Black Hills Information Security logo

Black Hills Information Security

Community-driven penetration testing firm known for free security education, open-source tools, Wild West Hackin' Fest, and practical offensive security services.

Founded
2008
Team Size
11-50
Geography
National
Last verified: Feb 2026

About

Black Hills Information Security is a penetration testing and security consultancy based in Spearfish, South Dakota, founded by John Strand in 2008. The company has built an outsized reputation relative to its location and size through its exceptional commitment to community education, open-source tool development, and deeply practical approach to offensive security. BHIS is widely known in the cybersecurity community for their free webcasts, training courses through their Wild West Hackin' Fest conference, and the Active Countermeasures platform for network threat hunting.

Their penetration testing services cover network testing, web application testing, social engineering, red teaming, and purple teaming, with a philosophy that emphasizes teaching clients to defend themselves rather than simply producing vulnerability reports. BHIS consultants are prolific speakers at security conferences and active contributors to the offensive security community.

The company is particularly respected for their work in active defense and deception technologies, helping organizations detect and respond to attackers in real time. They serve mid-market organizations, state and local government, and enterprises across various industries. Their consultants hold OSCP, GPEN, GCIH, and other certifications and are known for their approachable, practical teaching style.

Compliance Expertise

Best For

Mid-MarketSMBGovernment

Methodologies

OWASPPTESNIST

Team Activity

Active in CTF competitions
Wild West Hackin' Fest Organizers
Speaker: Wild West Hackin' Fest
Speaker: DEF CON
Speaker: BSides
Speaker: SANS Summit
Open source: Active Countermeasures
Open source: Backdoors & Breaches

Compare With

Reviews

Be the first to share your experience with Black Hills Information Security.

Be the first to review Black Hills Information Security
Is this your company? Claim this profile

Related Providers

TrustedSec logo

TrustedSec

Elite offensive security firm founded by a former NSA operator, delivering CREST-accredited penetration testing, red teaming, and adversary simulation to Fortune 500 and government clients.

Fairlawn, Ohio, United StatesContact for pricing
Web ApplicationNetworkCloudAPI+7
CRESTPCI QSA
Verified Mar 2026
Secureworks logo

Secureworks

Dell Technologies-backed cybersecurity firm with elite Counter Threat Unit intelligence informing enterprise penetration testing and adversary simulation.

Atlanta, Georgia, United StatesContact for pricing
Web ApplicationNetworkCloudAPI+6
SOC 2ISO 27001
Verified Feb 2026
Best UK ProviderBest for EnterpriseResearch Leaders
NCC Group logo

NCC Group

Global cybersecurity consultancy with CREST, CHECK, and CBEST accreditation, renowned for deep technical research and comprehensive penetration testing services.

Manchester, United KingdomContact for pricing
Web ApplicationNetworkMobile AppIoT+12
CRESTCHECKCBESTISO 27001+5
Verified Feb 2026
Bulletproof logo

Bulletproof

CREST-accredited UK cybersecurity and compliance provider offering penetration testing, managed security services, and regulatory consultancy to over 2,000 customers from its Stevenage headquarters.

Stevenage, United KingdomContact for pricing
Web ApplicationNetworkMobile AppCloud+7
CRESTISO 27001Cyber EssentialsCyber Essentials Plus+2
Verified Feb 2026