# Leviathan Security Group > Official Leviathan Security Group business agent. Leviathan Security Group provides penetration testing, security assessments, hardware and IoT security… ## Ask it a question Leviathan Security Group answers for itself at https://api.hailera.com/mcp/leviathansecurity. A client that speaks MCP can connect to that address; the tool is ask_leviathansecurity and the protocol is 2026-07-28. Where this file and the agent disagree, the agent is current. ## About Leviathan Security Group Leviathan Security Group is a cybersecurity consulting firm focused on helping organizations execute their security vision across products, services, and platforms. Background - Founded in 2006 by industry leaders with deep security expertise. - Headquartered in the Seattle, Washington area. - Employs an elite group of consultants across the United States and internationally. Approach and mission - Uses a structured methodology to help clients improve processes and advance their security maturity. - Focuses on supporting innovators and ensuring that they use safe security practices. - Emphasizes superior customer experience and satisfaction, taking a thorough approach to clients' security objectives. Team and expertise Leviathan hires experienced security professionals who: - Speak at conferences worldwide. - Write open source security software. - Conduct advanced security research. - Contribute to security standards, industry podcasts, and review boards. Leadership Leviathan's leadership team includes roles such as: - Senior Managing Director - Managing Directors - Directors overseeing operations, project management, and vendor security assessment practices Specific names and roles may change over time; refer to the website's leadership section for the latest information. Source: https://www.leviathansecurity.com ## What Leviathan Security Group does Leviathan Security Group provides cybersecurity consulting and assessment services for enterprises and other organizations that rely on complex digital systems. Core service areas - Application and network penetration testing - Risk advisory and virtual CISO (vCISO) services - Hardware, IoT, and smart device security testing - Vendor security management and third-party risk Typical clients and focus - Large enterprises and technology companies - Organizations that operate web applications, connected devices, and cloud environments - Businesses that need independent security testing, advisory support, and help building or improving security programs. Leviathan Security Group provides risk advisory services to help organizations build and mature their security programs. Core risk advisory offerings - Virtual CISO (vCISO) services to provide executive-level security leadership and guidance. - Tabletop exercises to rehearse responses to security incidents and improve organizational readiness. - Audit preparation support to help teams prepare for security and compliance assessments. - Policy and gap analysis to identify weaknesses in existing security policies, standards, and processes. Objectives - Establish and refine security strategy aligned with business goals. - Improve organizational resilience to cyber threats. - Support compliance with relevant security and privacy requirements. - Provide expert guidance without requiring a full-time in-house CISO. Leviathan Security Group helps organizations manage cybersecurity, compliance, and operational risks associated with third-party vendors. How Leviathan supports vendor security programs Leviathan can help organizations: - Create third-party security policies. - Establish and structure a third-party security program. - Discover and maintain an inventory of vendors. - Prepare vendor assessment questionnaires based on trusted cybersecurity frameworks. - Assess vendors' security posture and track vulnerabilities and issues across the vendor ecosystem. - Share mitigation strategies with clients and their vendors. - Review compliance reports from vendors. - Conduct ongoing follow-up with vendors to support continuous improvement. Risk areas addressed Vendor security management services consider a wide range of risk domains, including: - Business and contractual controls - Security awareness and training - Regulatory and compliance obligations - Incident and change management - Operational and technology risk - Third-party security and privacy requirements (including data protection laws such as GDPR) - Physical, network, endpoint, and server security controls These services are intended to reduce the likelihood and impact of vendor-related security incidents, protect sensitive data, and support regulatory and contractual compliance. Source: https://www.leviathansecurity.com ## Where Leviathan Security Group works How to contact Leviathan Security Group Organizations interested in Leviathan's penetration testing, vendor security, risk advisory, or other cybersecurity services can reach out using the contact form on the website or by phone. - Phone: 888-297-9872 - Fax: 206-260-1464 A general contact form is available on the website to request information about services such as penetration testing, vendor security management, and risk and advisory services. Mailing address Leviathan Security Group, Inc. 631 Strander Blvd Suite A2 Tukwila, WA 98188 Lists Seattle and Tukwila as a location. Names Washington and United States as a service area. Areas beyond these are not published. Source: https://www.leviathansecurity.com ## Application and Network Penetration Testing Services Leviathan Security Group performs in-depth application and network penetration testing to identify security vulnerabilities before attackers can exploit them. Web application penetration testing Leviathan approaches web application security testing from the perspective of real-world attackers, using artisanal, manually crafted attack techniques rather than relying solely on automated scanners. Key characteristics of Leviathan's web application penetration testing include: - Artisanal attack philosophy: tests are tailored to the specific application and business context. - Manual-first approach: security engineers manually probe applications to uncover deeper and more complex vulnerabilities. - Alignment with industry standards: testing is aligned with respected testing standards, including the OWASP Top 10, to address the most critical web application risks. Methodology highlights Leviathan's penetration testing methodology typically includes: - Comprehensive mapping of the application's attack surface, including entry points and architecture. - Analysis of configurations, technologies, and operational practices that affect security. - A blend of manual and automated techniques, including proprietary tools, to identify a wide range of vulnerabilities. - Prioritization of findings based on likelihood of exploitation and potential business impact. Outcomes for clients - Clear reporting that focuses on meaningful, actionable issues rather than noise. - Tactical and strategic remediation recommendations that support rapid, secure software development. - A collaborative engagement between Leviathan's experts and client teams to improve the security of critical applications and supporting infrastructure. Source: https://www.leviathansecurity.com ## Hardware, IoT, and Smart Device Security Testing Leviathan Security Group provides hardware security and penetration testing services for connected and embedded technologies. Types of systems assessed - Internet of Things (IoT) devices - Smart devices and appliances - Premarket and connected medical technologies - Virtual and connected devices used in modern environments Focus of hardware and device security assessments - Identifying vulnerabilities that could affect the safety, privacy, or reliability of devices. - Evaluating how devices interact with cloud services, mobile apps, and networks. - Providing practical recommendations to strengthen device and ecosystem security. These services are designed to help organizations bring innovative products to market with stronger security controls and greater confidence. Source: https://www.leviathansecurity.com ## What Leviathan Security Group has not published yet These are things people ask Leviathan Security Group that its published information does not yet cover. - prices - availability - delivery times or project timelines - service guarantees or outcomes - regulatory or legal compliance commitments - data breach liability or insurance coverage Ask anyway — the agent will say plainly that it is not published rather than guess. ## Where this comes from https://www.leviathansecurity.com