TWI
TWI engaged with UK Cyber Defence with a view to overhauling the organisations approach to information security. Now we are their global SOC.
SOC status:Duty analyst on shift
Managed SOC · Penetration testing · Virtual CISO · Consulting · Cyber Essentials
Twenty-four-hour detection and response, honest testing and senior advice for UK organisations that would rather run their business than run a security operation. One team, one company, based at The Officers' Mess in Duxford.
CREST accreditedISO 27001 · ISO 9001Cyber Essentials PlusDuxford, CambridgeshireEst. 2009
Accredited
Since 2009 we have tested and defended organisations where a bad day has real consequences: regulators, patients, passengers, payrolls. We built our own SOC platform, we test our own defences, and we say what we think. Everything we do follows one model — detect what others miss, defend what others overlook, disrupt the attackers behind it — and the result is fewer surprises, calmer boards and a security posture you can explain to an auditor in one page.
How we work
Three disciplines, one team. Offensive, defensive and intelligence work feed each other instead of living in separate companies.
Continuous monitoring, threat hunting, engineered detections and intelligence-led correlation through SOC365, our own platform.
Incident response, containment, forensics and the engineering changes that close attack paths for good.
Penetration testing, red teaming and deception devices built into the SOC, so attackers are found on our terms rather than theirs.
01
Managed SOCSOC365 · 24/7
SOC365 watches your endpoints, identities, cloud, network and OT every hour of every day, staffed by analysts who can tell a real intrusion from a noisy scanner. Our own platform, our own detection engineering, our own deception network and our own threat intelligence — with EmilyAI, the SOC assistant we built in 2018, taking the repetitive work so analysts can concentrate on judgement. You get a named duty analyst, a measured response time and reporting a board can read.
02
Penetration testingCREST · Red team
External, internal and Active Directory, web, API, mobile, cloud, wireless and full red-team engagements, following OSSTMM and PTES and mapped to MITRE ATT&CK and OWASP. Scoped in a thirty-minute call and reported in plain English with a fix list your engineers can actually work through. Because we run a SOC too, we know which findings get exploited in practice and which merely look alarming.
03
Virtual CISOLeadership on retainer
Strategy, risk registers, board papers, supplier reviews, insurer questionnaires and the awkward conversations with auditors, handled by someone who has held the CISO title at FTSE-listed companies. A fixed number of days a month, a standing agenda, and a named person your board recognises.
04
ConsultingCompliance · Engineering · Readiness
ISO 27001 and Cyber Essentials programmes, DORA, NIS2 and PCI DSS gap assessments, incident response plans and tabletop exercises your executives will remember — plus the security engineering that makes the paperwork true: identity hardening, cloud and Microsoft 365 uplift, segmentation and the logging your SOC needs. Practical work with clear deliverables, not a slide deck that gathers dust.
05
Cyber EssentialsCertification · Plus audits
We take organisations through Cyber Essentials and Cyber Essentials Plus with the minimum of fuss: a readiness check against the five controls, the fixes that matter, the assessment, and the certificate your customers and insurers ask for.
Measured performance
<8min
Mean time to detect
<20min
Mean time to respond
95%
Threat disruption success
99.995%
Service availability
How an incident flows through SOC365
Stage 01
Behavioural analytics, engineered detections, threat intelligence and deception signals fire across endpoint, identity, cloud and network telemetry.
Stage 02
An analyst confirms the signal, gathers context and suppresses the false positives so you only hear about what is real.
Stage 03
Isolation, credential locking and blocking, executed with your approval or automatically where you have pre-authorised it.
Stage 04
Root cause, actions taken and what to change next, in a form your board and your auditors can both use.
Case studies
TWI engaged with UK Cyber Defence with a view to overhauling the organisations approach to information security. Now we are their global SOC.
The successful collaboration between NGS and UK Cyber Defence, showcasing the benefits of proactive cybersecurity measures.
Seeking urgent assistance to secure their business and navigate the regulatory aftermath of a breach, CEL turned to UK Cyber Defence IR team,
Insights
It consolidates the seven vertical-specific products (TI-2026-0717-001 through -007) into a single distribution-ready deliverable.
The trade body and membership organisation vertical continues to be shaped by three structural characteristics that shape the threat picture: (i) the sector holds sensitive membership registers, financial information (dues, event bookings…
The retail vertical continues to be shaped by the M&S / Co-op / Harrods retrospective — reclassified by UK observers as a "Category 2 cyber hurricane" with total combined costs assessed at £270m–£440m — and by the continued arrests connected to the DragonForce / Scattered Spider cluster.
Start a conversation
Thirty minutes with an analyst or our CEO. We will tell you what we would do in your position, whether or not it involves us.