Halcyon

Halcyon is a private cybersecurity company focused exclusively on defeating ransomware. Founded in 2021, it built its business around a dedicated anti-ransomware platform rather than a broad, general-purpose security stack. Its approach combines prevention, detection, expert-led response, and recovery support to help organizations avoid ransom payments, reduce operational disruption, and maintain business continuity.

Halcyon’s core value proposition centers on stopping ransomware across the full attack chain, including pre-execution activity, data exfiltration, and encryption. The company pairs its software with a 24/7 Ransomware Operations Center and a recovery-backed warranty, positioning itself as a purpose-built option for organizations that want ransomware-specific resilience without replacing the rest of their security environment.

Offerings, Capabilities, and Integrations

Halcyon delivers layered ransomware defense designed to detect and disrupt attacker behavior early, limit the impact of active attacks, and support rapid recovery if encryption occurs. Its offering spans endpoint-focused prevention, protection against data theft and extortion, anti-tamper controls for security tooling, and expert-led monitoring and response. The platform is designed to complement existing security investments rather than force a wholesale stack replacement.

Halcyon integrates into established security environments. It is positioned to work alongside common EDR tools such as Microsoft Defender, CrowdStrike Falcon, SentinelOne Singularity, and Palo Alto Cortex XDR, and it is also used with backup platforms from providers including Veeam, Cohesity, Acronis, and Commvault. For operations teams, Halcyon supports alert streaming into SIEM, SOAR, and XDR environments through its API, with customer workflows spanning platforms such as Microsoft Sentinel, Google SecOps, Splunk, Sumo Logic, and Exabeam.

Products and Services

  • Halcyon Anti-Ransomware Platform: Halcyon’s flagship platform for preventing ransomware, disrupting attacker activity, stopping data extortion attempts, and supporting recovery from encryption events across the ransomware attack chain.
  • Halcyon Ransomware Operations Center (ROC): A 24/7 expert-led ransomware operations service that investigates alerts, responds to threats, and helps lead recovery efforts for Halcyon customers.
  • The Halcyon Ransomware Warranty: A services-backed warranty that provides incident response and recovery support when a covered ransomware incident bypasses defenses.
  • Emergency Ransomware Recovery: A professional service that mobilizes Halcyon and incident response partners to contain active ransomware attacks, accelerate recovery, and reduce the risk of reinfection.
  • Data Exfiltration Protection (DXP): A capability focused on detecting and interrupting suspicious data movement associated with exfiltration and double-extortion tactics.
  • Encryption Detection + Key Capture: A recovery-oriented capability that captures encryption keys and related cryptographic material during an attack so encrypted data can be decrypted and restored more quickly.
  • Halcyon Greenlight Containment and Eradication Service: A ransomware-focused containment and eradication service delivered with incident response partners to help stabilize environments, remove adversaries, and support clean recovery paths.
  • Halcyon for Microsoft Sentinel (Preview): A Microsoft marketplace offering for Azure environments that extends Halcyon ransomware defense into Microsoft Sentinel-centered security workflows.

Target Customers

Halcyon targets organizations that face meaningful operational, financial, or regulatory exposure from ransomware. Its core focus is on mid-market and enterprise customers, while its messaging and packaging also address smaller organizations that need ransomware-specific protection without the staffing or budget burden of a large in-house security program.

The company serves a broad mix of industries where downtime and data extortion can be especially damaging, including education, energy, federal, finance, government, healthcare, manufacturing, retail, technology, telecommunications, and transportation. Halcyon also courts MSSPs and MSPs that want to add dedicated anti-ransomware protection to managed security offerings, as well as incident response partners that need specialized ransomware containment and recovery capabilities.

Cloud Integrations and Marketplace

  • AWS Marketplace: Halcyon Anti-Ransomware Platform is available in AWS Marketplace as a SaaS offering deployed on AWS.
  • Microsoft Azure Marketplace: Halcyon Anti-Ransomware Platform is listed in Microsoft Azure Marketplace, and Halcyon also has a Microsoft marketplace app for Microsoft Sentinel in preview.

Key People

  • Aaron Mick: COO & Interim CEO
  • Scott Stout: President
  • Jon Miller: Chief Scientist & Co-Founder
  • Ryan Smith: CTO & Co-Founder
  • Jeff St. Clair: Chief Revenue Officer
  • Jeff Williams: Chief Growth Officer
  • Kris Lamb: Chief Product Officer
  • Oliver Newbury: Chief Strategy Officer
  • Tom Lee: Chief Information Officer
  • Ryan Schultz: Chief Customer Officer
  • Clark Lindsey: Chief Architect
  • Mitch Plonski: President of Strategic Growth and Public Sector

Key Facts

  • Headquarters: San Diego, California, United States
  • Employees: Approximately 292
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: Private
Halcyon

Enter a search