Mandiant (part of Google Cloud)

Elite incident response and offensive security consultancy operating as the threat-intelligence arm of Google Cloud Security.

CompanyPenetration Testing FirmsCloud

Pricing: Custom (contact sales)

Updated June 2026.

What is Mandiant (part of Google Cloud)?

Founded in 2004 by Kevin Mandia, Mandiant built a global reputation responding to the world's most high-profile breaches. After acquisition by FireEye in 2013 and by Google for ~$5.4B in 2022, the firm retained its brand and now operates inside Google Cloud as a specialist consultancy for incident response, threat intelligence, and offensive security.

Best for: Enterprises needing top-tier incident response, nation-state threat intelligence, or board-defensible breach engagement
Pros
  • Frontline visibility into nation-state and ransomware intrusions through real IR casework
  • Deep threat intelligence backed by APT group tracking (APT1, APT28, APT41)
  • Backed by Google Cloud scale, telemetry, and engineering resources
  • Brand recognition that satisfies board and regulator expectations after a breach
Cons
  • Premium enterprise pricing with bespoke engagements and no public price list
  • Lead times can be long outside an active retainer relationship
  • Brand and roadmap increasingly tied to Google Cloud's strategic priorities

Key Features

Incident response and breach investigations
Red team and adversary emulation engagements
Penetration testing across network, application, and cloud
Threat intelligence subscriptions and analyst briefings
Tabletop exercises and cyber crisis simulations
Compromise and security program assessments
Strategic readiness and CISO advisory
Managed defense (XDR) and incident response retainers