Best Breach and Attack Simulation (BAS) Software for Small Business

How Many Breach and Attack Simulation (BAS) Software Products Does G2 Track?

Total Products under this Category: 57

Category Stats (Oct 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Pentera (+0.55%) - Among all products in this category, Pentera recorded the largest rating increase compared to last month

Last updated: October 07, 2026

How Does G2 Rank Breach and Attack Simulation (BAS) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,300+ Authentic Reviews
  • 57+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Breach and Attack Simulation (BAS) Software

G2 Grid® for Breach and Attack Simulation (BAS) Software plotting products by satisfaction and market presence

Highlighted products: Picus Security, Pentera, vPenTest, AI-Native Continuous Offensive Security Platform, Simulations Labs, and Defendify All-In-One Cybersecurity Solution.

Underlying data: [Grid® JSON](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.json?focus%5B%5D=picus-security&focus%5B%5D=pentera&focus%5B%5D=vpentest&focus%5B%5D=ai-native-continuous-offensive-security-platform&focus%5B%5D=simulations-labs&focus%5B%5D=defendify-all-in-one-cybersecurity-solution&segment=small-business)

Picus Security

Picus Security helps organizations continuously validate which exposures attackers can exploit, how far they can reach, and whether security controls can prevent or detect their attacks. The Picus Platform brings together Exposure Validation, Autonomous Penetration Testing, and Breach and Attack Simulation (BAS) in one coordinated program. Each validation method answers a different security question while sharing evidence across assets, exposures, identities, controls, and threats. Exposure Validation determines whether exposures are exploitable across affected assets, helping security teams prioritize remediation based on validated exploitability rather than vulnerability severity alone. Autonomous Penetration Testing chains real exploits from initial access through privilege escalation and lateral movement to uncover exploitable vulnerabilities and validate attack paths to critical assets. Breach and Attack Simulation safely runs real attacker techniques against live security controls to show whether attacks are prevented, detected, or missed. Instead of creating separate findings and priorities for each testing method, Picus uses a shared findings model that is deduplicated, evidence-backed, and asset-aware. This gives security teams shared context and a prioritized backlog for remediation and revalidation. Numi AI and Picus Swarm add an agentic layer across the platform. Specialist agents support discovery, exploitation, validation, mobilization, and reporting workflows. Organizations can run workflows on demand, under human supervision, or autonomously, with decision gates and audit trails that keep teams in control. Picus helps security teams move from scheduled security testing toward change-driven validation, so emerging vulnerabilities, new attack campaigns, security control changes, and infrastructure changes can trigger the right validation method. Teams can use the resulting evidence to prioritize proven risk, remediate or mitigate findings, and revalidate fixes.

Average Rating: 4.8/5.0

Total Reviews: 229

Who Is the Company Behind Picus Security?

  • Seller: Picus Security
  • Company Website:
  • Year Founded: 2013
  • HQ Location: San Francisco, California
  • Twitter: @PicusSecurity
    2,916 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    317 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Cyber Security Specialist, Cyber Security Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Large, 37% Medium

What Do G2 Reviewers Say About Picus Security?

AI-generated summary from verified user reviews

Pros
  • Users commend Picus Security for its realistic attack simulations that enhance defenses and confidence in cybersecurity resilience.
  • Users find Picus Security incredibly easy to use, ensuring rapid identification of security gaps with professional support.
  • Users commend Picus Security for its continuous proactive validation of security controls, enhancing defense and resilience against attacks.
  • Users highlight the actionable insights from Picus Security, enhancing defense optimization and improving overall security posture.
  • Users value the seamless integration with existing tools, enhancing security through tailored recommendations and real-time updates.
Cons
  • Users experience reporting limitations with Picus Security, leading to extra work in finalizing reports and occasional issues.
  • Users experience integration issues, particularly with third-party tools, impacting the initial setup and validation process.
  • Users find the steep learning curve of Picus Security challenging, requiring time and training for effective utilization.
  • Users find the complex setup process of Picus Security to be challenging, requiring extra configuration effort initially.
  • Users find the limited customization in Picus Security's reports and dashboards restrictive for their specific needs.

What Are Recent G2 Reviews of Picus Security?

What Are G2 Users Discussing About Picus Security?

Pentera

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

Average Rating: 4.6/5.0

Total Reviews: 187

Who Is the Company Behind Pentera?

  • Seller: Pentera
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Boston, MA
  • Twitter: @penterasec
    3,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    460 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Government Administration, Banking
  • Company Size: 52% Large, 34% Medium

What Do G2 Reviewers Say About Pentera?

AI-generated summary from verified user reviews

Pros
  • Users find Pentera's ease of use exceptional, thanks to its automation, customizable scenarios, and simple interface.
  • Users value the effective vulnerability scanning and remediation capabilities of Pentera, enhancing overall security posture.
  • Users value the automation capabilities of Pentera, enhancing their security testing and validation processes efficiently.
  • Users value the responsive customer support from Pentera, enhancing their experience and facilitating smooth operations.
  • Users value the realistic attack simulations offered by Pentera, enhancing their security posture through continuous validation.
Cons
  • Users find the reporting inadequate, suggesting it requires improvement for better enterprise-level insights.
  • Users express concern about the lack of a robust RBAC system, limiting proper access control and user rights management.
  • Users desire improvement in handling false positives, though overall satisfaction with Pentera remains high.
  • Users note the limited reporting capabilities of Pentera, especially for enterprise-level assessments and lacking Spanish translation.
  • Users are concerned about the missing features in Pentera, including updates on vulnerabilities and insufficient RBAC options.

What Are Recent G2 Reviews of Pentera?

vPenTest

Vonahi Security is building the future of offensive cybersecurity by delivering automated, high-quality penetration testing through its SaaS platform, vPenTest. Designed to replicate the tools, techniques, and methodologies of experienced consultants, vPenTest brings the benefits of manual network penetration testing into an easy-to-use, automated solution. Traditionally, penetration testing has been a manual, time consuming, and expensive process that many organizations only perform once or twice a year. This often leaves businesses exposed to emerging threats between assessments. vPenTest addresses this gap by offering fast, consistent, and on-demand testing that helps organizations evaluate their real-time cybersecurity risk more effectively. Powered by a proprietary framework that evolves through continuous research and real-world insights, vPenTest stays aligned with the latest attack techniques and industry best practices. The platform is backed by over 13 years of offensive security expertise, with the team holding certifications such as CISSP, OSCP, OSCE, CEH, and more. Their knowledge is built directly into the platform, ensuring each test is conducted with depth, consistency, and accuracy—without the delays or variability of manual testing.
 vPenTest enables organizations to run internal and external network penetration tests as often as needed monthly, quarterly, or prior to audits or insurance reviews. The automated reports provide actionable insights that make it easy to prioritize remediation and demonstrate progress toward compliance. Today, over 22,000 organizations rely on vPenTest to strengthen their security posture and reduce risk. This includes managed service providers, managed security service providers, financial institutions, compliance-driven organizations, and internal IT teams. Whether you're working to meet regulatory requirements, secure cyber insurance coverage, or proactively defend against evolving threats, vPenTest makes network penetration testing easy, affordable, and scalable.

Average Rating: 4.6/5.0

Total Reviews: 245

Who Is the Company Behind vPenTest?

  • Seller: Kaseya
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Miami, FL
  • Twitter: @KaseyaCorp
    17,411 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,483 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 69% Small, 24% Medium

What Do G2 Reviewers Say About vPenTest?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of vPenTest, praising its intuitive interface and smooth setup process.
  • Users praise the detailed and reliable technical reports from vPenTest, enhancing their remediation efforts effectively.
  • Users appreciate the user-friendly interface of vPenTest, enhancing their efficiency in conducting penetration tests.
  • Users commend the easy setup of vPenTest, finding it a smooth experience for managing security solutions effectively.
  • Users highlight the ease of implementation of vPenTest, appreciating its quick setup and seamless integration into workflows.
Cons
  • Users find the limited scope of vPenTest frustrating, as it doesn't cover all necessary pentesting aspects.
  • Users find the setup process complex, highlighting challenges with initial configuration and integration with existing systems.
  • Users find the lack of detail in vPenTest confusing, complicating communication and understanding of findings.
  • Users find the inadequate reporting of vPenTest restricts customization and leads to repetitive findings over time.
  • Users find vPenTest to be expensive, especially for smaller organizations facing pricing and contract challenges.

What Are Recent G2 Reviews of vPenTest?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

AI-Native Continuous Offensive Security Platform

RidgeBot by Ridge Security is a leading agentic AI-driven offensive security platform, supporting continuous threat management programs. It enables CISOs to minimize cyber risks by continuously validating the cybersecurity posture and controls protecting attack surfaces against increasingly sophisticated and frequent attacks. RidgeBot automatically tests an organization’s entire IP-based environment, including network infrastructure, applications, websites, IoT, and OT, using ethical hacking techniques to pinpoint the most critical vulnerabilities. It's dynamic AI-powered decision-making supports DevSecOps, compliance, incident response verification, and custom attack simulations. RidgeBot maintains a library of over 36,000 plugins to launch complex penetration tests and attack simulations, with detailed reporting of results and remediation recommendations.

Average Rating: 4.5/5.0

Total Reviews: 98

Who Is the Company Behind AI-Native Continuous Offensive Security Platform?

  • Seller: Ridge Security Technology
  • Company Website:
  • Year Founded: 2020
  • HQ Location: Santa Clara, California
  • Twitter: @RidgeSecurityAI
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    49 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Small, 45% Medium

What Do G2 Reviewers Say About AI-Native Continuous Offensive Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the automation capabilities of RidgeBot, streamlining penetration testing and providing accurate vulnerability assessments efficiently.
  • Users appreciate the ease of use of the AI-Native Continuous Offensive Security Platform for streamlined penetration testing.
  • Users commend the pentesting efficiency of RidgeBot, automating tests and validating vulnerabilities seamlessly to save time.
  • Users appreciate the automated vulnerability identification of RidgeBot, which effectively validates risks and streamlines security processes.
  • Users value the efficiency of RidgeBot, as it automates testing to save time and enhance security processes.
Cons
  • Users find RidgeBot's setup to be complex and challenging, particularly in customized or legacy system environments.
  • Users find the complex setup challenging, especially due to limited documentation and support for new admins.
  • Users find the missing features such as improved API testing and customizable reporting templates quite limiting.
  • Users find the poor customer support challenging, as documentation is often lacking for troubleshooting issues.
  • Users find the poor documentation challenging, making initial setup and onboarding confusing for new admins.

What Are Recent G2 Reviews of AI-Native Continuous Offensive Security Platform?

Simulations Labs

Simulations Labs is an ai-powered platform that enables organizations, educators, and security teams to create realistic, reusable, and scalable hands-on cybersecurity simulations—without complex setup or infrastructure. Fully Managed Hosting Without Infrastructure Overhead Organizations run CTFs and simulations without DevOps, server setup, or maintenance. No Worries About Attacks or Server Downtime Simulations Labs automatically manages security, monitoring, and uptime, even during large-scale events. Organizers don’t need to worry about servers being attacked, crashing, or going offline. Custom Simulation Creation with Dashboard Simulations Labs offers a dashboard that allows organizers to create and manage fully custom simulations. Each simulation provisions isolated environments for participants, supports web application challenges, and can include dynamic flags to prevent cheating AI-Powered Challenge Creation Unlike traditional platforms that require technical expertise, our AI-powered tools enable non-technical users to create simulations and challenges quickly and easily.

Average Rating: 4.8/5.0

Total Reviews: 10

Who Is the Company Behind Simulations Labs?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Simulations Labs?

Defendify All-In-One Cybersecurity Solution

Founded in 2017, Defendify is pioneering All-In-One Cybersecurity® for organizations with growing security needs, backed by experts offering ongoing guidance and support. Delivering multiple layers of protection, Defendify provides an all-in-one, easy-to-use platform designed to strengthen cybersecurity across people, process, and technology, continuously. With Defendify, organizations streamline cybersecurity assessments, testing, policies, training, detection, response & containment in one consolidated and cost-effective cybersecurity solution. 3 layers, 13 solutions, 1 platform, including: • Managed Detection & Response • Cyber Incident Response Plan • Cybersecurity Threat Alerts • Phishing Simulations • Cybersecurity Awareness Training • Cybersecurity Awareness Videos • Cybersecurity Awareness Posters & Graphics • Technology Acceptable Use Policy • Cybersecurity Risk Assessments • Penetration Testing • Vulnerability Scanning • Compromised Password Scanning • Website Security Scanning See Defendify in action at www.defendify.com.

Average Rating: 4.7/5.0

Total Reviews: 57

Who Is the Company Behind Defendify All-In-One Cybersecurity Solution?

  • Seller: Defendify
  • Year Founded: 2017
  • HQ Location: Portland, Maine
  • Twitter: @defendify
    305 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    38 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 65% Small, 35% Medium

What Do G2 Reviewers Say About Defendify All-In-One Cybersecurity Solution?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Defendify, streamlining cybersecurity management for small and medium-sized businesses.
  • Users praise Defendify for its comprehensive and cost-effective cybersecurity features, streamlining management for small to medium-sized businesses.
  • Users appreciate the easy setup of Defendify, finding it quick and simple for effective cybersecurity management.
  • Users value the ease of use of Defendify, appreciating quick setup and actionable insights for cybersecurity management.
  • Users value the continuous monitoring features of Defendify, easing the burden of network security management significantly.
Cons
  • Users note that inadequate reporting hinders effective communication, calling for improvements in clarity and detail.
  • Users feel that the poor reporting features hinder effective communication and internal analysis of cybersecurity efforts.
  • Users express frustration over the lack of concise information in reports, preferring clearer and more detailed summaries.
  • Users find the limited customization options restrictive, wishing for more personalized reporting and branding capabilities.
  • Users desire custom reporting options and co-branding features to enhance the personalization of their experience.

What Are Recent G2 Reviews of Defendify All-In-One Cybersecurity Solution?

What Are G2 Users Discussing About Defendify All-In-One Cybersecurity Solution?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated