Security as a standing service
Prove your security. Then keep proving it.
Compliance, testing and monitoring, run as continuing services for UK companies — so the evidence is already current the day a prime, a buyer or an assessor asks for it.
The problem
The old choice was bad at both ends.
You have had two options, and both are snapshots. A consultant writes down what you say you do — out of date before anyone reads it. An assessor checks whether you actually do it, once a year — a true picture of a single day. Neither is watching. Neither is evidence.
Meanwhile the questionnaires keep arriving — a prime's flow-down, a council's procurement pack, an enterprise buyer's due diligence. Same questions, different words, always a deadline. And answered from scratch each time, because there has never been one place for the answers to live.
Three services. One standing defence.
Each one runs continuously on annual terms — not a project that ends. Together they answer the three questions every prime, assessor and customer security team asks in some form: are you in order, are you tested, are you watched?
-
Lybica Atlas
The living map.
One place holding your assets, controls, risks, suppliers and continuity plans — current, rather than eighteen months stale. Map the controls once, and the next questionnaire is a lookup instead of a project.
-
Lybica Crucible
The proving fire.
Independent testing at the frequency you choose — nightly to monthly — with AI establishing what is genuinely exploitable and a named person deciding what actually matters before you see it.
-
Lybica Vigil
The watch.
Continuous monitoring of your endpoints, workloads and network against a baseline we establish with you, with AI on duty and a person checking before you are told anything.
Answer once
One evidence base, every framework.
Every scheme asks about the same control families in slightly different language. Governance. Asset management. Supply chain. Vulnerability management. Testing. Monitoring. Incident response. Recovery. The words change; the evidence does not.
| Control family | Where the evidence comes from |
|---|---|
| Governance and risk management | Atlas — policies, risk register, decisions and owners, held current |
| Asset management | Atlas — what you run, who owns it, what it is worth to an attacker |
| Supply-chain management | Atlas — your suppliers, their risk position, the obligations you flow down |
| Vulnerability management | Crucible — findings, validation, and a tracked remediation position |
| Security testing | Crucible — independent testing on a stated cadence, reported |
| Security monitoring | Vigil — monitoring running against a baseline, evidenced monthly |
| Incident response | Vigil — validated alerts, response records, a plan that has been used |
| Business continuity and recovery | Atlas and Vigil — plans that exist, get exercised, and get recorded |
The same evidence base answers all of these:
- Cyber Essentials and Cyber Essentials Plus
- Def Stan 05-138 and Defence Cyber Certification
- NHS Data Security and Protection Toolkit
- NCSC Cyber Assessment Framework
- ISO 27001
- The customer questionnaire on your desk
Answer once. Evidence once. Reuse everywhere.
AI where it counts. People where it matters.
Every vendor says “AI-powered”. We'd rather tell you exactly what ours does.
- In Atlas
- AI reads every control answer against what the standard actually requires, and cross-references the whole assessment — so a claim made in one section cannot quietly contradict an exception described in another.
- In Crucible
- AI runs the testing at your chosen cadence and attempts safe validation, to establish what is genuinely exploitable rather than theoretical — so the list you get is short and true.
- In Vigil
- AI watches continuously against the baseline established for your environment, screening what is ordinary from what is not, at a volume no person could read.
In all three, a named person reviews before anything reaches you. Nothing automated is sent unchecked.
Who this is for.
Not a market segment so much as a recurring predicament: a technically capable founder or IT lead, no security team, and a requirement in a contract they cannot currently evidence.
-
Defence supply chain
Def Stan 05-138, Defence Cyber Certification, and DEFCON 658 flowing down from a prime.
-
Government suppliers
Central, devolved and local, where Cyber Essentials is a condition of the contract.
-
Health and social care suppliers
The NHS Data Security and Protection Toolkit, every year, with evidence behind it.
-
Regulated and critical sectors
NIS obligations, the NCSC Cyber Assessment Framework, and a sector regulator who asks.
-
Anyone facing enterprise security due diligence
ISO 27001 and the security questionnaire that arrives with every enterprise deal.
And who it is not for: if nobody is asking you to prove anything yet, you do not need us. We would rather say that now than at renewal.
Defence suppliers
The clock is running.
MOD has asked all industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026. Higher levels are set by the Cyber Risk Profile assigned to an individual contract, and apply from award.
In development — offered when they meet our bar
On the horizon.
-
In development
Rapid-response incident team
The people who deploy in person when the real thing happens.
-
In development
Secure AI hosting
Sovereign hosting and deployment of AI models in environments you control. Available to the public sector through G-Cloud 15.
-
In development
Secure communications
Hardened devices and secure meeting environments for sensitive work.
Questions people ask us first.
We're a 30-person company. Is any of this proportionate for us?
Requirements scale with the risk of the contract, not the size of the supplier. The starting point is what your contract actually says, not what feels reasonable.
Can Lybica certify us?
No. Certification is issued by the relevant certification body. We get you ready, produce the evidence, and keep it current so the assessment is a formality.
We already have Cyber Essentials. Is that enough?
For some contracts, yes. For most frameworks, no — Cyber Essentials covers technical controls, and schemes like Def Stan 05-138, the DSPT and ISO 27001 also want governance, supply-chain management, monitoring and recovery.
We keep getting security questionnaires and they all ask different things. Is there a way to stop redoing this?
Mostly they ask the same things in different words. Map the controls once and hold the evidence in one place, and each new questionnaire becomes a mapping exercise rather than a project.
Do you monitor 24 hours a day?
No. Monitoring runs continuously; human validation and response are during UK business hours, to defined response times. We would rather tell you that than sell you cover we cannot honestly staff.
Isn't automated testing something our developers should already be doing?
Yes, and increasingly they are. What your own pipeline cannot give you is independence — which is the thing customers, primes and assessors are asking for.
How much does it cost?
Four tiers from £300 to £1,200 a month plus VAT, on an annual term billed monthly. The full rate card is on our pricing page. No demo required to find out.
Talk to us before the next questionnaire lands.
One scoping call. We map what your contracts require, what you can evidence today, and what the gap is costing you.