Who We Are
Relentless in Mission. Realistic in Practice. Resilient by Design.
The leading platform for Adversarial Exposure Validation (AEV)
We help security teams make better decisions by continuously measuring how adversaries can exploit gaps across people, processes, and technology.
Our platform goes beyond testing individual controls. We deliver the insight needed to prioritize exposures, validate safeguards, and guide strategy — so you can move from reactive response to proactive readiness.
Whether you’re a Fortune 500 enterprise, a federal agency, or an MSSP, we help you operationalize threat-informed defense and prove resilience at scale.
Our Story
From Testing to Decision Support. From Validation to Exposure Management.
Founded in 2014, AttackIQ pioneered the Breach and Attack Simulation (BAS) category with the industry’s first commercial platform. But as adversaries evolved, so did we.
Today, we lead the market in Adversarial Exposure Validation (AEV), providing automated, production-safe testing aligned with the MITRE ATT&CK® framework and built to support Continuous Threat Exposure Management (CTEM).
We’ve moved beyond security control validation to deliver complete exposure management. Our platform helps organizations understand how attackers move, where defenses fail, and which exposures matter most. The result is smarter, faster, and more risk-informed decision-making.
Security teams trust AttackIQ to:
- Continuously test controls across hybrid and cloud environments
- Emulate adversaries to surface real attack paths
- Validate compensating controls and security coverage
- Prioritize and reduce exposure with confidence
Our Mission
To Make the World Safe for Compute
Software powers our society, from critical infrastructure and global finance to the mobile devices we use every day. But as our digital footprint expands, so does our attack surface.
Attackers exploit the gap between how security is supposed to work and how it actually performs in production. That’s why we focus on validating not just vulnerabilities, but how adversaries move through real environments—and whether your controls, configurations, and compensating safeguards actually stop them.
By aligning security with real-world threats, we help ensure the systems we rely on remain secure, resilient, and trustworthy.
Our Vision
Turn Security Into a Strategic Advantage
Most organizations treat cybersecurity as a reactive cost center. We’re changing that.
AttackIQ empowers security teams to transform their programs into proactive, data-driven enablers of business resilience.
We envision a world where security is:
- Planned and engineered, not ad hoc and reactive
- Continuously tested, not assumed
- Based on data, not guesswork
- A business enabler, not a source of fear
We help teams move:
- From open-loop assumptions → to closed-loop validation
- From manual guesswork → to automated evidence
- From siloed tools → to unified operations
- From fear-driven decisions → to threat-informed strategy
AttackIQ Core Values
One Team
We win together with urgency, honesty, and shared purpose.
Impress Every Customer
Exceed expectations every time. Listen deeply. Deliver real value.
Do the Right Thing
Act with integrity, even when no one’s watching.
Innovate With Purpose
Challenge norms. Push boundaries. Raise the bar for cybersecurity.
Operate with Transparency
Own mistakes, share information, and celebrate wins.
People First
Support the whole person with flexibility, wellness, and trust.
AttackIQ Leadership Team
We’re guided by industry veterans and co-founders who understand both the complexity of cyber threats and the realities of enterprise operations.
Brett Galloway
CEO
Brett has more than 30 years of executive and entrepreneurial experience in the technology industry. He has brought together technology, product, and business expertise to innovate and deliver a stream of successful product businesses. Most recently he co-founded Mist Systems and served as its Chairman before its sale to Juniper. He is the former president and CEO of Airespace, which he sold to Cisco. He served at Cisco as the Senior Vice President of the Network Services Group and Enterprise Strategy. Prior to Airespace, he was the co-founder, chief operating officer, and later CEO of Packeteer, which launched an initial public offering (IPO) in 1999. Brett holds Bachelor and Master of Science degrees in electrical engineering from Stanford University.
Stephan Chenette
Co-Founder and CTO
Stephan is the Founder and CTO of AttackIQ where he led the company, product, and vision for the first 5 years and today focuses on customer success and influencing the technology vision. He is a 20-year veteran of information security, servicing clients ranging from startups to multinational corporations as a researcher, security and risk consultant, solutions architect, and technical leader and executive. He has presented at numerous conferences including RSA, Black Hat, ATT&CKCon, EkoParty, ToorCon, BSides, CanSecWest, RECon, AusCERT, SecTor, SOURCE, and PacSec.
Rajesh Sharma
Co-Founder and Chief Software Architect
Rajesh has more than 20 years of experience in the security industry. He has served as Principal Engineer and Software Architect at various companies; where he developed key kernel components used in numerous security products.
George Tomic
Cheif Development Officer
George Tomic joins AttackIQ having served in senior roles at Trustwave and McAfee where he led security platform and product development activities.
Carl Wright
Cheif Commercial Officer
Carl is a seasoned entrepreneur and executive with experience in the security, storage, virtualization, and software sectors. He has held executive operational roles and has extensive experience in all aspects of enterprise information technology deployments.
Eric Yeaman
Cheif Financial Officer
Eric is Chief Financial Officer at AttackIQ and brings extensive experience in finance and executive leadership across the technology industry.
Pete Luban
Field Chief Information Security Officer
Pete has nearly 30 years experience in infrastructure architecture, cybersecurity engineering, and risk management acquired through various roles at many well-known organizations.
Eric Woerner
Vice President, Platform Architecture and Engineering
Eric brings nearly two decades of experience in software engineering and architecture, focusing on building secure, scalable cloud platforms.
Jose Barajas
Vice President, Worldwide Sales Engineering
Jose has over a decade of experience as a security researcher and is now focused on improving security control efficacy at AttackIQ.
Brandt Mackey
Vice President, Field Engineering
Brandt has a strong technical background and a successful history at technology start-up companies.
Rob Stitch
Vice President, Product
Rob focuses on driving new growth and optimizing product value through strategic partnerships and innovative features.
Jon Baker
Vice President, Threat-Informed Defense
Jon brings over 20 years of experience leading innovation in cybersecurity, focusing on making security more efficient and effective at scale.
Paul Reid
Vice President, Adversary Research
Paul studies real-world adversaries and translates their tactics into practical, testable defenses.
Jeffrey Rogers
Vice President, Customer Success
Jeffrey has a career dedicated to helping organizations maximize the value of their security investments.
Maarten Kok
Vice President, EMEA & Global Channel
Maarten brings more than 20 years of experience in cybersecurity sales and leadership.
Our Investors
We’re backed by leading investors who understand the critical role cybersecurity plays in global resilience and who believe in our mission to make the world safe for compute.