Cold email software for cybersecurity firms
Acqro gives cybersecurity and IT security firms cold email that researches each prospect's company before writing. Below: verified federal data on the industry across all 50 states, the buyers it sells to, and a playbook for outreach that earns replies.
Onboarding in batches. No credit card to join.
How many cybersecurity firms are in the United States?
The United States had 13,275 establishments in NAICS 541519, other computer related services, in 2023, employing 168,654 people. The largest markets by establishments were California, Florida and Virginia. Source: U.S. Census Bureau County Business Patterns.
Cybersecurity firms in the US by the numbers
- US establishments
- 13,275+10.7% vs 2022Census CBP 2023, NAICS 541519
- Paid employees
- 168,654Census CBP 2023
- Average annual pay
- $123,684Census CBP 2023
- Firms under 10 employees
- 85.6%Census CBP 2023
- Largest state
- CaliforniaBy establishments, CBP 2023
Census does not publish a separate category for cybersecurity and IT security firms; figures use NAICS 541519, Other Computer Related Services, the closest official industry. 85.6% of establishments have fewer than 10 employees, so most firms in the industry run outbound with a founder or a very small sales team. The 1,787 firms with 10 to 249 employees are the ones most likely to be building a repeatable outbound process.
The five largest states hold 40.0% of all establishments. Among states with at least 100 establishments, the fastest growth between 2022 and 2023 was in Delaware (+57.3%), Connecticut (+38.8%) and Colorado (+25.8%). Growing markets bring new competitors and new buyers at the same time, which rewards outreach that is specific rather than volume-driven.
Cybersecurity firms by state
All states and DC ranked by number of establishments, with the change since 2022.
| Rank | State | Establishments | Employees | Change vs 2022 |
|---|---|---|---|---|
| 1 | California | 1,524 | 17,057 | +19.8% |
| 2 | Florida | 1,276 | 12,126 | +13.2% |
| 3 | Virginia | 1,036 | 21,148 | +2.8% |
| 4 | Texas | 769 | 13,414 | +14.4% |
| 5 | New York | 706 | 7,339 | +10.1% |
| 6 | Illinois | 631 | 4,956 | +1.1% |
| 7 | New Jersey | 614 | 5,457 | +2.7% |
| 8 | Georgia | 546 | 6,884 | +9.9% |
| 9 | Pennsylvania | 535 | 4,505 | +13.1% |
| 10 | Maryland | 488 | 6,028 | +15.1% |
| 11 | Massachusetts | 391 | 4,687 | +2.6% |
| 12 | Minnesota | 385 | 2,054 | +4.3% |
| 13 | Michigan | 383 | 8,111 | +10.1% |
| 14 | Washington | 337 | 3,388 | +2.7% |
| 15 | Colorado | 312 | 5,620 | +25.8% |
| 16 | Arizona | 267 | 4,380 | +6.4% |
| 17 | North Carolina | 255 | 4,707 | +22.6% |
| 18 | Ohio | 242 | 4,584 | +21.6% |
| 19 | South Carolina | 196 | 1,510 | +6.5% |
| 20 | Oklahoma | 180 | 1,401 | +10.4% |
| 21 | Delaware | 173 | 2,329 | +57.3% |
| 22 | Utah | 161 | 1,524 | −2.4% |
| 23 | Nevada | 139 | 611 | +7.8% |
| 24 | Indiana | 129 | 1,527 | +18.3% |
| 25 | Missouri | 125 | 1,252 | +3.3% |
| 26 | Connecticut | 118 | 949 | +38.8% |
| 27 | Oregon | 118 | 956 | +9.3% |
| 28 | Wisconsin | 111 | 2,276 | −1.8% |
| 29 | Tennessee | 110 | 4,516 | +19.6% |
| 30 | Louisiana | 98 | 881 | +5.4% |
| 31 | Kentucky | 95 | 1,039 | +23.4% |
| 32 | District of Columbia | 93 | 932 | −19.8% |
| 33 | Idaho | 80 | 467 | 0.0% |
| 34 | Kansas | 76 | 2,988 | +8.6% |
| 35 | Alabama | 62 | 691 | −4.6% |
| 36 | Nebraska | 51 | 1,177 | +15.9% |
| 37 | Wyoming | 50 | 142 | +13.6% |
| 38 | New Hampshire | 48 | 544 | 0.0% |
| 39 | Arkansas | 47 | 380 | +27.0% |
| 40 | Iowa | 42 | 1,063 | +10.5% |
| 41 | New Mexico | 35 | — | −7.9% |
| 42 | Hawaii | 30 | 123 | +25.0% |
| 43 | Montana | 30 | — | 0.0% |
| 44 | Rhode Island | 30 | 319 | +30.4% |
| 45 | South Dakota | 30 | — | +50.0% |
| 46 | Mississippi | 27 | 124 | +35.0% |
| 47 | Maine | 23 | 1,131 | +35.3% |
| 48 | Alaska | 21 | 188 | +5.0% |
| 49 | Vermont | 21 | 116 | +5.0% |
| 50 | West Virginia | 17 | 155 | +21.4% |
| 51 | North Dakota | 12 | — | +200.0% |
Who cybersecurity firms sell to
Common buyer industries for cybersecurity and IT security firms, with US establishment counts and how many have 10 to 249 employees.
| Buyer industry | Establishments | 10–249 employees | Employees |
|---|---|---|---|
| Depository Credit Intermediation | 108,792 | 33,938 | 2,072,993 |
| Offices of Physicians | 218,066 | 58,939 | 2,771,935 |
| Legal Services | 181,092 | 23,511 | 1,190,297 |
| Data Processing, Hosting, and Related Services | 18,544 | 5,338 | 629,527 |
How cybersecurity firms should run cold email
Cybersecurity and IT security firms sell security assessments, managed detection, compliance readiness and incident response. These are the contacts, triggers and messages that make a first email relevant rather than generic.
Who to email
- CISO or head of security at larger firms
- IT director or CIO
- CFO or COO where there is no security lead
- Compliance officer
Signals worth researching
- Compliance frameworks being pursued, such as SOC 2, visible in job posts or trust pages
- Security or IT job openings
- New cyber insurance, audit or regulatory requirements in their industry
- Rapid growth in remote staff or locations
What to say
- Anchor the message in a compliance or business requirement, not fear
- Reference the framework or role you found
- Offer a scoped readiness review with a clear deliverable
What to avoid
- Scanning a prospect's systems and emailing the results unsolicited
- Breach-scare subject lines
Cold email for cybersecurity firms, answered
How many cybersecurity firms are there in the US?
There were 13,275 establishments in NAICS 541519 (Other Computer Related Services) in 2023, employing 168,654 people. Source: U.S. Census Bureau, County Business Patterns 2023.
Which states have the most cybersecurity firms?
By establishments in 2023: California (1,524), Florida (1,276), Virginia (1,036), Texas (769) and New York (706). Source: U.S. Census Bureau, County Business Patterns 2023.
How should cybersecurity firms approach cold email?
Lead with a business requirement the prospect is visibly facing, such as a SOC 2 effort, an audit, a cyber insurance renewal or a new regulation. Avoid fear-based messaging and never send unsolicited scan results, which damages trust and can raise legal concerns.
Who is the buyer for security services at mid-sized companies?
Many mid-sized companies have no dedicated security leader, so the IT director, CFO or COO often owns the decision. Where a CISO exists, they are the primary buyer, with compliance and finance involved in larger engagements.
Is cold email legal in the United States?
Yes. The federal CAN-SPAM Act permits commercial email to business contacts without prior consent, provided the message identifies the sender accurately, uses a truthful subject line, includes a valid physical postal address and a working opt-out, and honours opt-out requests promptly. CAN-SPAM applies in every state and preempts most state commercial email laws, except provisions aimed at falsity or deception. This is general information, not legal advice.
Explore related pages
Cybersecurity Firms by state
Other industries
Sources and methodology
Every figure on this page comes from a federal statistical release and is shown with its source and reference year. Figures the agencies withhold or publish with high noise are left out rather than estimated. Page updated September 17, 2026.
- U.S. Census Bureau, County Business Patterns 2023 and 2022: establishments, paid employment for the pay period including March 12, annual payroll, and establishments by employment size. Industries use NAICS 2017 codes.
- Industry definition: NAICS 541519, Other Computer Related Services, used as the closest official category for cybersecurity and IT security firms.
Built for cybersecurity firms who sell to a finite list
Acqro researches every account on your list and writes the first email from what it finds.
Prefer a conversation? Get in touch.