SBS CyberSecurity
ClaimedUS cybersecurity consulting, audit and testing firm founded in 2004, focused on community banks and credit unions, with external, internal, web application, wireless and PCI DSS penetration testing plus CMMC Level 1 and 2 readiness work.
Featured in: Penetration Testing for Defense
Visit SBS CyberSecurityKey facts
- Founded in Madison, South Dakota in 2004; co-founders Chad Knutson and Jon Waldman took full ownership in July 2022.
- Core market is regulated financial institutions: community banks and credit unions.
- More than 1,500 organisations use its TRAC governance, risk and compliance platform.
- Platinum Member of the American Bankers Association Partner Network, with preferred provider relationships across more than 20 state banking associations.
- Named to the Inc. 5000 in consecutive years from 2013 and to the Inc. 5000 Honor Roll, which recognises companies listed five or more times.
- Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11, aligned to NIST, OWASP and PTES.
- CMMC work covers Level 1 and Level 2 readiness: gap identification, documentation, and preparation that carries into assessment by a Certified Third Party Assessment Organisation.
- The SBS Institute has delivered cybersecurity certification programmes since 2014.
- Headquartered in Madison, South Dakota, United States.
- Team of 51-200 security professionals.
- Delivers 7 penetration testing services.
- Serves clients in North America.
- Specialises in Financial Institution Security, CMMC Readiness, and Virtual CISO.
- Compliance expertise across CMMC, NIST CSF, PCI DSS, and HIPAA.
About
SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions: community banks and credit unions, which it serves through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022.
Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES and delivered by human testers rather than tool output alone. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management.
For defence contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification and assessment preparation. That readiness work carries into the certification assessment itself, which is completed by a separate Certified Third Party Assessment Organisation.
The firm is a Platinum Member of the American Bankers Association Partner Network and holds preferred provider relationships with more than 20 state banking associations. Its education arm, the SBS Institute, has run cybersecurity certification programmes since 2014.
By the numbers
Figures published by SBS CyberSecurity.
Accreditations
- Inc. 5000 Honor RollSBS describes itself as "a 2019 Inc. 5000 honoree." Inc.'s own list shows a longer run: SBS made the list in consecutive years from 2013, and the Honor Roll recognises companies listed five or more times.
- American Bankers Association Partner Network, Platinum MemberListed in the ABA's own partner directory. Platinum is the top membership tier.
- G2 High Performer, Summer 2026Plus a G2 Clients Love Us milestone badge, both based on verified customer reviews.
- State banking association endorsementsPreferred provider and partnership relationships across more than 20 US state banking associations.
- SBS InstituteIn-house education arm running cybersecurity certification programmes since 2014.
- CEO Chad Knutson and President Jon Waldman in Investing.comOn AI-driven cyber threats: attackers now operate faster than many defenders can respond, and effective governance requires real access controls, not just AI tooling.
- CEO Chad Knutson and Director of Product Development Toni Meyer in International Business TimesOn regulated industries moving off spreadsheet-based compliance toward integrated GRC platforms.
- Chad Knutson: banking AI speaking engagements, June 2026Sessions at the AI in Banking Virtual Summit and the Graduate School of Banking's AI Innovation Series, both aimed at bank executives and operational leadership.
- Chad Knutson: Program Coordinator, Graduate School of Banking (University of Wisconsin, Madison)Listed on GSB's own faculty page for the Bank Technology Management School, since 2014.
Awards and memberships, not security accreditations. Not scored.
Services
"SBS CyberSecurity is focused on empowering your cybersecurity decisions. We provide robust risk management programs, IT audit services, and cybersecurity testing solutions, enabling you to protect your organization."
SBS CyberSecurity in Depth
EnhancedOverview
SBS CyberSecurity has spent two decades in one market rather than spreading across many. It was founded in Madison, South Dakota in 2004 to help banks meet examiner expectations, and regulated financial institutions are still the centre of the business: community banks, credit unions, and the state banking associations that endorse it. That focus shows in the work, which pairs offensive testing with the audit, risk management and governance programmes examiners actually ask for.
The company sells testing and tooling together. TRAC, its governance, risk and compliance platform, is used by more than 1,500 organisations, and the SBS Institute has run cybersecurity certification programmes since 2014.
Approach
Penetration testing is human-led and mapped to NIST, OWASP and PTES, across five defined engagement types: external network, internal network, web application, wireless, and PCI DSS Requirement 11. Red team, purple team and social engineering assessments are sold separately, as are vulnerability assessments, which are scoped as an ongoing programme rather than a one-off scan. On the advisory side, virtual CISO, NIST Cybersecurity Framework assessments and cybersecurity maturity assessments feed the same reporting model: a prioritised action plan aimed at a board or an examiner rather than a raw findings dump.
What They Test
Working with SBS CyberSecurity
Services
+ Also offers 1 more service
Methodologies
No reviews yet. Share your experience →