ChannelLife Australia - Industry insider news for technology resellers
Australia
A-LIGN buys Pathfynder in cyber services expansion

A-LIGN buys Pathfynder in cyber services expansion

Fri, 4th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

A-LIGN has acquired cybersecurity firm Pathfynder, adding offensive and defensive security services to its portfolio.

Pathfynder will retain its specialist team and operate separately from A-LIGN's assurance and assessment practice.

The transaction brings together two parts of the cyber market that have often been sold separately. Compliance work typically assesses whether required controls are in place, while offensive security testing examines whether an attacker could bypass those controls in practice.

The acquisition gives A-LIGN's customer base access to penetration testing, red teaming, adversary emulation, incident response and other technical services through the same provider that already handles compliance and audit work. A-LIGN serves more than 6,400 organisations and has completed more than 36,000 audits.

Pathfynder is a veteran-owned business with staff drawn from cybersecurity, military and intelligence backgrounds. Its work includes network, cloud and web application penetration testing, alongside forensics and incident response.

Market shift

The move reflects a wider shift in corporate security spending as companies try to reconcile regulatory demands with a more aggressive threat environment. Businesses have long treated compliance as a governance requirement and offensive testing as a separate technical exercise, often handled by different suppliers.

That distinction has become harder to maintain as boards and security teams seek evidence that documented controls can withstand real attacks. The growth of AI-enabled attack methods has added pressure on companies to test systems more frequently and in more realistic ways.

Pathfynder will remain under the parent brand while keeping its identity as Pathfynder by A-LIGN. The structure is intended to preserve separation between audit-related work and penetration testing.

That separation matters in a market where independence is closely scrutinised. Audit and assessment providers must avoid conflicts that could arise if the same team both evaluates a control framework and tries to defeat it in a test designed to simulate an adversary.

Scott Price, Chief Executive Officer of A-LIGN, said the company had long supported a model that combines compliance and technical cyber work in one organisation.

"Since our inception, A-LIGN has believed in the power of combined compliance and technical cybersecurity services under one roof," said Scott Price, Chief Executive Officer of A-LIGN. "The acquisition of Pathfynder enables A-LIGN to offer customers advanced offensive security services delivered by a team that operates independently from our assurance and assessment practice while leveraging institutional knowledge of the customer to enhance the cybersecurity services. Pathfynder will remain a highly experienced and specialised team under the A-LIGN parent brand, maintaining its brand as Pathfynder by A-LIGN. This structure preserves the independence between A-LIGN's assurance and assessment teams and Pathfynder's penetration testers to protect the integrity of both functions. For A-LIGN's more than 6,400 existing customers, it also means access to advanced, real-world security testing from a trusted partner, without the friction of managing another vendor relationship."

Service expansion

For A-LIGN, the acquisition strengthens its position in a cybersecurity market where buyers increasingly want fewer suppliers and closer alignment between assurance, risk and technical testing. Companies under pressure to meet standards such as SOC 2, ISO 27001, FedRAMP, PCI and HITRUST often also commission separate red-team exercises and penetration tests to satisfy customers, insurers and internal risk committees.

By adding Pathfynder, A-LIGN can now offer those services within a single corporate structure while keeping the teams operationally separate. That may appeal to larger enterprises that want to reduce procurement complexity without merging the audit and testing functions themselves.

Pathfynder's founder said the two companies shared a common focus on helping customers address security gaps and regulatory demands.

"We are excited to join the A-LIGN team and bring our trusted expertise and proven capabilities to their existing suite of services," said DJ Fuller, Founder of Pathfynder. "We share the same core values and mission: helping companies close security gaps and meet regulatory requirements, so they can reduce the risk of financial and reputational damage from a cyberattack."

A-LIGN is known in the compliance market as a major issuer of SOC 2 reports and as a FedRAMP assessor. Founded in 2009, it has built its business around audit and risk services for organisations facing growing regulatory oversight and customer scrutiny over cyber controls.

The addition of Pathfynder signals that A-LIGN sees offensive security testing as increasingly central to that work rather than adjacent to it. Pathfynder's remit spans not only conventional penetration testing but also testing of complex and emerging systems, an area of the market that has drawn more demand as cloud adoption and software complexity have increased.

For buyers, the immediate change is likely to be in how services are sourced rather than in the underlying need. Companies still need audit evidence for regulators and customers, and they still need realistic testing to understand whether those controls hold up under attack.

Pathfynder will remain a specialised team operating separately from A-LIGN's assurance and assessment practice.