SBS CyberSecurity logo

SBS CyberSecurity

Claimed

US cybersecurity consulting, audit and testing firm founded in 2004, focused on community banks and credit unions, with external, internal, web application, wireless and PCI DSS penetration testing plus CMMC Level 1 and 2 readiness work.

Featured in: Penetration Testing for Defense

Visit SBS CyberSecurity
Founded
2004
Team Size
51-200
Geography
North America
Last verified: Sept 2026

Key facts

  • Founded in Madison, South Dakota in 2004; co-founders Chad Knutson and Jon Waldman took full ownership in July 2022.
  • Core market is regulated financial institutions: community banks and credit unions.
  • More than 1,500 organisations use its TRAC governance, risk and compliance platform.
  • Platinum Member of the American Bankers Association Partner Network, with preferred provider relationships across more than 20 state banking associations.
  • Named to the Inc. 5000 in consecutive years from 2013 and to the Inc. 5000 Honor Roll, which recognises companies listed five or more times.
  • Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11, aligned to NIST, OWASP and PTES.
  • CMMC work covers Level 1 and Level 2 readiness: gap identification, documentation, and preparation that carries into assessment by a Certified Third Party Assessment Organisation.
  • The SBS Institute has delivered cybersecurity certification programmes since 2014.
  • Headquartered in Madison, South Dakota, United States.
  • Team of 51-200 security professionals.
  • Delivers 7 penetration testing services.
  • Serves clients in North America.
  • Specialises in Financial Institution Security, CMMC Readiness, and Virtual CISO.
  • Compliance expertise across CMMC, NIST CSF, PCI DSS, and HIPAA.

About

SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions: community banks and credit unions, which it serves through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022.

Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES and delivered by human testers rather than tool output alone. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management.

For defence contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification and assessment preparation. That readiness work carries into the certification assessment itself, which is completed by a separate Certified Third Party Assessment Organisation.

The firm is a Platinum Member of the American Bankers Association Partner Network and holds preferred provider relationships with more than 20 state banking associations. Its education arm, the SBS Institute, has run cybersecurity certification programmes since 2014.

By the numbers

20
years in the cybersecurity industry
500+
monthly Hacker Hour registrants
1,500+
organisations using TRAC
2,500+
cybersecurity certifications issued

Figures published by SBS CyberSecurity.

Accreditations

Recognition

Awards and memberships, not security accreditations. Not scored.

"SBS CyberSecurity is focused on empowering your cybersecurity decisions. We provide robust risk management programs, IT audit services, and cybersecurity testing solutions, enabling you to protect your organization."

SBS CyberSecurity in Depth

Enhanced

Overview

SBS CyberSecurity has spent two decades in one market rather than spreading across many. It was founded in Madison, South Dakota in 2004 to help banks meet examiner expectations, and regulated financial institutions are still the centre of the business: community banks, credit unions, and the state banking associations that endorse it. That focus shows in the work, which pairs offensive testing with the audit, risk management and governance programmes examiners actually ask for.

The company sells testing and tooling together. TRAC, its governance, risk and compliance platform, is used by more than 1,500 organisations, and the SBS Institute has run cybersecurity certification programmes since 2014.

Approach

Penetration testing is human-led and mapped to NIST, OWASP and PTES, across five defined engagement types: external network, internal network, web application, wireless, and PCI DSS Requirement 11. Red team, purple team and social engineering assessments are sold separately, as are vulnerability assessments, which are scoped as an ongoing programme rather than a one-off scan. On the advisory side, virtual CISO, NIST Cybersecurity Framework assessments and cybersecurity maturity assessments feed the same reporting model: a prioritised action plan aimed at a board or an examiner rather than a raw findings dump.

What They Test

External network
Internet-facing systems and perimeter defences, testing what an attacker reaches before any access is granted.
Internal network
Simulates an attacker who already has network access, covering lateral movement and privilege escalation.
Web application
Public and internal applications, covering injection, cross-site scripting and authentication flaws.
Wireless
Encryption, network segmentation and unauthorised access points across the wireless estate.
PCI DSS Requirement 11
Scoped specifically to meet the testing obligation for cardholder data environments.
Social engineering and red team
Phishing and pretext-based assessments, plus red and purple team engagements sold as separate exercises.

Working with SBS CyberSecurity

Can SBS certify us for CMMC?
SBS prepares organisations for CMMC Level 1 and Level 2: identifying gaps, building documentation, and getting the programme ready. That readiness work is designed to carry straight into the certification assessment, which is completed by a Certified Third Party Assessment Organisation.
What accreditations does SBS hold?
SBS is a Platinum Member of the American Bankers Association Partner Network, a G2 High Performer, and an Inc. 5000 Honor Roll company. Its testers hold individual certifications including CISSP, CISA and CEH. Its current programme does not include a company-level security accreditation such as CREST, ISO 27001 or SOC 2, which our scoring model reflects the same way for every provider.
Who is SBS a good fit for?
Community banks, credit unions and other regulated financial institutions that want testing, audit and governance from one firm, and organisations that need a readiness partner before a CMMC Level 1 or Level 2 assessment. It suits buyers who value a board-ready action plan over a raw findings dump, and who will use TRAC or a similar platform alongside the testing.
What does SBS offer beyond testing?
Virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, IT and network security audits, vendor risk management, and incident response. It also runs the TRAC governance, risk and compliance platform, used by more than 1,500 organisations, and the SBS Institute, which has delivered cybersecurity certification programmes since 2014.

Methodologies

NISTOWASPPTES
Visit SBS CyberSecurity