Skip to content
Lybica

The approach

Continuous, not annual.

The founding argument, and it has not changed: between audits, nobody is watching. An annual assessment describes one day of the year, and the eleven months either side of it are where the work actually happens — and where the questions actually arrive.

So everything here is built to run continuously and to be true on the day someone asks, rather than true on the day it was written.

The output

Evidence is the output.

The point is not activity. Anyone can produce activity. The point is something defensible you can hand to an assessor, a prime, or a customer's security team — and have it answer the question the first time.

That is why every service here produces a record as a by-product of doing the work, rather than requiring a separate exercise to write one up afterwards. A monthly monitoring report exists because monitoring ran. A remediation position exists because testing found things and they were tracked.

Division of labour

AI does the reading. People make the calls.

Every vendor says “AI-powered”. We'd rather tell you exactly what ours does, and exactly where it stops.

It reads at a volume and a persistence no person can match: every control answer against what the standard requires, every finding against what is genuinely exploitable, every hour of telemetry against your baseline. That is reading, comparison and drafting — the work that is enormous and mechanical.

What it does not do is decide. A named person reviews before anything reaches you: whether a finding is real, whether an alert is worth your attention, whether an evidence narrative actually says what it claims. Nothing automated is sent unchecked — which is a constraint on how fast we can grow, and we would rather have it than not.

Who you deal with

Small and senior.

You deal with the people doing the work, led from Edinburgh. There is no account layer between you and whoever is actually looking at your environment.

Behind that is years of senior UK government delivery experience, much of it on work we are not free to describe. So take that as background rather than as proof. What we can point at is that we build and run our own platforms — Offmon for UK law enforcement and Cenefits for public bodies in Scotland and Wales — and operating our own services, under the same obligations we are describing to you, is what keeps the method honest.

Your data

Your data stays where it belongs.

Alerts, findings, evidence and risk records are designed to stay in the UK and in environments we control — not routed through a third-party platform on another continent because it was cheaper to build that way.

Our services are built in alignment with the UK National Cyber Security Centre's Cloud Security Principles.

Getting started

How an engagement starts.

Four steps, deliberately dull, so you always know what happens next.

  1. Scoping call

    What your contracts require you to prove, and what you can evidence today. You already know what it costs — the rate card is published.

  2. Gap assessment

    Against whichever framework your contract actually points at — not a generic maturity score against something nobody asked for.

  3. Proposal

    Which tier, what it covers, what it does not, and what remains your job. In writing, at the published price.

  4. Onboarding

    Your estate mapped into Atlas, testing scoped, agents deployed and baselined where Vigil is in play. Then the service simply runs.

See where you actually stand.

Stay close.

Occasional notes on what UK contracts are starting to ask suppliers to prove, and how to be ready before they do. Infrequent, no noise.

We use analytics cookies to understand how the site is used. See our Privacy Policy.