The Best Cyber Security Companies London
The best cyber security companies in London in 2026 span very different sizes and ownership structures. This guide compares 7 firms with a genuine London office: Precursor Security, NCC Group, Redscan (Kroll), JUMPSEC, S-RM, Claranet Cyber Security, and Orange Cyberdefense UK, on accreditation, HQ and ownership, and pricing transparency. Precursor ranks first for London financial services, legal, and government clients that want offensive testing and defensive monitoring from one CREST-accredited team, delivered from our Leeds and Newcastle technical teams with a dedicated London client office.
Seven cyber security companies with a genuine London office compared on the criteria that actually matter to buyers: verifiable accreditation, HQ and ownership, pricing you can see before a sales call, and whether the London address is a working office or a brass plate.
We are Precursor Security, and we have ranked ourselves first on this list.
We are honest about what our London office is: a client engagement office serving financial services, legal sector, and government organisations, with in-person scoping, briefings, and debriefs. It is not where our technical work happens. Penetration testing is delivered by our CREST-accredited team from Leeds, and 24/7 SOC monitoring runs from our Newcastle facility. If you need a firm whose testers and analysts sit at a desk in London itself, several firms on this list genuinely do, and we say so plainly against each one.
We publish the selection criteria in full, describe every competitor fairly using only public information, and link the independent CREST member directory so you can check our working. Read the trade-offs listed against every firm, including us, before you shortlist anyone.
Seven London firms, side by side
| Provider | HQ / ownership | Pricing published | From |
|---|---|---|---|
| 1. Precursor Security | Leeds, UK, independent (London client office) | Yes | From £2,500 (pentest) / £900/mo (MDR) |
| 2. NCC Group | Manchester, UK (London office), publicly listed (LSE: NCC, FTSE 250) | No | On application |
| 3. Redscan (Kroll) | London, UK, part of Kroll Inc. (HQ New York, US) since 2021 | No | On application |
| 4. JUMPSEC | Acton, West London, UK, independent | No | On application |
| 5. S-RM | London, UK, independent | No | On application |
| 6. Claranet Cyber Security | London, UK, part of Claranet Group | No | On application |
| 7. Orange Cyberdefense UK | London, UK, part of Orange SA (France) since 2022 | No | On application |
HQ, office, and ownership facts verified against Companies House, the CREST member directory, and each firm's own office-locations or newsroom pages, September 2026. "Not published" means we could not find pricing publicly stated; it does not mean the firm lacks a rate card.
The 7 best cyber
security companies in London
1. Precursor Security
Precursor holds triple CREST accreditation across Penetration Testing, Vulnerability Assessment, and Security Operations Centre services. Our London office serves financial services, legal sector, and government clients with face-to-face scoping, executive briefings, and debriefs, backed by a specialist FCA, DORA, and NCSC Cyber Assessment Framework account team. Every tester and analyst is a UK-based, DBS-checked employee, nothing is subcontracted or offshored. Pricing is published: penetration testing from £2,500, and MDR/SOC from £900 per month.
Trade-off: Precursor's London office is a genuine client-facing presence, not a technical delivery site. Penetration testing runs from our CREST-accredited Leeds headquarters and 24/7 SOC monitoring from our Newcastle facility. An organisation that specifically needs its tester or analyst physically desk-based in London should ask directly; ours are not, though your account manager is.
2. NCC Group
NCC Group is one of the largest listed cyber security consultancies in the world, headquartered in Manchester and listed on the London Stock Exchange as a FTSE 250 constituent. It maintains a central London office for client meetings and account management alongside its wider UK delivery bench.
Trade-off: Pricing is not published, and the bulk of NCC Group's UK headcount and leadership sit in Manchester rather than London. The engagement model is built for enterprise procurement rather than a smaller organisation buying its first test.
3. Redscan (Kroll)
Redscan was founded and built its reputation as a London-headquartered MDR and testing provider before Kroll, the New York-headquartered risk and financial advisory firm, acquired it in 2021. Its London Bridge office now operates inside Kroll's global Cyber Risk practice, pairing testing with Kroll's wider forensics and incident response bench.
Trade-off: Pricing on application. Buyers are engaging with a US-owned global practice rather than a standalone London specialist.
4. JUMPSEC
JUMPSEC is headquartered in Acton, West London, and holds NCSC CHECK status alongside CREST accreditation, the combination that matters for PSN-connected environments and government work that mandates CHECK delivery. It is listed as a Crown Commercial Service supplier, which shortens public-sector procurement.
Trade-off: Pricing on application. CHECK status is a specific procurement requirement, not every organisation needs it, and Acton sits further from the City and Canary Wharf than some buyers expect from a London-based tester.
5. S-RM
S-RM is a London-headquartered, privately held intelligence and risk consultancy that holds CREST accreditation for its cyber security practice. Founded in 2005, it has grown into a genuinely London-based firm with a broader corporate intelligence, investigations, and risk advisory business sitting alongside its incident response and testing work.
Trade-off: Pricing on application, and cyber security sits inside a broader corporate intelligence and risk consultancy rather than being the firm's sole focus. An organisation wanting a pure-play testing specialist may prefer a narrower firm.
6. Claranet Cyber Security
Claranet Cyber Security is headquartered at 110 High Holborn, London, and is CREST-accredited and NCSC CHECK green-light approved. It operates as the cyber security division within the wider Claranet Group, an international managed services group headquartered in London.
Trade-off: Pricing on application, and testing is one service line inside a much larger managed hosting and cloud group, now owned by a Portuguese telecoms operator rather than a UK-focused parent.
7. Orange Cyberdefense UK
Orange Cyberdefense UK is headquartered at 250 Waterloo Road, London, and holds CREST and NCSC CHECK accreditation. It operates as the UK arm of Orange Cyberdefense, itself a wholly owned subsidiary of Orange SA, the French telecommunications group, since 2022.
Trade-off: Pricing on application. A buyer is engaging with a French telecom-owned global security operation rather than an independent UK specialist.
How we ranked them
Six criteria, each something a London buyer should care about and can verify without taking anyone's word for it. Weighting is ours; the underlying facts are checkable.
Whether the firm has a real, staffed London office or a registered address used only for correspondence. Ask directly where the people scoping and delivering your engagement actually sit.
Whether client data, logs, and findings stay within the UK throughout an engagement, regardless of where the parent company is headquartered.
Whether the firm runs offensive testing, defensive monitoring, and compliance under one roof, our closed-loop model, or is a single-discipline specialist.
Whether you can see rates before a sales call. Pricing on application costs London buyers days of procurement time and makes comparison across firms difficult.
Company-level CREST accreditation confirmed in the CREST directory, and NCSC CHECK status where relevant, not just a badge on a website.
Whether the engagement model, minimum scope, and account structure suit a mid-market London business, or are built for FTSE 100 procurement.
Red flags when choosing
a London cyber security company
Whichever firm you choose, including us, walk away if you see these.
A serviced-office-only "London" presence
Some firms list a London address that is a serviced office or mail-forwarding suite with no dedicated staff. Ask directly whether the office is staffed daily and who you would actually meet there.
Enterprise-only minimums for a mid-market need
If your organisation is 50 to 500 people, a minimum-scope engagement, account structure, or contract length built for FTSE 100 procurement will cost you time and money you do not need to spend.
POA on absolutely everything
A firm that cannot give you a rate range before a discovery call is optimising for deal-size discovery, not your budget. UK CREST day rates run £1,000 to £1,500; anyone refusing to anchor near that range is hiding something, in either direction.
Offshore delivery behind a London address
A London-registered company and a UK-based delivery team are not the same thing. Ask specifically where the testers or SOC analysts working on your account are located and employed.
Accreditation that does not check out
Verify every CREST and NCSC CHECK claim against the official directories at crest-approved.org and ncsc.gov.uk. If a claim does not appear there, ask why before you proceed.
Consultancy-day-rate creep
A quote that looks competitive at scoping stage and then grows through change requests, extra scope, and follow-on consultancy days. Ask for a fixed price against a defined scope before you sign.
What London cyber security services cost
Six of the seven firms on this list price on application, so a real number only arrives after a scoping call. Precursor publishes both rates as an anchor: penetration testing from £2,500, and MDR/SOC from £900 per month. Across the wider market, CREST-accredited testing typically runs £1,000 to £1,500 per consultant day, with managed detection and response priced per endpoint or user on a monthly subscription. A London postcode does not, by itself, carry a price premium; scope and accreditation drive the number.
See our published pricingComparing a specific service or a UK-wide list?
This guide compares whole companies with a London presence. If you want a UK-wide comparison, a discipline-specific breakdown, or more on our own London office, these go deeper.
Compare our London office against anyone on this list.
Fixed pricing published before you call. A written quote within 24 hours of a scoping conversation. Face-to-face meetings in London, technical delivery from our CREST-accredited Leeds and Newcastle teams.
Choosing a London cyber security company
The questions buyers ask most when comparing London providers.
Precursor Security, NCC Group, Redscan (Kroll), JUMPSEC, S-RM, Claranet Cyber Security, and Orange Cyberdefense UK all have a genuine London office and a real claim to a place on a London shortlist. Precursor ranks first for London financial services, legal, and government clients that want offensive testing and defensive monitoring from one CREST-accredited team with published pricing; NCC Group and Orange Cyberdefense UK for enterprise and multinational scale; Redscan for Kroll's global forensics bench; JUMPSEC for NCSC CHECK and public sector work; S-RM for corporate intelligence alongside testing; and Claranet for a bundled managed hosting relationship. Which is right for you depends on your organisation's size, sector, and whether you need the technical team physically in London or simply UK-based.
Usually not specifically. UK data residency and a meeting cadence that suits your team matter more to most buyers than the postcode on a provider's registered office. Many strong providers serve London clients perfectly well from Leeds, Manchester, Newcastle, or elsewhere in the UK, provided testers and analysts are UK-based employees and your data never leaves the country. A London office becomes genuinely useful when you want in-person scoping workshops and executive debriefs without travel, which matters more for financial services, legal, and government clients with strict on-site meeting expectations.
Most firms serving London price on application rather than publishing a rate card, so budgeting requires a scoping call before you see a number. Precursor publishes both rates as an anchor: penetration testing from £2,500 for a focused external test, rising with scope, and MDR/SOC from £900 per month. Across the wider market, CREST-accredited penetration testing typically runs £1,000 to £1,500 per consultant day, and managed detection and response is usually priced per endpoint or user on a monthly subscription. London-specific premiums are not standard; the driver is scope and accreditation, not postcode.
Look for CREST accreditation at company level, confirmed independently in the CREST member directory at crest-approved.org, plus individually certified testers. For government-connected or PSN work, check NCSC CHECK status at ncsc.gov.uk. ISO 27001 shows the firm manages its own information security to an audited standard. For financial services clients specifically, ask how the firm aligns testing and reporting to FCA, PRA, and DORA expectations, since a London office alone does not guarantee sector-specific regulatory fluency.
Yes. Precursor Security's London office provides client engagement for financial services, legal sector, and government organisations: in-person scoping workshops, executive briefings, and post-engagement debriefs. Technical delivery is not based in London; CREST-accredited penetration testing runs from our Leeds headquarters and 24/7 SOC monitoring from our Newcastle facility, with the London team acting as your single point of contact throughout. Every engagement is delivered by UK-based, DBS-checked staff with no offshoring of work.



