atsec information security: Company Profile
Background
atsec information security is an independent, privately-owned company specializing in laboratory testing, evaluation, validation, and training services for information security. Founded in January 2000, atsec has grown into an international entity with offices in the United States, Europe, and Asia. The company's mission is to provide professional and independent advice on information security that empowers business and operations. atsec's vision is to be a globally trusted leader in evaluating and testing complex software-based IT systems for vendors and government agencies. Operating in the information security industry, atsec is recognized for its commitment to impartiality and integrity, ensuring that its services remain unbiased and focused solely on IT security.
Key Strategic Focus
atsec's strategic focus centers on delivering comprehensive information security services, including:
- IT Product Evaluation & Assessment: Conducting standards-based evaluations of commercial off-the-shelf (COTS) hardware, software, and organizational security.
- Cryptographic Testing: Providing FIPS 140-3 testing services and conformance testing for the Cryptographic Algorithm Validation Program (CAVP) and Entropy Source Validation (ESV).
- Telecommunication Security: Offering GSMA NESAS Audits and SCAS Testing, as well as BSI-NESAS services within the Network Equipment Security Assurance Scheme (NESAS).
- Identity Verification: Providing testing services for the NIST Personal Identity Verification Program (NPIVP) and supporting secure, passwordless authentication standards through FIDO accreditation.
- IT Product Certification: Serving as an accredited private Certification Body according to ISO/IEC 17065, specializing in Common Criteria ISO/IEC 15408 and 18045.
- Payment Security: Offering a full range of services to support organizations in achieving PCI compliance, including assessments for P2PE, 3DS, PIN security, and more.
The company utilizes key technologies such as Security Content Automation Protocol (SCAP), Open Trusted Technology Provider Standard (O-TTPS), and IEEE 2621 certification for medical device cybersecurity. Primary markets targeted include vendors of network equipment products supporting 3GPP-defined functions, U.S. federal identification products, and organizations seeking PCI compliance.
Financials and Funding
As a privately-owned company, atsec information security does not publicly disclose detailed financial information. Estimates suggest that the company has approximately 80 employees and an annual revenue of around $16.3 million. Specific details regarding funding history, total funds raised, recent funding rounds, and notable investors are not publicly available. The company continues to reinvest in its services and global expansion to meet the growing demand for information security solutions.
Pipeline Development
atsec's pipeline development focuses on enhancing its service offerings and expanding its global presence. The company is actively involved in:
- International Cryptographic Module Conference (ICMC): atsec is the founder and permanent Platinum Sponsor of the ICMC, which brings together vendors, labs, agencies, and academia to advance cryptographic module validation.
- Crypto Module User Forum (CMUF): Established by atsec in 2014, the CMUF serves as a platform for sharing ideas and inspiring innovation among crypto module professionals, with over 800 members.
- Common Criteria User Forum (CCUF): atsec has been instrumental in creating the CCUF for evaluators, vendors, and certification bodies to discuss the Common Criteria standard and has been a member of the CCUF management board since its inception.
These initiatives demonstrate atsec's commitment to advancing information security standards and fostering collaboration within the industry.
Technological Platform and Innovation
atsec distinguishes itself through several proprietary technologies and scientific methodologies:
- Proprietary Technologies: The company offers specialized services such as FIPS 140-3 testing, GSMA NESAS Audits, and BSI-NESAS services, which are critical for ensuring the security of cryptographic modules and network equipment.
- Significant Scientific Methods: atsec employs rigorous evaluation and testing methodologies aligned with international standards, including Common Criteria (ISO/IEC 15408), FIPS 140-3, and PCI DSS, to ensure comprehensive security assessments.
- AI-Driven Capabilities: While specific AI-driven capabilities are not detailed, atsec's focus on advanced cryptographic testing and secure authentication standards indicates a commitment to integrating cutting-edge technologies into its services.
Leadership Team
atsec's leadership team comprises experienced professionals dedicated to the company's mission:
- Staffan Persson: Founder and Director, with extensive experience in information security and a strong commitment to the company's independent and impartial approach.
- Gerald Krummeck: Director of Certification, overseeing the company's certification processes and ensuring adherence to international standards.
- Yi Mao: Managing Director, responsible for strategic direction and operational management across atsec's global offices.
- Wendy Hughes: Chief Operating Officer and HR Director, managing day-to-day operations and human resources to support the company's growth.
- Andreas Fabis: Marketing Director, leading marketing initiatives to promote atsec's services and expand its market presence.
- Marcos Portnoi: Lab Director, overseeing laboratory operations and ensuring the quality and integrity of testing and evaluation services.
- Rasma Araby: Managing Director at atsec information security AB, contributing to the company's leadership in Europe.
- Valerio Mag