Cyber · Information Security · AI Governance

Cyber security deep enough to govern AI

An independent consultancy for organisations where the consequences of failure reach beyond the balance sheet.

Cyber and information security is our foundation and our core practice. It is also what gives us the depth and breadth to advise on AI — because knowing how to use AI safely starts with knowing exactly what unsafe looks like. We have spent careers finding out.

Accreditation
CSyPCHARTERED Chartered Security Professional

The highest chartered designation in the security profession, spanning cyber, physical and personnel security.

ChCSPCHARTERED Chartered Cyber Security Professional

Chartered status in cyber security specifically, awarded against the UK Cyber Security Council standard.

Very few practitioners in the UK hold both. Our practice is led by someone who does.

Cyber Essentials Plus certified Cyber Essentials Plus certified

Independently audited against the UK government-backed scheme — the standard we help our own clients reach.

ISO 27001 Lead Auditor BSI Lead Auditor MBCS NCSC engaged
Our core practice

Cyber & Information Security

CISO expertise and leadership across the full spectrum — governance, risk and compliance, security assurance and penetration testing, identity and privileged access, infrastructure security, security architecture, and CISO as a Service. Delivered inside FTSE 100 estates, critical national infrastructure and national health data.

  • CISO as a Service
  • GRC & certification
  • Security architecture
  • IAM & PAM
  • SOC & SIEM
  • ISO 27001
Explore Cyber & Information Security
Built on that foundation

AI Governance & Assurance

What AI is used for, what data it touches, who owns it and what controls hold it — then the governance framework and the secure operating model underneath.

  • Defensibility reviews
  • ISO 42001 & EU AI Act
  • Fractional ISO
Explore AI Governance
£47.2m
Security transformation portfolio delivered
79.9%
Of realised benefits landing against EBITDA
1.5 3.0
NIST CSF maturity uplift, FTSE 100 CNI
100%
First-time certification success rate
10
National data security standards co-authored
Who we are

A cyber security consultancy that understands AI

We came to AI from security, not the other way round. That order matters, and it shows up in the work.

Our people have spent their careers securing airline groups, energy utilities, national health data and government estates. That is the practice, and it remains the majority of what we do. It is also precisely why boards ask us about AI — because the questions that decide whether AI can be used safely are identity, data classification, supplier assurance and incident response. Those are cyber security questions wearing different clothes.

The foundation

Deep cyber security practice

Chartered practitioners, ISO 27001 lead auditors, an NCSC working relationship, and delivery inside estates where downtime is measured in grounded aircraft.

What it earns us

Credibility on AI

An AI policy is only as strong as the controls beneath it. We can write both, and we will tell you when the foundation has to come first.

Using AI safely is not a separate discipline. It is security, applied to something new.

AI Governance & Assurance

AI adoption your board can explain, govern and defend

AI is already entering your business through staff, suppliers, client expectations and everyday tools. It is usually live across the organisation before anyone can say who owns it, what data it touches, or whether its use could be defended to a client, an insurer or a regulator.

Most AI advice starts with the tools. We start with the conditions under which their use can be defended — and we build the secure operating model underneath the policy, because that is what makes the policy true.

Where clients start

Two front doors, both fixed-scope

Neither requires a programme commitment. Both give your board something it can act on.

Cyber & information security

Security posture assessment

An honest read on where your controls actually stand, benchmarked against the framework your regulators and insurers already use.

  • Maturity assessed against NIST CSF, ISO 27001 or the NCSC CAF
  • The gap between the posture as reported and the posture as it is
  • A prioritised remediation plan, sequenced by risk not by ease
  • Certification readiness where clients or insurers require evidence
See the practice
AI governance

AI Defensibility Review

A fixed-scope, fixed-fee review your board can commission on its own authority — rather than a study that ends in a slide deck.

  • An AI use register, risk-scored red, amber or green
  • Each use held to four questions: advantage, risk, control, owner
  • An owner-led action plan: what to stop, permit and pilot
  • A concise written report and a leadership briefing
See the practice
Full service range

Four practices, one discipline

Security is the thread running through all of it. Most engagements draw on more than one practice.

Results

Delivered where failure carries consequences

Our clients operate critical national infrastructure, handle national health data and run global operations. References are available at C-suite level.

Sectors

Where a breach is more than a line in the accounts

Aviation & air transportAirlines, groups, MRO, aftermarket
Energy & CNIUtilities, national infrastructure
Financial servicesBanking, insurance, payments
Logistics & supply chainAir, land and sea operations
Health & public sectorNational health data, government
Professional servicesArchitecture, engineering, advisory
Automotive & manufacturingIndustry 4.0, plant and OT
Standards we work to
ISO/IEC 27001ISO/IEC 27701ISO/IEC 27017Cyber Essentials PlusNIST CSF 2.0NCSC CAFUK GDPRPCI DSSISO/IEC 42001EU AI ActNIST AI RMFIEC 62443
The next step

Start with one hour

Bring us the thing you are least comfortable with — a certification deadline, a client questionnaire you cannot answer, an identity estate nobody fully understands, or AI already running across the business without an owner. We will give you a straight read on where you stand.

Arrange the briefing

No preparation required. No obligation to proceed.