Skip to content
Lybica

Security as a standing service

Prove your security. Then keep proving it.

Compliance, testing and monitoring, run as continuing services for UK companies — so the evidence is already current the day a prime, a buyer or an assessor asks for it.

The problem

The old choice was bad at both ends.

You have had two options, and both are snapshots. A consultant writes down what you say you do — out of date before anyone reads it. An assessor checks whether you actually do it, once a year — a true picture of a single day. Neither is watching. Neither is evidence.

Meanwhile the questionnaires keep arriving — a prime's flow-down, a council's procurement pack, an enterprise buyer's due diligence. Same questions, different words, always a deadline. And answered from scratch each time, because there has never been one place for the answers to live.

Three services. One standing defence.

Each one runs continuously on annual terms — not a project that ends. Together they answer the three questions every prime, assessor and customer security team asks in some form: are you in order, are you tested, are you watched?

  • Lybica Atlas

    The living map.

    One place holding your assets, controls, risks, suppliers and continuity plans — current, rather than eighteen months stale. Map the controls once, and the next questionnaire is a lookup instead of a project.

    Explore Atlas →

  • Lybica Crucible

    The proving fire.

    Independent testing at the frequency you choose — nightly to monthly — with AI establishing what is genuinely exploitable and a named person deciding what actually matters before you see it.

    Explore Crucible →

  • Lybica Vigil

    The watch.

    Continuous monitoring of your endpoints, workloads and network against a baseline we establish with you, with AI on duty and a person checking before you are told anything.

    Explore Vigil →

Answer once

One evidence base, every framework.

Every scheme asks about the same control families in slightly different language. Governance. Asset management. Supply chain. Vulnerability management. Testing. Monitoring. Incident response. Recovery. The words change; the evidence does not.

Which Lybica service produces the evidence for each control family
Control family Where the evidence comes from
Governance and risk managementAtlas — policies, risk register, decisions and owners, held current
Asset managementAtlas — what you run, who owns it, what it is worth to an attacker
Supply-chain managementAtlas — your suppliers, their risk position, the obligations you flow down
Vulnerability managementCrucible — findings, validation, and a tracked remediation position
Security testingCrucible — independent testing on a stated cadence, reported
Security monitoringVigil — monitoring running against a baseline, evidenced monthly
Incident responseVigil — validated alerts, response records, a plan that has been used
Business continuity and recoveryAtlas and Vigil — plans that exist, get exercised, and get recorded

The same evidence base answers all of these:

  • Cyber Essentials and Cyber Essentials Plus
  • Def Stan 05-138 and Defence Cyber Certification
  • NHS Data Security and Protection Toolkit
  • NCSC Cyber Assessment Framework
  • ISO 27001
  • The customer questionnaire on your desk

Answer once. Evidence once. Reuse everywhere.

AI where it counts. People where it matters.

Every vendor says “AI-powered”. We'd rather tell you exactly what ours does.

In Atlas
AI reads every control answer against what the standard actually requires, and cross-references the whole assessment — so a claim made in one section cannot quietly contradict an exception described in another.
In Crucible
AI runs the testing at your chosen cadence and attempts safe validation, to establish what is genuinely exploitable rather than theoretical — so the list you get is short and true.
In Vigil
AI watches continuously against the baseline established for your environment, screening what is ordinary from what is not, at a volume no person could read.

In all three, a named person reviews before anything reaches you. Nothing automated is sent unchecked.

Who this is for.

Not a market segment so much as a recurring predicament: a technically capable founder or IT lead, no security team, and a requirement in a contract they cannot currently evidence.

  • Defence supply chain

    Def Stan 05-138, Defence Cyber Certification, and DEFCON 658 flowing down from a prime.

  • Government suppliers

    Central, devolved and local, where Cyber Essentials is a condition of the contract.

  • Health and social care suppliers

    The NHS Data Security and Protection Toolkit, every year, with evidence behind it.

  • Regulated and critical sectors

    NIS obligations, the NCSC Cyber Assessment Framework, and a sector regulator who asks.

  • Anyone facing enterprise security due diligence

    ISO 27001 and the security questionnaire that arrives with every enterprise deal.

And who it is not for: if nobody is asking you to prove anything yet, you do not need us. We would rather say that now than at renewal.

Defence suppliers

The clock is running.

MOD has asked all industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026. Higher levels are set by the Cyber Risk Profile assigned to an individual contract, and apply from award.

In development — offered when they meet our bar

On the horizon.

  • In development

    Rapid-response incident team

    The people who deploy in person when the real thing happens.

  • In development

    Secure AI hosting

    Sovereign hosting and deployment of AI models in environments you control. Available to the public sector through G-Cloud 15.

  • In development

    Secure communications

    Hardened devices and secure meeting environments for sensitive work.

Questions people ask us first.

We're a 30-person company. Is any of this proportionate for us?

Requirements scale with the risk of the contract, not the size of the supplier. The starting point is what your contract actually says, not what feels reasonable.

Can Lybica certify us?

No. Certification is issued by the relevant certification body. We get you ready, produce the evidence, and keep it current so the assessment is a formality.

We already have Cyber Essentials. Is that enough?

For some contracts, yes. For most frameworks, no — Cyber Essentials covers technical controls, and schemes like Def Stan 05-138, the DSPT and ISO 27001 also want governance, supply-chain management, monitoring and recovery.

We keep getting security questionnaires and they all ask different things. Is there a way to stop redoing this?

Mostly they ask the same things in different words. Map the controls once and hold the evidence in one place, and each new questionnaire becomes a mapping exercise rather than a project.

Do you monitor 24 hours a day?

No. Monitoring runs continuously; human validation and response are during UK business hours, to defined response times. We would rather tell you that than sell you cover we cannot honestly staff.

Isn't automated testing something our developers should already be doing?

Yes, and increasingly they are. What your own pipeline cannot give you is independence — which is the thing customers, primes and assessors are asking for.

How much does it cost?

Four tiers from £300 to £1,200 a month plus VAT, on an annual term billed monthly. The full rate card is on our pricing page. No demo required to find out.

Talk to us before the next questionnaire lands.

One scoping call. We map what your contracts require, what you can evidence today, and what the gap is costing you.

Stay close.

Occasional notes on what UK contracts are starting to ask suppliers to prove, and how to be ready before they do. Infrequent, no noise.

We use analytics cookies to understand how the site is used. See our Privacy Policy.