main logo icon

Published on

August 22, 2026

|

10 min read

Black Hills Information Security (BHIS) Alternatives (2026): Penetration Testing Firms Compared

An independent 2026 buyer's guide to Black Hills Information Security alternatives, with eight US and North American penetration testing firms compared.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Black Hills Information Security is a Sturgis, South Dakota consultancy founded in 2008, and one of the most community-credible names in offensive security: Antisyphon Training, Wild West Hackin' Fest, Backdoors and Breaches, free webcasts and 51 security consultants profiled publicly. Its published 2025 findings report covers 853 penetration tests over 15 months, and the service split shows where the firm's center of gravity sits: 305 external network tests, 200 internal network tests and 112 assumed-compromise tests, against 190 web application tests. BHIS does not publish pricing and does not name CREST on its penetration testing pages. Buyers who need application-layer and API depth, firm-level accreditation, or a price they can read before contact should compare alternatives. Stingrai is a CREST-accredited offensive security company. Its penetration testers simulate real-world attacks across applications, cloud, networks, and people, with testing delivered through its PTaaS platform. TrustedSec is the closest US consultancy like-for-like, SpecterOps owns identity attack paths, NetSPI leads managed PTaaS scale, and Software Secured publishes the most complete public price list.

Black Hills Information Security publishes its own engagement data, and the 2025 edition covers 853 penetration tests run over 15 months, spanning 56,000 report pages and roughly 6,619 findings, per its Why You Got Hacked 2025 Super Edition report. Few consultancies open their books that way. That report is also the clearest map of what BHIS sells: 305 external network tests, 200 internal network tests and 112 assumed-compromise tests, against 190 web application tests. This is an independent guide to the eight strongest US and North American alternatives for buyers whose scope sits elsewhere, or whose procurement needs a number before a conversation starts.

TL;DR: The Best BHIS Alternatives in 2026

  • Best overall: Stingrai. Stingrai is a CREST-accredited offensive security company. Two named penetration testers run each engagement, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and a founding member of Uber's offensive security team among them. Where BHIS is strongest on network and assumed compromise work, Stingrai's centre of gravity is the application layer: web and API testing authenticated across every user role for broken authorization, IDOR and business logic, with source-assisted review, alongside mobile, AI and LLM, cloud, internal and external network, Active Directory, social engineering and assumed-breach red team scopes, with findings posted to its PTaaS portal as they are confirmed, live chat with the assigned testers, Jira and Slack integration, retesting and an attestation letter with every report.

  • Closest US like-for-like: TrustedSec. Practitioner-led, research-heavy, deeper consulting bench.

  • Identity and Active Directory: SpecterOps. The team behind BloodHound.

  • Managed PTaaS scale: NetSPI. More than 350 in-house penetration testers.

  • Continuous exposure management: Praetorian. Offensive services around Chariot.

  • Mid-market generalist: Secure Ideas. Pentesting plus PCI QSA work under one roof.

  • Cloud and AWS depth: Rhino Security Labs. Cloud tooling and public research.

  • Self-serve platform speed: Cobalt. Scope and launch through a platform.

What Black Hills Information Security Actually Is

A fair comparison starts by describing the incumbent accurately. BHIS is a strong firm, and buyers who pick it for the right scope are choosing well.

Signal

Detail

Headquarters

890 Lazelle Street, Sturgis, South Dakota, per its own site footer

Founded

2008, serving "community banks to the Fortune 100 since 2008"

Public bench

51 security consultants profiled on its consultants page

Testing services

Penetration testing, web application testing, ANTISOC continuous testing, Fusion PenTest, AI and blockchain assessments, plus ActiveSOC, incident response and GRC

Red team and social engineering

Red team, physical penetration testing and hunt teaming appear on its contact form; ANTISOC includes phishing

Community footprint

Antisyphon Training, Wild West Hackin' Fest, Active Countermeasures, Backdoors and Breaches, free webcasts, a public Discord

Accreditation

CREST is not named on its penetration testing services pages

Pricing

Not published. Engagements route through a contact form

The community footprint is the part competitors cannot copy quickly. The BHIS Tribe of Companies page describes a network built "to disrupt the traditional training industry." Founder John Strand's line on the services page states the testing model plainly: the goal "is not just to hack a company but to collaboratively develop effective security solutions and technologies to enhance overall protection. Testing should be cooperative, not adversarial."

Bhis Engagement Mix 2025

Why Buyers Compare BHIS Against Alternatives

These are trade-offs rather than faults, each verifiable from BHIS's own material.

Pricing is not published. No package, day rate or indicative band appears anywhere on the site. That is normal for consultancies, and it means a buyer cannot benchmark a budget before entering a sales cycle. Our pentest cost calculator fills the gap.

The engagement mix leans to network and infrastructure. In the 2025 report, external, internal, assumed-compromise and command-and-control work accounts for roughly 664 of 896 reports, against 190 web application tests. Buyers whose crown jewels are a SaaS product and its APIs are shopping outside the firm's densest experience.

Fusion is scoped to the external perimeter. BHIS launched Fusion PenTest in 2026 as an AI-plus-human external network assessment, and says it "runs at about a third the cost of a traditional external pentest, a human tester still signs off on every finding" (Introducing Fusion AI). It is credible, and it is not an application-layer offering.

Firm-level accreditation is not published. Buyers whose frameworks or contracts require an accredited supplier must confirm separately.

Black Hills InfoSec Alternatives Compared

Provider

Headquarters

Founded

Delivery model

Published pricing

1. Stingrai

Toronto, plus London

2021

Two named penetration testers per engagement, application-layer depth plus network, cloud and red team, one-time or continuous through PTaaS

Yes

2. TrustedSec

Fairlawn, Ohio

2012

Consultancy

No

3. SpecterOps

Alexandria, Virginia

2017

Consultancy plus BloodHound Enterprise

No

4. NetSPI

Minneapolis, Minnesota

2001

PTaaS platform, in-house testers

No

5. Praetorian

Austin, Texas

2010

Consultancy plus Chariot exposure management

No

6. Secure Ideas

Jacksonville, Florida

2010

Consultancy

No

7. Rhino Security Labs

Seattle, Washington

2013

Consultancy

No

8. Cobalt

Boston, Massachusetts

2013

PTaaS, vetted tester community

Partly

Black Hills InfoSec

Sturgis, South Dakota

2008

Consultancy plus ANTISOC

No

Founding years come from each provider's own site where published, otherwise from public records.

Bhis Alternatives Pricing Transparency 2026

The 2026 Ranking

1. Stingrai

World-Class Offensive Security.

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

Where BHIS is strongest on network and assumed compromise work, Stingrai's centre of gravity is the application layer: web and API testing authenticated across every user role for broken authorization, IDOR and business logic, with source-assisted review, alongside cloud, internal and external network, Active Directory and assumed-breach red team scopes. Two named penetration testers run each engagement, with 18 published CVEs across the team and a founding member of Uber's offensive security team among them. Findings are posted to its PTaaS portal as they are confirmed, with live chat with the assigned testers, Jira and Slack integration, retesting and an attestation letter with every report. Explore the PTaaS platform.

Attackers don't just run scanners, and neither does Stingrai. Its penetration testers work black, grey or white box, test every user role for broken authorization and business logic, chain findings into real attack paths, document each one with a working proof of concept, and post them to the PTaaS portal as they are confirmed, so remediation starts before the report and the included retest closes the loop.

Alongside the Toronto headquarters there is a London, UK office. Stingrai delivers both one-time annual penetration tests and continuous programs that test every release.

Services and scope

Delivery and evidence

Every finding arrives with a working proof of concept and prioritized remediation guidance, retesting of fixes is included, and each report ships with an attestation letter and a verified badge. The portal adds live chat with the assigned penetration testers during the test, Jira and Slack push, redactable PDF reports and an executive dashboard. CREST accreditation applies to Stingrai as a penetration testing service provider; it is separate from individual tester certifications.

Where Snipe fits

Snipe is Stingrai's autonomous agent for web application penetration testing, including the application's APIs. It covers recon, authentication, access control, business logic, injection and remote code execution, tests black box, authenticated grey box and white box against source, opens AutoFix pull requests and can gate pull requests. The Autonomous package is Snipe alone; in a Hybrid engagement Snipe and Stingrai's penetration testers test together throughout. Mobile, AI and LLM, cloud, network, Active Directory, social engineering and red and purple team scopes are human-led.

Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs at US$3,000 and US$6,800 per assessment, or US$650 and US$1,275 per month; network, cloud, Active Directory and red team scopes are quoted, so request a quote. Best for: buyers leaving BHIS who need application and API depth, firm-level accreditation and a number up front, on an annual or continuous cadence.

2. TrustedSec

Fairlawn, Ohio, founded in 2012 by David Kennedy. A practitioner-led consultancy in the same tradition as BHIS, reporting more than 7,400 engagements, seven zero-days uncovered and a 92 percent Net Promoter Score. Red team and social engineering are core capabilities, compliance work spans CMMC and privacy programs, and pricing is not published. Best for: the closest US like-for-like to BHIS. (TrustedSec)

3. SpecterOps

Alexandria, Virginia, founded in 2017, and the team behind BloodHound. Red team exercises, penetration testing, web application assessments, attack path assessments, purple team work and AI red teaming sit alongside BloodHound Enterprise. It raised a US$75 million Series B led by Insight Partners in March 2025. The output is attack path reduction rather than framework evidence, and pricing is not published. Best for: organizations whose real risk is Active Directory and Entra ID sprawl. (SpecterOps)

4. NetSPI

Minneapolis, Minnesota, founded in 2001, and among the firms that made PTaaS a category. It employs more than 350 in-house penetration testers rather than brokering work to a marketplace, covering application, API, mobile, cloud, network, mainframe, hardware and OT, plus red team operations, social engineering and secure code review. Pricing is not published. Best for: large mixed estates that need one supplier across every asset class. (NetSPI)

5. Praetorian

Austin, Texas, founded in 2010 by Nathan Sportsman. Adversarial emulation and penetration testing are paired with Chariot, its continuous threat exposure management platform, so findings feed a standing program rather than a point-in-time report. Red team work is the headline capability, and pricing is not published. Best for: teams moving from annual testing to continuous exposure work. (Praetorian)

6. Secure Ideas

Jacksonville, Florida, founded in 2010 by Kevin Johnson. A boutique with a community posture close to the BHIS spirit, covering penetration testing, vulnerability management, advisory work, expert witness services and training, and reporting an 85 Net Promoter Score alongside CREST and PCI QSA credentials. Its pricing calculator was offline at the time of writing. Best for: mid-market buyers who want pentesting and PCI expertise from one small team. (Secure Ideas)

7. Rhino Security Labs

Seattle, Washington, founded in 2013 by Benjamin Caudill. A specialist consultancy strongest in cloud, with dedicated AWS, Azure and GCP testing alongside network, web application, mobile and secure code review. Social engineering covers phishing and vishing, red team engagements are offered directly, and pricing is not published. Best for: AWS-heavy environments that want cloud-native attack paths tested. (Rhino Security Labs)

8. Cobalt

San Francisco, California, founded in 2013. A PTaaS platform delivered by the Cobalt Core community of vetted penetration testers, with work purchased in credits, where one credit represents eight hours of testing. Coverage spans web, API, AI and LLM, network, cloud, red teaming and secure code review. An Autonomous Pentest is listed at US$3,500 per test; credit rates are quoted privately. Best for: teams that want to scope and launch through a platform. (Cobalt pricing)

Stingrai vs Black Hills Information Security

Both firms are practitioner-led and research-active. They are built for different scopes.

Dimension

Black Hills InfoSec

Stingrai

Center of gravity

Network, infrastructure, assumed compromise

Web applications, APIs, source code

AI in the engagement

Fusion PenTest, scoped to the external perimeter

Snipe, hunting IDOR, business logic and broken authorization flaws, plus white-box review

Human model

Consultant-led, collaborative, openly educational

Penetration testers work alongside Snipe throughout, directing and extending it

Firm accreditation

Not named on its pentest pages

CREST-accredited penetration testing service provider

Engagement shapes

Point-in-time tests plus ANTISOC

One-time annual tests and continuous programs

Public record

Antisyphon, Wild West Hackin' Fest, free webcasts

BSides research, 18 published CVEs, bug bounty Hall of Fame listings at Apple, Google and the US Department of Defense, 5.0/5.0 across 20 Clutch reviews

Pricing

Not published

Autonomous US$3,000 or US$650 per month; Hybrid US$6,800 or US$1,275 per month, each for one web application and its APIs

BHIS wins on community credibility, training depth and a collaborative testing style that makes internal teams better. The "cooperative, not adversarial" posture is not marketing. Where risk lives in Active Directory, a flat internal network or an exposed perimeter, BHIS is an excellent choice.

Stingrai wins on application-layer depth, accreditation and commercial clarity. Snipe reaches the vulnerability classes generic scanners miss, penetration testers work beside it throughout, and a scoped web application test is priced publicly.

How to Choose

Work through four questions in order.

1. Where does your risk live? Map your last two incidents and your crown jewels. Internal network and identity risk points toward BHIS, SpecterOps or TrustedSec. Application and API risk points toward Stingrai or Cobalt.

2. Do you need firm-level accreditation? Some frameworks, insurers and enterprise customers require an accredited supplier. Stingrai holds it at firm level. Confirm the scope in writing.

3. One-time or continuous? An annual test satisfies most audit cycles, and a continuous program suits weekly deploys. Stingrai, NetSPI, Praetorian and Cobalt offer both, and BHIS offers ANTISOC alongside its point-in-time work.

4. Can you get a number up front? Stingrai publishes enough for a real budget conversation, and Cobalt publishes a single headline price. For the rest, expect a scoping cycle. Our pricing page and cost calculator benchmark any quote you receive.

Frequently Asked Questions

What is the best Black Hills Information Security alternative in 2026? Stingrai is the strongest overall alternative for mid-market and SaaS buyers. It is a CREST-accredited penetration testing service provider whose two named penetration testers, drawn from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP and 18 published CVEs, test web applications and APIs authenticated across every role for broken authorization, IDOR and business logic, and also cover mobile, cloud, network, Active Directory, social engineering and red team scopes. Snipe, its autonomous web application agent, works the same engagement alongside them, findings land in the portal as they are confirmed with live tester chat and Jira and Slack push, retesting and an attestation letter are included, both one-time annual tests and continuous programs are sold, and the web packages are priced publicly. TrustedSec is the closest US consultancy like-for-like, SpecterOps is strongest for identity attack paths, and NetSPI leads on managed PTaaS scale.

Does Black Hills Information Security publish pricing? No. BHIS does not publish package prices, day rates or indicative bands, and engagements are scoped and quoted through its contact form. Among the alternatives here, Stingrai publishes figures, and Cobalt publishes one headline price for its Autonomous Pentest.

Is Black Hills Information Security CREST accredited? CREST accreditation is not named on the BHIS penetration testing services pages. Buyers whose contracts or frameworks require an accredited supplier should confirm this directly with the firm. Stingrai holds CREST accreditation at firm level.

How much does a penetration test cost compared with BHIS? Because BHIS quotes privately, there is no public figure to compare. Published reference points from this list are Stingrai at US$3,000 per Autonomous assessment or US$650 per month, and US$6,800 or US$1,275 per month for a Hybrid engagement, each covering one web application and its APIs; and Cobalt at US$3,500 for an Autonomous Pentest.

Which BHIS alternative is best for web application and API testing? Stingrai. The published 2025 engagement data shows BHIS is weighted toward network and infrastructure work, and its AI offering, Fusion PenTest, is scoped to the external perimeter. Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs. It is available for autonomous web testing or alongside penetration testers in a Hybrid web engagement.

Can any alternative match the BHIS community and training footprint? Not directly. Antisyphon Training, Wild West Hackin' Fest, Active Countermeasures and Backdoors and Breaches together form a footprint no competitor on this list replicates. TrustedSec and SpecterOps come closest on research and training. Where free training and community access are part of what you are buying, that favors staying with BHIS.

Conclusion

Black Hills Information Security earned its reputation honestly, and the findings report it publishes is more transparency than most of the industry offers. The reasons buyers look elsewhere are structural rather than critical: pricing is private, firm-level accreditation is not published, and the engagement mix leans toward network and infrastructure work. For buyers whose risk sits in applications and APIs, Stingrai is the strongest alternative, and our best penetration testing companies in the USA and top penetration testing companies guides go wider. Scoped work is priced on the pricing page, larger scopes go through the Get a Quote form, and a 30-minute session with the founder covers a Snipe demo and your requirements.

0 views

0

X

Related reading

Penetration Testing Requirements for Insurance Companies (2026): NYDFS Part 500, NAIC Model Law, OSFI B-13 and SOC 2
Web App SecurityNetwork Security

Penetration Testing Requirements for Insurance Companies (2026): NYDFS Part 500, NAIC Model Law, OSFI B-13 and SOC 2

NYDFS 500.5 requires annual pentests of non-exempt NY-licensed insurers, agents and brokers. What the NAIC model, OSFI B-13, AMF and SOC 2 expect, and costs.

38 min read

Manufacturing Penetration Testing (2026): IT/OT Segmentation, Customer Audits, CMMC and Cost
Network SecurityWeb App Security

Manufacturing Penetration Testing (2026): IT/OT Segmentation, Customer Audits, CMMC and Cost

What manufacturers should pentest in 2026: the perimeter, Active Directory and IT/OT segmentation, what CMMC, TISAX and insurers ask, safe rules and cost.

30 min read

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Contents

X