SGS Expands Cybersecurity Push With Prescient Security Stake


Digital Trust
A broad assurance category covering cybersecurity, data protection, software integrity, compliance evidence and the controls organizations use to prove digital systems are reliable.
TIC
Short for testing, inspection and certification, a professional-services sector that verifies whether products, processes and systems meet required standards.
Penetration testing
A controlled security test in which specialists attempt to find and exploit weaknesses before attackers do.
SOC 2, PCI DSS and FedRAMP
Common assurance and compliance frameworks used to evaluate service-provider controls, payment-card security and U.S. federal cloud-security requirements.
SGS
other
SGS Acquires Prescient Security in the US, an Expert in Enterprise Cybersecurity and Digital Compliance
SGS
other
SGS acquires Prescient Security in the US, an expert in enterprise cybersecurity and digital compliance
PR Newswire / Prescient Security
news
SGS acquires Prescient Security in the US, an expert in enterprise cybersecurity and digital compliance
Majority stake
SGS completed the acquisition of a majority stake in U.S.-based Prescient Security on October 2.
5,000 clients
Prescient brings more than 350 employees and more than 5,000 customers worldwide to SGS’s Digital Trust platform.
Revenue target
SGS is targeting at least CHF 200 million in additional Digital Trust revenue by 2027 compared with 2023.
SGS said Oct. 2 that it completed the acquisition of a majority stake in Prescient Security, a U.S.-based provider of information compliance and cybersecurity services, expanding the Swiss testing, inspection and certification group’s Digital Trust platform.1
The transaction adds more than 350 Prescient employees and more than 5,000 clients worldwide. Prescient’s services include information-security certification, payment security, data protection, cybersecurity and penetration testing.2 Financial terms were not disclosed. The deal was also noted in European equity-market coverage as a majority-stake acquisition by SGS.6
For SGS, the significance is both strategic and additive. The company is targeting at least CHF 200 million in additional Digital Trust revenue by 2027 compared with 2023 and described Prescient as an important step in expanding that platform.2 In practice, the deal moves digital trust closer to SGS’s core testing and certification model, rather than treating it as an adjacent advisory line.
Prescient gives SGS a broader bench in enterprise cyber assurance. The company provides certification and compliance services across SOC 2, ISO, PCI DSS, HITRUST, FedRAMP and CMMC, according to the SGS and Prescient release.3
That standards coverage matters for regulated customers in financial services, healthcare, retail, technology and defense. In those sectors, security controls increasingly must be tested, documented and evidenced for customers, regulators and auditors.1
The acquisition also adds offensive-security and penetration-testing capabilities. SGS said Prescient combines expert-led manual testing, scalable digital approaches and AI-assisted models, supported by proprietary automation technology for compliance workflows and security processes.1
Prescient’s own description emphasizes high-growth software-as-a-service and enterprise customers, with services that bridge offensive testing and compliance readiness.3
Traditional testing, inspection and certification companies built their position by validating physical products, industrial processes and regulated supply chains. The Prescient deal reflects a broader shift: the same customers now need assurance for software, cloud environments, payment systems, data handling and cyber controls.
That makes digital trust a natural extension of the TIC model. Regulated companies are being asked to prove not only that products meet technical standards, but also that digital systems are resilient, compliant and auditable.
In SGS’s framing, the acquisition gives it a more complete Digital Trust portfolio, particularly in digital trust audits, while combining Prescient’s capabilities with SGS’s independence, technical depth and global network.4
The timing is notable because cybersecurity, data protection and artificial intelligence governance are increasingly board-level operating risks. Buyers are not only looking for point-in-time cyber assessments. They want repeatable evidence, continuous validation and assurance that can stand up to procurement reviews, customer due diligence and regulatory scrutiny.
Prescient’s focus on audit-ready evidence and continuous validation fits that demand.3
The acquisition gives SGS a U.S.-based platform in a market where cyber assurance and compliance services are becoming part of enterprise risk management. Market-facing summaries described the transaction as an expansion of SGS’s cybersecurity and digital compliance footprint and a way to integrate digital security testing into its global TIC framework.8
That is the central rationale: SGS is not just buying a niche cyber services provider. It is buying people, clients, standards expertise and automated workflows that can be distributed through a global assurance network.
If SGS can integrate Prescient effectively, it can cross-sell cyber and compliance services to customers that already rely on it for testing, inspection and certification in other domains.
The integration risk is that cyber services operate on faster cycles than many legacy TIC businesses. Penetration testing, cloud compliance and AI-assisted security workflows require rapid tool development, specialized talent and continuous updating as threats and standards evolve.
SGS’s challenge will be to preserve Prescient’s technical velocity while embedding it into a larger public-company platform.
The first marker is revenue contribution. SGS has set a target of at least CHF 200 million in additional Digital Trust revenue by 2027 versus 2023, giving investors and customers a concrete benchmark for whether acquisitions are converting into platform growth.2
The second is portfolio integration. Prescient brings capabilities in SOC 2, ISO, PCI DSS, HITRUST, FedRAMP and CMMC. SGS brings global reach, brand trust and a long-standing assurance model.3 The opportunity is to turn those ingredients into a unified digital-trust offering for regulated customers operating across multiple jurisdictions.
The third is whether digital trust becomes a recurring assurance relationship rather than a project-based cyber service. If customers use SGS for continuous evidence, compliance readiness, penetration testing and certification support, the acquisition could help reposition digital trust as a core growth platform inside the TIC sector.
Comments