Three Sectors. Deep Fluency in Each.
We work in environments where credentials, clearance, and delivery discipline matter more than generalist breadth. Three sectors served well, rather than twenty served superficially.
Defence Supply Chain
Tier 2 and Tier 3 UK defence suppliers navigating prime contractor flow-downs, JOSCAR reassessment cycles, and the ISO 27001 gate to the next contract.
- Who they are
- UK Tier 2 and Tier 3 defence suppliers ranging from 20-employee specialist engineering firms to mid-sized suppliers serving prime contractors. Holding Cyber Essentials Plus, operating under JOSCAR, and delivering to MOD primes and the wider defence supply chain.
- What they need
- ISO 27001 implementation alongside existing Cyber Essentials Plus. JOSCAR preparation. Supplier security questionnaire responses for prime contractors. SC-cleared programme leadership on classified-adjacent work. Evidence packages that pass supply chain assurance in the first round.
- How we deliver
- Fixed-scope engagements calibrated to the defence SME commercial reality. No subcontracting of delivery. Work aligned to MOD supplier assurance requirements and JOSCAR scoring thresholds. Sector fluency across defence supply chain, NATO multinational, and UK SECRET-accredited environments.
Regulated Enterprise
UK mid-market financial services, critical national infrastructure, energy, healthcare technology, and regulated professional services facing overlapping regulatory regimes.
- Who they are
- Organisations of 50 to 2,000 employees in financial services, energy and critical national infrastructure, healthcare technology, and regulated professional services. Operating under one or more of FCA, PRA, Ofgem, NHS, or sector-specific regulator oversight. Often running compliance programmes across multiple frameworks with overlapping evidence requirements.
- What they need
- ISO 27001 implementation for demonstrable information security management. ISO 42001 readiness where AI is deployed in regulated contexts. DORA and NIS2 scoping for organisations navigating the incoming obligations. Board-ready assurance narratives that translate technical controls into regulatory and commercial language.
- How we deliver
- We slot alongside internal compliance, risk, and IT leadership rather than replacing them. Fixed-scope deliverables. Joined-up regulatory scoping that recognises DORA, NIS2, the Cyber Security and Resilience Bill, and ISO 27001 and ISO 42001 as a connected set, not siloed exercises.
Public Sector Supply Chain
NHS suppliers, local authority suppliers, and CCS framework participants delivering services into the UK public sector under cleared delivery requirements.
- Who they are
- NHS suppliers, local authority suppliers, and CCS framework participants delivering technology, programme leadership, or compliance services into UK central government departments, arms-length bodies, and the public sector. Often subject to OFFICIAL or OFFICIAL-SENSITIVE handling requirements and NCSC guidance.
- What they need
- Embedded SC-cleared technical programme management for cleared delivery. ISO 27001 implementation calibrated against NCSC Cyber Assessment Framework and DSPT obligations. Cyber governance uplift aligned to GovAssure. AI governance frameworks for AI-driven public sector services. Delivery leadership that can operate under cleared handling requirements without friction.
- How we deliver
- Engaged through a direct preferred-supplier relationship. Embedded delivery rather than advisory-at-arms-length. SC clearance and public sector supply chain fluency from day one.
UK SaaS Scaleups
Series A through Series C UK SaaS, fintech, and healthtech organisations facing enterprise customer compliance demands. SOC 2, ISO 27001, and GDPR readiness for fast-growing tech businesses scaling toward enterprise sales.
- Who they are
- 50 to 300 employee UK SaaS, fintech, and healthtech businesses, Series A to C, UK-based or UK-headquartered. Engagement typically initiated by CTOs, Heads of Engineering, Heads of Compliance, or founders.
- What they need
- SOC 2 Type 1 and Type 2 readiness. ISO 27001 implementation calibrated for fast-growing tech businesses. GDPR alignment as standard. ISO 42001 for organisations formalising AI governance ahead of enterprise scrutiny. Cyber Essentials Plus where procurement requires it.
- How we deliver
- Senior practitioner-led delivery on a fixed scope, with the timeline agreed at scoping. Structured nineteen-activity ISO 27001 methodology. AI-accelerated execution via proprietary internal delivery tooling. Partner CPA firm for SOC 2 attestation, with clean separation between implementation and audit.
Defence Supply
JOSCAR Registered
Cyber Hygiene
Cyber Essentials Certified
Engagement Model
Founder-Led Delivery
