SBS CyberSecurity vs NCC Group

SBS CyberSecurity

SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.

Pros
  • Two decades focused specifically on regulated financial institutions, with reporting built for board and examiner audiences
  • Platinum Member of the American Bankers Association Partner Network, with preferred provider relationships across more than 20 state banking associations
  • TRAC GRC platform used by more than 1,500 organizations, bundling testing findings into ongoing risk management rather than a standalone report
  • CMMC readiness work maps directly to Level 1 and Level 2 gap preparation for defense contractors

Pricing: Custom (contact sales)

NCC Group

NCC Group was formed in 1999 when the National Computing Centre's commercial divisions were spun out and is headquartered in Manchester, listed on the London Stock Exchange. With 2,000+ staff across the UK, North America, Europe, and APAC, the group operates technical assurance, managed services, and software escrow divisions and is a founding CREST member.

Pros
  • Founding CREST member with deep accreditation across CHECK, CBEST, and TIBER-EU
  • Recognised research output, including former Cryptography Services and Exploit Development Group
  • Broad global delivery footprint with UK government-cleared consultants
  • Combines offensive testing with MDR, IR, and escrow under one umbrella

Pricing: Custom (contact sales)