TWI
TWI engaged with UK Cyber Defence with a view to overhauling the organisations approach to information security. Now we are their global SOC.
SOC status:Duty analyst on shift
Managed SOC · Penetration testing · Virtual CISO · Consulting · Cyber Essentials
Twenty-four-hour detection and response, honest testing and senior advice for UK organisations that would rather run their business than run a security operation. One team, one company, based at The Officers' Mess in Duxford.
CREST accreditedISO 27001 · ISO 9001Cyber Essentials PlusDuxford, CambridgeshireEst. 2009
Accredited
Since 2009 we have tested and defended organisations where a bad day has real consequences: regulators, patients, passengers, payrolls. We built our own SOC platform, we test our own defences, and we say what we think. Everything we do follows one model — detect what others miss, defend what others overlook, disrupt the attackers behind it — and the result is fewer surprises, calmer boards and a security posture you can explain to an auditor in one page.
Trusted by
Broadcasters, banks, insurers, retailers, research institutions, regulators and operators of critical infrastructure, in the UK, Gibraltar and beyond. Each has agreed to be named; the case studies tell the rest.





























How we work
Three disciplines, one team. Offensive, defensive and intelligence work feed each other instead of living in separate companies.
Continuous monitoring, threat hunting, engineered detections and intelligence-led correlation through SOC365, our own platform.
Incident response, containment, forensics and the engineering changes that close attack paths for good.
Penetration testing, red teaming and deception devices built into the SOC, so attackers are found on our terms rather than theirs.
01
Managed SOCSOC365 · 24/7
SOC365 watches your endpoints, identities, cloud, network and OT every hour of every day, staffed by analysts who can tell a real intrusion from a noisy scanner. Our own platform, our own detection engineering, our own deception network and our own threat intelligence — with EmilyAI, the SOC assistant we built in 2018, taking the repetitive work so analysts can concentrate on judgement. You get a named duty analyst, a measured response time and reporting a board can read.
02
Penetration testingCREST · Red team
External, internal and Active Directory, web, API, mobile, cloud, wireless and full red-team engagements, following OSSTMM and PTES and mapped to MITRE ATT&CK and OWASP. Scoped in a thirty-minute call and reported in plain English with a fix list your engineers can actually work through. Because we run a SOC too, we know which findings get exploited in practice and which merely look alarming.
03
Virtual CISOLeadership on retainer
Strategy, risk registers, board papers, supplier reviews, insurer questionnaires and the awkward conversations with auditors, handled by someone who has held the CISO title at FTSE-listed companies. A twelve-month retainer, a standing agenda, and a named person your board recognises.
04
ConsultingCompliance · Engineering · Readiness
ISO 27001 and Cyber Essentials programmes, DORA, NIS2 and PCI DSS gap assessments, incident response plans and tabletop exercises your executives will remember — plus the security engineering that makes the paperwork true: identity hardening, cloud and Microsoft 365 uplift, segmentation and the logging your SOC needs. Practical work with clear deliverables, not a slide deck that gathers dust.
05
Cyber EssentialsCertification · Plus audits
We take organisations through Cyber Essentials and Cyber Essentials Plus with the minimum of fuss: a readiness check against the five controls, the fixes that matter, the assessment, and the certificate your customers and insurers ask for.
Measured performance
<8min
Mean time to detect
<20min
Mean time to respond
95%
Threat disruption success
99.995%
Service availability
How an incident flows through SOC365
Stage 01
Behavioural analytics, engineered detections, threat intelligence and deception signals fire across endpoint, identity, cloud and network telemetry.
Stage 02
An analyst confirms the signal, gathers context and suppresses the false positives so you only hear about what is real.
Stage 03
Isolation, credential locking and blocking, executed with your approval or automatically where you have pre-authorised it.
Stage 04
Root cause, actions taken and what to change next, in a form your board and your auditors can both use.
Case studies
TWI engaged with UK Cyber Defence with a view to overhauling the organisations approach to information security. Now we are their global SOC.
The successful collaboration between NGS and UK Cyber Defence, showcasing the benefits of proactive cybersecurity measures.
Seeking urgent assistance to secure their business and navigate the regulatory aftermath of a breach, CEL turned to UK Cyber Defence IR team,
Insights
Trade bodies and membership organisations face a phishing-first threat picture: 30% of UK charities reported a breach or attack in the past year, and the newly listed Starlette vulnerability reaches the FastAPI back-ends behind many membership portals.
State-linked reconnaissance leads the defence and R&D picture — Volt Typhoon probing contractor login portals and APT41 active across 15+ industries — alongside KEV additions for JFrog Artifactory and BerriAI LiteLLM that bear directly on build chains and AI workflows.
Healthcare's week is defined by Boston Scientific's global network outage, the McKesson disclosure of roughly 284 million patient-related records exfiltrated via third-party applications, and Medusa ransomware passing 500 victims.
Start a conversation
Thirty minutes with an analyst or our CEO. We will tell you what we would do in your position, whether or not it involves us.