Save

SecurityMetrics

Med Traffic

securitymetrics.com

Overview

SecurityMetrics is a data security and compliance company specializing in PCI DSS, HIPAA, GDPR, and related regulatory assessments for businesses of all sizes. The company provides a comprehensive suite of services including vulnerability scanning, penetration testing, data discovery, incident response, and security training. It serves sectors such as retail, healthcare, education, and government.

IndustryCybersecurity & Compliance
Founded2000
HQOrem, Utah, USA
Team Size200-500

By the Numbers

23+ years
Domain Age
Domain registered August 2001
#65,941
Tranco Web Traffic Rank
As of recent measurement, mid-tier global ranking
10+
Compliance Standards Covered
Including PCI DSS, HIPAA, GDPR, HITRUST, SOC 2
4+ major sectors
Industries Served
Retail, healthcare, education, government

Founders

Brad CaldwellFounder & CEO

Brad Caldwell founded SecurityMetrics with a focus on making payment card industry compliance accessible to small and mid-sized merchants. He has led the company through its growth into a recognized QSA (Qualified Security Assessor) firm.

SecurityMetrics became one of the earliest QSA companies approved by the PCI Security Standards Council, giving it a strong first-mover advantage in PCI compliance services.

Funding

Bootstrapped
Last RoundUnknown
ValuationUnknown

Competitors

Trustwave

Larger enterprise focus with managed security services and a broader global presence

Coalfire

Strong focus on cloud compliance and FedRAMP assessments for government clients

Sysnet Global Solutions

Focuses on PCI compliance for small merchants through payment processor partnerships

ControlScan

Targets small to mid-sized merchants with bundled PCI compliance and managed security

Verizon Security Solutions

Backed by a major telecom with extensive threat intelligence and breach investigation resources

Key People

Gary GloverVP of Assessment Services / CISSP, QSA

Gary Glover is a senior security professional at SecurityMetrics with extensive experience in PCI DSS assessments and public security education. He is a frequent author and speaker on PCI compliance topics.

Jen StonePrincipal Security Analyst, MSCIS, CISSP, QSA

Jen Stone is a recognized security analyst and educator at SecurityMetrics known for her work in HIPAA security training and PCI compliance guidance. She contributes regularly to the SecurityMetrics podcast and educational content.

Revenue & Model

$20M-$50M ARR
Business ModelProfessional services and SaaS — recurring compliance scanning subscriptions, one-time assessment fees, and managed security retainers
Headcount~250-400Stable
View pricing →

Hiring Signals

~15open rolesStable
Other
2
Sales
4
Engineering
5
Compliance/Assessment
4

Tech Stack

Google Tag ManagerSalesforce PardotLinkedIn Insight TagWordPressSSL/TLSCloudflareHubSpot (likely)YouTube (content delivery)

Notable Customers

Small and mid-sized merchants (via payment processor referrals)Healthcare providers requiring HIPAA complianceEducational institutionsGovernment contractors

Web Presence

Global traffic rank#65,941
Domain registered2001-08-15 (25 yrs)
RegistrarTucows Domains Inc.
Hacker News mentions6

Verified from public records — not AI-estimated.

Trackers & Analytics

3services detected
Tag Managers
Google Tag Manager
Advertising & Retargeting
LinkedIn Insight Tag
Marketing & CRM
Salesforce Pardot

Scanned from the HTML securitymetrics.comserves — scripts a tag manager injects later won't appear here.

How They're Doing

Stable

SecurityMetrics continues to operate as a well-established QSA and cybersecurity compliance firm with a stable customer base across retail, healthcare, and government sectors. The company has maintained its Tranco traffic rank in the mid tier (~#65,941), suggesting steady but not explosive web traffic growth. It appears to be a profitable, bootstrapped business focused on consistent service delivery rather than hypergrowth.

Maintains active incident response hotline and 24/7 support capabilities

Continues to offer updated PCI DSS v4.0 compliance assessments following the standard's 2022 release

Prognosis

Neutral

SecurityMetrics is well-positioned to benefit from increasing regulatory complexity, especially as PCI DSS v4.0 full enforcement deadlines approach in 2025 and healthcare data security requirements tighten. The company's bootstrapped, profitable model limits rapid expansion but also insulates it from market downturns. Long-term risk lies in commoditization of compliance scanning and competition from larger managed security service providers.

Opportunities

PCI DSS v4.0 transition driving demand for reassessment and consulting through 2025

Growing HIPAA enforcement and healthcare data breach incidents increasing compliance services demand

Expansion into SMB cybersecurity awareness training as regulations extend to smaller organizations

Risks

Commoditization of vulnerability scanning and compliance tools by cloud-native competitors

Larger MSSPs and consulting firms undercutting on price or bundling compliance with broader security contracts

Difficulty scaling without external investment compared to VC-backed competitors

Recent News

2023-03

SecurityMetrics publishes guidance on PCI DSS v4.0 transition requirements for merchants

SecurityMetrics Blog

2022-10

SecurityMetrics updates HIPAA compliance assessment offerings amid rising healthcare breaches

SecurityMetrics Blog

2022-04

PCI Security Standards Council releases PCI DSS v4.0; SecurityMetrics among first QSAs to offer v4.0 assessments

Industry

Fun Facts

  • 01SecurityMetrics was one of the original QSA companies certified by the PCI Security Standards Council when the PCI DSS standard launched in 2004, giving it over two decades of specialization.
  • 02The company is headquartered in Orem, Utah — part of a growing tech corridor sometimes called 'Silicon Slopes,' making it unusual among East Coast-dominated cybersecurity firms.
  • 03Despite competing with publicly traded and PE-backed giants, SecurityMetrics has remained privately held and bootstrapped for over two decades, a rarity in the cybersecurity compliance space.

Timeline

2023

Continued expansion of incident response and security awareness training offerings

2022

PCI DSS v4.0 released; SecurityMetrics updates assessment portfolio

2018

Added GDPR compliance assessment offerings ahead of EU enforcement deadline

2016

Launched managed security and continuous monitoring services

2010

Expanded services to include HIPAA compliance assessments for healthcare sector

2004

PCI DSS standard launched; SecurityMetrics becomes one of the first certified QSA companies

2001

Domain securitymetrics.com registered in August

2000

SecurityMetrics founded in Utah, focused on data security for merchants