About us

We work as part of your security function, not alongside it

An independent consultancy for organisations where the consequences of failure reach beyond the balance sheet.

Cyber and information security is our core practice, delivered by chartered practitioners inside FTSE 100 estates, critical national infrastructure and national health data. Around that foundation sit three further practices — AI governance, cloud security and software engineering, and intelligent automation.

Who we are

Focused consulting, delivered by senior people

Cyberbase Consulting is an independent, rapidly growing consultancy providing focused solutions in cyber security and information security — and, increasingly, in the governance of AI that sits on top of them.

We are an agile company. We work with organisations of every size, from FTSE 100 groups and government departments through to professional practices that have no in-house security function at all. What does not change is who turns up: you work directly with our senior practitioners, which brings both quality and value — deep expertise without the overhead structures of larger firms.

Our consultants bring domain knowledge as well as technical depth. In sectors where a breach grounds aircraft, interrupts a utility or exposes patient records, understanding the operational consequence is as important as understanding the control.

We deliver with a transparent ethos that engages your teams rather than talking past them.

How we work

Integration, not a parallel workstream

Most security consulting creates a second team running beside the first. Findings arrive as a document, ownership never transfers, and the capability leaves when the invoices stop. We are built the other way round.

The usual arrangement

Consultants beside your team

01Separate workstream

The consultancy works apart from the internal function, with periodic updates rather than shared working.

02Findings delivered as a report

Analysis lands as a document. Understanding of it stays largely with the people who wrote it.

03Ownership stays external

Recommendations have no internal name against them, so nothing moves once attention shifts.

04The capability leaves

When the engagement ends, so does the expertise. The next problem needs another engagement.

The result is a dependency that has to be renewed rather than a capability that compounds.

How Cyberbase works

Practitioners inside your function

01Full integration

We work as part of your core security function, in your meetings and your tooling, as one team rather than two.

02Transparency by default

You see the working, not just the conclusion. Stakeholders across the business are engaged as the analysis forms.

03Every recommendation gets an internal owner

Wherever an internal owner exists, the action carries their name — including where that means less work for us.

04We mentor, train and hand over

Alongside the delivery we develop your in-house skills, so the capability stays behind when we leave.

A consultancy that cannot describe how you stop needing it is selling a dependency. We would rather be the firm you call again because you chose to.

Commercial models

Structured to suit the work, not our billing

We provide consulting services on a time and materials or statement of work basis, and as ongoing retained capability where a named accountable role is what is actually needed.

Time and materials

Where the scope will evolve, or where our people are integrating into your teams for a sustained period. Transparent rates, agreed seniority, no hidden pyramid.

Statement of work

Fixed scope, fixed fee, defined deliverables. The right structure for assessments, reviews and certification programmes where the outcome can be specified up front.

Retained capability

CISO as a Service and fractional Information Security Officer, on an agreed number of days per month with a formal review point at which the commitment can be adjusted.

What we hold to

Four things you can hold us to

01

We will tell you what you do not want to hear

If the cyber baseline has to be closed before the AI programme means anything, we say so. If certification is expensive overhead you do not need, we say that too. An adviser who only confirms your plan is not adding anything to it.

02

We recommend ourselves only where it is warranted

Our reports routinely name a client's existing advisers — legal, insurance, managed-services partner — as the right route for work that is not ours. External help is proposed where specialist depth genuinely warrants it, not by default.

03

Governance has to live in your organisation

Every recommendation carries an internal owner wherever one exists. A framework that needs a consultant in the room to operate is not governance, and it will not survive its first year.

04

Security work is judged on whether it holds

Not on the size of the deck. We work to the standards your regulators, insurers and clients already recognise, because that is the evidence that counts when someone asks.

Accreditation

Chartered, audited and independently certified

Security advice is worth what the person giving it can evidence. Ours is led by chartered practitioners, and we hold ourselves to the same certification we help clients reach.

Professional standing
CSyPCHARTERED Chartered Security Professional

The highest chartered designation in the security profession, spanning cyber, physical and personnel security.

ChCSPCHARTERED Chartered Cyber Security Professional

Chartered status in cyber security specifically, awarded against the UK Cyber Security Council standard.

Very few practitioners in the UK hold both. Our practice is led by someone who does.

Cyber Essentials Plus certified Cyber Essentials Plus certified

Independently audited against the UK government-backed scheme — the standard we help our own clients reach.

Also held across the practice

  • ISO 27001 Lead Auditor — with BSI-qualified Lead Auditors on the team
  • MBCS — Member of the British Computer Society
  • CISSP and CCSP — information systems and cloud security certification
  • NCSC working relationship — threat intelligence, bulletins and incident reporting
  • 100% first-time certification success rate, including ISO 27001 Stage 2 audits completed with zero major nonconformities
  • SAFe, PRINCE2 and MSP — for programme and agile delivery at scale
Sectors

Where a breach is more than a line in the accounts

We built our practice in transport and mobility — airlines, aerospace, rail, shipping, courier and logistics — and that depth remains. The same disciplines now carry into every sector where disruption has consequences beyond the balance sheet.

Aviation & aerospaceAirlines, groups, MRO, aftermarket
Energy & CNIUtilities, national infrastructure
Financial servicesBanking, insurance, payments
Logistics & shippingRail, road, sea and courier networks
Health & public sectorNational health data, government
Professional servicesArchitecture, engineering, advisory
Automotive & manufacturingIndustry 4.0, plant and OT
What we do

One core practice, three built around it

Our people

You work with the people who scoped the work

Leadership

Chartered practitioners who have held the accountability themselves

Our leadership has sat on a national advisory panel shaping data security policy, held senior information risk accountability across government and utilities, and led security transformation inside FTSE 100 airline groups. Not advisers describing the role from outside it.

Meet our leadership team
National
Advisory panel shaping data security policy
SIRO
Senior information risk accountability, government and utilities
£47.2m
Security transformation portfolio delivered
The next step

Start with a conversation

Bring us the thing you are least comfortable with — a certification deadline, a client questionnaire you cannot answer, an identity estate nobody fully understands, or AI already running across the business without an owner. We will tell you what it takes, and whether we are the right firm for it.

Arrange a conversation

References available at C-suite level on request.