About Insight Recon

"We've spent our careers finding the ways in. We built Insight Recon to help you close them."

Founded by practitioners Built on offense. Focused on defense. A Breach Point product

Who we are

Built by the people who find these problems for a living.

Insight Recon is built by practitioners. The two people behind it have spent their careers on the offensive side of security, running penetration tests, red team operations, and security assessments across industries and organizations of every size.

After years of finding the same Active Directory exposures in environment after environment, and watching security teams struggle to interpret and act on the results, they decided to build something better.

Most AD security tools give you data. A score, a list of findings, a PDF. They tell you something is wrong but not what it means to an attacker, which findings actually matter, or where to start. After delivering hundreds of assessments between them, Heath and Brad kept running into the same gap: organizations would receive technically correct output and still not know what to do next.

Why we built it

Insight Recon was built to close that gap. Attacker-perspective output that security teams can understand, prioritize, and act on, and that can be handed to a CISO or a board without a translator.

Heath Adams, Co-Founder of Insight Recon
Heath Adams
Co-Founder, Insight Recon

Co-Founder

Heath Adams

Heath Adams is one of the most recognized practitioners in offensive security. He founded TCM Security, a veteran-owned penetration testing, security assessment, and consulting firm that he grew into one of the most respected brands in practical security before its acquisition by a national training organization in 2025.

Heath created the Practical Network Penetration Tester (PNPT) certification, the first hands-on pentest certification designed to simulate a real-world engagement. Candidates perform a live assessment and deliver a professional report to pass. The PNPT became an industry benchmark for practical, affordable certification that prepares practitioners for how security work actually happens. He has taught over one million students across platforms.

Heath has spoken at security conferences around the world for more than six years, with keynote appearances at Wild West Hackin' Fest, BSides Greenville, BSides Ahmedabad, Hack at the Harbor, and CIA Con. He has also presented at the NYPD Cyber Intelligence and Counterterrorism Conference, CarolinaCon, H@cktivitycon, and US Cyber Games, among others.

He co-founded VetSec, a nonprofit dedicated to helping veterans transition into cybersecurity careers, and served in the United States Army Reserve. He completed the Harvard Business School General Management Program in 2025.

At Insight Recon, Heath brings the attacker mindset developed across hundreds of engagements directly into how the product frames and prioritizes risk.

Certifications
OSCP CISSP PNPT GSNA PCI QSA eWPT OSWP
Selected speaking engagements
Building a Winning Team Culture Wild West Hackin' Fest · 2023 Keynote
Building a Winning Team Culture BSides Greenville · 2023 Keynote
Hacking the Police NYPD Cyber Intel Conference · 2023 Speaker
Keynote BSides Ahmedabad · 2022 Keynote
How to Hire and Get Hired in Cybersecurity Hack at the Harbor · 2022 Keynote
My Journey into Cybersecurity CIA Con · 2020 Keynote
The Top 5 Ways I Owned Your Internal Network BSides Charlotte / Charleston / RDU · 2019 Speaker
Before You Accept That Offer US Cyber Games · 2025 Speaker

Co-Founder

Bradley Thornton

Bradley Thornton is the founder and CEO of Threat Potential, an offensive security firm based in Richmond, Virginia. His background spans both sides of the security equation in a way that directly shaped how Insight Recon works.

Brad spent nearly six years at GE in enterprise identity and access management, including as Lead Security Engineer for Privileged Identity Management. That experience gave him a depth of understanding of how identity infrastructure is built, how it drifts over time, and how those drifts become exploitable. He then moved to offensive work, serving as Senior Penetration Tester at North State and later as Red Team Leader and Penetration Test Leader at ICSynergy, leading assessments across complex enterprise environments. He also served as Director of Risk and Governance at TCM Security.

That combination of enterprise identity management on one side and red team operations on the other is exactly the perspective Insight Recon needed. Brad understands how AD environments are built and how attackers exploit them. Both lenses are present in how Insight Recon's findings are framed, prioritized, and presented.

Brad holds a degree from the University of North Carolina at Wilmington.

Certifications
OSCP CISSP PNPT GSNA PCI QSA CyberArk EPV MS Principal Cyber Detective Lean Six Sigma GB
Bradley Thornton, Co-Founder of Insight Recon
Bradley Thornton
Co-Founder, Insight Recon

The thinking behind Insight Recon

Attacker perspective. Defender output.

After years of engagements, we kept seeing the same problem. Here is what we set out to fix.

PROBLEM 01

Tools give you data. Not answers.

A list of 500 findings tells you that things are wrong. It doesn't tell you what an attacker can actually do with your environment, which findings are genuinely dangerous, or what to fix first.

PROBLEM 02

Reports get delivered and shelved.

Technically correct output that doesn't connect findings to attacker impact doesn't drive remediation. Teams fix the loudest finding and miss the one that actually matters. We built Insight Recon to change that.

PROBLEM 03

Security findings shouldn't need a translator.

A good report works for the person fixing it and the person approving the budget to fix it. Insight Recon is designed for both. Technical depth where you need it, clarity everywhere else.

See it for yourself

See your Active Directory the way we would.

Run a free scan and get a prioritized report of real exposure in about 20 minutes. Read-only, no production impact, no credit card.