The Rochester, New York company betting that Managed Service Providers want fewer security tools, not more features - and folding a whole stack into a single dashboard.
Ask a Managed Service Provider what keeps them up at night and the honest answer is rarely a specific threat. It is the sprawl - ten consoles, ten invoices, ten places a client's risk could be hiding. CYRISMA was founded in 2018 in Rochester, New York on a plain premise: that identifying, assessing and reducing cyber risk should not require assembling and babysitting a shelf of separate products.
The company builds a cloud-hosted cyber risk management platform that consolidates the work most organizations spread across many tools. In a single multi-tenant dashboard it runs vulnerability and patch management, sensitive data discovery, secure configuration scanning, attack surface visibility, dark web monitoring, compliance tracking, and a feature the company calls risk monetization - putting an estimated dollar figure on exposure so a finding can survive a conversation with the CFO.
The target user is specific. CYRISMA is built first for MSPs and MSSPs - the outsourced IT and security teams that protect small and mid-sized businesses - and secondarily for internal IT departments that face the same tool fatigue. That focus shows up everywhere in the product, from multi-tenant management to integrations with the professional-services-automation systems these partners already run.
This investment will allow us to continue delivering an affordable and comprehensive risk management solution, empowering MSPs to protect their clients effectively.
*Figures cited in review-site aggregates and partner materials - treat as approximate.
Each module below is usually sold as its own product elsewhere. CYRISMA's argument is that an MSP should not have to integrate them by hand.
Continuous scanning to find, prioritize and remediate vulnerabilities, with patching to close the gaps it surfaces.
Locates and classifies sensitive data so an organization knows where its crown-jewel information actually lives.
Checks systems against secure baselines to catch the misconfigurations attackers love.
Gives visibility into internal and external exposure - what an adversary would see.
Watches the dark web for leaked credentials and exposed data tied to the organization.
Quantifies cyber risk in financial terms, estimating potential incident cost for boardroom decisions.
Automated compliance tracking and executive score-card reports across frameworks like HIPAA and PCI.
The vulnerability-management market is crowded with capable names - Qualys, Tenable, Rapid7 - and newer aggregators like Nucleus Security and Vulcan Cyber. Most are excellent at one thing. CYRISMA's wager is different: breadth in one place, priced so a service provider can actually resell it.
Two choices set it apart. First, it bills per endpoint rather than per seat, aligning cost with how an MSP's book of business grows. Second, it plugs into the PSA systems partners already run - ConnectWise, Autotask, Halo PSA - so risk and compliance data lands in the tools their technicians live in, not a fourth tab nobody opens.
Blueprint Equity's Sheldon Lewis, who led the 2024 round, pointed at exactly this when explaining the investment.
We were drawn to the breadth of the CYRISMA platform and their strong customer satisfaction... an unparalleled insight into the MSP market.
Illustrative emphasis of the platform's pitch - not audited benchmarks.
Between single-purpose enterprise scanners and broad GRC suites - a mid-market, MSP-first platform that trades depth-in-one for coverage-in-one.
CYRISMA's customers are, for the most part, other people's security teams. Managed Service Providers and Managed Security Service Providers use the platform to deliver risk and compliance services to their own clients, while internal IT departments use it directly. Company and partner materials describe thousands of organizations reached this way, with partner references citing 3,000-plus.
The business model follows the buyer. CYRISMA is B2B SaaS on a multi-tenant, per-endpoint subscription, distributed heavily through the channel. In 2023 it joined the Pax8 marketplace, putting consolidated risk management in front of that platform's large base of MSPs at once. Top-20 global MSSP CyFlare has cited the MSP-friendly pricing as a reason it partnered.
That channel-first posture is the strategy, not a side effect. By making the product easy to resell - multi-tenant, integrated, predictably priced - CYRISMA lets its partners turn cyber risk and compliance from a cost center into a billable service line. The company grows when its partners do.
Leadership reflects a company in its scaling phase. Co-founder Liam Downward, whose security career began in 1998 at Gateway computers, serves as Chief Product Officer; fellow co-founder Oliver Downward led as CEO through the fundraise. In early 2025 Mark Balovnev, previously CEO of Vantyr, was named Chief Executive Officer to drive the next stage of growth.
Liam Downward, Oliver Downward, Mike Hoag and Vlad Georgiev launch the cyber risk platform in Rochester, NY.
The platform adds financial risk quantification and automated compliance tracking.
New modules push toward full-spectrum risk visibility.
Channel distribution expands to thousands of MSPs.
Blueprint Equity leads, with SaaS Ventures and Golden Ventures, to accelerate product and go-to-market.
A new chief executive joins to scale the MSP-focused business.
It provides a unified, cloud-hosted cyber risk management platform combining vulnerability and patch management, sensitive data discovery, secure configuration scanning, attack surface management, dark web monitoring, risk monetization and compliance tracking in one dashboard.
Primarily Managed Service Providers (MSPs), MSSPs and internal IT/security teams that want to deliver risk and compliance services without stitching together multiple point tools.
CYRISMA is headquartered in Rochester, New York and was founded in 2018.
It raised a $7M Series A in October 2024 led by Blueprint Equity, bringing total disclosed funding to roughly $8.95M.
CYRISMA consolidates several security functions into one MSP-friendly, multi-tenant platform with per-endpoint pricing and PSA integrations, rather than focusing on a single capability like vulnerability scanning.