Cybersecurity firms trade at higher multiples than almost any adjacent IT services category. But most cyber founders never see those multiples — because generic brokers can't distinguish an MSSP from a compliance shop, and cyber-native buyers won't take a call unless the seller speaks their language.
Take the Free 3-Min Sale-Ready ScorecardManaged IT trades in a fairly tight band — 3-5x SDE for small MSPs, maybe 4-6x EBITDA for MRR-heavy shops. Recurring revenue determines position within that band, but the band itself is narrow.
Cybersecurity is different. The same size firm can go from 2x SDE to 8x EBITDA depending on FIVE factors that most generic brokers cannot evaluate:
A 30-second bio, so you know who's writing this: I'm Dave Lieske, principal at Wolfspire Solutions. 30+ years as a technology executive — CIO roles at Fortune 50 companies, DoD, and Aerospace & Defense. I understand the compliance-heavy end of cyber because I lived on that side of the buyer table for most of my career. Now I acquire small tech-enabled service businesses ($1M-$5M revenue) in Central Florida and the Southeast, with cybersecurity firms as a specific focus area.
The Southeast has a cyber boom happening quietly. MacDill AFB, USSOCOM, USCENTCOM, Space Force presence, plus a growing defense contractor base, plus insurance and finance concentrations that require heavy cyber spend — Florida cybersecurity demand is at historic highs.
But most FL cyber founders built their firms during a period when the market wasn't ready to pay premium multiples. They priced services for the market they knew, not the market that's here now. Their P&L, their contracts, and their pitch to potential buyers all reflect the older, lower-multiple mental model.
The result: a founder in Tampa, Orlando, or Jacksonville with $2M revenue and $500K EBITDA might get offers around $1M-$1.5M from a generic broker. The same firm, positioned properly to the right strategic acquirer, could clear $2.5M-$3.5M. That gap is real, it's persistent, and it's specific to how the cyber firm is presented — not what the firm actually is.
Cyber founders often over-focus on TECHNICAL excellence and under-focus on BUYER-FACING evidence. Your technical stack is great. Your team's certifications are impressive. Your incident response times are best-in-class. None of it converts to a higher offer unless it's documented in the form a buyer's diligence team can consume in two weeks. The gap between "you know it" and "the buyer can verify it in a data room" is where 30-50% of your firm's value hides.
I'm not a broker. There is no auction process, no 10% listing fee coming out of your sale price, no marketing your firm to strangers who won't understand it.
I'm a direct buyer for cyber firms that fit. I acquire cybersecurity businesses using SBA-structured financing. Sellers get fair value calibrated to actual buyer economics, keep their team intact, and often stay involved as CTO or advisor during transition on terms that respect what they built.
For cyber firms not yet ready to sell, I offer consulting-for-equity. A 12+ month partnership with three compensation components: an engagement retainer, an ongoing monthly fee (both sized to your business's revenue and EBITDA), and equity (typically 10-20%). Retainer and monthly fee cover focused, ongoing execution. Equity aligns us to your exit outcome. Together we systematically close the buyer-facing gaps that block premium multiples: recasting your revenue mix presentation, documenting your compliance posture as a transferable asset, restructuring contracts to reduce cancellation risk, and translating your technical excellence into diligence-ready language. Full CFE details here.
Yes. 30+ years in DoD and Aerospace & Defense. I've lived through DFARS 252.204-7012, the NIST 800-171 transition, and now the CMMC Level 2 / Level 3 rollout. If your firm serves the DoD supply chain or holds CMMC certifications, that's an asset I know how to value.
Very common — most FL cyber shops also offer managed IT. The right positioning separates the two revenue streams so each gets its correct multiple. Blended presentation costs you money. Separated presentation captures it.
Brokers move restaurants and landscaping firms — they price cyber as "IT services" and miss the premium. Investment banks focus on transactions above $50M — you're below their minimum. Direct buyer with actual cyber understanding is the underserved middle where I operate.
Sweet spot is $1M-$5M revenue with $250K+ EBITDA. Can flex up to $10M using SBA. For cyber firms specifically, I also consider strong-recurring shops under $1M revenue if the growth trajectory is real.
Meaningful asset. Cleared personnel and cleared facility credentials transfer with the acquisition if structured correctly — and that's a specific negotiation I know how to protect for you. Generic brokers often leave clearance value on the table because they don't know how to price it.
Neither. Wolfspire Solutions is operator-led. No fund committee, no portfolio timeline pressure, no plan to strip and flip. I install a GM post-close, keep the team intact, and operate the business long-term.
Neither commits you to anything. Both give you a sharper read on where you stand.