Industries

Industries we support.

We work with regulated and high-trust organisations across the UK. Every sector below is one we run as a day job — not a brochure entry.

At a glance

Five sectors where we do most of our work.

  • Legal

    Law firms hold privileged material that attackers actively target. Controls have to hold up to SRA scrutiny and client due diligence questionnaires.

  • Healthcare

    NHS suppliers, private clinical groups and HealthTech vendors operate against a patient-safety bar and the DSPT submission cycle.

  • Retail & e-commerce

    Online merchants and omnichannel retailers face card-data obligations, account-takeover pressure and supplier-driven downtime risk.

  • Financial services

    Wealth managers, IFAs, fintechs and payments firms need controls that hold up under FCA scrutiny and client due diligence.

  • Channel / IT partners

    MSPs, IT consultancies and resellers who need a credible security partner to stand behind their clients without competing for the relationship.

Sector · Healthcare

Healthcare

NHS suppliers, private clinical groups and HealthTech vendors operate against a patient-safety bar and the DSPT submission cycle.

Top risks
  • Ransomware on clinical systems with direct impact on EPR, PACS and scheduling.
  • Supply-chain compromise via MedTech and SaaS vendors.
  • Insider access to sensitive records, including VIP and safeguarding cases.
What they typically need
  • DSPT evidence mapped to the controls you actually run.
  • Segmentation between clinical, corporate and guest networks.
  • Clear reporting lines aligned to NHS England and the ICO.
How our services fit
  • Managed Security

    Out-of-hours cover and clinical-aware incident handling.

  • VMaaS

    Coverage of externally exposed clinical portals and patient-facing services.

  • Penetration Testing

    Scoped to clinical-safety boundaries and integration points.

  • Compliance Support

    DSPT, DCB0129/0160 and Cyber Essentials Plus evidence.

Proof we provide
  • Sample DSPT evidence index mapped to technical controls.
  • Quarterly clinical-risk review notes alongside the IG lead.
  • Incident runbook excerpt with NHS England notification timings.
Sector · Retail & e-commerce

Retail & e-commerce

Online merchants and omnichannel retailers face card-data obligations, account-takeover pressure and supplier-driven downtime risk.

Top risks
  • Magecart-style skimming and tampering of payment pages.
  • Account takeover and credential stuffing against customer portals.
  • PCI DSS scope creep through poorly segmented payment flows.
What they typically need
  • PCI DSS 4.0 alignment with realistic scope reduction.
  • Visibility of changes to checkout, tag managers and third-party scripts.
  • A response plan that protects revenue during peak trading.
How our services fit
  • Managed Security

    Change control and monitoring across storefront, ESP and payment estate.

  • VMaaS

    Continuous scanning of checkout, APIs and customer-facing services.

  • Penetration Testing

    Web application and API testing aligned to OWASP and PCI requirements.

  • Compliance Support

    PCI DSS 4.0 scoping, SAQ support and evidence collection.

Proof we provide
  • Sample monthly trading-risk report with peak-readiness checklist.
  • Redacted PCI scoping diagram and SAQ working papers.
  • Change-freeze and incident runbook for peak periods.
Sector · Financial services

Financial services

Wealth managers, IFAs, fintechs and payments firms need controls that hold up under FCA scrutiny and client due diligence.

Top risks
  • Authorised push payment fraud and impersonation of clients and staff.
  • Concentration risk in cloud, custody and KYC vendors.
  • Privileged access misuse on production systems.
What they typically need
  • Mapped important business services with measurable impact tolerances.
  • Third-party risk assessment of critical SaaS and payment providers.
  • Board and regulator-ready governance evidence each quarter.
How our services fit
  • Managed Security

    Monitoring, change control and structured monthly reporting.

  • VMaaS

    Continuous coverage of customer portals and authenticated APIs.

  • Penetration Testing

    Annual testing plus targeted red team exercises for mature clients.

  • Compliance Support

    FCA SYSC, PCI DSS and DORA-adjacent evidence.

Proof we provide
  • Quarterly governance pack ready for board and regulator review.
  • Third-party risk register with tiering and review dates.
  • Redacted important-business-service mapping example.
Sector · Channel / IT partners

Channel / IT partners

MSPs, IT consultancies and resellers who need a credible security partner to stand behind their clients without competing for the relationship.

Top risks
  • Client expectations outpacing in-house security capability.
  • Shared tooling and access creating cross-client blast radius.
  • Lack of independent evidence to support client audits and renewals.
What they typically need
  • A white-labelled or co-branded service that fits your delivery model.
  • Predictable commercials and clear demarcation of responsibility.
  • Reporting your clients can hand to their auditors without rework.
How our services fit
  • Managed Security

    Shared SOC capacity with named engineers and joint runbooks.

  • VMaaS

    Multi-tenant scanning with per-client reporting.

  • Penetration Testing

    Independent testing your clients can rely on at renewal.

  • Compliance Support

    Cyber Essentials, ISO 27001 and SOC 2 evidence support for your book.

Proof we provide
  • Sample partner pack with commercial model and service boundaries.
  • Per-client monthly report template you can co-brand.
  • Joint incident runbook covering handover and escalation.
Tell us your sector

Pick a sector and we'll point you at the right next step.

Each sector has a different starting point. Choose yours and we'll recommend where to begin.

Recommended next step for Legal:

See the legal sector page