CyPro
Jonny Pelter & Rob McBride
- Location
- London
- Credentials
- CREST, ISO 27001, Cyber Essentials, SOC 2, DORA
- Rating
- n/a
- Focus
- Financial services, fintech, legal
A researched shortlist of the virtual and fractional CISO leaders serving London and the wider UK, from independent operators to dedicated security boutiques. Compared on credentials, service clarity, and track record, with a lens on the ISO 27001, Cyber Essentials, UK GDPR and FCA demands that shape London's market.
Not every vCISO sits inside a firm. These are named, independent operators serving London and the UK who offer fractional or virtual CISO leadership. Often the most hands-on option when you want a single named leader owning your security.
A veteran UK MSP operator moving into independent fractional IT and security leadership. Deep expertise in the MSP market and in cybersecurity positioning, brought to growing UK businesses as a fractional CIO and CISO on a retainer basis.
Runs his own London advisory practice offering fractional CISO leadership to organisations that need senior security direction without a full-time hire.
An independent fractional CISO, CIO and CTO working with London-area companies that need senior technology and security leadership on a part-time basis.
A fractional CISO and CIO, board advisor and non-executive director, and an international speaker on cybersecurity leadership.
A CISO and executive security advisor with Aquila Advisory Group, advising London organisations on security strategy and risk.
An interim and fractional CISO serving London organisations that need experienced security leadership on a temporary or part-time basis.
Individuals are listed based on public LinkedIn profiles where they present fractional, interim or virtual CISO services. Anyone can request an update or removal.
Weighted to genuine London and UK presence and dedicated vCISO focus, with a lens on the FCA, ISO 27001 and Cyber Essentials demands common to London firms.
A London-HQ boutique run by two heavily credentialed named practitioners (CISSP, CISM, CISA, CRISC), CREST-accredited, with a strong financial-services and fintech roster. The clearest "real named experts" story of the set.
The only firm here with a strong, verifiable third-party rating (Trustpilot 5.0, 49 reviews), plus a broad UK footprint and deep compliance coverage across ISO 27001/9001/22301, Cyber Essentials Plus and CREST.
A London-HQ boutique led by Amar Singh, a publicly recognised UK security figure (Chair of ISACA UK's Security Advisory Group, GCHQ-certified trainer), with enterprise clients including NHS, UBS and BNP Paribas.
A genuine London boutique (Savoy Place, founded 2015) led by a named practitioner with 25 years across KPMG, Atos, QinetiQ and UK Government. CISM, CITP and MIET credentialed.
Not a boutique but a UK-headquartered assurance group with the deepest independently verifiable certification stack of the set (full CREST suite, PCI DSS QSA, NCSC CHECK). The enterprise-grade option.
Every firm here is researched against its own website and tagged by type so you can tell a dedicated vCISO boutique from an MSSP or an MSP that also offers vCISO.
Jonny Pelter & Rob McBride
Southampton + London presence
Founder Amar Singh
Founder Hani Banayoti
MD Cyber Howard Hughes
Newbury + Aberdeen
Founder Michala Liavaag
Microsoft security partner
Altrincham
London (EC1V)
Jersey HQ + London
Listings reflect public information verified July 2026. Certifications and service lines are as presented on each firm's own website. Firms can request an update or removal.
"CISO" is one title covering four very different backgrounds, and most bad security hires are the right person from the wrong camp. Before you compare providers, work out which camp your situation calls for. (Credit to David Lane, featured above, for pushing us to spell this out.)
Came up through GRC, audit, or big-firm consulting. Fluent in ISO 27001 clauses, FCA expectations, and evidence folders.
Right hire when a regulator, auditor, insurer, or enterprise customer is the reason you are hiring: FCA authorisation, ISO 27001 or SOC 2, security questionnaires blocking deals.
Watch for: some have never secured a live system. The policies pass the audit while the estate stays soft. Ask what they have hardened, not just what they have certified.
Came up through penetration testing, security engineering, or software development. Thinks like an attacker and can read your codebase.
Right hire when your risk lives in your own product: SaaS and cloud-native companies, engineering-led teams, anything where a breach means your code or infrastructure failed.
Watch for: governance bores this camp. Audit prep drifts, board reporting stays thin, and the ISO project stalls unless someone else owns the paperwork.
Came up through IT operations, infrastructure, or an MSP. Knows Microsoft 365, endpoints, backups, and networks from the inside.
Right hire when you run an infrastructure-heavy business: offices, devices, servers, M365. The practical camp that actually fixes the misconfigurations.
Watch for: board presence and regulatory depth can be thin. Great at locking the estate down, weaker at translating risk for a regulator or an audit committee.
Strong on certifications and coursework, short on scar tissue. Increasingly common as cyber degree programmes feed the market.
Right hire when you already have senior security leadership and need capable hands: an analyst or deputy growing under a fractional or full-time CISO.
Watch for: a graduate should never be your first and only security leader. Your budget becomes their training ground, and they carry no weight with auditors or boards.
| What is driving the hire | Camp to hire from |
|---|---|
| FCA authorisation, audit, or regulator attention | Compliance specialist |
| Enterprise deal stuck on ISO 27001 or a security questionnaire | Compliance specialist |
| SaaS or cloud-native product, engineering-led team | Hacker / engineer |
| Recent incident or breach, need to know how they got in | Hacker / engineer |
| Infrastructure-heavy business: offices, devices, M365 | Sysadmin turned CISO |
| Cyber insurance renewal with tougher conditions | Compliance specialist, backed by a sysadmin camp lead |
| Building a security function on a budget | Fractional senior from any camp, with a graduate as deputy |
Most fractional engagements need two camps at once, which is a reason to pick a provider who is honest about which camp they are from and who covers their gaps.
Most London vCISO engagements run between £4,000 and £12,000 per month depending on scope, company size, and compliance load, with FCA-regulated and financial-services work at the higher end. Project work, such as an ISO 27001 or Cyber Essentials Plus readiness sprint, is often quoted as a fixed fee. That compares with £150,000 to £300,000+ per year for a full-time CISO in London.
An MSPs run your day-to-day IT and often bundle security tools. A vCISO sits above that: they set the security strategy, own compliance and risk, and hold vendors (including your MSP) accountable. Some firms on this directory are MSPs that also offer vCISO, which we tag so you can tell them apart from dedicated security boutiques.
Look for hands-on experience with the frameworks that matter in the UK: ISO 27001 (ideally a Lead Implementer or Lead Auditor on the team), Cyber Essentials and Cyber Essentials Plus, UK GDPR, and, for financial firms, direct FCA experience. Individual leaders often hold CISSP, CISM or C-CISO.
CISO backgrounds fall into four camps: compliance specialists, hackers and engineers, sysadmins who moved into security, and graduates. Hire a compliance specialist when a regulator, auditor, or enterprise customer is driving the hire. Hire from the hacker or engineer camp when the risk lives in your own product and cloud. Hire a sysadmin-background CISO for an infrastructure-heavy business. A graduate belongs under senior leadership, not as your first security leader. See the full breakdown above.
A dedicated boutique gives you a named security leader with no product to upsell. An MSSP brings 24/7 monitoring and scale. An MSP is convenient if you want IT and security under one roof, but confirm the vCISO is a real strategic role and not a light add-on. Match the model to whether you need strategy, operations, or both.
Get verified and listed in this directory, and apply to be considered for the curated Top Picks. Featured providers also get access to our MSP referral network, a two-way stream of warm introductions. No fee for placement.
This directory is maintained by NUOPTIMA, the AI-search growth partner for MSPs and technology firms. If you want to rank and get cited by AI search the way these providers do, we can run the same play for you.