SBS CyberSecurity vs Trail of Bits
SBS CyberSecurity
SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.
Pros
- Two decades focused specifically on regulated financial institutions, with reporting built for board and examiner audiences
- Platinum Member of the American Bankers Association Partner Network, with preferred provider relationships across more than 20 state banking associations
- TRAC GRC platform used by more than 1,500 organizations, bundling testing findings into ongoing risk management rather than a standalone report
- CMMC readiness work maps directly to Level 1 and Level 2 gap preparation for defense contractors
Pricing: Custom (contact sales)
Trail of Bits
Co-founded in 2012 by Dan Guido and headquartered in New York City, Trail of Bits combines academic-style security research with hands-on engineering. The firm is best known for advanced software assurance work across cryptography, AI/ML, blockchain, and low-level systems, and for releasing widely used open-source tooling such as the Slither smart contract analyzer.
Pros
- Strong academic and research-grade reputation with published peer-reviewed work
- Open-source tooling footprint including Slither, Echidna, Manticore
- Recognised leader in smart-contract auditing for top-tier protocols
- Engineering depth that translates findings into custom defensive tooling
Pricing: Custom (contact sales)