Cybersecurity Firms

Cold email software for cybersecurity firms

Acqro gives cybersecurity and IT security firms cold email that researches each prospect's company before writing. Below: verified federal data on the industry across all 50 states, the buyers it sells to, and a playbook for outreach that earns replies.

Onboarding in batches. No credit card to join.

How many cybersecurity firms are in the United States?

Direct answer

The United States had 13,275 establishments in NAICS 541519, other computer related services, in 2023, employing 168,654 people. The largest markets by establishments were California, Florida and Virginia. Source: U.S. Census Bureau County Business Patterns.

Verified data

Cybersecurity firms in the US by the numbers

US establishments
13,275+10.7% vs 2022Census CBP 2023, NAICS 541519
Paid employees
168,654Census CBP 2023
Average annual pay
$123,684Census CBP 2023
Firms under 10 employees
85.6%Census CBP 2023
Largest state
CaliforniaBy establishments, CBP 2023

Census does not publish a separate category for cybersecurity and IT security firms; figures use NAICS 541519, Other Computer Related Services, the closest official industry. 85.6% of establishments have fewer than 10 employees, so most firms in the industry run outbound with a founder or a very small sales team. The 1,787 firms with 10 to 249 employees are the ones most likely to be building a repeatable outbound process.

The five largest states hold 40.0% of all establishments. Among states with at least 100 establishments, the fastest growth between 2022 and 2023 was in Delaware (+57.3%), Connecticut (+38.8%) and Colorado (+25.8%). Growing markets bring new competitors and new buyers at the same time, which rewards outreach that is specific rather than volume-driven.

Cybersecurity firms by state

All states and DC ranked by number of establishments, with the change since 2022.

NAICS 541519, Other Computer Related Services. Source: U.S. Census Bureau, County Business Patterns 2023 and 2022. — = not published.
RankStateEstablishmentsEmployeesChange vs 2022
1California1,52417,057+19.8%
2Florida1,27612,126+13.2%
3Virginia1,03621,148+2.8%
4Texas76913,414+14.4%
5New York7067,339+10.1%
6Illinois6314,956+1.1%
7New Jersey6145,457+2.7%
8Georgia5466,884+9.9%
9Pennsylvania5354,505+13.1%
10Maryland4886,028+15.1%
11Massachusetts3914,687+2.6%
12Minnesota3852,054+4.3%
13Michigan3838,111+10.1%
14Washington3373,388+2.7%
15Colorado3125,620+25.8%
16Arizona2674,380+6.4%
17North Carolina2554,707+22.6%
18Ohio2424,584+21.6%
19South Carolina1961,510+6.5%
20Oklahoma1801,401+10.4%
21Delaware1732,329+57.3%
22Utah1611,524−2.4%
23Nevada139611+7.8%
24Indiana1291,527+18.3%
25Missouri1251,252+3.3%
26Connecticut118949+38.8%
27Oregon118956+9.3%
28Wisconsin1112,276−1.8%
29Tennessee1104,516+19.6%
30Louisiana98881+5.4%
31Kentucky951,039+23.4%
32District of Columbia93932−19.8%
33Idaho804670.0%
34Kansas762,988+8.6%
35Alabama62691−4.6%
36Nebraska511,177+15.9%
37Wyoming50142+13.6%
38New Hampshire485440.0%
39Arkansas47380+27.0%
40Iowa421,063+10.5%
41New Mexico35−7.9%
42Hawaii30123+25.0%
43Montana300.0%
44Rhode Island30319+30.4%
45South Dakota30+50.0%
46Mississippi27124+35.0%
47Maine231,131+35.3%
48Alaska21188+5.0%
49Vermont21116+5.0%
50West Virginia17155+21.4%
51North Dakota12+200.0%

Who cybersecurity firms sell to

Common buyer industries for cybersecurity and IT security firms, with US establishment counts and how many have 10 to 249 employees.

Source: U.S. Census Bureau, County Business Patterns 2023. The choice of buyer industries is Acqro's editorial guidance; the counts are Census figures.
Buyer industryEstablishments10–249 employeesEmployees
Depository Credit Intermediation108,79233,9382,072,993
Offices of Physicians218,06658,9392,771,935
Legal Services181,09223,5111,190,297
Data Processing, Hosting, and Related Services18,5445,338629,527
Outreach playbook

How cybersecurity firms should run cold email

Cybersecurity and IT security firms sell security assessments, managed detection, compliance readiness and incident response. These are the contacts, triggers and messages that make a first email relevant rather than generic.

Who to email

  • CISO or head of security at larger firms
  • IT director or CIO
  • CFO or COO where there is no security lead
  • Compliance officer

Signals worth researching

  • Compliance frameworks being pursued, such as SOC 2, visible in job posts or trust pages
  • Security or IT job openings
  • New cyber insurance, audit or regulatory requirements in their industry
  • Rapid growth in remote staff or locations

What to say

  • Anchor the message in a compliance or business requirement, not fear
  • Reference the framework or role you found
  • Offer a scoped readiness review with a clear deliverable

What to avoid

  • Scanning a prospect's systems and emailing the results unsolicited
  • Breach-scare subject lines
Questions

Cold email for cybersecurity firms, answered

How many cybersecurity firms are there in the US?

There were 13,275 establishments in NAICS 541519 (Other Computer Related Services) in 2023, employing 168,654 people. Source: U.S. Census Bureau, County Business Patterns 2023.

Which states have the most cybersecurity firms?

By establishments in 2023: California (1,524), Florida (1,276), Virginia (1,036), Texas (769) and New York (706). Source: U.S. Census Bureau, County Business Patterns 2023.

How should cybersecurity firms approach cold email?

Lead with a business requirement the prospect is visibly facing, such as a SOC 2 effort, an audit, a cyber insurance renewal or a new regulation. Avoid fear-based messaging and never send unsolicited scan results, which damages trust and can raise legal concerns.

Who is the buyer for security services at mid-sized companies?

Many mid-sized companies have no dedicated security leader, so the IT director, CFO or COO often owns the decision. Where a CISO exists, they are the primary buyer, with compliance and finance involved in larger engagements.

Is cold email legal in the United States?

Yes. The federal CAN-SPAM Act permits commercial email to business contacts without prior consent, provided the message identifies the sender accurately, uses a truthful subject line, includes a valid physical postal address and a working opt-out, and honours opt-out requests promptly. CAN-SPAM applies in every state and preempts most state commercial email laws, except provisions aimed at falsity or deception. This is general information, not legal advice.

Sources and methodology

Every figure on this page comes from a federal statistical release and is shown with its source and reference year. Figures the agencies withhold or publish with high noise are left out rather than estimated. Page updated September 17, 2026.

  • U.S. Census Bureau, County Business Patterns 2023 and 2022: establishments, paid employment for the pay period including March 12, annual payroll, and establishments by employment size. Industries use NAICS 2017 codes.
  • Industry definition: NAICS 541519, Other Computer Related Services, used as the closest official category for cybersecurity and IT security firms.

Built for cybersecurity firms who sell to a finite list

Acqro researches every account on your list and writes the first email from what it finds.

Prefer a conversation? Get in touch.