# Best Breach and Attack Simulation (BAS) Software for Medium-Sized Businesses

## How Many Breach and Attack Simulation (BAS) Software Products Does G2 Track?

**Total Products under this Category:** 54

### Category Stats (Aug 2026)

- **Average Rating:** 4.56/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** OpenAEV by Filigran (+5.56%) - Among all products in this category, OpenAEV by Filigran recorded the largest rating increase compared to last month

_Last updated: August 15, 2026_

## How Does G2 Rank Breach and Attack Simulation (BAS) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,200+ Authentic Reviews
- 54+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Breach and Attack Simulation (BAS) Software
 ![G2 Grid® for Breach and Attack Simulation (BAS) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.png?focus%5B%5D=56073&focus%5B%5D=56001&focus%5B%5D=1458180&focus%5B%5D=100365&focus%5B%5D=98391&focus%5B%5D=124451&focus%5B%5D=1312654)

Highlighted products: Picus Security, Cymulate, Adaptive Security, Sophos PhishThreat, Pentera, Right-Hand Cybersecurity, and AI-Native Continuous Offensive Security Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.json?focus%5B%5D=picus-security&focus%5B%5D=cymulate&focus%5B%5D=adaptive-security&focus%5B%5D=sophos-phishthreat&focus%5B%5D=pentera&focus%5B%5D=right-hand-cybersecurity&focus%5B%5D=ai-native-continuous-offensive-security-platform&segment=mid-market)

**Sponsored**

### BrandMail

BrandMail is a specialized email branding solution developed by BrandQuantum, designed to assist organizations in maintaining a consistent brand image across all email communications. By integrating seamlessly with Microsoft Outlook and Google Workspace, BrandMail empowers employees to create professionally branded emails effortlessly through a single, user-friendly toolbar. This tool provides access to the latest pre-approved content and brand standards, ensuring that every outgoing email aligns with the organization's branding guidelines. Targeted at businesses of all sizes, BrandMail is particularly beneficial for marketing teams, human resources, and any departments that rely heavily on email as a primary communication channel. The software addresses common challenges faced by organizations, such as inconsistent branding, unauthorized content use, and the complexities of managing email signatures and banners across a large workforce. With BrandMail, companies can ensure that all employees adhere to brand guidelines without the need for extensive training or oversight, thereby simplifying the branding process. Key features of BrandMail include centrally managed, tamper-proof email signatures, banners, and content, which guarantee that all outgoing communications accurately reflect the organization's branding. The tool also provides comprehensive analytics and reporting capabilities, enabling organizations to track engagement and assess the effectiveness of their email campaigns. Its compatibility with various platforms, including Outlook desktop (from 2010 to O365), O365 Web, Mac, and mobile devices, ensures that users can access the tool on their preferred devices, enhancing flexibility and usability. Moreover, BrandMail supports over 133 languages, making it an ideal choice for multinational organizations that require consistent branding across diverse markets. The software also offers 24/7 user and VIP admin support, ensuring that users have access to assistance whenever needed. This robust support system enhances the overall user experience, allowing organizations to streamline their email branding process effectively. By providing a comprehensive solution that prioritizes brand integrity and communication effectiveness, BrandMail stands out as a valuable tool for organizations aiming to elevate their email communications.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2047&secure%5Bchosen_at%5D=2026-08-15T09%3A15%3A16Z&secure%5Bdisplayable_resource_id%5D=1126&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=139550&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=139550&secure%5Bresource_id%5D=2047&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fbreach-and-attack-simulation-bas%2Fmid-market&secure%5Btoken%5D=41c8bc19eb00f33298a56a43cf7436171db147a246194c58fd3db60463f98c90&secure%5Burl%5D=https%3A%2F%2Fbrandquantum.com%2Fbrandmail-free-trial%3Futm_source%3Dg2%26utm_medium%3Dg2clicks%26utm_campaign%3Dcomp&secure%5Burl_type%5D=free_trial)

### [Picus Security](https://www.g2.com/products/picus-security/reviews)

Picus Security helps enterprise security teams reduce cyber risk with the Picus Autonomous Exposure Validation Platform. Picus proves what attackers can actually exploit in your environment and what your security controls stop, turning every exposure into a defensible decision: patch, mitigate, monitor, or accept. The platform validates attack surfaces, exposures, and security controls as one continuous loop, uniting breach and attack simulation, automated penetration testing, and exposure validation. With techniques mapped to MITRE ATT&CK, teams prioritize by real exploitation risk instead of severity scores, prove their EDR, SIEM, and firewall controls work, and report measurable risk reduction to leadership. Picus pioneered Breach and Attack Simulation in 2013 and works with security teams across financial services, healthcare, energy, and technology.

**Average Rating:** 4.8/5.0

**Total Reviews:** 229

#### Who Is the Company Behind Picus Security?

- **Seller:** [Picus Security](https://www.g2.com/sellers/picus-security)
- **Company Website:** www.picussecurity.com
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California
- **Twitter:** @PicusSecurity  
2,916 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1071751e714fd0ce1530e5a7b8ca294f43039133144caf44668408ee0d546e8f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpicus-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
315 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Cyber Security Specialist, Cyber Security Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 38% Large, 37% Medium

#### What Do G2 Reviewers Say About Picus Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Picus Security for its **realistic and proactive attack simulations** , enhancing defenses and fostering confidence in cybersecurity.
- Users commend the **ease of use** of Picus Security, highlighting its reliable performance and responsive support team.
- Users commend **continuous validation** in Picus Security, enhancing security posture and identifying gaps through real-world simulations.
- Users value the **actionable insights** from Picus Security, optimizing defenses through real-world attack simulations and clear reporting.
- Users praise the **seamless integration** of Picus Security with existing tools, enhancing overall cybersecurity effectiveness.

##### Cons

- Users face **reporting limitations** with Picus Security, requiring additional effort to finalize reports and access data.
- Users face **integration issues** with limited third-party coverage, hindering seamless validation and complicating initial setup.
- Users face a **steep learning curve** with Picus Security, requiring time and training to fully utilize its features.
- Users find the **complex setup** of Picus Security requires considerable effort, especially for advanced configurations.
- Users find the **limited customization** options for reports and dashboards restrict their ability to tailor security assessments.

#### What Are Recent G2 Reviews of Picus Security?

**["A Proactive Approach to Threat Readiness"](https://www.g2.com/survey_responses/picus-security-review-11441729)**

**Rating:** 4.5/5.0 stars

_— Rohit Y._

[Read full review](https://www.g2.com/survey_responses/picus-security-review-11441729)

**["Picus Makes Our Security Stronger"](https://www.g2.com/survey_responses/picus-security-review-11497382)**

**Rating:** 5.0/5.0 stars

_— Ved Prakash M._

[Read full review](https://www.g2.com/survey_responses/picus-security-review-11497382)

#### What Are G2 Users Discussing About Picus Security?

- [What is Picus Security used for?](https://www.g2.com/discussions/what-is-picus-security-used-for)

### [Cymulate](https://www.g2.com/products/cymulate/reviews)

Designed for security teams to continuously validate threats and build exposure-informed defenses, the Cymulate Platform combines advanced attack simulation with an agentic cyber defense engineering control plane to continuously prove, prioritize and adapt security controls for the latest threats. With a daily feed of threat intelligence and a comprehensive attack library, Cymulate is a SaaS offering that applies AI to tailor offensive testing to the environment while integrating with security stack to push updates for immediate prevention and detection. Core use cases include threat validation, control validation & tuning, detection engineering, and vulnerability validation and prioritization.

**Average Rating:** 4.9/5.0

**Total Reviews:** 176

#### Who Is the Company Behind Cymulate?

- **Seller:** [Cymulate](https://www.g2.com/sellers/cymulate)
- **Company Website:** www.cymulate.com
- **Year Founded:** 2016
- **HQ Location:** Holon, Israel
- **Twitter:** @CymulateLtd  
1,079 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ecaa1ad35895f03003e3d88c09d51eac6f2490113ea2af6c7e64d48000f425ff&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcymulate&secure%5Burl_type%5D=linkedin_company_website)  
231 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Analyst, Cyber Security Engineer
- **Top Industries:** Financial Services, Banking
- **Company Size:** 56% Large, 43% Medium

#### What Do G2 Reviewers Say About Cymulate?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **intuitive and user-friendly design** of Cymulate, enabling easy deployment and effective management.
- Users value the **effective continuous security validation** provided by Cymulate, enhancing their assessment of security controls.
- Users value the **continuous and actionable vulnerability identification** in Cymulate, enhancing threat assessments and risk management.
- Users appreciate the **extensive customization options** of Cymulate, enhancing their simulation and assessment capabilities.
- Users appreciate the **excellent customer support** provided by Cymulate, enhancing their overall experience and effectiveness.

##### Cons

- Users note that **dynamic reporting and integration stability** need improvement for better execution and overall experience.
- Users find **integration issues** significant, as they seek better feasibility and stability with third-party platforms.
- Users find the **reporting process time-consuming** and complicated, especially when presenting to management and for beginners.
- Users find that **advanced features can be complex to configure** , leading to a steep learning curve for newcomers.
- Users find the **inefficient alert system** challenging, affecting real-time notifications and making assessments cumbersome to manage.

#### What Are Recent G2 Reviews of Cymulate?

**["Comprehensive BAS with Easy Setup and Stellar Coverage"](https://www.g2.com/survey_responses/cymulate-review-12504573)**

**Rating:** 5.0/5.0 stars

_— Shubham A._

[Read full review](https://www.g2.com/survey_responses/cymulate-review-12504573)

**["Realistic, Continuous Security Validation Without Disrupting Production"](https://www.g2.com/survey_responses/cymulate-review-12619957)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/cymulate-review-12619957)

### [Adaptive Security](https://www.g2.com/products/adaptive-security/reviews)

Adaptive Security is the security layer for the AI era, protecting organizations and their employees from modern cyberattacks. AI has changed how every company works, and it's changed how every company gets attacked. Employees use AI tools IT doesn't know about. Attackers craft deepfakes, vishing calls, and spear phishing emails that get past filters. Adaptive addresses all of it in one unified platform: managing AI tool usage before it becomes a liability, training employees on the threats they'll actually face, simulating AI-powered attacks in a safe environment, and protecting the inbox and browser so threats never reach their intended targets. Because it's one platform, Adaptive develops a complete risk picture and uses it automatically, applying targeted training, attack simulations, real-time interventions, and policy controls to lower risk over time. More than 1,000 organizations run Adaptive to manage their human security program, and the company has raised $150M+ from investors including NVIDIA, Andreessen Horowitz, Bain Capital Ventures, and Citi Ventures.

**Average Rating:** 4.9/5.0

**Total Reviews:** 115

#### Who Is the Company Behind Adaptive Security?

- **Seller:** [Adaptive Security](https://www.g2.com/sellers/adaptive-security)
- **Company Website:** www.adaptivesecurity.com
- **Year Founded:** 2024
- **HQ Location:** New York, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=edc74b1bab2dbad86ff02cc7b07c6b2a2fade49be4035b1c6903fe89569a0d13&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fadaptivesecurity&secure%5Burl_type%5D=linkedin_company_website)  
242 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** IT Manager
- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 71% Medium, 16% Large

#### What Do G2 Reviewers Say About Adaptive Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **engaging and customizable training** in Adaptive Security, enhancing employee awareness and relevance to business needs.
- Users praise the **user-friendly interface** of Adaptive Security, making setup and navigation quick and easy.
- Users commend the **responsive customer support** of Adaptive Security, providing quick and helpful assistance throughout their experience.
- Users commend the **easy implementation** of Adaptive Security, enabling swift deployment and efficient setup processes.
- Users value the **increase in awareness** provided by Adaptive Security, enjoying effective simulations and insightful analytics.

##### Cons

- Users find **limited customization options** frustrating, desiring more control for tailored user management and communications.
- Users find the **group management feature underdeveloped** , causing manual effort and delays in training assignments.
- Users point out the need for **inadequate reporting** , as the tool lacks flexibility for metrics presentation and exports.
- Users find **integration issues** with Adaptive Security challenging, especially for those lacking technical expertise during setup.
- Users find the **learning curve challenging** , particularly during initial setup and configuration of integrations and analytics.

#### What Are Recent G2 Reviews of Adaptive Security?

**["Great product and an even better team"](https://www.g2.com/survey_responses/adaptive-security-review-13272548)**

**Rating:** 5.0/5.0 stars

_— Dawid S._

[Read full review](https://www.g2.com/survey_responses/adaptive-security-review-13272548)

**["Excellent onboarding, strong simulation depth, and an API growing quickly"](https://www.g2.com/survey_responses/adaptive-security-review-13244398)**

**Rating:** 5.0/5.0 stars

_— Paul D._

[Read full review](https://www.g2.com/survey_responses/adaptive-security-review-13244398)

### [Sophos PhishThreat](https://www.g2.com/products/sophos-phishthreat/reviews)

Sophos Phish Threat is a cloud-based security awareness training and phishing simulation platform designed to educate employees on identifying and responding to phishing attacks. By simulating realistic phishing scenarios and providing interactive training modules, it helps organizations strengthen their human firewall against cyber threats. Key Features and Functionality: - Realistic Phishing Simulations: Offers hundreds of customizable templates that mimic real-world phishing attacks, enabling organizations to test and improve employee vigilance. - Automated Training Modules: Provides over 30 interactive training courses covering security and compliance topics, automatically enrolling users who fall for simulated attacks. - Comprehensive Reporting: Delivers actionable insights through intuitive dashboards, tracking user susceptibility, training progress, and overall organizational risk levels. - Multi-Language Support: Available in nine languages, ensuring accessibility for diverse workforces. - Seamless Integration: Integrates with Sophos Central, allowing unified management alongside other security solutions like email and endpoint protection. Primary Value and Problem Solved: Sophos Phish Threat addresses the critical challenge of human error in cybersecurity by transforming employees into proactive defenders against phishing attacks. By combining realistic simulations with targeted training, it reduces the likelihood of successful phishing attempts, thereby enhancing the organization's overall security posture and minimizing the risk of data breaches and financial loss.

**Average Rating:** 4.4/5.0

**Total Reviews:** 26

#### Who Is the Company Behind Sophos PhishThreat?

- **Seller:** [Sophos](https://www.g2.com/sellers/sophos)
- **Year Founded:** 1985
- **HQ Location:** Oxfordshire
- **Twitter:** @Sophos  
36,759 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e7bb09f1d9ceb61adf28e57fdaf53266846612b2c5e7a5d2a80d0008113c9990&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5053%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,500 employees on LinkedIn®
- **Ownership:** LSE:SOPH

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 59% Medium, 30% Small

#### What Are Recent G2 Reviews of Sophos PhishThreat?

**["Sophos Phish Threat helped us build our human firewall - our employees now catch phishing emails"](https://www.g2.com/survey_responses/sophos-phishthreat-review-13185522)**

**Rating:** 5.0/5.0 stars

_— Shibu K._

[Read full review](https://www.g2.com/survey_responses/sophos-phishthreat-review-13185522)

**["Smooth Sophos Central Onboarding with Automated Campaigns and One-Click Outlook Reporting"](https://www.g2.com/survey_responses/sophos-phishthreat-review-13201866)**

**Rating:** 5.0/5.0 stars

_— Prateek T._

[Read full review](https://www.g2.com/survey_responses/sophos-phishthreat-review-13201866)

#### What Are G2 Users Discussing About Sophos PhishThreat?

- [How do you conduct a phishing test?](https://www.g2.com/discussions/how-do-you-conduct-a-phishing-test)
- [What are the available formats for Phish threat awareness training?](https://www.g2.com/discussions/what-are-the-available-formats-for-phish-threat-awareness-training)
- [How do I use Phish threat Sophos?](https://www.g2.com/discussions/how-do-i-use-phish-threat-sophos)
- [Does Sophos protect against phishing?](https://www.g2.com/discussions/does-sophos-protect-against-phishing)

### [Pentera](https://www.g2.com/products/pentera/reviews)

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

**Average Rating:** 4.5/5.0

**Total Reviews:** 171

#### Who Is the Company Behind Pentera?

- **Seller:** [Pentera](https://www.g2.com/sellers/pentera)
- **Company Website:** pentera.io
- **Year Founded:** 2015
- **HQ Location:** Boston, MA
- **Twitter:** @penterasec  
3,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9f2c0c558c875a98d2d9fc35b9d10d7247ea125fd4eaf33d374195bfe744ebba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpenterasecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
483 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Banking, Government Administration
- **Company Size:** 52% Large, 36% Medium

#### What Do G2 Reviewers Say About Pentera?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **automation features** of Pentera, enhancing ease of use and enabling efficient continuous operation.
- Users recognize the **powerful automation and detailed remediation suggestions** of Pentera for effective vulnerability detection.
- Users value Pentera's **effective vulnerability scanning and remediation suggestions** , enhancing their overall security posture and testing efficacy.
- Users value the **responsive customer support** of Pentera, enhancing their overall vulnerability scanning experience.
- Users appreciate the **efficiency** of Pentera, notably for its quick implementation and time-saving automation.

##### Cons

- Users find the **reporting inadequate** , particularly for enterprise-level assessments, necessitating significant improvements.
- Users experience a **lack of essential features** , including limited TTP updates and inadequate user permissions management.
- Users find the **reporting in Pentera lacking** , especially for enterprise-level needs and multilingual support.
- Users find Pentera demands a **high amount of system resources** , which can hinder overall performance and efficiency.
- Users report **technical issues** , particularly with module compatibility and unexpected upgrade failures, though support is responsive.

#### What Are Recent G2 Reviews of Pentera?

**["Reliable Tool for Vulnerability Detection but Script Issues"](https://www.g2.com/survey_responses/pentera-review-12864934)**

**Rating:** 4.0/5.0 stars

_— Avitzur Y._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864934)

**["Cutting-Edge Security with a Real Attacker Approach"](https://www.g2.com/survey_responses/pentera-review-12864952)**

**Rating:** 4.5/5.0 stars

_— Yaron C._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864952)

### [Right-Hand Cybersecurity](https://www.g2.com/products/right-hand-cybersecurity/reviews)

Right-Hand is a Human Risk Management company supporting organizations across North America and APAC, working with teams across a wide range of industries including finance, education, retail, healthcare, and manufacturing. The platform is built to help security leaders understand, measure, and reduce human-initiated risk in modern, distributed environments where technology alone is no longer enough. Most security programs generate large volumes of alerts and telemetry but struggle to translate that data into meaningful insight about human behavior. Right-Hand addresses this challenge by integrating with core security tools such as email security, EDR, DLP, CASB, and SIEM. These integrations surface high-signal events and contextual risk indicators tied directly to user actions, giving teams visibility into where risky behavior occurs, which patterns lead to incidents, and how human risk changes over time across the organization. Building on this foundation, Right-Hand provides purpose-built AI agents that support security awareness execution at scale. The vishing agent enables realistic voice-based simulations, the email agent supports the creation of phishing templates and scenarios, and the training agent helps generate and adapt learning content based on role, behavior, and exposure. Together, these agents allow teams to move beyond static programs and deliver continuous, relevant awareness without relying on one-size-fits-all content or manual effort. The primary value of Right-Hand is turning visibility into action. Instead of compliance-driven training disconnected from real risk, organizations gain a data-informed program that links behavior, learning, and outcomes. Security teams can reduce repeat incidents, lower operational noise, demonstrate progress over time, and build a stronger, more resilient security culture aligned with how people actually work.

**Average Rating:** 4.8/5.0

**Total Reviews:** 71

#### Who Is the Company Behind Right-Hand Cybersecurity?

- **Seller:** [Right-Hand Cybersecurity](https://www.g2.com/sellers/right-hand-cybersecurity)
- **Company Website:** right-hand.ai
- **Year Founded:** 2019
- **HQ Location:** Lewes, Delaware
- **Twitter:** @righthand\_ai  
139 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=01553b007a3f666b68510ad751ef1adcbcdd6feec1c913c176caa85894cc9089&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F19126566&secure%5Burl_type%5D=linkedin_company_website)  
44 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 54% Medium, 28% Large

#### What Do G2 Reviewers Say About Right-Hand Cybersecurity?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **exceptional customer support** from Right-Hand Cybersecurity, enhancing their experience and fostering effective training outcomes.
- Users value the **user-friendly platform** and dedicated support from their Customer Success Manager, enhancing overall experience.
- Users find the **exceptional support** from Right-Hand Cybersecurity, particularly Charlton, invaluable in enhancing their security training experience.
- Users value the **comprehensive training support** provided by Right-Hand Cybersecurity, enhancing employee engagement and learning experiences.
- Users appreciate the **personalized approach** of Right-Hand Cybersecurity, enhancing training with real-time insights and support.

##### Cons

- Users find **limited automations and features** on Right-Hand Cybersecurity, affecting customization and control within the portal.
- Users find the **inadequate reporting** of Right-Hand Cybersecurity limits their ability to gain detailed insights effectively.
- Users recommend improving the **PhishArm feature's resolution workflow** and reporting capabilities for better usability.
- Users note **integration issues** , as limited automations and incomplete API hinder advanced functionality and compatibility.
- Users find the **limited customization** options in Right-Hand Cybersecurity restrict their ability to tailor the tool effectively.

#### What Are Recent G2 Reviews of Right-Hand Cybersecurity?

**["Human help for Human Risk"](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-10935784)**

**Rating:** 4.5/5.0 stars

_— Verified User in Primary/Secondary Education_

[Read full review](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-10935784)

**["Amazing Customer Success Team!"](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-12935468)**

**Rating:** 5.0/5.0 stars

_— Charlize L._

[Read full review](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-12935468)

#### What Are G2 Users Discussing About Right-Hand Cybersecurity?

- [What is Right-Hand Cybersecurity used for?](https://www.g2.com/discussions/right-hand-cybersecurity-what-is-right-hand-cybersecurity-used-for)
- [What is Right-Hand Cybersecurity used for?](https://www.g2.com/discussions/what-is-right-hand-cybersecurity-used-for)

### [AI-Native Continuous Offensive Security Platform](https://www.g2.com/products/ai-native-continuous-offensive-security-platform/reviews)

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

**Average Rating:** 4.5/5.0

**Total Reviews:** 98

#### Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

- **Seller:** [Ridge Security Technology](https://www.g2.com/sellers/ridge-security-technology)
- **Company Website:** ridgesecurity.ai
- **Year Founded:** 2020
- **HQ Location:** Santa Clara, California
- **Twitter:** @RidgeSecurityAI  
1,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f4ee553fba315e6da91ba8fe2c2763c183623acefb48c5a2db8aa8bcd2d740de&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fridge-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
47 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Small, 45% Medium

#### What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of RidgeBot, enabling quick setup and straightforward penetration testing automation.
- Users value the **automation capabilities** of RidgeBot, significantly enhancing efficiency in penetration testing and vulnerability validation.
- Users value the **high efficiency of RidgeBot's pentesting** , enabling quick, automated vulnerability validation and seamless integration.
- Users commend RidgeBot for its **effective vulnerability identification** , providing reliable, automated testing and integration for security efficiency.
- Users praise RidgeBot for its **efficiency** in automating vulnerability testing and streamlining security processes seamlessly.

##### Cons

- Users find the **complex setup** of RidgeBot challenging, particularly for new admins requiring better documentation and support.
- Users find RidgeBot's setup overly **complex** , particularly when working with customized or legacy systems.
- Users find the **missing features** in RidgeBot, such as limited reporting and API testing, hinder optimal usage.
- Users find **poor customer support** frustrating, often lacking resources for resolving issues independently.
- Users find the **poor documentation** of RidgeBot challenging, especially for new admins during setup and onboarding.

#### What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

**["Powerful Vulnerability Assessment and Remediation Capabilities"](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12910247)**

**Rating:** 5.0/5.0 stars

_— Daniel Felipe P._

[Read full review](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12910247)

**["Powerful and Efficient, Although It Requires Manual Validations"](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12940521)**

**Rating:** 4.5/5.0 stars

_— Henry A._

[Read full review](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12940521)

Spotlight Categories

[Experience Management Software](https://www.g2.com/categories/experience-management)

[Analytics Platforms](https://www.g2.com/categories/analytics-platforms)

[Sales Training and Onboarding Software](https://www.g2.com/categories/sales-training-and-onboarding)

[Partner Relationship Management (PRM) Software](https://www.g2.com/categories/partner-relationship-management-prm)

[AI Writing Assistants](https://www.g2.com/categories/ai-writing-assistant)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Deception Technology](/categories/deception-technology)

- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)
- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)

- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)
- [Security Orchestration, Automation, and Response (SOAR)](/categories/security-orchestration-automation-and-response-soar)

[Browse Breach and Attack Simulation (BAS) Themes](/categories/breach-and-attack-simulation-bas/themes)