RM increasingly closely to the cyber insurance ecosystem — a structurally significant relationship, since insurer-affiliated incident responders often get early, high-volume visibility into real-world breach patterns across many policyholders.
For CISOs, S-RM’s practical relevance is strongest during and after an actual incident — its 24/7 IR team and forensics capability — and as a strategic advisory resource that blends cyber, corporate intelligence, and crisis response expertise, rather than as an ongoing SOC monitoring platform vendor.
Innovation Matrix Assessment
As a services-led consultancy rather than a product company, its pace of change is reflected in service line expansion (offensive security, managed services) rather than rapid software release cycles.
24/7 incident response combined with broader corporate intelligence and digital forensics capability gives customer security teams a genuinely wider risk-response resource than a narrow technical IR shop.
Growing integration with AXA XL, including a majority ownership stake and plans for full acquisition, signals strong strategic demand for S-RM's capability from a major global insurer.
A conventional, if broad, incident response and risk consultancy model rather than a technology-driven reinvention of SOC or detection capability.
Two decades of operating history and deepening ties to a major cyber insurer (which has direct visibility into claims outcomes) are a reasonable, if indirect, signal of demonstrated real-world incident response capability.
Insurer-integrated incident response and broader corporate risk intelligence remain strategically relevant as cyber insurance increasingly shapes how breaches are managed and priced.
Why CISOs Should Care
CISOs get access to a 24/7 incident response team with insurer-backed scale and cross-portfolio breach pattern visibility via its AXA XL ownership relationship, plus broader corporate intelligence and crisis response capability beyond pure technical response.
What Makes It Different
S-RM's dual heritage in corporate/geopolitical risk intelligence and technical cyber incident response, combined with deepening integration into AXA XL's insurance ecosystem, differentiates it from both pure-play IR boutiques and pure cyber insurers.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A well-established, insurer-integrated incident response and intelligence consultancy whose broad risk lens and claims-data visibility via AXA XL are genuine differentiators, functioning as a services firm rather than a technology platform vendor.
Editorial Note: Claims vs. Verified Findings
Incorporation date and company number are confirmed via the UK's Companies House register; the approximately 49% AXA XL ownership stake and plans for full acquisition are stated on S-RM's own site, and independent confirmation of the precise ownership percentage and timeline was not found beyond that source.
Sources
Alternatives to S-RM
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…
Google Security Operations
Google's cloud-scale SIEM/SOAR (formerly Chronicle), unifying a petabyte-scale data lake with Mandiant frontline threat intelligence and Gemini-powered investigation.