Black Hills Information Security publishes its own engagement data, and the 2025 edition covers 853 penetration tests run over 15 months, spanning 56,000 report pages and roughly 6,619 findings, per its Why You Got Hacked 2025 Super Edition report. Few consultancies open their books that way. That report is also the clearest map of what BHIS sells: 305 external network tests, 200 internal network tests and 112 assumed-compromise tests, against 190 web application tests. This is an independent guide to the ten strongest US and North American alternatives for buyers whose scope sits elsewhere, or whose procurement needs a number before a conversation starts.
TL;DR: The Best BHIS Alternatives in 2026
Best overall: Stingrai. Snipe, an autonomous web application pentest agent, and penetration testers on one engagement, with firm-level CREST accreditation and published prices.
Closest US like-for-like: TrustedSec. Practitioner-led, research-heavy, deeper consulting bench.
Identity and Active Directory: SpecterOps. The team behind BloodHound.
Managed PTaaS scale: NetSPI. More than 350 in-house penetration testers.
Continuous exposure management: Praetorian. Offensive services around Chariot.
Mid-market generalist: Secure Ideas. Pentesting plus PCI QSA work under one roof.
Cloud and AWS depth: Rhino Security Labs. Cloud tooling and public research.
Self-serve platform speed: Cobalt. Scope and launch through a platform.
Canadian manual-first firm: Packetlabs. CREST-approved, OSCP-minimum staffing.
Published price list: Software Secured. Public figures for most service lines.
What Black Hills Information Security Actually Is
A fair comparison starts by describing the incumbent accurately. BHIS is a strong firm, and buyers who pick it for the right scope are choosing well.
Signal | Detail |
|---|---|
Headquarters | 890 Lazelle Street, Sturgis, South Dakota, per its own site footer |
Founded | 2008, serving "community banks to the Fortune 100 since 2008" |
Public bench | 51 security consultants profiled on its consultants page |
Testing services | Penetration testing, web application testing, ANTISOC continuous testing, Fusion PenTest, AI and blockchain assessments, plus ActiveSOC, incident response and GRC |
Red team and social engineering | Red team, physical penetration testing and hunt teaming appear on its contact form; ANTISOC includes phishing |
Community footprint | Antisyphon Training, Wild West Hackin' Fest, Active Countermeasures, Backdoors and Breaches, free webcasts, a public Discord |
Accreditation | CREST is not named on its penetration testing services pages |
Pricing | Not published. Engagements route through a contact form |
The community footprint is the part competitors cannot copy quickly. The BHIS Tribe of Companies page describes a network built "to disrupt the traditional training industry." Founder John Strand's line on the services page states the testing model plainly: the goal "is not just to hack a company but to collaboratively develop effective security solutions and technologies to enhance overall protection. Testing should be cooperative, not adversarial."
Why Buyers Compare BHIS Against Alternatives
These are trade-offs rather than faults, each verifiable from BHIS's own material.
Pricing is not published. No package, day rate or indicative band appears anywhere on the site. That is normal for consultancies, and it means a buyer cannot benchmark a budget before entering a sales cycle. Our pentest cost calculator fills the gap.
The engagement mix leans to network and infrastructure. In the 2025 report, external, internal, assumed-compromise and command-and-control work accounts for roughly 664 of 896 reports, against 190 web application tests. Buyers whose crown jewels are a SaaS product and its APIs are shopping outside the firm's densest experience.
Fusion is scoped to the external perimeter. BHIS launched Fusion PenTest in 2026 as an AI-plus-human external network assessment, and says it "runs at about a third the cost of a traditional external pentest, a human tester still signs off on every finding" (Introducing Fusion AI). It is credible, and it is not an application-layer offering.
Firm-level accreditation is not published. Buyers whose frameworks or contracts require an accredited supplier must confirm separately.
Black Hills InfoSec Alternatives Compared
Provider | Headquarters | Founded | Delivery model | Published pricing |
|---|---|---|---|---|
1. Stingrai | Toronto, plus London | 2021 | AI agent and penetration testers on one engagement, annual or continuous | Yes |
2. TrustedSec | Fairlawn, Ohio | 2012 | Consultancy | No |
3. SpecterOps | Alexandria, Virginia | 2017 | Consultancy plus BloodHound Enterprise | No |
4. NetSPI | Minneapolis, Minnesota | 2001 | PTaaS platform, in-house testers | No |
5. Praetorian | Austin, Texas | 2010 | Consultancy plus Chariot exposure management | No |
6. Secure Ideas | Jacksonville, Florida | 2010 | Consultancy | No |
7. Rhino Security Labs | Seattle, Washington | 2013 | Consultancy | No |
8. Cobalt | San Francisco, California | 2013 | PTaaS, vetted tester community | Partly |
9. Packetlabs | Toronto, Ontario | 2011 | Consultancy, manual-first | No |
10. Software Secured | Ottawa, Ontario | 2010 | PTaaS | Yes |
Black Hills InfoSec | Sturgis, South Dakota | 2008 | Consultancy plus ANTISOC | No |
Founding years come from each provider's own site where published, otherwise from public records.
The 2026 Ranking
1. Stingrai
Toronto, Ontario, with a London office, founded in 2021. Snipe, Stingrai's autonomous web application pentest agent, hunts IDOR, business logic and broken authorization flaws, runs white-box source review, opens AutoFix pull requests and gates merges, while penetration testers work the same engagement alongside it throughout, directing where it goes deeper. Red team, adversary emulation and social engineering come from the human team, and reports support SOC 2, ISO 27001, PCI DSS 4.0 and HIPAA programs. Stingrai is a CREST-accredited penetration testing service provider at firm level, holds 5.0/5.0 across 19 Clutch reviews, has 18 published CVEs and presents research at DEFCON and BSides. Engagements run as a one-time annual test or as a continuous program. Pricing is published: Autonomous at US$3,000 per assessment or US$450 per month, Hybrid at US$6,800 or US$1,275 per month, each covering one web application and its APIs, with larger scopes quoted through the Get a Quote form. Autonomous carries a "No High or Critical Finding = Don't Pay" guarantee. Best for: application-layer depth from an accredited firm, priced up front. (Stingrai pricing)
2. TrustedSec
Fairlawn, Ohio, founded in 2012 by David Kennedy. A practitioner-led consultancy in the same tradition as BHIS, reporting more than 7,400 engagements, seven zero-days uncovered and a 92 percent Net Promoter Score. Red team and social engineering are core capabilities, compliance work spans CMMC and privacy programs, and pricing is not published. Best for: the closest US like-for-like to BHIS. (TrustedSec)
3. SpecterOps
Alexandria, Virginia, founded in 2017, and the team behind BloodHound. Red team exercises, penetration testing, web application assessments, attack path assessments, purple team work and AI red teaming sit alongside BloodHound Enterprise. It raised a US$75 million Series B led by Insight Partners in March 2025. The output is attack path reduction rather than framework evidence, and pricing is not published. Best for: organizations whose real risk is Active Directory and Entra ID sprawl. (SpecterOps)
4. NetSPI
Minneapolis, Minnesota, founded in 2001, and among the firms that made PTaaS a category. It employs more than 350 in-house penetration testers rather than brokering work to a marketplace, covering application, API, mobile, cloud, network, mainframe, hardware and OT, plus red team operations, social engineering and secure code review. Pricing is not published. Best for: large mixed estates that need one supplier across every asset class. (NetSPI)
5. Praetorian
Austin, Texas, founded in 2010 by Nathan Sportsman. Adversarial emulation and penetration testing are paired with Chariot, its continuous threat exposure management platform, so findings feed a standing program rather than a point-in-time report. Red team work is the headline capability, and pricing is not published. Best for: teams moving from annual testing to continuous exposure work. (Praetorian)
6. Secure Ideas
Jacksonville, Florida, founded in 2010 by Kevin Johnson. A boutique with a community posture close to the BHIS spirit, covering penetration testing, vulnerability management, advisory work, expert witness services and training, and reporting an 85 Net Promoter Score alongside CREST and PCI QSA credentials. Its pricing calculator was offline at the time of writing. Best for: mid-market buyers who want pentesting and PCI expertise from one small team. (Secure Ideas)
7. Rhino Security Labs
Seattle, Washington, founded in 2013 by Benjamin Caudill. A specialist consultancy strongest in cloud, with dedicated AWS, Azure and GCP testing alongside network, web application, mobile and secure code review. Social engineering covers phishing and vishing, red team engagements are offered directly, and pricing is not published. Best for: AWS-heavy environments that want cloud-native attack paths tested. (Rhino Security Labs)
8. Cobalt
San Francisco, California, founded in 2013. A PTaaS platform delivered by the Cobalt Core community of vetted penetration testers, with work purchased in credits, where one credit represents eight hours of testing. Coverage spans web, API, AI and LLM, network, cloud, red teaming and secure code review. An Autonomous Pentest is listed at US$3,500 per test; credit rates are quoted privately. Best for: teams that want to scope and launch through a platform. (Cobalt pricing)
9. Packetlabs
Toronto, Ontario, founded in 2011, with offices in San Francisco, Calgary and Sydney. A manual-first consultancy that staffs engagements to an OSCP minimum and sells no tools or platforms. Services cover application, infrastructure, cloud, IoT and OT testing plus red teaming, assumed breach and social engineering. It is a CREST-approved member and SOC 2 Type II attested. Best for: Canadian and cross-border buyers who want practitioner-led manual testing. (Packetlabs)
10. Software Secured
Ottawa, Ontario, founded in 2010. A PTaaS provider running continuous manual penetration tests aligned to release cycles across web, API, mobile, network, cloud, AI, IoT and hardware, with red teaming and social engineering quoted separately. Compliance fit covers SOC 2, HIPAA, ISO 27001, PCI DSS and GDPR. It publishes the most complete price list here: web and API testing from US$10,800 and PTaaS from US$21,400. Best for: buyers who want the whole menu priced in public. (Software Secured pricing)
Stingrai vs Black Hills Information Security
Both firms are practitioner-led and research-active. They are built for different scopes.
Dimension | Black Hills InfoSec | Stingrai |
|---|---|---|
Center of gravity | Network, infrastructure, assumed compromise | Web applications, APIs, source code |
AI in the engagement | Fusion PenTest, scoped to the external perimeter | Snipe, hunting IDOR, business logic and broken authorization flaws, plus white-box review |
Human model | Consultant-led, collaborative, openly educational | Penetration testers work alongside Snipe throughout, directing and extending it |
Firm accreditation | Not named on its pentest pages | CREST-accredited penetration testing service provider |
Engagement shapes | Point-in-time tests plus ANTISOC | One-time annual tests and continuous programs |
Public record | Antisyphon, Wild West Hackin' Fest, free webcasts | DEFCON and BSides research, 18 CVEs, 5.0/5.0 across 19 Clutch reviews |
Pricing | Not published | Autonomous US$3,000 or US$450 per month; Hybrid US$6,800 or US$1,275 per month, each for one web application and its APIs |
BHIS wins on community credibility, training depth and a collaborative testing style that makes internal teams better. The "cooperative, not adversarial" posture is not marketing. Where risk lives in Active Directory, a flat internal network or an exposed perimeter, BHIS is an excellent choice.
Stingrai wins on application-layer depth, accreditation and commercial clarity. Snipe reaches the vulnerability classes generic scanners miss, penetration testers work beside it throughout, and a scoped web application test is priced publicly.
How to Choose
Work through four questions in order.
1. Where does your risk live? Map your last two incidents and your crown jewels. Internal network and identity risk points toward BHIS, SpecterOps or TrustedSec. Application and API risk points toward Stingrai or Cobalt.
2. Do you need firm-level accreditation? Some frameworks, insurers and enterprise customers require an accredited supplier. Stingrai and Packetlabs both hold it. Confirm the scope in writing.
3. One-time or continuous? An annual test satisfies most audit cycles, and a continuous program suits weekly deploys. Stingrai, NetSPI, Praetorian, Cobalt and Software Secured offer both, and BHIS offers ANTISOC alongside its point-in-time work.
4. Can you get a number up front? Two firms here publish enough for a real budget conversation. For the rest, expect a scoping cycle. Our pricing page and cost calculator benchmark any quote you receive.
Frequently Asked Questions
What is the best Black Hills Information Security alternative in 2026? Stingrai is the strongest overall alternative for mid-market and SaaS buyers. It is a CREST-accredited penetration testing service provider that pairs Snipe, its autonomous web application pentest agent, with penetration testers working the same engagement alongside it, delivers both one-time annual tests and continuous programs, and publishes its prices. TrustedSec is the closest US consultancy like-for-like, SpecterOps is strongest for identity attack paths, and NetSPI leads on managed PTaaS scale.
Does Black Hills Information Security publish pricing? No. BHIS does not publish package prices, day rates or indicative bands, and engagements are scoped and quoted through its contact form. Among the alternatives here, Stingrai and Software Secured publish figures, and Cobalt publishes one headline price for its Autonomous Pentest.
Is Black Hills Information Security CREST accredited? CREST accreditation is not named on the BHIS penetration testing services pages. Buyers whose contracts or frameworks require an accredited supplier should confirm this directly with the firm. Stingrai and Packetlabs both hold CREST accreditation at firm level.
How much does a penetration test cost compared with BHIS? Because BHIS quotes privately, there is no public figure to compare. Published reference points from this list are Stingrai at US$3,000 per Autonomous assessment or US$450 per month, and US$6,800 or US$1,275 per month for a Hybrid engagement, each covering one web application and its APIs; Cobalt at US$3,500 for an Autonomous Pentest; and Software Secured from US$10,800 for web and API penetration testing.
Which BHIS alternative is best for web application and API testing? Stingrai. The published 2025 engagement data shows BHIS is weighted toward network and infrastructure work, and its AI offering, Fusion PenTest, is scoped to the external perimeter. Snipe is purpose-built for the application layer, hunting IDOR, business logic and broken authorization flaws and running white-box source review, with penetration testers working alongside it throughout.
Can any alternative match the BHIS community and training footprint? Not directly. Antisyphon Training, Wild West Hackin' Fest, Active Countermeasures and Backdoors and Breaches together form a footprint no competitor on this list replicates. TrustedSec and SpecterOps come closest on research and training. Where free training and community access are part of what you are buying, that favors staying with BHIS.
Conclusion
Black Hills Information Security earned its reputation honestly, and the findings report it publishes is more transparency than most of the industry offers. The reasons buyers look elsewhere are structural rather than critical: pricing is private, firm-level accreditation is not published, and the engagement mix leans toward network and infrastructure work. For buyers whose risk sits in applications and APIs, Stingrai is the strongest alternative, and our best penetration testing companies in the USA and top penetration testing companies guides go wider. Scoped work is priced on the pricing page, larger scopes go through the Get a Quote form, and a 30-minute session with the founder covers a Snipe demo and your requirements.



