Penetration Testing Isn't About Finding Vulnerabilities—It's About Reducing Business Risk
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Customer Story
AttackIQ offers a SaaS-based solution that continuously evaluates the effectiveness of their customers’ security controls. This unique platform offers dozens of solutions for real-world security scenarios including automated testing, control auditing, and software supply chain security.
AttackIQ
$36.4M annual revenue
Technology
SOC 2 Compliance
The Challenge
Apply security assessment over the AICPA SOC 2 Trust Services Criteria (TSC) to identify where client could clearly demonstrate the success verbiage needed to meet SOC 2 requirements. Map TSC to the NIST 800-53 and create baseline controls to meet future compliance frameworks such as HIPAA and FedRAMP.
As the largest independent vendor in the breach and attack simulation (BAS) market, AttackIQ supports customers across a variety of industries including government, FSI, technology, manufacturing, and healthcare. These customers increasingly sought details about how AttackIQ addresses security themselves as part of due diligence of the supply chain. The Company needed a streamlined, more efficient way to communicate the details, rather than using clunky spreadsheets and questionnaires.
AttackIQ enlisted RKONto review and validate AttackIQ’s robust business and platform security program, leveraging RKON’s years of success helping clients meet SOC 2 compliance via deep AWS security expertise.
AttackIQ sought expert-to-expert consulting, and understood that a third-party audit against a recognized framework would build trust with enterprise procurement teams, thus accelerating sales. AttackIQ selected the SOC 2 compliance framework to communicate how they successfully manage the security, confidentiality, and availability of their platform.
Our Solution
The RKON team examined the entire security posture of their cloud business ecosystem. Together the team reviewed minor modifications to deliver a more secure environment without a ton of retooling or long lead time.
The RKON team applied our security assessment over the AICPA SOC 2 Trust Services Criteria (TSC) so that we could identify where theAttackIQ team could more clearly demonstrate the success verbiage needed to meet SOC 2 requirements.
We mapped the TSC to the NIST 800-53 and created a solid baseline of controls to allow AttackIQ to meet future compliance frameworks such as HIPAA and FedRAMP.
RKON delivered the CloudSec Kickstart – SOC 2 engagement that included an interactive SOC 2 bootcamp, a platform security architecture review, and a SOC 2 compliance readiness assessment. The written report provided tailored analysis and recommendations to leverage AWS services and security features to reduce friction for developers and lower operating costs.
AttackIQ ended their engagement with us with discrete and specific outcomes: they had a list of prioritized recommendations that they could pursue to optimize their containerized workloads on AWS; and they had a line-by-line list of executable directions to successfully demonstrate SOC 2 compliance. Finally, they had a brand new set of NIST-sourced controls for their company that would scale into the more comprehensive frameworks in preparation of pursuing additional markets.
"Our business is security controls, so we already understood the SOC 2 criteria. RKON showed us how to succeed with SOC 2 beyond just implementing the controls. The team provided expert guidance and support along the way."
- Vinod Peris, VP of Engineering at Attack IQ
“An independent SOC 2 attestation offers stronger assurance for our customers. I’m confident that we’ll be able to accelerate our sales cycles, particularly with customers in regulated industries. We definitely won’t miss answering security questionnaire spreadsheets.”
- Brandt Mackey, VP of Product at Attack IQ
Penetration Testing Isn’t About Finding Vulnerabilities—It’s About Reducing Business Risk The most valuable penetration ...
Cyber Risk Is Continuously Evolving. Your Security Validation Strategy Should Keep Pace. Many organizations view penetra...
Why Validating Your Defenses Is Just as Important as Investing in Them Organizations continue to invest heavily in cyber...
The System Security Plan is dead. FedRAMP’s Consolidated Rules for 2026 (CR26), published June 24, retired the document ...