Skip to main content

A-LIGN Acquires Pathfynder to Add Offensive Security to Compliance Suite

Tampa – September 07, 2026 -- A-LIGN, a cybersecurity compliance firm serving more than 6,400 organizations worldwide, has acquired offensive and defensive security specialist Pathfynder, extending its portfolio beyond audits into penetration testing and adversary emulation.

A-LIGN adds veteran-owned offensive security team to its compliance business

Pathfynder, a veteran-owned firm, employs specialists with military and intelligence community backgrounds delivering network, cloud, and web application penetration testing, red team operations, adversary emulation, and forensics and incident response services.

Pathfynder will operate under its own brand while staying independent from A-LIGN's assessment practice

The unit will retain its identity as "Pathfynder by A-LIGN," with A-LIGN structuring the deal to keep Pathfynder's penetration testers operationally separate from its assurance and assessment teams, preserving the integrity of both functions.

Scott Price, CEO of A-LIGN, said the acquisition lets the company deliver offensive security services through a team that operates independently of its compliance practice while still applying institutional knowledge of existing clients.

Deal targets enterprises facing AI-accelerated cyberattacks that compliance checks alone cannot stop

A-LIGN has completed more than 36,000 audits and holds the position of top issuer of SOC 2 reports, alongside ranking among the top three FedRAMP assessors. The company frames the acquisition as a response to a threat landscape it describes as increasingly costly and AI-accelerated, arguing that compliance frameworks alone no longer verify whether an organization's defenses can withstand real adversaries.

For A-LIGN's existing customer base, the deal is positioned as giving direct access to offensive security testing without adding a separate vendor relationship. DJ Fuller, founder of Pathfynder, said the combined team shares a mission of helping companies close security gaps and meet regulatory requirements to reduce financial and reputational damage from cyberattacks.

Published by
fairsonline_team
Company