SecurityMetrics
Med Trafficsecuritymetrics.com
Overview
SecurityMetrics is a data security and compliance company specializing in PCI DSS, HIPAA, GDPR, and related regulatory assessments for businesses of all sizes. The company provides a comprehensive suite of services including vulnerability scanning, penetration testing, data discovery, incident response, and security training. It serves sectors such as retail, healthcare, education, and government.
By the Numbers
Founders
Brad Caldwell founded SecurityMetrics with a focus on making payment card industry compliance accessible to small and mid-sized merchants. He has led the company through its growth into a recognized QSA (Qualified Security Assessor) firm.
SecurityMetrics became one of the earliest QSA companies approved by the PCI Security Standards Council, giving it a strong first-mover advantage in PCI compliance services.
Funding
Competitors
Larger enterprise focus with managed security services and a broader global presence
Strong focus on cloud compliance and FedRAMP assessments for government clients
Focuses on PCI compliance for small merchants through payment processor partnerships
Targets small to mid-sized merchants with bundled PCI compliance and managed security
Backed by a major telecom with extensive threat intelligence and breach investigation resources
Key People
Gary Glover is a senior security professional at SecurityMetrics with extensive experience in PCI DSS assessments and public security education. He is a frequent author and speaker on PCI compliance topics.
Jen Stone is a recognized security analyst and educator at SecurityMetrics known for her work in HIPAA security training and PCI compliance guidance. She contributes regularly to the SecurityMetrics podcast and educational content.
Revenue & Model
Hiring Signals
Tech Stack
Notable Customers
Web Presence
Verified from public records — not AI-estimated.
Trackers & Analytics
Scanned from the HTML securitymetrics.comserves — scripts a tag manager injects later won't appear here.
How They're Doing
SecurityMetrics continues to operate as a well-established QSA and cybersecurity compliance firm with a stable customer base across retail, healthcare, and government sectors. The company has maintained its Tranco traffic rank in the mid tier (~#65,941), suggesting steady but not explosive web traffic growth. It appears to be a profitable, bootstrapped business focused on consistent service delivery rather than hypergrowth.
●Maintains active incident response hotline and 24/7 support capabilities
●Continues to offer updated PCI DSS v4.0 compliance assessments following the standard's 2022 release
Prognosis
SecurityMetrics is well-positioned to benefit from increasing regulatory complexity, especially as PCI DSS v4.0 full enforcement deadlines approach in 2025 and healthcare data security requirements tighten. The company's bootstrapped, profitable model limits rapid expansion but also insulates it from market downturns. Long-term risk lies in commoditization of compliance scanning and competition from larger managed security service providers.
●PCI DSS v4.0 transition driving demand for reassessment and consulting through 2025
●Growing HIPAA enforcement and healthcare data breach incidents increasing compliance services demand
●Expansion into SMB cybersecurity awareness training as regulations extend to smaller organizations
●Commoditization of vulnerability scanning and compliance tools by cloud-native competitors
●Larger MSSPs and consulting firms undercutting on price or bundling compliance with broader security contracts
●Difficulty scaling without external investment compared to VC-backed competitors
Recent News
SecurityMetrics publishes guidance on PCI DSS v4.0 transition requirements for merchants
SecurityMetrics Blog
SecurityMetrics updates HIPAA compliance assessment offerings amid rising healthcare breaches
SecurityMetrics Blog
PCI Security Standards Council releases PCI DSS v4.0; SecurityMetrics among first QSAs to offer v4.0 assessments
Industry
Fun Facts
- 01SecurityMetrics was one of the original QSA companies certified by the PCI Security Standards Council when the PCI DSS standard launched in 2004, giving it over two decades of specialization.
- 02The company is headquartered in Orem, Utah — part of a growing tech corridor sometimes called 'Silicon Slopes,' making it unusual among East Coast-dominated cybersecurity firms.
- 03Despite competing with publicly traded and PE-backed giants, SecurityMetrics has remained privately held and bootstrapped for over two decades, a rarity in the cybersecurity compliance space.
Timeline
Continued expansion of incident response and security awareness training offerings
PCI DSS v4.0 released; SecurityMetrics updates assessment portfolio
Added GDPR compliance assessment offerings ahead of EU enforcement deadline
Launched managed security and continuous monitoring services
Expanded services to include HIPAA compliance assessments for healthcare sector
PCI DSS standard launched; SecurityMetrics becomes one of the first certified QSA companies
Domain securitymetrics.com registered in August
SecurityMetrics founded in Utah, focused on data security for merchants