Summary
- Intrusion has the right buyer promise but not yet the right proof of business scale. Its Shield products sell prevention rather than alert volume: inspect connections, check IP and DNS reputation, and block dangerous inbound and outbound traffic before the customer pays for incident response. That value proposition is easy to understand in government, critical infrastructure, public safety, schools, cloud workloads and smaller organizations without deep security teams.
- The company-level evidence is still strained. Intrusion generated $7.1 million of revenue in 2025, lost $9.1 million, used $6.8 million of operating cash, and depended on U.S. government customers for 94.6% of revenue. Q1 2026 revenue fell to $0.9 million, cash dropped to $1.4 million, and the company needed a secured Streeterville note after quarter-end. A June 2026 VigilAigent acquisition could add ARR and channel reach, but it also adds dilution, integration risk and a new set of claims that must show up in filings.
- The judgment is conditional: Intrusion can be a valuable niche prevention layer if customers trust its blocking decisions and if acquired and partner channels convert into recurring commercial revenue. Until then, it remains a small, capital-constrained security vendor asking buyers and investors to believe that avoided losses will outrun false positives, sales cost and competition from larger platforms.
The customer is buying the absence of a disaster
The cleanest way to understand Intrusion is to begin with the buyer's invoice, not the company's product sheet. A sheriff's office, cloud operator, manufacturer, school district, managed-service provider or mid-market company does not wake up hoping to add another security tool. It wants to avoid downtime, ransom negotiation, legal notification, overtime, forensic consultants, insurance trouble, public embarrassment and lost operating control. If the expected cost of one serious incident is high enough, a recurring security subscription can look cheap even before it generates a visible daily return.
That is the economic space Intrusion wants to occupy. The company is not primarily trying to sell elegance, brand breadth or a security operating center transformation. It is selling the idea that bad communications can be stopped at the connection layer. If a remote system with a bad history tries to reach a protected network, or a compromised device tries to talk outward to dangerous infrastructure, Shield is meant to make the decision before an analyst has to read an alert. In that story, the product saves money because the breach never enters the accounting system.
This is a stronger promise than ordinary alerting. Alerting can become a cost center: more data, more events, more triage, more integration, more people. Prevention is more direct. If a customer trusts the decision, the security control turns from a monitoring expense into an operating hedge. The buyer can justify payment with the same logic used for backup power, insurance, fraud controls, fire suppression or industrial safety. The product is paid to make rare, expensive outcomes less likely.
But that same clarity creates Intrusion's hardest test. A product that blocks traffic must be right at the moment of action. A false negative leaves the buyer exposed; a false positive interrupts legitimate work. Monitoring products can survive some ambiguity because they pass decisions to humans. Inline prevention products cannot hide so easily. They have to prove that the avoided incident is worth the operational authority granted to the tool. If buyers leave the product in observe mode, or buy it only for narrow use cases, the avoided-loss argument weakens.
Intrusion's economic question is therefore not whether cyber risk is real. It plainly is. The FBI's internet-crime reporting, Verizon's breach research and CISA's ransomware guidance all point to a security environment where exploitation, ransomware, social engineering and operational disruption remain expensive. The question is whether Intrusion can capture enough of that avoided-loss value. A security event can cost millions; the vendor does not automatically get to charge millions for reducing the probability of it.
The customer can spend on firewalls, endpoint platforms, cloud-native controls, managed detection, identity, backup, segmentation, training, insurance and incident readiness instead. Intrusion must show that its particular blocking layer changes the risk equation more efficiently than those alternatives.
What Intrusion actually controls
Intrusion's defensible boundary is narrower than the phrase "cybersecurity company" suggests. It is best understood as a reputation-based connection-control business built around a proprietary intelligence asset. The company says its TraceCop database contains historical behavior, associations and reputational information covering more than 8.5 billion IP and DNS combinations. Shield applies that memory to traffic. The company describes products that can run behind the firewall, in cloud environments, on endpoints, in a monitoring-only role, and through a central management console.
That boundary matters because it keeps the analysis honest. Intrusion is not a full replacement for identity governance, endpoint process telemetry, email security, vulnerability management, cloud posture management, data backup, application-layer protection, incident response, SIEM analytics or user training. It can complement those controls by asking a specific question: should this connection be allowed? If the answer is no, Shield aims to block it quickly and quietly.
That is a plausible niche. Many attacks use infrastructure before they use a payload that a signature product can identify. Command-and-control, exfiltration, beaconing, scanning, suspicious outbound traffic and known-bad hosting patterns all create network traces. A product with long historical memory can sometimes see risk where a newer, narrower feed cannot. For customers with limited human security capacity, a blocking decision can be more useful than a well-written alert.
The on-premise use case is especially intuitive in data-center, operational-technology and public-sector environments. A 10 Gbps appliance placed in the network path has a clean promise: inspect traffic both ways, report what it would block, then enforce when the customer is comfortable. The cloud use case is also rational. Shield Stratus is presented as an AWS and Azure deployment that integrates with cloud load-balancing patterns and uses fixed hourly pricing. The endpoint use case reaches remote users and mobile or field deployments, where a customer's network perimeter is less meaningful.
The limitation is that reputation is not the whole security problem. Some legitimate infrastructure becomes compromised. Some malicious infrastructure is new. Some attacks ride trusted services. Some damage occurs through identity abuse, supply-chain compromise, malicious insiders, vulnerable applications, misconfiguration or stolen session tokens. A connection reputation product can reduce exposure, but it cannot be the entire answer.
Buyers that already pay for Microsoft, CrowdStrike, Palo Alto Networks, Cloudflare, Zscaler, Darktrace, Trellix, Recorded Future or managed providers will ask whether Intrusion is additive enough to justify budget and operational complexity.
That is why Intrusion's own proof-of-value motion is strategically important. The buyer needs to see what Shield would have blocked in its own environment. Generic threat counts are less persuasive than a report showing outbound risk, unexpected traffic, known-bad destinations, suspicious countries, risky autonomous systems or vulnerable operating patterns inside the customer's network. Intrusion's best sale is not a broad category pitch. It is a practical demonstration that the customer's existing stack is missing harmful communications and that Shield can block them without breaking normal work.
The revenue base is still mostly government and services
The financials show a company with real revenue, but not yet a proven subscription engine. Intrusion reported $7.1 million of revenue in 2025, up from $5.8 million in 2024. The increase sounds encouraging until the mix is examined. Consulting services were $5.3 million in 2025. Product revenue was $1.7 million. Shield revenue was $1.8 million, roughly a quarter of total revenue. Commercial revenue was only $0.4 million, down from $0.9 million in 2024. The company remains much more dependent on government work than a typical scalable software story would prefer.
The concentration is severe. U.S. government customers accounted for 94.6% of 2025 revenue. The company disclosed that four government customers through direct and indirect channels made up that government revenue, while three individual government customers represented 94.4% of total revenue. This is validation and fragility at the same time. Government customers can be sophisticated, demanding and credible, particularly for cyber and critical-infrastructure work. If they keep buying, they help prove the product has operational value.
But a company with fewer than $10 million of annual revenue cannot afford much slippage in a few government programs.
The 2026 first quarter demonstrates that problem. Revenue fell to $888,000 from $1.775 million in the prior-year quarter. Management attributed the decline to the timing impact of a delayed defense-related contract extension caused by federal funding and procurement delays. That explanation may be true. It may also be exactly the kind of risk that comes with a concentrated government book. A delayed award, continuing-resolution politics, agency priority shift, reseller timing issue or program-specific procurement pause can change a small vendor's quarterly story.
This matters for pricing because subscription businesses are normally valued for predictability. If Shield were already a broad, recurring commercial product, a delayed government consulting or critical-infrastructure program would not dominate the quarter. The customer base would absorb the delay. Intrusion has not reached that point. The company is still trying to convert a long government heritage and technical data asset into a diversified commercial revenue base.
Management's argument is that government concentration will decline as Shield gains traction in commercial markets. That is the right goal. It is not yet the result. The practical test is whether new revenue comes from repeatable channels rather than isolated wins. Cloud marketplace listings, PortNexus deployments, state-government contracts and the VigilAigent acquisition all point toward diversification. The filings have to show that these are not just announcements but collections, renewals, margins and retention.
Gross margin hints at leverage, but operating cost overwhelms it
At the gross-margin line, Intrusion has something to work with. The company reported a 75.8% gross profit margin for 2025 and a 74% margin for Q1 2026. Those figures suggest that once the product and service are sold, direct costs are not the main obstacle. A reputation database, software subscription, cloud image, hardware-assisted deployment or recurring support relationship can have attractive contribution economics if revenue scales.
The operating expense line is the obstacle. Intrusion's 2025 operating expenses were $14.5 million against $7.1 million of revenue. Sales and marketing, research and development, and general and administrative costs together consumed far more than gross profit. In Q1 2026, operating expenses were $4.2 million against $888,000 of revenue. The company lost $3.6 million in that quarter alone.
This creates a harsh arithmetic. A 75% gross margin is valuable only if the revenue base is large enough to carry the fixed and semi-fixed costs of the company. A small public cybersecurity company must fund engineering, threat-data maintenance, product updates, customer support, government compliance, sales, channel enablement, leadership, audit, legal, investor relations and listing costs. Intrusion can say its database is proprietary and its prevention layer is differentiated, but the income statement asks a simpler question: how many customers pay, how much, how often, and at what sales cost?
The visible AWS Marketplace price for Shield Stratus sharpens this issue. The listing shows usage charges of $0.14 to $0.16 per hour depending on instance size, with a free trial and additional AWS infrastructure costs. At continuous use, that public software price is roughly $100 to $117 per 30-day month per listed instance before infrastructure. That low entry point can help adoption. It makes testing easier, gives managed-service providers a simple packaging component, and lowers friction for cloud teams.
But it also means the public marketplace path needs volume, support attach, larger deployments, private offers or a broader managed service to move the company-level income statement.
On-premise and government pricing may be materially different, and the company may sell support, hardware, consulting, subscriptions and bundled arrangements that carry more value than a small cloud image. Still, buyers comparing security tools will notice price. If Intrusion prices too low, the product cannot carry sales and support. If it prices too high, customers can choose broader platforms with larger ecosystems. The avoided-loss argument gives Intrusion room, but not unlimited room.
The ideal economics would look like this: a low-friction trial shows risky connections; the customer moves from observe to protect mode; annual subscription revenue begins; support remains manageable; gross margin stays high; renewals improve; partner channels reduce direct sales cost; and the same intelligence engine powers multiple deployment models. That is a good business if it works. The current reported numbers show the ambition, not the proof.
False positives are not a technical footnote
False positives are often discussed as a product-quality issue. For Intrusion they are also a pricing issue, a sales issue and a trust issue. The customer is not merely buying a report. It is granting a security tool the right to stop traffic. Every incorrect block can become an operational cost: a broken application, a delayed public service, a failed backup, a customer complaint, an emergency exception, a support call, or a leadership meeting about why a security vendor interrupted work.
That does not mean inline blocking is a bad idea. It means the product must earn its authority. Intrusion's observe mode is economically important because it lets the buyer compare claimed value with production reality. A customer can ask what would have been blocked, whether those blocks were legitimate, what business systems were involved, which exceptions are needed, and how much staff time the product creates or saves. A prevention tool moves from promise to purchase only when the report convinces the operations team as well as the security team.
The false-positive problem is also why reputation history is central to Intrusion's story. The company argues that decades of IP and DNS intelligence make its decisions better than a simple threat feed or signature tool. If that is true, it lowers the cost of trust. A buyer can accept automation when the evidence shows that the decision engine is conservative enough to protect normal operations and aggressive enough to stop harmful traffic.
But independent public evidence is limited. Company pages, partner quotes and customer testimonials are useful signals. They are not the same as a broad, audited technical study of blocking accuracy, false positives, false negatives, retention and operational impact across many customer environments. The company's prior legal history increases the burden. The SEC settled charges over older Shield marketing statements, including allegations that public claims overstated beta conversion. A separate class settlement was approved over alleged Shield-related misrepresentations.
Current management, current products and current claims may be different; the point is that the market should ask for evidence, not adjectives.
This is why Intrusion's best path is not louder marketing. It is measured proof. Publish enough anonymized deployment evidence to show what customers learn in observe mode, how often they move to protect mode, what categories are blocked, how exceptions are handled, and how many customers renew after the first year. Buyers do not need every proprietary detail. They do need confidence that the product will not turn risk reduction into operational noise.
The supplier and channel story is mixed
Intrusion's supplier dependencies appear manageable on paper. The 2025 filing says the company uses certain software and solution license agreements that add value to its cybersecurity solutions but are not considered material and are generally available to other parties on similar terms. That reduces the risk that a single unavailable supplier breaks the offering. At the same time, the company depends on practical infrastructure: hardware for on-premise appliances, cloud marketplaces, AWS and Azure deployment mechanics, support systems, resellers and managed providers.
The channel story is more important. A small cybersecurity vendor cannot outspend the largest platforms on brand, field sales or ecosystem reach. It needs distribution leverage. PortNexus is one such route. The partnership embeds Intrusion security into MyFlare and PLEDGE-related public-safety and mobile-field deployments. That is strategically sensible because it changes the buyer conversation. Intrusion is not asking every small customer to evaluate a stand-alone cyber product; it becomes part of a safety or fleet solution that already has a reason to be purchased.
The P.O.S.S.E. program extends that logic into law enforcement. Intrusion says the program uses Shield OnPremise to help protect sheriff and law-enforcement environments, and company materials describe pilot adoption and blocked threats. If the channel can reach many small public-sector buyers through a trusted partner, it could diversify revenue. It also fits the service-continuity theme: a sheriff's office or school system may not have a large security staff, but it has low tolerance for downtime or compromise.
The risk is that partner announcements are not revenue. A channel can look large in logos and small in collections. Public-safety customers face funding cycles, procurement rules, political scrutiny and budget limits. A partner may absorb installation and first-line support, improving Intrusion's margin profile, but it also controls part of the customer relationship. Intrusion needs the channel to produce recurring revenue with low churn, not just demonstrations and anecdotes.
The cloud marketplace route has similar strengths and limits. Being on AWS and Azure lowers procurement and deployment friction, especially for cloud-native teams and managed-service providers. It also puts Intrusion beside many alternatives. The listing makes pricing transparent and testing easier, but it does not solve demand creation. A buyer browsing a marketplace still asks why Shield belongs in the budget ahead of native cloud firewalls, security groups, WAF tools, SASE products, managed detection or the security features already bundled into a cloud or endpoint platform.
VigilAigent can change the math, but not by press release alone
The June 2026 VigilAigent acquisition is the most important new development because it attacks Intrusion's core weakness: scale. Management says the acquired business adds about $3.5 million of annual recurring revenue, more than 80 reseller partners and an installed base of about 1,000 customers. If those claims translate into retained, collectible revenue, the acquisition could nearly transform Intrusion's revenue base compared with 2025 commercial revenue.
The strategic idea is clear. Intrusion has a long-running threat-intelligence asset and prevention products. VigilAigent brings a managed security service provider platform, customer base, reseller network and event-processing capability. The combination could give Intrusion a broader service wrapper around its blocking intelligence. Instead of selling only a security control, Intrusion could sell a managed outcome, attach Shield to existing customers, and use the acquired channel to reduce sales friction.
The deal structure shows both opportunity and stress. Intrusion acquired 60% at the first closing for $1.95 million consideration, mostly paid in stock, with only $160,000 of cash plus a deposit credit. The second closing for the remaining 40% requires $1.3 million in cash and depends on conditions, including approvals. Earn-outs of up to $6.9 million are tied to ARR and operating cash-flow milestones. Those milestones are useful because they force the seller's upside to depend on actual business performance. They also imply that the acquired company must grow materially for the full consideration to be justified.
For Intrusion, this is a race between integration and capital. If the acquisition adds recurring revenue quickly, improves gross profit, gives Shield more accounts to sell into, and reduces concentration, it could be the commercial bridge the company needed. If it consumes management attention, requires cash the company does not comfortably have, or produces revenue that is less durable than advertised, it could add complexity to an already fragile balance sheet.
The acquisition also changes the evidence burden. Before the deal, investors could ask whether Shield could become a commercial product. After the deal, they should ask whether Intrusion can report cleanly on acquired ARR, retention, cross-sell, gross margin, customer count, reseller productivity and cash conversion. ARR is a useful metric only when it renews and collects. A larger top-line story that still burns cash would not answer the core question.
Capital pressure limits patience
Intrusion's balance sheet does not give it unlimited time to prove the thesis. At March 31, 2026, the company had $1.4 million in cash and negative working capital. It used $1.8 million of cash in operations during Q1. After quarter-end, it raised $3.0 million in cash through a secured Streeterville note. That note carries more than ordinary interest cost.
It has an original issue discount, daily compounding, a monitoring-fee feature that can increase the outstanding balance, first-priority security over assets and intellectual property, covenants, a participation right in future financings, and monthly redemption rights beginning six months after issuance.
This kind of financing is understandable for a small public company trying to bridge to contracts and a strategic acquisition. It is also a signal. Customers and investors should recognize that Intrusion is not funding growth from abundant free cash flow. The company is relying on external capital while trying to convert product claims into revenue. The secured nature of the note means the lender has strong protection. Common shareholders and employees bear more of the execution risk.
Nasdaq compliance adds pressure. The May 2026 minimum-bid notice does not immediately delist the stock, but it gives the company a deadline and raises the possibility of a reverse split or other measures if the share price does not recover. A weak share price makes stock consideration more dilutive and can complicate customer confidence, employee retention and future financing. Security buyers usually do not select vendors solely on stock price, but mission-critical customers do care whether a small vendor will be around to support the product.
This capital context changes how to read management's profitability target. Management says it expects improvement and has pointed to contract recovery, state-government work, P.O.S.S.E. momentum and the acquisition. Those could help. But the company needs more than a better quarter. It needs a visible path to cash self-sufficiency. A product with high gross margin and low customer churn can earn that path. A company dependent on intermittent government timing, secured notes and stock issuance cannot assume it.
Competition is not just named rivals
Intrusion names Darktrace, Trellix and Recorded Future as principal competitors in the data-mining and advanced-persistent-threat markets. Those are meaningful comparisons, but the real buyer alternative set is wider. A chief information security officer or managed-service provider can allocate the same dollar to a next-generation firewall, endpoint detection and response, extended detection and response, zero-trust access, SASE, cloud-native firewalls, DNS security, WAF, threat intelligence, SIEM, managed detection, vulnerability management, backup, cyber insurance or staff.
That matters because Intrusion's category is not protected by a clean budget line. A buyer may like the prevention thesis and still decide that a larger platform is easier to justify. Microsoft can bundle analytics and security into an enterprise relationship. CrowdStrike can expand from endpoint into cloud, identity, exposure and SIEM. Palo Alto Networks can attach threat prevention to firewalls and a broader security platform. Cloudflare can protect network edges through its global infrastructure. Zscaler can frame traffic control inside a broader zero-trust exchange.
Darktrace can argue for self-learning behavior across network, cloud, OT and email. Trellix can sell NDR and related response tools. Recorded Future shows how well-capitalized threat intelligence can become when tied to a large financial-network owner.
Intrusion's answer must be specificity. It should not try to sound like every platform. Its strongest claim is that its owned historical reputation engine can block dangerous communications quickly across specific deployment points without requiring a full platform replacement. If the company can prove that, it can coexist with larger tools. The buyer does not need to rip out the existing stack; it can add a blocking layer where the risk and price justify it.
The danger is being perceived as a point product with public-company overhead and limited integration gravity. Security teams are already consolidating vendors in many environments. They prefer fewer consoles, fewer renewals and fewer small suppliers to diligence. Intrusion's Command Hub and managed-service acquisition help address that, but the company needs evidence of reduced complexity. A prevention layer that adds exceptions, support tickets and another renewal fight will lose to incumbents. A prevention layer that quietly removes risky traffic and creates clear reports can win targeted deployments.
Regulation and geopolitics help the need, not automatically the vendor
The policy environment supports Intrusion's problem statement. NIST's zero-trust architecture work and CISA's maturity model make clear that modern security cannot rely on static perimeter trust. Federal and critical-infrastructure buyers are under pressure to verify, segment, monitor, log and reduce exposure. Ransomware guidance emphasizes layered resilience rather than one magic product. AI-augmented attack patterns, vulnerability exploitation and mobile/social engineering keep raising the cost of weak controls.
That environment should increase willingness to pay for useful controls. It does not guarantee willingness to pay Intrusion. Federal standards define architectures and maturity goals; they do not bless one vendor's reputation engine. In fact, the standards context may make buyers more demanding. They will ask how Shield fits identity, data, device, network and application pillars. They will ask whether it improves zero-trust outcomes or merely uses zero-trust language. They will ask for logging, auditability, integration, exception handling, encryption compatibility, procurement compliance and continuity plans.
Geopolitics can help demand in public-sector and critical-infrastructure markets. State-linked attacks, ransomware groups, cloud abuse and supply-chain compromise make outbound and inbound visibility more important. Small agencies and local institutions may increasingly need security controls without large security teams. Intrusion's automated blocking pitch fits that need.
But public-sector demand brings procurement delays, budget timing, funding constraints and contract cancellation rights. Intrusion's own filings warn that government customers may cancel orders or contracts with little or no prior notice and that government spending patterns can disrupt sales. The same market that validates the company can also make revenue lumpy. A small company cannot treat government demand as a smooth subscription base until renewals and multi-customer diversification prove it.
The unofficial signals are useful but bounded
Intrusion has a number of market signals that should not be ignored. It has product pages that describe specific deployment modes rather than only abstractions. Its AWS Marketplace listing is real and includes visible pricing. Partner materials from PortNexus explain a concrete embedded-security route. Company-curated proof pages include customer and partner quotes. Unofficial earnings-call transcripts capture management discussion of PortNexus, cloud listings, government timing and pricing ranges. The acquisition press release gives concrete numbers for ARR, partners and customers.
These signals are encouraging because they show motion. They suggest the company is not just describing an old government tool but trying to build a commercial channel. They also help explain why Intrusion might appeal to small public agencies or organizations that need security but cannot build a large security function. Embedded security inside a public-safety platform is often easier to buy than a stand-alone enterprise cyber tool.
The signals remain bounded because they are not the same as reported recurring revenue and cash flow. Testimonials do not measure churn. Partner pages do not show Intrusion's margin. Marketplace listings do not show usage. Management commentary does not prove that contract delays will reverse. ARR statements in an acquisition release do not prove collection quality or renewal durability. For a small vendor with prior Shield-marketing legal history, the difference between signal and proof matters.
The right analytical posture is neither dismissal nor credulity. The product may be useful. Customers may value it. The acquisition may be strategically sound. But the company should be judged on harder future evidence: revenue mix, recurring revenue, customer count, renewal rates, commercial contribution, gross margin, operating cash flow, concentration reduction and capital needs.
What would make the judgment better
There is a credible bullish case, but it needs specific facts. First, Intrusion would need to show that Q1 2026 was a timing trough, not a demand warning. Delayed government revenue should appear in later quarters, preferably without creating an even greater dependency on one program. Second, the $4 million state-government contract should convert into recognized revenue and customer validation. Third, the P.O.S.S.E. and PortNexus channels should produce measurable commercial or public-sector subscription contribution, not just deployments or pilots.
Fourth, VigilAigent should show up as retained ARR with improving economics. If the acquisition really brings $3.5 million of annual recurring revenue, more than 80 partners and about 1,000 customers, Intrusion should be able to report better diversification. The key is not only top-line addition. It is cross-sell. The strategic value of the deal is higher if Shield can attach to those customers and if the managed-service wrapper makes the prevention layer easier to buy and support.
Fifth, the company needs product evidence that reduces false-positive concern. Even aggregated metrics would help: observe-to-protect conversion, renewal rate, number of protected sites, typical exception burden, customer retention by product, and independent case studies with enough technical detail to be credible. Security buyers do not need the secret sauce disclosed. They do need to trust the outcome.
Sixth, Intrusion needs capital proof. A turn toward positive operating cash flow would change the risk profile more than another product announcement. Even a credible narrowing of operating loss, combined with recurring revenue growth and less dilutive financing, would matter. Nasdaq compliance without repeated reverse-split pressure would also improve the commercial story because customers and partners could focus on product value rather than vendor viability.
The facts that would reverse the cautious judgment are therefore concrete: sustained revenue above the post-acquisition base, lower government concentration, material Shield subscription growth, positive operating cash generation, low false positives, strong renewal evidence, and fewer emergency financings. Without those, the company remains dependent on hope that upcoming contracts and channels will arrive quickly enough.
The final call
Intrusion's business is built around an economically sensible idea: the most valuable alert is the one the customer never has to read because the harmful connection was stopped. That is a real customer pain point. It fits a world of ransomware, exploit-driven breaches, cloud sprawl, thinly staffed public institutions and overloaded security teams. It is also a better pitch than selling more noise.
But a good prevention thesis is not the same as a proven company. Intrusion's reported revenue base is small, concentrated and still heavily tied to government work. Its operating costs exceed gross profit by too much. Its liquidity has required secured financing. Its share listing is under pressure. Its commercial Shield traction has not yet become the majority of revenue. The new VigilAigent acquisition may improve that picture, but the improvement must be earned in reported numbers.
The right judgment is that Intrusion deserves attention as a niche prevention vendor with potentially valuable data, a clear buyer problem and new commercial routes. It does not yet deserve the benefit of assuming that avoided-loss pricing will automatically cover data, engineering, support, sales, public-company overhead and capital costs. The company must prove that customers will not only test Shield but renew it, trust it in protect mode, expand it across environments, and buy it through channels that lower acquisition cost.
If Intrusion does that, its economics can change quickly. A small company with high gross margin, growing recurring revenue, a proprietary reputation asset and a partner-driven sales model can become much more valuable than its historical losses suggest. If it does not, the same prevention thesis will remain available to larger vendors with broader platforms, deeper balance sheets and easier procurement paths. Intrusion's opportunity is real, but narrow: make threat prevention worth more than false positives before the market decides that the safer purchase is somebody else's bundle.
Sources
- https://www.sec.gov/Archives/edgar/data/736012/000168316826002196/intz_i10k-123125.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826003931/intrusion_i10q-033126.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826003916/intrusion_ex9901.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826003758/intrusion_8k.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826002782/intrusion_8k.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826005193/intrusion_8k.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826005193/intrusion_ex9901.htm
- https://www.sec.gov/Archives/edgar/data/736012/000168316826005193/intrusion_ex1001.htm
- https://ir.intrusion.com/financials/sec-filings/default.aspx
- https://ir.intrusion.com/news/default.aspx
- https://ir.intrusion.com/events-and-presentations/
- https://ir.intrusion.com/overview/
- https://intrusion.com/
- https://intrusion.com/company/about/
- https://intrusion.com/why-intrusion/
- https://intrusion.com/products/
- https://intrusion.com/products/on-premise-network-protection/
- https://intrusion.com/products/cloud-network-security/
- https://intrusion.com/applied-threat-intelligence/
- https://intrusion.com/document-hub/
- https://intrusion.com/proof/
- https://aws.amazon.com/marketplace/pp/prodview-4pobngnssr5ug
- https://docs.aws.amazon.com/marketplace/latest/userguide/pricing-overview.html
- https://docs.aws.amazon.com/marketplace/latest/userguide/pricing-ami-products.html
- https://www.nasdaq.com/press-release/intrusion-inc-launches-posse-program-expanding-deployment-shield-technology-2026-02
- https://myflarealerts.com/press-releases/intrusion-cyber-security-now-inside/
- https://myflarealerts.com/press-releases/portnexus-corporation-and-intrusion-inc-to-deliver-immersive-demonstration-of-myflare-alert-school-safety-system-at-texas-information-security-forum-may-28-29-2025/
- https://www.sec.gov/Archives/edgar/data/736012/000168316825008165/intrusion_ex9901.htm
- https://www.fool.com/earnings/call-transcripts/2026/03/25/intrusion-intz-q4-2025-earnings-call-transcript/
- https://www.alphaspread.com/security/nasdaq/intz/investor-relations/earnings-call/q4-2025
- https://www.sec.gov/enforcement-litigation/litigation-releases/lr-25854
- https://law.justia.com/cases/federal/district-courts/texas/txedce/4%3A2021cv00307/205488/74/
- https://securities.stanford.edu/filings-case.html?id=107692
- https://uspto.report/company/Intrusion-Inc
- https://patents.google.com/patent/US8056115B2/en
- https://www.uspto.gov/patents/search/patent-public-search
- https://csrc.nist.gov/pubs/sp/800/207/final
- https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
- https://www.cisa.gov/stopransomware
- https://www.fbi.gov/file-repository/2025_ic3report.pdf/view
- https://www.verizon.com/business/resources/reports/dbir/
- https://www.darktrace.com/products/network
- https://www.trellix.com/products/network-detection-and-response/
- https://www.recordedfuture.com/platform/threat-intelligence
- https://www.mastercard.com/news/press/2024/september/mastercard-to-acquire-recorded-future/
- https://www.paloaltonetworks.com/network-security/next-generation-firewall
- https://www.crowdstrike.com/en-us/platform/
- https://www.cloudflare.com/magic-firewall/
- https://www.zscaler.com/products-and-solutions/zero-trust-exchange-zte
- https://www.microsoft.com/en-us/security/business/microsoft-sentinel

