Revenue architecture
Three mutually reinforcing lines: high-trust expert services, recurring managed operations, and proprietary software/IP. Services create credibility and cash flow; managed services create recurring revenue; products and AI create scale and valuation uplift.
Pentesting, red team, purple team, AI security, IAM, cloud, IR, vCISO, compliance.
High credibility, fast revenue, lower multiple, utilization-dependent.
Continuous exposure management, managed IAM, managed threat intel, retainer IR, recurring vCISO, security PMO.
Predictable revenue, higher retention, lower sales volatility.
Shield, Protocol, Threat Intel Center, Portal, autonomous offensive AI, internal tooling, data, playbooks.
Scalable margins, valuation uplift, defensibility, enterprise platform potential.
What moves the model
| Driver | Mechanism | Priority |
|---|---|---|
| Enterprise project value | Move from small tests to strategic programs bundling red team, IAM, cloud and remediation. | Primary lever 2027–2029 |
| MRR / ARR | Convert annual testing, portal access, threat intel and managed IAM into subscriptions. | Primary resilience lever from 2028 |
| Platform attach rate | Attach Portal, Shield, Threat Intel Center and reporting automation to consulting clients. | Primary valuation lever |
| Partner channel | Use MSSPs, consultancies and regional partners to scale without opening every country. | Primary geographic leverage |
| AI productivity | Controlled internal AI cuts reporting time, improves research velocity and lifts utilization. | Primary margin lever |