Wolfspire Solutions
For Cybersecurity Founders

You Built the Firm. Buyers Have No Idea How to Price It.

Cybersecurity firms trade at higher multiples than almost any adjacent IT services category. But most cyber founders never see those multiples — because generic brokers can't distinguish an MSSP from a compliance shop, and cyber-native buyers won't take a call unless the seller speaks their language.

Take the Free 3-Min Sale-Ready Scorecard

The multiple range for cyber is wider than any other IT services category

Managed IT trades in a fairly tight band — 3-5x SDE for small MSPs, maybe 4-6x EBITDA for MRR-heavy shops. Recurring revenue determines position within that band, but the band itself is narrow.

Cybersecurity is different. The same size firm can go from 2x SDE to 8x EBITDA depending on FIVE factors that most generic brokers cannot evaluate:

  1. Service line composition. Managed detection & response (MDR) trades at 5-7x. vCISO/advisory trades at 2-3x. Pen testing trades at 3-4x. Compliance consulting (CMMC, SOC 2, HIPAA) trades at 3-5x depending on renewal rates. If your buyer thinks you're "cybersecurity" as a monolith, you get the average of the low ones.
  2. Recurring vs. project mix. Same as MSP world, but more extreme — cyber MRR is worth MORE than MSP MRR because switching costs are higher. A 60% MRR cyber shop can pull 5-7x EBITDA. Below 40% MRR and buyers apply steep discounts.
  3. Compliance certifications you hold (not just deliver). ISO 27001, SOC 2 Type II, CMMC Level 2, StateRAMP, FedRAMP — these matter more for YOUR firm than the projects you complete for clients. Your certifications become part of the acquired asset's value.
  4. Analyst tier / SIEM stack. A SOC with Tier 1/2/3 analysts and a documented playbook library is a different asset than a SOC with two people who "watch alerts." Same team size, different multiple.
  5. Contract structure and cancellation clauses. Cyber clients are terrified of switching. Multi-year contracts with tight cancellation clauses are the highest-value asset a cyber firm has. Month-to-month agreements — even at the same revenue — cut the multiple in half.

A 30-second bio, so you know who's writing this: I'm Dave Lieske, principal at Wolfspire Solutions. 30+ years as a technology executive — CIO roles at Fortune 50 companies, DoD, and Aerospace & Defense. I understand the compliance-heavy end of cyber because I lived on that side of the buyer table for most of my career. Now I acquire small tech-enabled service businesses ($1M-$5M revenue) in Central Florida and the Southeast, with cybersecurity firms as a specific focus area.

Why Florida cyber firms are especially undervalued right now

The Southeast has a cyber boom happening quietly. MacDill AFB, USSOCOM, USCENTCOM, Space Force presence, plus a growing defense contractor base, plus insurance and finance concentrations that require heavy cyber spend — Florida cybersecurity demand is at historic highs.

But most FL cyber founders built their firms during a period when the market wasn't ready to pay premium multiples. They priced services for the market they knew, not the market that's here now. Their P&L, their contracts, and their pitch to potential buyers all reflect the older, lower-multiple mental model.

The result: a founder in Tampa, Orlando, or Jacksonville with $2M revenue and $500K EBITDA might get offers around $1M-$1.5M from a generic broker. The same firm, positioned properly to the right strategic acquirer, could clear $2.5M-$3.5M. That gap is real, it's persistent, and it's specific to how the cyber firm is presented — not what the firm actually is.

What most cyber founders get wrong

Cyber founders often over-focus on TECHNICAL excellence and under-focus on BUYER-FACING evidence. Your technical stack is great. Your team's certifications are impressive. Your incident response times are best-in-class. None of it converts to a higher offer unless it's documented in the form a buyer's diligence team can consume in two weeks. The gap between "you know it" and "the buyer can verify it in a data room" is where 30-50% of your firm's value hides.

What Wolfspire Solutions does for cyber founders

I'm not a broker. There is no auction process, no 10% listing fee coming out of your sale price, no marketing your firm to strangers who won't understand it.

I'm a direct buyer for cyber firms that fit. I acquire cybersecurity businesses using SBA-structured financing. Sellers get fair value calibrated to actual buyer economics, keep their team intact, and often stay involved as CTO or advisor during transition on terms that respect what they built.

For cyber firms not yet ready to sell, I offer consulting-for-equity. A 12+ month partnership with three compensation components: an engagement retainer, an ongoing monthly fee (both sized to your business's revenue and EBITDA), and equity (typically 10-20%). Retainer and monthly fee cover focused, ongoing execution. Equity aligns us to your exit outcome. Together we systematically close the buyer-facing gaps that block premium multiples: recasting your revenue mix presentation, documenting your compliance posture as a transferable asset, restructuring contracts to reduce cancellation risk, and translating your technical excellence into diligence-ready language. Full CFE details here.

Common questions from cyber founders

Do you understand the CMMC / DoD contracting environment?

Yes. 30+ years in DoD and Aerospace & Defense. I've lived through DFARS 252.204-7012, the NIST 800-171 transition, and now the CMMC Level 2 / Level 3 rollout. If your firm serves the DoD supply chain or holds CMMC certifications, that's an asset I know how to value.

What if my firm has managed services alongside cyber?

Very common — most FL cyber shops also offer managed IT. The right positioning separates the two revenue streams so each gets its correct multiple. Blended presentation costs you money. Separated presentation captures it.

How do you compare to a business broker or investment bank?

Brokers move restaurants and landscaping firms — they price cyber as "IT services" and miss the premium. Investment banks focus on transactions above $50M — you're below their minimum. Direct buyer with actual cyber understanding is the underserved middle where I operate.

What sizes do you acquire?

Sweet spot is $1M-$5M revenue with $250K+ EBITDA. Can flex up to $10M using SBA. For cyber firms specifically, I also consider strong-recurring shops under $1M revenue if the growth trajectory is real.

What if I have security clearances or team members with clearances?

Meaningful asset. Cleared personnel and cleared facility credentials transfer with the acquisition if structured correctly — and that's a specific negotiation I know how to protect for you. Generic brokers often leave clearance value on the table because they don't know how to price it.

Are you a fund or PE roll-up?

Neither. Wolfspire Solutions is operator-led. No fund committee, no portfolio timeline pressure, no plan to strip and flip. I install a GM post-close, keep the team intact, and operate the business long-term.

Two ways to start

Neither commits you to anything. Both give you a sharper read on where you stand.

Take the 3-Min Scorecard Book a 25-Min Call