# Best Breach and Attack Simulation (BAS) Software

## How Many Breach and Attack Simulation (BAS) Software Products Does G2 Track?

**Total Products under this Category:** 56

### Category Stats (Aug 2026)

- **Average Rating:** 4.56/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Right-Hand Cybersecurity (+0.13%) - Among all products in this category, Right-Hand Cybersecurity recorded the largest rating increase compared to last month

_Last updated: August 30, 2026_

## How Does G2 Rank Breach and Attack Simulation (BAS) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,300+ Authentic Reviews
- 56+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Breach and Attack Simulation (BAS) Software
 ![G2 Grid® for Breach and Attack Simulation (BAS) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.png?focus%5B%5D=56073&focus%5B%5D=56001&focus%5B%5D=1458180&focus%5B%5D=100365&focus%5B%5D=98391&focus%5B%5D=1584476&focus%5B%5D=124451&focus%5B%5D=168853)

Highlighted products: Picus Security, Cymulate, Adaptive Security, Sophos PhishThreat, Pentera, HTB CTF & Threat Range, Right-Hand Cybersecurity, and vPenTest.

Underlying data: [Grid® JSON](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.json?focus%5B%5D=picus-security&focus%5B%5D=cymulate&focus%5B%5D=adaptive-security&focus%5B%5D=sophos-phishthreat&focus%5B%5D=pentera&focus%5B%5D=htb-ctf-threat-range&focus%5B%5D=right-hand-cybersecurity&focus%5B%5D=vpentest)

### [Picus Security](https://www.g2.com/products/picus-security/reviews)

Picus Security helps enterprise security teams reduce cyber risk with the Picus Autonomous Exposure Validation Platform. Picus proves what attackers can actually exploit in your environment and what your security controls stop, turning every exposure into a defensible decision: patch, mitigate, monitor, or accept. The platform validates attack surfaces, exposures, and security controls as one continuous loop, uniting breach and attack simulation, automated penetration testing, and exposure validation. With techniques mapped to MITRE ATT&CK, teams prioritize by real exploitation risk instead of severity scores, prove their EDR, SIEM, and firewall controls work, and report measurable risk reduction to leadership. Picus pioneered Breach and Attack Simulation in 2013 and works with security teams across financial services, healthcare, energy, and technology.

**Average Rating:** 4.8/5.0

**Total Reviews:** 229

#### Who Is the Company Behind Picus Security?

- **Seller:** [Picus Security](https://www.g2.com/sellers/picus-security)
- **Company Website:** www.picussecurity.com
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California
- **Twitter:** @PicusSecurity  
2,916 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1071751e714fd0ce1530e5a7b8ca294f43039133144caf44668408ee0d546e8f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpicus-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
315 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Cyber Security Specialist, Cyber Security Engineer
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 38% Large, 37% Medium

#### What Do G2 Reviewers Say About Picus Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Picus Security for its **realistic attack simulations** that enhance defenses and confidence in cybersecurity resilience.
- Users find Picus Security **incredibly easy to use** , ensuring rapid identification of security gaps with professional support.
- Users commend Picus Security for its **continuous proactive validation** of security controls, enhancing defense and resilience against attacks.
- Users highlight the **actionable insights** from Picus Security, enhancing defense optimization and improving overall security posture.
- Users value the **seamless integration** with existing tools, enhancing security through tailored recommendations and real-time updates.

##### Cons

- Users experience **reporting limitations** with Picus Security, leading to extra work in finalizing reports and occasional issues.
- Users experience **integration issues** , particularly with third-party tools, impacting the initial setup and validation process.
- Users find the **steep learning curve** of Picus Security challenging, requiring time and training for effective utilization.
- Users find the **complex setup** process of Picus Security to be challenging, requiring extra configuration effort initially.
- Users find the **limited customization** in Picus Security's reports and dashboards restrictive for their specific needs.

#### What Are Recent G2 Reviews of Picus Security?

**["A Proactive Approach to Threat Readiness"](https://www.g2.com/survey_responses/picus-security-review-11441729)**

**Rating:** 4.5/5.0 stars

_— Rohit Y._

[Read full review](https://www.g2.com/survey_responses/picus-security-review-11441729)

**["Picus Makes Our Security Stronger"](https://www.g2.com/survey_responses/picus-security-review-11497382)**

**Rating:** 5.0/5.0 stars

_— Ved Prakash M._

[Read full review](https://www.g2.com/survey_responses/picus-security-review-11497382)

#### What Are G2 Users Discussing About Picus Security?

- [What is Picus Security used for?](https://www.g2.com/discussions/what-is-picus-security-used-for)

### [Cymulate](https://www.g2.com/products/cymulate/reviews)

Designed for security teams to continuously validate threats and build exposure-informed defenses, the Cymulate Platform combines advanced attack simulation with an agentic cyber defense engineering control plane to continuously prove, prioritize and adapt security controls for the latest threats. With a daily feed of threat intelligence and a comprehensive attack library, Cymulate is a SaaS offering that applies AI to tailor offensive testing to the environment while integrating with security stack to push updates for immediate prevention and detection. Core use cases include threat validation, control validation & tuning, detection engineering, and vulnerability validation and prioritization.

**Average Rating:** 4.9/5.0

**Total Reviews:** 176

#### Who Is the Company Behind Cymulate?

- **Seller:** [Cymulate](https://www.g2.com/sellers/cymulate)
- **Company Website:** www.cymulate.com
- **Year Founded:** 2016
- **HQ Location:** Holon, Israel
- **Twitter:** @CymulateLtd  
1,079 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ecaa1ad35895f03003e3d88c09d51eac6f2490113ea2af6c7e64d48000f425ff&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcymulate&secure%5Burl_type%5D=linkedin_company_website)  
231 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Analyst, Cyber Security Engineer
- **Top Industries:** Financial Services, Banking
- **Company Size:** 56% Large, 43% Medium

#### What Do G2 Reviewers Say About Cymulate?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **intuitive and user-friendly design** of Cymulate, enhancing accessibility for organizations of all sizes.
- Users value the **effective continuous security validation** offered by Cymulate, enhancing their overall security posture.
- Users appreciate Cymulate's **effective vulnerability identification** , enabling actionable insights and continuous threat assessment with ease.
- Users value Cymulate's **extensive customization options** , benefiting from dynamic dashboards and a large threat library.
- Users appreciate the **helpful and friendly customer support** of Cymulate, enhancing their overall experience and effectiveness.

##### Cons

- Users note that **integration issues** hinder Cymulate's effectiveness and call for enhanced compatibility with existing systems.
- Users note that **dynamic reporting and integration stability** need improvement for better execution and overall experience.
- Users find **reporting issues** time consuming, with delays and a lack of critical data affecting efficiency.
- Users note that **advanced features can be complex** to configure, making the initial setup time-consuming for newcomers.
- Users find the **learning curve steep** , especially for advanced scenarios and managing EDR alerts without expertise.

#### What Are Recent G2 Reviews of Cymulate?

**["Realistic, Continuous Security Validation Without Disrupting Production"](https://www.g2.com/survey_responses/cymulate-review-12619957)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/cymulate-review-12619957)

**["Comprehensive BAS with Easy Setup and Stellar Coverage"](https://www.g2.com/survey_responses/cymulate-review-12504573)**

**Rating:** 5.0/5.0 stars

_— Shubham A._

[Read full review](https://www.g2.com/survey_responses/cymulate-review-12504573)

### [Adaptive Security](https://www.g2.com/products/adaptive-security/reviews)

Adaptive Security is the security layer for the AI era, protecting organizations and their employees from modern cyberattacks. AI has changed how every company works, and it's changed how every company gets attacked. Employees use AI tools IT doesn't know about. Attackers craft deepfakes, vishing calls, and spear phishing emails that get past filters. Adaptive addresses all of it in one unified platform: managing AI tool usage before it becomes a liability, training employees on the threats they'll actually face, simulating AI-powered attacks in a safe environment, and protecting the inbox and browser so threats never reach their intended targets. Because it's one platform, Adaptive develops a complete risk picture and uses it automatically, applying targeted training, attack simulations, real-time interventions, and policy controls to lower risk over time. More than 1,000 organizations run Adaptive to manage their human security program, and the company has raised $150M+ from investors including NVIDIA, Andreessen Horowitz, Bain Capital Ventures, and Citi Ventures.

**Average Rating:** 4.9/5.0

**Total Reviews:** 127

#### Who Is the Company Behind Adaptive Security?

- **Seller:** [Adaptive Security](https://www.g2.com/sellers/adaptive-security)
- **Company Website:** www.adaptivesecurity.com
- **Year Founded:** 2024
- **HQ Location:** New York, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=edc74b1bab2dbad86ff02cc7b07c6b2a2fade49be4035b1c6903fe89569a0d13&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fadaptivesecurity&secure%5Burl_type%5D=linkedin_company_website)  
242 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** IT Manager
- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 72% Medium, 16% Large

#### What Do G2 Reviewers Say About Adaptive Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **concise and engaging training** of Adaptive Security, enhancing employee awareness and participation effectively.
- Users praise the **ease of use** of Adaptive Security, enjoying smooth deployment and intuitive integration with existing systems.
- Users appreciate the **excellent customer support** from Adaptive Security, noting their responsiveness and helpfulness as key benefits.
- Users appreciate the **easy implementation** of Adaptive Security, ensuring a smooth setup and quick integration into daily operations.
- Users value the **dramatic increase in security awareness** provided by Adaptive Security, ensuring consistent engagement across teams.

##### Cons

- Users feel the **limited customization options** hinder their ability to edit and manage user information effectively.
- Users feel **group management is underdeveloped** , requiring manual training assignments and lacking flexible content customization options.
- Users find the **reporting inadequate** , lacking flexibility in data presentation for effective exports and stakeholder reviews.
- Users find the **integration process challenging** , especially for those without technical expertise, complicating overall usability.
- Users find the **learning curve steep** , making setup challenging for non-technical individuals and first-time admins.

#### What Are Recent G2 Reviews of Adaptive Security?

**["Great product and an even better team"](https://www.g2.com/survey_responses/adaptive-security-review-13272548)**

**Rating:** 5.0/5.0 stars

_— Dawid S._

[Read full review](https://www.g2.com/survey_responses/adaptive-security-review-13272548)

**["Excellent onboarding, strong simulation depth, and an API growing quickly"](https://www.g2.com/survey_responses/adaptive-security-review-13244398)**

**Rating:** 5.0/5.0 stars

_— Paul D._

[Read full review](https://www.g2.com/survey_responses/adaptive-security-review-13244398)

### [Sophos PhishThreat](https://www.g2.com/products/sophos-phishthreat/reviews)

Sophos Phish Threat is a cloud-based security awareness training and phishing simulation platform designed to educate employees on identifying and responding to phishing attacks. By simulating realistic phishing scenarios and providing interactive training modules, it helps organizations strengthen their human firewall against cyber threats. Key Features and Functionality: - Realistic Phishing Simulations: Offers hundreds of customizable templates that mimic real-world phishing attacks, enabling organizations to test and improve employee vigilance. - Automated Training Modules: Provides over 30 interactive training courses covering security and compliance topics, automatically enrolling users who fall for simulated attacks. - Comprehensive Reporting: Delivers actionable insights through intuitive dashboards, tracking user susceptibility, training progress, and overall organizational risk levels. - Multi-Language Support: Available in nine languages, ensuring accessibility for diverse workforces. - Seamless Integration: Integrates with Sophos Central, allowing unified management alongside other security solutions like email and endpoint protection. Primary Value and Problem Solved: Sophos Phish Threat addresses the critical challenge of human error in cybersecurity by transforming employees into proactive defenders against phishing attacks. By combining realistic simulations with targeted training, it reduces the likelihood of successful phishing attempts, thereby enhancing the organization's overall security posture and minimizing the risk of data breaches and financial loss.

**Average Rating:** 4.4/5.0

**Total Reviews:** 25

#### Who Is the Company Behind Sophos PhishThreat?

- **Seller:** [Sophos](https://www.g2.com/sellers/sophos)
- **Year Founded:** 1985
- **HQ Location:** Oxfordshire
- **Twitter:** @Sophos  
36,759 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e7bb09f1d9ceb61adf28e57fdaf53266846612b2c5e7a5d2a80d0008113c9990&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5053%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,500 employees on LinkedIn®
- **Ownership:** LSE:SOPH

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 58% Medium, 31% Small

#### What Are Recent G2 Reviews of Sophos PhishThreat?

**["Seamless Sophos Central Integration with Robust Templates and Fast Remediation Training effective"](https://www.g2.com/survey_responses/sophos-phishthreat-review-13141589)**

**Rating:** 5.0/5.0 stars

_— Dheeraj S._

[Read full review](https://www.g2.com/survey_responses/sophos-phishthreat-review-13141589)

**["Smooth Sophos Central Onboarding with Automated Campaigns and One-Click Outlook Reporting"](https://www.g2.com/survey_responses/sophos-phishthreat-review-13201866)**

**Rating:** 5.0/5.0 stars

_— Prateek T._

[Read full review](https://www.g2.com/survey_responses/sophos-phishthreat-review-13201866)

#### What Are G2 Users Discussing About Sophos PhishThreat?

- [How do you conduct a phishing test?](https://www.g2.com/discussions/how-do-you-conduct-a-phishing-test)
- [What are the available formats for Phish threat awareness training?](https://www.g2.com/discussions/what-are-the-available-formats-for-phish-threat-awareness-training)
- [How do I use Phish threat Sophos?](https://www.g2.com/discussions/how-do-i-use-phish-threat-sophos)
- [Does Sophos protect against phishing?](https://www.g2.com/discussions/does-sophos-protect-against-phishing)

## FAQs About Breach and Attack Simulation (BAS) Software

Generated using AI

Last updated: June 3, 2026

### Which Breach And Attack Simulation BAS vendors provide strong implementation guidance for team adoption

Based on G2 reviews, these BAS vendors are most often praised for onboarding, setup, and guidance.

- [Picus Security](https://www.g2.com/products/picus-security) — onboarding help and vendor-specific remediation.
- [Cymulate](https://www.g2.com/products/cymulate) — easy setup with actionable mitigation guidance.
- [Right-Hand Cybersecurity](https://www.g2.com/products/right-hand-cybersecurity) — hands-on support for campaigns and rollout.
- [RidgeBot](https://www.g2.com/products/ridgebot) — straightforward setup with validated findings.

### Breach And Attack Simulation BAS solutions combining ease of use with advanced integration capabilities

According to verified users, BAS buyers often look for a balance between fast deployment and meaningful integrations with the rest of the security stack. In recent G2 reviews, that combination shows up in mentions of intuitive dashboards, simple setup, and the ability to connect with SIEM, EDR, XDR, firewalls, web application firewalls, and other existing controls. Reviewers value platforms that make simulations easy to run without heavy operational overhead, while still helping teams validate logs, isolate which control blocked an attack, and turn findings into remediation steps. Integration breadth matters most when it improves visibility, reduces manual testing, and supports continuous validation across multiple layers of defense.

### Most reliable Breach And Attack Simulation BAS platforms proven by long-term enterprise deployments

Based on G2 reviews, these BAS platforms appear most often in feedback describing dependable use in ongoing programs.

- [Picus Security](https://www.g2.com/products/picus-security) — continuous validation across enterprise security controls.
- [Cymulate](https://www.g2.com/products/cymulate) — recurring assessments with broad control coverage.
- [Right-Hand Cybersecurity](https://www.g2.com/products/right-hand-cybersecurity) — sustained phishing and awareness program management.
- [Adaptive Security](https://www.g2.com/products/adaptive-security) — ongoing simulations and training at scale.

### What are the most important features in bas tools

According to verified users, the most important features in bas tools are realistic attack simulation, continuous validation, and clear remediation guidance. Recent reviews also emphasize broad threat libraries, support for MITRE-aligned scenarios, and reporting that helps both technical teams and leadership understand gaps. Buyers repeatedly mention integration with SIEM, EDR, XDR, firewalls, and web security tools as a priority because it helps confirm whether controls are detecting or blocking attacks as expected. Ease of setup and ease of use also matter because teams want to run assessments regularly, not just occasionally. The strongest products help teams find misconfigurations, validate detections, prioritize fixes, and keep security programs proactive instead of reactive.

### How do teams use Breach and Attack Simulation (BAS) for remediation guidance

G2 reviewers mention that teams use BAS to move from identifying gaps to fixing them faster. In recent reviews, users describe running attack simulations to expose weak points across endpoint, network, email, web, and broader security controls, then using the resulting guidance to tune configurations, improve detection rules, and prioritize remediation work. Some reviewers specifically value vendor-specific or easy-to-apply recommendations because they reduce guesswork for analysts and administrators. Others highlight retesting after changes to confirm that fixes actually worked. For buyers, the practical value of BAS is not just finding exposure, but making remediation more measurable, repeatable, and aligned with how real attacks would interact with existing defenses.

### [Pentera](https://www.g2.com/products/pentera/reviews)

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

**Average Rating:** 4.5/5.0

**Total Reviews:** 171

#### Who Is the Company Behind Pentera?

- **Seller:** [Pentera](https://www.g2.com/sellers/pentera)
- **Company Website:** pentera.io
- **Year Founded:** 2015
- **HQ Location:** Boston, MA
- **Twitter:** @penterasec  
3,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9f2c0c558c875a98d2d9fc35b9d10d7247ea125fd4eaf33d374195bfe744ebba&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpenterasecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
483 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Government Administration, Banking
- **Company Size:** 52% Large, 36% Medium

#### What Do G2 Reviewers Say About Pentera?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **effective vulnerability scanning and remediation** capabilities of Pentera, enhancing overall security posture.
- Users value the **automation capabilities** of Pentera, enhancing their security testing and validation processes efficiently.
- Users value the **responsive customer support** from Pentera, enhancing their experience and facilitating smooth operations.
- Users value the **time-saving automation** of Pentera, enabling more efficient focus on critical cybersecurity tasks.
- Users value the **fully automated testing** of Pentera, appreciating its ease of use and quick implementation.

##### Cons

- Users find the **reporting inadequate** , suggesting it requires improvement for better enterprise-level insights.
- Users are concerned about the **missing features** in Pentera, including updates on vulnerabilities and insufficient RBAC options.
- Users find Pentera to be **resource intensive** , as it demands significant system resources for optimal performance.
- Users express concern about the **lack of a robust RBAC system** , limiting proper access control and user rights management.
- Users are frustrated by **access restrictions** due to insufficient RBAC, limiting user capabilities and adaptability.

#### What Are Recent G2 Reviews of Pentera?

**["Reliable Tool for Vulnerability Detection but Script Issues"](https://www.g2.com/survey_responses/pentera-review-12864934)**

**Rating:** 4.0/5.0 stars

_— Avitzur Y._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864934)

**["Cutting-Edge Security with a Real Attacker Approach"](https://www.g2.com/survey_responses/pentera-review-12864952)**

**Rating:** 4.5/5.0 stars

_— Yaron C._

[Read full review](https://www.g2.com/survey_responses/pentera-review-12864952)

### [HTB CTF & Threat Range](https://www.g2.com/products/htb-ctf-threat-range/reviews)

The HTB CTF Platform turns cyber training into an addictive team experience. Choose from 250+ scenarios, host events for hundreds of players, and launch in less than 10 minutes without additional setup required. Live scoreboards, team chat, and advanced reporting reveal strengths, gaps and next best steps. Leaders calling CTFs the best way to beat burnout and improve performance, HTB delivers the proven formula for engaged, attack-ready teams.

**Average Rating:** 4.7/5.0

**Total Reviews:** 22

#### Who Is the Company Behind HTB CTF & Threat Range?

- **Seller:** [Hack The Box](https://www.g2.com/sellers/hack-the-box)
- **Company Website:** www.hackthebox.com
- **Year Founded:** 2017
- **HQ Location:** Folkestone, GB
- **Twitter:** @hackthebox\_eu  
246,095 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=93e823e3029a5e11a0c833d029e9923464f3633e4d7499dd0733bc0b6f34614a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fhackthebox%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,272 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 45% Large, 36% Small

#### What Are Recent G2 Reviews of HTB CTF & Threat Range?

**["Outstanding Experience from Start to Finish"](https://www.g2.com/survey_responses/htb-ctf-threat-range-review-12003820)**

**Rating:** 5.0/5.0 stars

_— Sathish V._

[Read full review](https://www.g2.com/survey_responses/htb-ctf-threat-range-review-12003820)

**["The Easiest Platform for Hands-On Penetration Testing Learning"](https://www.g2.com/survey_responses/htb-ctf-threat-range-review-11984171)**

**Rating:** 5.0/5.0 stars

_— Verified User in Security and Investigations_

[Read full review](https://www.g2.com/survey_responses/htb-ctf-threat-range-review-11984171)

### [vPenTest](https://www.g2.com/products/vpentest/reviews)

Vonahi Security is building the future of offensive cybersecurity by delivering automated, high-quality penetration testing through its SaaS platform, vPenTest. Designed to replicate the tools, techniques, and methodologies of experienced consultants, vPenTest brings the benefits of manual network penetration testing into an easy-to-use, automated solution. Traditionally, penetration testing has been a manual, time consuming, and expensive process that many organizations only perform once or twice a year. This often leaves businesses exposed to emerging threats between assessments. vPenTest addresses this gap by offering fast, consistent, and on-demand testing that helps organizations evaluate their real-time cybersecurity risk more effectively. Powered by a proprietary framework that evolves through continuous research and real-world insights, vPenTest stays aligned with the latest attack techniques and industry best practices. The platform is backed by over 13 years of offensive security expertise, with the team holding certifications such as CISSP, OSCP, OSCE, CEH, and more. Their knowledge is built directly into the platform, ensuring each test is conducted with depth, consistency, and accuracy—without the delays or variability of manual testing.  vPenTest enables organizations to run internal and external network penetration tests as often as needed monthly, quarterly, or prior to audits or insurance reviews. The automated reports provide actionable insights that make it easy to prioritize remediation and demonstrate progress toward compliance. Today, over 22,000 organizations rely on vPenTest to strengthen their security posture and reduce risk. This includes managed service providers, managed security service providers, financial institutions, compliance-driven organizations, and internal IT teams. Whether you're working to meet regulatory requirements, secure cyber insurance coverage, or proactively defend against evolving threats, vPenTest makes network penetration testing easy, affordable, and scalable.

**Average Rating:** 4.6/5.0

**Total Reviews:** 244

#### Who Is the Company Behind vPenTest?

- **Seller:** [Kaseya](https://www.g2.com/sellers/kaseya)
- **Company Website:** www.kaseya.com
- **Year Founded:** 2000
- **HQ Location:** Miami, FL
- **Twitter:** @KaseyaCorp  
17,411 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c9a31f82a811b1e3cc7be6babe8882bb8f6b2927e142d98dd6f5662a0d0e4d2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fkaseya%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,471 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CEO
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 69% Small, 24% Medium

#### What Do G2 Reviewers Say About vPenTest?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of vPenTest, praising its intuitive interface and smooth setup process.
- Users praise the **detailed and reliable technical reports** from vPenTest, enhancing their remediation efforts effectively.
- Users appreciate the **user-friendly interface** of vPenTest, enhancing their efficiency in conducting penetration tests.
- Users commend the **easy setup** of vPenTest, finding it a smooth experience for managing security solutions effectively.
- Users highlight the **ease of implementation** of vPenTest, appreciating its quick setup and seamless integration into workflows.

##### Cons

- Users find the **setup process complex** , highlighting challenges with initial configuration and integration with existing systems.
- Users find the **limited scope** of vPenTest frustrating, as it doesn't cover all necessary pentesting aspects.
- Users find vPenTest to be **expensive** , especially for smaller organizations facing pricing and contract challenges.
- Users find the **inadequate reporting** of vPenTest restricts customization and leads to repetitive findings over time.
- Users find the **lack of detail** in vPenTest confusing, complicating communication and understanding of findings.

#### What Are Recent G2 Reviews of vPenTest?

**["Great Product, Easy to Use, does exactly as described."](https://www.g2.com/survey_responses/vpentest-review-9009510)**

**Rating:** 5.0/5.0 stars

_— Kamran H._

[Read full review](https://www.g2.com/survey_responses/vpentest-review-9009510)

**["Fast, Actionable Pen Testing Baselines with Clear, Customer-Ready Reports"](https://www.g2.com/survey_responses/vpentest-review-12881608)**

**Rating:** 4.5/5.0 stars

_— Darren ._

[Read full review](https://www.g2.com/survey_responses/vpentest-review-12881608)

### [Right-Hand Cybersecurity](https://www.g2.com/products/right-hand-cybersecurity/reviews)

Right-Hand is a Human Risk Management company supporting organizations across North America and APAC, working with teams across a wide range of industries including finance, education, retail, healthcare, and manufacturing. The platform is built to help security leaders understand, measure, and reduce human-initiated risk in modern, distributed environments where technology alone is no longer enough. Most security programs generate large volumes of alerts and telemetry but struggle to translate that data into meaningful insight about human behavior. Right-Hand addresses this challenge by integrating with core security tools such as email security, EDR, DLP, CASB, and SIEM. These integrations surface high-signal events and contextual risk indicators tied directly to user actions, giving teams visibility into where risky behavior occurs, which patterns lead to incidents, and how human risk changes over time across the organization. Building on this foundation, Right-Hand provides purpose-built AI agents that support security awareness execution at scale. The vishing agent enables realistic voice-based simulations, the email agent supports the creation of phishing templates and scenarios, and the training agent helps generate and adapt learning content based on role, behavior, and exposure. Together, these agents allow teams to move beyond static programs and deliver continuous, relevant awareness without relying on one-size-fits-all content or manual effort. The primary value of Right-Hand is turning visibility into action. Instead of compliance-driven training disconnected from real risk, organizations gain a data-informed program that links behavior, learning, and outcomes. Security teams can reduce repeat incidents, lower operational noise, demonstrate progress over time, and build a stronger, more resilient security culture aligned with how people actually work.

**Average Rating:** 4.8/5.0

**Total Reviews:** 73

#### Who Is the Company Behind Right-Hand Cybersecurity?

- **Seller:** [Right-Hand Cybersecurity](https://www.g2.com/sellers/right-hand-cybersecurity)
- **Company Website:** right-hand.ai
- **Year Founded:** 2019
- **HQ Location:** Lewes, Delaware
- **Twitter:** @righthand\_ai  
139 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=01553b007a3f666b68510ad751ef1adcbcdd6feec1c913c176caa85894cc9089&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F19126566&secure%5Burl_type%5D=linkedin_company_website)  
44 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 53% Medium, 29% Large

#### What Do G2 Reviewers Say About Right-Hand Cybersecurity?

_AI-generated summary from verified user reviews_

##### Pros

- Users highly value the **outstanding customer support** from Right-Hand Cybersecurity, enhancing their overall training experience significantly.
- Users enjoy the **user-friendly interface** of Right-Hand Cybersecurity, enhanced by dedicated support from their account manager.
- Users find Charlton to be **very helpful** , enhancing their experience and exceeding expectations with exceptional support.
- Users value the **comprehensive training support** from Right-Hand Cybersecurity, enhancing engagement and ease of customization.
- Users praise the **personalized approach** of Right-Hand Cybersecurity, enhancing training with real-time insights and engaging tools.

##### Cons

- Users note the **limited automations and integrations** in Right-Hand Cybersecurity, wishing for more granular control within the platform.
- Users find the **inadequate reporting** capabilities of Right-Hand Cybersecurity limits their access to detailed insights and analysis.
- Users find the **Phishing issues** in Right-Hand Cybersecurity need better resolution workflows and reporting capabilities.
- Users face **integration issues** with limited APIs and missing connections to essential tools like Drata.
- Users note the **limited customization** options with Right-Hand Cybersecurity, wishing for more flexibility in roles and reporting.

#### What Are Recent G2 Reviews of Right-Hand Cybersecurity?

**["Amazing Customer Success Team!"](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-12935468)**

**Rating:** 5.0/5.0 stars

_— Charlize L._

[Read full review](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-12935468)

**["Great Customer Service And Platform Features"](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-13332598)**

**Rating:** 5.0/5.0 stars

_— Verified User in Retail_

[Read full review](https://www.g2.com/survey_responses/right-hand-cybersecurity-review-13332598)

#### What Are G2 Users Discussing About Right-Hand Cybersecurity?

- [What is Right-Hand Cybersecurity used for?](https://www.g2.com/discussions/right-hand-cybersecurity-what-is-right-hand-cybersecurity-used-for)
- [What is Right-Hand Cybersecurity used for?](https://www.g2.com/discussions/what-is-right-hand-cybersecurity-used-for)

### [AI-Native Continuous Offensive Security Platform](https://www.g2.com/products/ai-native-continuous-offensive-security-platform/reviews)

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

**Average Rating:** 4.5/5.0

**Total Reviews:** 98

#### Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

- **Seller:** [Ridge Security Technology](https://www.g2.com/sellers/ridge-security-technology)
- **Company Website:** ridgesecurity.ai
- **Year Founded:** 2020
- **HQ Location:** Santa Clara, California
- **Twitter:** @RidgeSecurityAI  
1,291 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f4ee553fba315e6da91ba8fe2c2763c183623acefb48c5a2db8aa8bcd2d740de&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fridge-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
47 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Small, 45% Medium

#### What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of the AI-Native Continuous Offensive Security Platform for streamlined penetration testing.
- Users praise the **automation capabilities** of RidgeBot, streamlining penetration testing and providing accurate vulnerability assessments efficiently.
- Users commend the **pentesting efficiency** of RidgeBot, automating tests and validating vulnerabilities seamlessly to save time.
- Users appreciate the **automated vulnerability identification** of RidgeBot, which effectively validates risks and streamlines security processes.
- Users value the **efficiency** of RidgeBot, as it automates testing to save time and enhance security processes.

##### Cons

- Users find the **complex setup** challenging, especially due to limited documentation and support for new admins.
- Users find RidgeBot's setup to be **complex and challenging** , particularly in customized or legacy system environments.
- Users find the **missing features** such as improved API testing and customizable reporting templates quite limiting.
- Users find the **poor customer support** challenging, as documentation is often lacking for troubleshooting issues.
- Users find the **poor documentation** challenging, making initial setup and onboarding confusing for new admins.

#### What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

**["Powerful Vulnerability Assessment and Remediation Capabilities"](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12910247)**

**Rating:** 5.0/5.0 stars

_— Daniel Felipe P._

[Read full review](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12910247)

**["Powerful and Efficient, Although It Requires Manual Validations"](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12940521)**

**Rating:** 4.5/5.0 stars

_— Henry A._

[Read full review](https://www.g2.com/survey_responses/ai-native-continuous-offensive-security-platform-review-12940521)

### [Defendify All-In-One Cybersecurity Solution](https://www.g2.com/products/defendify-all-in-one-cybersecurity-solution/reviews)

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

**Average Rating:** 4.7/5.0

**Total Reviews:** 57

#### Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

- **Seller:** [Defendify](https://www.g2.com/sellers/defendify)
- **Year Founded:** 2017
- **HQ Location:** Portland, Maine
- **Twitter:** @defendify  
305 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=43c15ef0c3df55163faa1afeb1111d8c8a808e2ecdcdbfdef9a0cfa63c68564d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F11098948%2F&secure%5Burl_type%5D=linkedin_company_website)  
37 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 65% Small, 35% Medium

#### What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of Defendify, streamlining cybersecurity management for small and medium-sized businesses.
- Users praise Defendify for its **comprehensive and cost-effective cybersecurity features** , streamlining management for small to medium-sized businesses.
- Users appreciate the **easy setup** of Defendify, finding it quick and simple for effective cybersecurity management.
- Users value the **ease of use** of Defendify, appreciating quick setup and actionable insights for cybersecurity management.
- Users value the **continuous monitoring** features of Defendify, easing the burden of network security management significantly.

##### Cons

- Users note that **inadequate reporting** hinders effective communication, calling for improvements in clarity and detail.
- Users feel that the **poor reporting** features hinder effective communication and internal analysis of cybersecurity efforts.
- Users express frustration over the **lack of concise information** in reports, preferring clearer and more detailed summaries.
- Users find the **limited customization options** restrictive, wishing for more personalized reporting and branding capabilities.
- Users desire **custom reporting options** and co-branding features to enhance the personalization of their experience.

#### What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

**["Comprehensive and robust protection"](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10560878)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10560878)

**["Perfect Vulnerability Management for Software Companies"](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10488301)**

**Rating:** 4.5/5.0 stars

_— Akhil V._

[Read full review](https://www.g2.com/survey_responses/defendify-all-in-one-cybersecurity-solution-review-10488301)

#### What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

- [What is Defendify Cybersecurity Platform used for?](https://www.g2.com/discussions/what-is-defendify-cybersecurity-platform-used-for)

### [Simulations Labs](https://www.g2.com/products/simulations-labs/reviews)

Simulations Labs is an ai-powered platform that enables organizations, educators, and security teams to create realistic, reusable, and scalable hands-on cybersecurity simulations—without complex setup or infrastructure. Fully Managed Hosting Without Infrastructure Overhead Organizations run CTFs and simulations without DevOps, server setup, or maintenance. No Worries About Attacks or Server Downtime Simulations Labs automatically manages security, monitoring, and uptime, even during large-scale events. Organizers don’t need to worry about servers being attacked, crashing, or going offline. Custom Simulation Creation with Dashboard Simulations Labs offers a dashboard that allows organizers to create and manage fully custom simulations. Each simulation provisions isolated environments for participants, supports web application challenges, and can include dynamic flags to prevent cheating AI-Powered Challenge Creation Unlike traditional platforms that require technical expertise, our AI-powered tools enable non-technical users to create simulations and challenges quickly and easily.

**Average Rating:** 4.8/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Simulations Labs?

- **Seller:** [Simulations Labs](https://www.g2.com/sellers/simulations-labs)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a2c09aa8f75a5be17b384db5c4d513818f1631cccd83db32e68cb22454bb9e6f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsimulation-labs-linkedin%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of Simulations Labs?

**["ASA Awareness CTFs Review"](https://www.g2.com/survey_responses/simulations-labs-review-11772604)**

**Rating:** 4.0/5.0 stars

_— Mubiito G._

[Read full review](https://www.g2.com/survey_responses/simulations-labs-review-11772604)

**["CTF Platform"](https://www.g2.com/survey_responses/simulations-labs-review-11774124)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer & Network Security_

[Read full review](https://www.g2.com/survey_responses/simulations-labs-review-11774124)

### [Datto SaaS Defense](https://www.g2.com/products/datto-saas-defense/reviews)

SaaS Defense is an advanced threat protection [ATP] and spam filtering solution that detects zero-day threats. This means it identifies and prevents threats that competitive solutions are missing. It proactively defends against malware, phishing, and business email compromise (BEC) attacks that target Microsoft 365 including Exchange, OneDrive, SharePoint, and Teams. Benefits to MSPs ✔Close detection gaps: Proactively monitor, detect, and eliminate the unknown cyber threats that other solutions miss with data-independent technology. ✔ Go beyond email security: SaaS Defense protects from a range of malicious attacks across the Microsoft 365 suite, not just email. ✔ Improve your bottom line: This tool is a profit builder that can be used to attract new market share and triple MSP margins. ✔ Seamless deployment & management: Get new clients up and running in minutes with two-click onboarding & multi-tenant management. ✔ Easily demonstrate your value: robust reporting capabilities, that can be shared with clients, that articulate why a threat was identified as malicious. ✔ Multi-layered detection, protection and recovery for Microsoft 365 with complete SaaS Protection integration.

**Average Rating:** 4.2/5.0

**Total Reviews:** 12

#### Who Is the Company Behind Datto SaaS Defense?

- **Seller:** [Kaseya](https://www.g2.com/sellers/kaseya)
- **Year Founded:** 2000
- **HQ Location:** Miami, FL
- **Twitter:** @KaseyaCorp  
17,411 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c9a31f82a811b1e3cc7be6babe8882bb8f6b2927e142d98dd6f5662a0d0e4d2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fkaseya%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,471 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 58% Small, 33% Medium

#### What Are Recent G2 Reviews of Datto SaaS Defense?

**["Very helpful, quiet is good no calls from clients"](https://www.g2.com/survey_responses/datto-saas-defense-review-9591017)**

**Rating:** 5.0/5.0 stars

_— Cary S._

[Read full review](https://www.g2.com/survey_responses/datto-saas-defense-review-9591017)

**["Datto SaaS"](https://www.g2.com/survey_responses/datto-saas-defense-review-10728884)**

**Rating:** 4.0/5.0 stars

_— Aaron K._

[Read full review](https://www.g2.com/survey_responses/datto-saas-defense-review-10728884)

#### What Are G2 Users Discussing About Datto SaaS Defense?

- [What is Datto SaaS Defense used for?](https://www.g2.com/discussions/what-is-datto-saas-defense-used-for)

### [NetSPI](https://www.g2.com/products/netspi-2026-02-04/reviews)

NetSPI PTaaS is a type of penetration testing as a service (PTaaS) solution designed to help organizations identify and remediate vulnerabilities within their systems, applications, and networks. This service utilizes a combination of skilled professionals, established processes, and advanced AI technology to provide contextualized security outcomes in real time, all accessible through a unified platform. By addressing the limitations of traditional penetration testing methods, NetSPI PTaaS offers a more efficient and comprehensive approach to security assessments. This service is targeted at businesses of all sizes, from startups to large enterprises, making it particularly beneficial for security teams looking to enhance their vulnerability management strategies. NetSPI PTaaS caters to a variety of use cases, including application security assessments, infrastructure testing, and evaluations of emerging technologies such as artificial intelligence. With over 50 different types of penetration tests available, including traditional point in time testing and our continuous offerings, organizations can customize their security evaluations to meet specific needs, ensuring thorough coverage across all potential attack surfaces. A key feature of NetSPI PTaaS is its commitment to delivering real-time findings through a single platform. This capability allows security teams to receive immediate insights into vulnerabilities, enabling them to act swiftly to mitigate risks based on role and priority, managing testing in just a few clicks. The platform's integration capabilities enhance its usability, allowing organizations to seamlessly incorporate findings into their existing security workflows. This streamlined approach not only saves time but also ensures that remediation efforts are based on high-fidelity, manually validated findings, thus improving overall security effectiveness. The expertise of NetSPI's team of over 350 in-house security professionals is another significant differentiator. Their extensive experience and knowledge in the field of cybersecurity ensure that the testing methodologies employed are rigorous and consistent, uncovering vulnerabilities, exposures, and misconfigurations that may be overlooked by other solutions. This white-glove approach to penetration testing emphasizes the importance of manual validation, providing organizations with reliable and actionable insights that can significantly enhance their security posture. NetSPI PTaaS stands out in the realm of penetration testing services by combining expert human analysis with advanced AI technology, delivering timely and accurate results. This empowers organizations to strengthen their defenses against evolving cyber threats, ensuring that they remain resilient in an increasingly complex security landscape.

**Average Rating:** 4.9/5.0

**Total Reviews:** 13

#### Who Is the Company Behind NetSPI?

- **Seller:** [NetSPI](https://www.g2.com/sellers/netspi)
- **Company Website:** www.netspi.com
- **Year Founded:** 2001
- **HQ Location:** Minneapolis, MN
- **Twitter:** @NetSPI  
4,041 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fc40e8c9ea893c5c5cbba7c0e7c2c446fe731066e4e27af4d2a77540f7888797&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnetspi%2F&secure%5Burl_type%5D=linkedin_company_website)  
568 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 46% Large, 38% Medium

#### What Do G2 Reviewers Say About NetSPI?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **expertise** of NetSPI's team, praising their exceptional leadership and effective project management throughout engagements.
- Users commend the **expertise and support** of the NetSPI team, enhancing the overall engagement experience significantly.
- Users value the **effective communication** of NetSPI, ensuring they're always updated and never left in the dark.
- Users value the **easy-to-use interface** of NetSPI, enhancing communication and project management throughout their engagements.
- Users praise the **exceptional service quality** of NetSPI, highlighting their effective communication and strong project management.

##### Cons

- Users find the **difficult navigation** of NetSPI's interface hinders their ability to efficiently use the platform.
- Users express concerns about **false positives** in the vulnerability report, making it unclear which devices are affected.
- Users find that the **vulnerability report lacks clarity** regarding which devices are affected, causing confusion.
- Users express concern about the **lack of detail** in vulnerability reports, making it unclear which devices are impacted.
- Users experience **lack of information** regarding specific device impacts in vulnerability reports, leading to confusion and uncertainty.

#### What Are Recent G2 Reviews of NetSPI?

**["Exceptional Pentesting and Seamless Collaboration"](https://www.g2.com/survey_responses/netspi-review-12705364)**

**Rating:** 4.5/5.0 stars

_— Jake B._

[Read full review](https://www.g2.com/survey_responses/netspi-review-12705364)

**["Attentive, Knowledgeable NetSPI Specialists with a Truly Human Touch"](https://www.g2.com/survey_responses/netspi-review-12678851)**

**Rating:** 5.0/5.0 stars

_— Verified User in Transportation/Trucking/Railroad_

[Read full review](https://www.g2.com/survey_responses/netspi-review-12678851)

### [Reflex Security](https://www.g2.com/products/reflex-security/reviews)

Reflex Security builds real incident response readiness through AI-driven tabletop exercises that adapt in real time to your team's decisions. The platform generates hyper-customized scenarios in minutes by researching your actual tech stack, industry, and threat landscape from public data. Every exercise is tailored to your organization, not pulled from a generic template. Exercises fight back. AI adversaries respond dynamically to participant decisions, creating realistic pressure and unpredictable outcomes that keep teams engaged throughout. An AI facilitator can join Zoom, Google Meet, or Teams to guide discussion, capture notes, and challenge individuals with role-specific questions. After each exercise, Reflex generates audit-ready reports with performance analytics and remediation guidance designed to support compliance requirements such as SOC 2, ISO 27001, DORA, CIRCIA and cyber insurance requirements. Built for CISOs and MSSPs who want to run tabletop exercises frequently at a fraction of the prep time and cost of traditional facilitated sessions.

**Average Rating:** 5.0/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Reflex Security?

- **Seller:** [Reflex Security](https://www.g2.com/sellers/reflex-security)
- **Year Founded:** 2025
- **HQ Location:** Los Angeles, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a78834d6e918525f65e85b00fa2c262dabd11bb95d87255faa2d153a53fa40d5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freflexsecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
5 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 75% Small, 25% Large

#### What Are Recent G2 Reviews of Reflex Security?

**["Real time tabletop simulator"](https://www.g2.com/survey_responses/reflex-security-review-12609729)**

**Rating:** 5.0/5.0 stars

_— Jared M._

[Read full review](https://www.g2.com/survey_responses/reflex-security-review-12609729)

**["Reflex Raises the Bar on Tabletop Exercises"](https://www.g2.com/survey_responses/reflex-security-review-12577737)**

**Rating:** 5.0/5.0 stars

_— Lee C._

[Read full review](https://www.g2.com/survey_responses/reflex-security-review-12577737)

### [Infection Monkey](https://www.g2.com/products/infection-monkey/reviews)

By deploying the Infection Monkey as an ongoing testing solution, you can verify the security baseline of your network and achieve full network coverage.

**Average Rating:** 4.8/5.0

**Total Reviews:** 3

#### Who Is the Company Behind Infection Monkey?

- **Seller:** [GuardiCore](https://www.g2.com/sellers/guardicore)
- **HQ Location:** Cambridge, US
- **Twitter:** @GuardiCore  
2,636 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3c9b6611037b9b00f2062b10ec0593b19c197bdc634f5c8e0159b5d7bbcc432e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fakamai-technologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
10,201 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of Infection Monkey?

**["Best Open Source Breach and Attack Simulation tool"](https://www.g2.com/survey_responses/infection-monkey-review-5232218)**

**Rating:** 4.5/5.0 stars

_— Satykam A._

[Read full review](https://www.g2.com/survey_responses/infection-monkey-review-5232218)

**["Best Breach and attack Simulation Tool"](https://www.g2.com/survey_responses/infection-monkey-review-5277995)**

**Rating:** 5.0/5.0 stars

_— Trilok A._

[Read full review](https://www.g2.com/survey_responses/infection-monkey-review-5277995)

#### What Are G2 Users Discussing About Infection Monkey?

- [What is Infection Monkey used for?](https://www.g2.com/discussions/what-is-infection-monkey-used-for)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/breach-and-attack-simulation-bas?order=g2_score&page=2#product-list)
- [3](/categories/breach-and-attack-simulation-bas?order=g2_score&page=3#product-list)
- [4](/categories/breach-and-attack-simulation-bas?order=g2_score&page=4#product-list)
- [Next &rsaquo; Next ›](/categories/breach-and-attack-simulation-bas?order=g2_score&page=2#product-list)

Spotlight Categories

[Restaurant POS Systems](https://www.g2.com/categories/restaurant-pos)

[Procure to Pay Software](https://www.g2.com/categories/procure-to-pay)

[Multi-Country Payroll Software](https://www.g2.com/categories/multi-country-payroll)

[Compensation Management Software](https://www.g2.com/categories/compensation-management)

[Identity Verification Software](https://www.g2.com/categories/identity-verification)

Similar Categories

- [Incident Response](/categories/incident-response)
- [Security Information and Event Management (SIEM)](/categories/security-information-and-event-management-siem)
- [Threat Intelligence](/categories/threat-intelligence)
- [AI SOC Agents](/categories/ai-soc-agents)
- [Deception Technology](/categories/deception-technology)

- [Digital Forensics](/categories/digital-forensics)
- [Digital Risk Protection (DRP) Platforms](/categories/digital-risk-protection-drp-platforms)
- [IoT Security Solutions](/categories/iot-security-solutions)
- [Malware Analysis Tools](/categories/malware-analysis-tools)
- [Managed Detection and Response (MDR)](/categories/managed-detection-and-response-mdr)

- [OT Secure Remote Access](/categories/ot-secure-remote-access)
- [OT Security Tools](/categories/ot-security-tools)
- [Red Teaming Tools](/categories/red-teaming-tools)
- [Security Orchestration, Automation, and Response (SOAR)](/categories/security-orchestration-automation-and-response-soar)

[Browse Breach and Attack Simulation (BAS) Themes](/categories/breach-and-attack-simulation-bas/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Breach and attack simulation (BAS) software is used to mimic real-world security threats to help businesses prepare incident response plans and discover potential vulnerabilities in their security systems. These simulated attacks might send fake phishing attacks to employees or attempt a cyberattack on a company’s [web application firewall](https://www.g2.com/categories/web-application-firewall-waf). Many tools even provide automated simulations with AI-based threat logic and continuous testing to ensure teams are always prepared to properly handle security incidents.

Most of these simulations are available at all times. Many businesses use them periodically as updates are made to security systems or security policies are changed. Without simulated attacks, it can be difficult to assess the efficacy of security operations; customized simulations can mimic various threats to different surface areas or within unique environments to help businesses prepare and evaluate their defense against all kinds of multivector threats.

Breach and attack simulation software tools are typically capable of performing [penetration tests](https://www.g2.com/categories/penetration-testing) or simulate attacks similar to some [dynamic application security testing](https://www.g2.com/categories/dynamic-application-security-testing-dast) tools and [vulnerability scanners](https://www.g2.com/categories/vulnerability-scanner). But most of those solutions only mimic a single kind of threat and are not continuously available. They also do not provide the same outcome details and report on vulnerabilities and security posture to the same degree of BAS solutions.

To qualify for inclusion in the Breach and Attack Simulation (BAS) software category, a product must:

- Deploy threats targeting various attack surfaces
- Simulate both cyberattacks and data breaches
- Quantify risk and evaluate security posture based on attack response
- Provide remediation process guidance and improvement suggestions

Show More