SOC status:Duty analyst on shift

UK Cyber Defence

Managed SOC · Penetration testing · Virtual CISO · Consulting · Cyber Essentials

Cyber defencethat lets you get onwith the day.

Twenty-four-hour detection and response, honest testing and senior advice for UK organisations that would rather run their business than run a security operation. One team, one company, based at The Officers' Mess in Duxford.

CREST accreditedISO 27001 · ISO 9001Cyber Essentials PlusDuxford, CambridgeshireEst. 2009

Accredited

CRESTPenetration testing · SOC · Vulnerability assessmentCREST AI CharterResponsible AI in security servicesISO 27001Information security managementISO 9001Quality managementCyber Essentials PlusIndependently assessedCMMCLevel 3
00Mandate

Most organisations do not need a security department. They need one they can call.

Since 2009 we have tested and defended organisations where a bad day has real consequences: regulators, patients, passengers, payrolls. We built our own SOC platform, we test our own defences, and we say what we think. Everything we do follows one model — detect what others miss, defend what others overlook, disrupt the attackers behind it — and the result is fewer surprises, calmer boards and a security posture you can explain to an auditor in one page.

Services
Managed SOC · Penetration testing · Virtual CISO · Consulting · Cyber Essentials
Model
Detect · Defend · Disrupt
Clients
Regulated, critical and just-plain-busy organisations across the UK and Europe
Established
2009 · Duxford, Cambridgeshire
Standards
CREST · ISO 27001 · ISO 9001 · Cyber Essentials Plus · CMMC L3

How we work

Detect. Defend. Disrupt.

Three disciplines, one team. Offensive, defensive and intelligence work feed each other instead of living in separate companies.

01

Detect

Continuous monitoring, threat hunting, engineered detections and intelligence-led correlation through SOC365, our own platform.

02

Defend

Incident response, containment, forensics and the engineering changes that close attack paths for good.

03

Disrupt

Penetration testing, red teaming and deception devices built into the SOC, so attackers are found on our terms rather than theirs.

01

Managed SOCSOC365 · 24/7

Detection and response, around the clock.

SOC365 watches your endpoints, identities, cloud, network and OT every hour of every day, staffed by analysts who can tell a real intrusion from a noisy scanner. Our own platform, our own detection engineering, our own deception network and our own threat intelligence — with EmilyAI, the SOC assistant we built in 2018, taking the repetitive work so analysts can concentrate on judgement. You get a named duty analyst, a measured response time and reporting a board can read.

Coverage
Endpoint · Identity · Cloud · Network · OT · Applications
Response
Analyst-validated alerts · Guided or pre-authorised containment
Platform
SOC365 · DecoyPulse deception · Pulsar endpoint control
Reporting
Monthly service review · Board-ready incident reports

02

Penetration testingCREST · Red team

Testing by people who also do the defending.

External, internal and Active Directory, web, API, mobile, cloud, wireless and full red-team engagements, following OSSTMM and PTES and mapped to MITRE ATT&CK and OWASP. Scoped in a thirty-minute call and reported in plain English with a fix list your engineers can actually work through. Because we run a SOC too, we know which findings get exploited in practice and which merely look alarming.

Accreditation
CREST member company
Scope
External · Internal/AD · Web · API · Mobile · Cloud · Wireless · Red team
Reporting
Executive summary + engineer's fix list + attack-path mapping
Retest
Included

03

Virtual CISOLeadership on retainer

A security leader, without the salary.

Strategy, risk registers, board papers, supplier reviews, insurer questionnaires and the awkward conversations with auditors, handled by someone who has held the CISO title at FTSE-listed companies. A fixed number of days a month, a standing agenda, and a named person your board recognises.

Format
Retained days per month
Outputs
Strategy · Risk register · Board reporting
Experience
Former FTSE 100 and Microsoft Europe CISO
Fit
50 to 2,000 staff

04

ConsultingCompliance · Engineering · Readiness

Getting ready, staying ready.

ISO 27001 and Cyber Essentials programmes, DORA, NIS2 and PCI DSS gap assessments, incident response plans and tabletop exercises your executives will remember — plus the security engineering that makes the paperwork true: identity hardening, cloud and Microsoft 365 uplift, segmentation and the logging your SOC needs. Practical work with clear deliverables, not a slide deck that gathers dust.

Frameworks
ISO 27001 · NIS2 · DORA · PCI DSS · NIST CSF · Cyber Essentials
Engineering
Identity · Cloud · Segmentation · Endpoint · OT/IoT
Exercises
Board and technical tabletops
Deliverables
Plans, policies, baselines, gap reports

05

Cyber EssentialsCertification · Plus audits

Certified in days, not months.

We take organisations through Cyber Essentials and Cyber Essentials Plus with the minimum of fuss: a readiness check against the five controls, the fixes that matter, the assessment, and the certificate your customers and insurers ask for.

Levels
Cyber Essentials · Cyber Essentials Plus
Typical time
Two to four weeks
Includes
Readiness check · Remediation guidance · Plus audit

Measured performance

<8min

Mean time to detect

<20min

Mean time to respond

95%

Threat disruption success

99.995%

Service availability

  1. Mean time to detect, Mean time to respond, Threat disruption success, Service availability: SOC365 service performance figure

How an incident flows through SOC365

From signal to all-clear

  1. Stage 01

    Detect

    Behavioural analytics, engineered detections, threat intelligence and deception signals fire across endpoint, identity, cloud and network telemetry.

    Input
    Telemetry · Deception · Intel
  2. Stage 02

    Validate

    An analyst confirms the signal, gathers context and suppresses the false positives so you only hear about what is real.

    Who
    Named duty analyst
  3. Stage 03

    Contain

    Isolation, credential locking and blocking, executed with your approval or automatically where you have pre-authorised it.

    Time
    Minutes, not hours
  4. Stage 04

    Report

    Root cause, actions taken and what to change next, in a form your board and your auditors can both use.

    Output
    Incident report · Monthly review

Start a conversation

Not sure which service you need? Neither are most people when they first call.

Thirty minutes with an analyst or our CEO. We will tell you what we would do in your position, whether or not it involves us.