A-LIGN has acquired Pathfynder, a specialized offensive and defensive cybersecurity firm, expanding its services for enterprises looking to strengthen their security posture and reduce the risk of cyberattacks.
The acquisition comes as enterprises face a costly and fast-moving threat landscape accelerated by artificial intelligence. A-LIGN said compliance alone is no longer enough as attackers become more sophisticated and persistent, requiring organizations to assess whether their defenses can withstand real-world adversaries.
Pathfynder is a veteran-owned company whose team includes cybersecurity, military and intelligence community specialists with decades of experience. Its technical offensive and defensive cybersecurity services include network, cloud and web application penetration testing, red team and adversary emulation, testing of complex and emerging capabilities and forensics and incident response.
“Since our inception, A-LIGN has believed in the power of combined compliance and technical cybersecurity services under one roof,” said Scott Price, CEO of A-LIGN. “The acquisition of Pathfynder enables A-LIGN to offer customers advanced offensive security services delivered by a team that operates independently from our assurance and assessment practice while leveraging institutional knowledge of the customer to enhance the cybersecurity services.”
Pathfynder will operate under the A-LIGN parent brand as Pathfynder by A-LIGN while maintaining its specialized team and brand. According to A-LIGN, the structure will preserve independence between its assurance and assessment teams and Pathfynder’s penetration testers to protect the integrity of both functions.
A-LIGN’s more than 6,400 existing customers will also gain access to advanced security testing from the company without having to manage another vendor relationship.
“We are excited to join the A-LIGN team and bring our trusted expertise and proven capabilities to their existing suite of services,” said DJ Fuller, founder of Pathfynder. “We share the same core values and mission: helping companies close security gaps and meet regulatory requirements, so they can reduce the risk of financial and reputational damage from a cyberattack.”
