Budget Security

Self-serve platform for booking and managing manual penetration tests with transparent, online procurement.

Website: https://budgetsecurity.com/

Cover Block

Public sources

Field Value
Name Budget Security
Tagline Self-serve platform for booking and managing manual penetration tests with transparent, online procurement.
Headquarters The Hague, Netherlands
Founded 2025
Business Model SaaS
Industry Security
Technology AI / Machine Learning
Geography Global / Remote-First
Growth Profile Venture Scale
Founding Team Co-Founders (2)

Links

Public sources

Executive Summary

Public sources Budget Security is a new entrant seeking to standardize and digitize the opaque procurement process for manual penetration testing, a wedge that could attract investor attention if the team can demonstrate repeatable sales motion beyond its own marketing. Founded in 2025 and based in The Hague, the company operates a self-serve SaaS platform where customers define an asset, goal, and budget, after which an AI proposes a test plan and a network of OSCP-certified testers executes the engagement [Budget Security, September 2026]. The founding story centers on operators with backgrounds in technical security and cybersecurity procurement who have, according to company statements, collectively delivered thousands of pentests over the past decade [Budget Security, September 2026].

The core differentiation is a transparent, fixed-price model starting at €849 per tester day, which the company positions as a significant discount to traditional consultancies that bundle substantial overhead into their rates [Budget Security, 2026]. One publicly identified co-founder, Bram Verhoeven, lists skills in Python, Django, and sales, though the full founding team and its prior venture experience are not detailed in public profiles [LinkedIn, Retrieved 2026]. Capitalization is not publicly disclosed; the company has announced no funding rounds, and revenue and valuation figures from third-party aggregators remain unverified [Prospeo]. Over the next 12-18 months, the critical watchpoints will be the validation of its claimed 35-person team and 30 certified testers, the publication of named customer case studies, and any move to raise institutional capital to scale its marketplace model.

Lightly corroborated -- Core claims sourced from company website; team details partially corroborated by LinkedIn; financials and funding unverified.

Taxonomy Snapshot

Axis Classification
Business Model SaaS
Industry / Vertical Security
Technology Type AI / Machine Learning
Geography Global / Remote-First
Growth Profile Venture Scale
Founding Team Co-Founders (2)

How the Company Got Here

Public sources

Budget Security B.V. is a privately held cybersecurity company founded in 2025 and headquartered in The Hague, Netherlands. The company operates a remote-first model, targeting a global customer base primarily in the European Union, United States, and United Kingdom [Budget Security, September 2026]. Its founding premise is to streamline the procurement of manual penetration testing by removing traditional consultancy overhead, a concept developed by founders with backgrounds in technical security and cybersecurity procurement [Budget Security, September 2026].

The company's primary public milestone is the launch of its self-serve platform, which it frames as a modern alternative to opaque, high-touch sales processes. By September 2026, the company reported having over 35 people, including a team of 30 OSCP-certified penetration testers [Budget Security, September 2026]. This team size and the publication of detailed pricing guides and a press kit represent the most concrete operational signals available from public sources.

Lightly corroborated -- Key operational claims (founding year, location, team size) are sourced from the company's own September 2026 materials. No independent public filings or third-party registries were located to corroborate the entity details or team scale.

Product and Technology

Sources and analysis

Budget Security’s core product is a self-serve platform designed to standardize the procurement and delivery of manual penetration testing. The company’s primary claim is that it has removed the traditional consulting overhead by eliminating dedicated sales teams and account managers, allowing it to publish a transparent day rate starting at €849 for an OSCP-certified tester [Budget Security, September 2026]. The process, as described on the company website, begins with a customer selecting an asset type, defining a testing goal, and setting a budget; an AI system then proposes a tailored test plan [Budget Security, September 2026]. Engagements are conducted by a claimed team of 30 OSCP-certified penetration testers, with results delivered through a client dashboard rather than solely as a static PDF report [Budget Security, September 2026].

  • Scope of services. The platform is positioned to handle manual testing across web applications, APIs, networks, cloud environments, and mobile applications [Budget Security, September 2026].
  • Compliance wedge. A significant portion of the product’s positioning targets specific regulatory frameworks, including SOC 2 readiness, NIS2 audit preparation, ISO 27001 scoping, and authenticated-only reviews [Budget Security, September 2026]. This suggests the underlying workflow and reporting are built to generate evidence for common audit requirements.
  • Pricing model. The company provides detailed pricing benchmarks on its blog, contrasting its model with traditional consultancies. It states that for a small business with a simple web application, a traditional firm might charge €3,000 to €8,000, while its platform would price the same engagement between €849 and €3,500 [Budget Security, 2026]. The stated mechanism for this discount is the removal of bundled overhead, which the company estimates at 30-60% of a traditional consultancy’s day rate [Budget Security, 2026].

The technology stack powering the platform is not detailed in public materials. The mention of AI for test plan generation and a dashboard for results delivery indicates a SaaS architecture, but specific tools, APIs, or security certifications for the platform itself are not disclosed. The operational claim of supporting 35+ people, including the tester cohort, implies a backend built for coordinating distributed, credentialed labor, though this is an inference from the company’s stated headcount [Budget Security, September 2026].

Lightly corroborated -- Product claims and pricing are detailed on the company's own website but lack independent verification. The team size and tester certifications are also company-sourced claims.

Where the Demand Sits

PUBLIC The market for penetration testing is being reshaped by regulatory mandates and the search for cost efficiency, creating an opening for a self-serve procurement model. Budget Security positions itself at the intersection of these forces, targeting small and mid-sized technology companies that face new compliance obligations but lack the procurement budgets of large enterprises.

The company's own research, published across its blog in 2026, provides the most concrete pricing benchmarks available for analysis. It frames the traditional market as opaque and expensive, with consultancies charging between €10,000 and €50,000 or more per engagement [Budget Security, 2026]. For a small business with a single web application, Budget Security estimates a traditional consultancy would charge €3,000 to €8,000, while its own platform would price the same work between €849 and €3,500 [Budget Security, 2026]. The core driver of this price differential, according to the company, is the elimination of bundled overhead for sales, account management, and project management, which it claims constitutes 30-60% of a traditional consultancy's day rate [Budget Security, 2026].

Regulatory compliance is cited as a primary demand catalyst. The company's content specifically highlights the EU's NIS2 Directive, SOC 2 for US SaaS companies, and the UK's Cyber Essentials Plus scheme as key compliance goals its platform supports [Budget Security, September 2026]. These mandates effectively create a non-discretionary budget for security testing among a previously underserved segment of companies. The adjacent market of automated vulnerability scanning serves as a partial substitute but does not fulfill the manual testing requirements of these compliance frameworks, leaving a gap for a streamlined service model.

A formal TAM or SAM figure from a third-party analyst firm is not publicly available in the cited sources. However, the company's published pricing data allows for a segmentation of the addressable market by engagement type and customer profile.

Metric Value
Traditional Small Web App Test 8000 €
Budget Security Small Web App Test 3500 €
Traditional Day Rate (High) 2500 €/day
Budget Security Day Rate 849 €/day

The chart illustrates the pricing wedge Budget Security is attempting to drive. The value proposition is not built on a technological breakthrough in testing itself, but on a radical simplification of the commercial and scoping process. The analyst takeaway is that the market opportunity hinges on converting compliance-driven demand into a transactional, productized service, displacing the traditional consultancy sales cycle.

Lightly corroborated -- Market sizing and pricing claims are sourced solely from the company's own published content. While internally consistent, they lack independent verification from industry reports or competitor disclosures.

Competitive Landscape

Sources and analysis Budget Security’s competitive position is defined by its attempt to disrupt the traditional, high-touch penetration testing consultancy model with a self-serve, fixed-price platform. The company’s public materials do not name specific competitors, and no named rivals were surfaced in the available research. The analysis therefore maps the landscape by segment rather than by direct, named comparison.

A competitive map for manual penetration testing reveals three primary segments. The first is the traditional cybersecurity consultancy, which includes large global firms and regional boutique providers. These incumbents typically charge between €10,000 and €50,000 or more per engagement, bundling significant overhead for sales, account management, and project management into their day rates [Budget Security, 2026]. The second segment consists of automated vulnerability scanning and continuous security testing platforms. These are not direct substitutes for manual, human-led testing but serve as adjacent solutions that address overlapping compliance and security needs, often at a lower price point for basic coverage. The third segment is the emerging category of online marketplaces and managed service platforms for security testing, where Budget Security aims to position itself.

Budget Security’s current defensible edge rests on two pillars: its transparent, published pricing and its claimed operational model. The company states it eliminates traditional consultancy overhead by using a self-serve platform, allowing it to publish day rates of €849 to €2,500 for OSCP- or CREST-qualified testers [Budget Security, 2026]. This price transparency and the promise of AI-assisted scoping represent a distribution and procurement edge. However, this edge is perishable. It depends on maintaining a lower-cost structure than incumbents, which could be eroded if consultancies launch their own streamlined digital offerings. The edge also relies on the quality and consistency of its 30+ OSCP-certified testers [Budget Security, September 2026], a talent pool that is difficult to scale and retain in a competitive hiring market.

The company’s most significant exposure lies in its lack of enterprise-grade channel relationships and its unproven ability to handle complex, multi-asset engagements that define the high-margin end of the market. Traditional consultancies hold an advantage in their ability to provide strategic advisory services, manage large-scale programs, and offer bundled compliance packages that go beyond discrete testing. Furthermore, Budget Security does not yet appear to have the brand recognition or case studies required to compete for large, risk-averse enterprise contracts where vendor reputation is paramount. Its focus on SMB and mid-market technology companies [Budget Security, September 2026] is a sensible wedge but leaves it vulnerable if incumbents decide to automate their own SMB sales motions.

In the most plausible 18-month scenario, the winner will be whichever player most effectively bridges the gap between automated efficiency and trusted human expertise. If Budget Security can scale its tester network while maintaining quality and begins to secure named enterprise logos for compliance-driven work (like NIS2 or SOC 2), it could solidify its position as a challenger brand. The loser in this scenario would be the mid-tier traditional consultancies that fail to digitize their procurement and delivery. These firms, which currently rely on high-touch sales for mid-market deals, would see their margins compressed as customers become accustomed to transparent, online pricing models.

Lightly corroborated -- Competitive analysis is based on the company's own characterization of the market and pricing. No independent verification of competitor positioning or market share is available.

Opportunity

Public sources The opportunity for Budget Security is to become the default procurement platform for regulated SMBs and mid-market companies that require regular, affordable penetration testing, capturing a significant share of a multi-billion euro market currently dominated by high-overhead consultancies.

The headline opportunity is the creation of a category-defining, self-serve platform for compliance-driven security testing. The company's positioning is not merely as a cheaper vendor but as a new procurement standard for a specific buyer: technology companies with 20-500 employees that face recurring compliance requirements like NIS2, SOC 2, or Cyber Essentials Plus [Budget Security, September 2026]. The evidence that makes this outcome reachable, rather than purely aspirational, is the clear pricing wedge. The company's own analysis states that traditional consultancies bundle 30-60% overhead for sales and account management into day rates [Budget Security, 2026]. By publishing a transparent day rate starting at €849 and offering a self-serve scoping and booking interface, Budget Security directly attacks this margin structure. If the model proves reliable and scales, it could redefine how a large segment of the market sources a critical, recurring service.

Growth could follow several distinct, concrete paths. The table below outlines two primary scenarios.

Scenario What happens Catalyst Why it's plausible
Compliance Standard-Bearer Budget Security becomes the go-to solution for EU companies preparing for NIS2 audits, embedding its platform into the compliance workflows of thousands of newly regulated entities. The full enforcement of the NIS2 Directive across member states, creating a surge in mandated testing for mid-sized companies [Budget Security, June 2026]. The company has already tailored its messaging and product goals (e.g., "NIS2 audit preparation") to this specific regulatory wave, suggesting a focused go-to-market motion [Budget Security, September 2026].
Platform Expansion The self-serve booking engine and dashboard become an embedded API or marketplace, allowing cloud providers, MSPs, and cybersecurity insurers to resell or integrate pentest services seamlessly. A strategic partnership with a major European cloud provider or a cybersecurity insurance carrier to offer testing as a bundled service. The company's model is built on a standardized, API-friendly service delivery (dashboard-based results) rather than bespoke consulting, making technical integration more feasible than for traditional firms.

Compounding for Budget Security would likely manifest as a data-driven improvement in scoping accuracy and pricing efficiency, creating a classic experience curve advantage. Each completed engagement adds to the dataset used by its AI for test plan generation, potentially allowing the platform to more precisely match tester effort to client assets and goals over time [Budget Security, September 2026]. This improved matching could drive down wasted effort, improve tester utilization, and allow for more competitive pricing or better margins,a flywheel where more volume leads to a better, cheaper product. While there is no public evidence this flywheel is already in motion, the product architecture is designed to enable it.

The size of the win can be framed by looking at the market gap the company identifies. Budget Security cites that traditional penetration testing firms charge between €10,000 and €50,000 or more per engagement [Budget Security, 2026]. For the small business segment it targets, the company estimates its pricing at €849 to €3,500 for a comparable scope where a traditional consultancy might charge €3,000 to €8,000 [Budget Security, 2026]. If Budget Security captured even a single-digit percentage of the European SMB and mid-market compliance testing spend,a market likely measured in hundreds of millions of euros annually,it could support a valuation significantly above the unverified €547,552 figure from Prospeo. A credible scenario, not a forecast, would be the company reaching a scale comparable to a specialized, efficient cybersecurity services platform, which in public markets often trade at revenue multiples between 3x and 6x.

Lightly corroborated -- Opportunity framing relies on company-cited market dynamics and pricing benchmarks; growth scenarios are plausible extrapolations from the company's stated focus, not from independent third-party validation.

Sources

Public sources

  1. [Budget Security, September 2026] About Budget Security: Modern Pentest Platform Built … | https://budgetsecurity.com/about/

  2. [LinkedIn, Retrieved 2026] Bram Verhoeven - Co-Founder and Co-Owner - Budget Security | LinkedIn | https://www.linkedin.com/in/bram-verhoeven-40444212/

  3. [Prospeo] Budget Security Revenue, Funding & Valuation | https://prospeo.io/c/budget-security-revenue

  4. [Budget Security, 2026] Cheap Pentest from €849/Day | Budget Security | https://budgetsecurity.com/blog/cheap-pentest/

  5. [Budget Security, June 2026] NIS2 Penetration Testing Requirements: What the Directive… | https://budgetsecurity.com/blog/nis2-pentest-requirements/

  6. [Budget Security, September 2026] Press Kit: Budget Security | Company Facts & Boilerplate | https://budgetsecurity.com/press-kit/

  7. [Budget Security, September 2026] Contact Us | Budget Security Penetration Testing | https://budgetsecurity.com/contact/

Articles about Budget Security

View on Startuply.vc