Summary
- SGS has acquired a majority stake in cybersecurity and digital-assurance specialist NetSentries.
- NetSentries adds offensive security, continuous exposure management, AI security, and post-quantum readiness capability.
- The transaction reflects growing convergence between traditional assurance businesses and enterprise cyber-resilience services.
Swiss testing and certification group SGS has acquired a majority stake in NetSentries, expanding its digital assurance business into offensive security, continuous exposure management, artificial-intelligence security, cyber resilience, and post-quantum readiness.
NetSentries will continue to operate under its existing brand, with co-founders Sudheer Elayadath and Arun Thomas remaining in charge of the business. SGS has not disclosed financial terms for the transaction.
The acquired company works primarily with banks, financial institutions, and other regulated enterprises across the Middle East and India. Its services include offensive security testing, independent assurance and validation, AI and emerging-technology security, resilience work, and assessments designed to determine whether organisations are prepared for post-quantum cryptographic change.
NetSentries also operates NST Assure, a platform intended to provide customers with an external view of exposed systems and continuously validate findings. SGS describes the capability as a move away from purely periodic testing towards continuous threat exposure management, although those performance and positioning claims remain the companies’ own.
The acquisition is notable because SGS comes from the testing, inspection, and certification market rather than the conventional cybersecurity product sector. Its wider business is built around organisations paying an independent party to verify whether products, processes, systems, or operations meet defined standards and requirements.
Cybersecurity is increasingly moving into that assurance model. Organisations are not only buying controls intended to prevent attacks; they are also being asked to provide evidence that systems have been tested, suppliers assessed, resilience exercised, and technology governed against contractual, regulatory, or industry expectations.
That creates room for companies that can combine technical testing with a recognised assurance function. Penetration tests, exposure reviews, AI assessments, and cryptographic-readiness work can all produce evidence that feeds into procurement decisions, audit programmes, board reporting, or regulatory supervision rather than existing solely inside a security team.
The expansion into AI and post-quantum work is particularly indicative of that shift. Both areas involve technical risk, but the immediate enterprise requirement is often one of evidence and planning: determining which systems are exposed, which controls exist, who is accountable, and how an organisation can demonstrate that a transition or deployment has been examined systematically.
There are limits to the convergence. Independent assurance and operational security services perform different functions, and a certificate or assessment does not itself prevent an incident. The value of external validation depends on the scope tested, the quality of the methodology, the independence of the assessor, and whether findings lead to changes in the underlying environment.
SGS is nevertheless betting that cyber risk will increasingly be treated alongside other areas in which organisations seek repeatable external verification. NetSentries gives the group deeper technical capability in areas where traditional compliance exercises can be insufficient, while SGS gives the cyber specialist access to a much larger international assurance business.
The deal adds another participant to a cyber market already being reshaped by consolidation between consultancies, testing firms, security vendors, and professional-services businesses. The common thread is that cyber resilience is becoming something organisations are expected not only to claim, but to evidence.





