SOC status:Duty analyst on shift

UK Cyber Defence

About · Est. 2009 · Duxford

One company.One team.No middlemen.

We started in 2009 as Hedgehog Security, launched our own SOC365 platform in 2022, and became Cyber Defence in 2024. Everything we sell, we run ourselves from The Officers' Mess in Duxford.

CRESTISO 27001 · ISO 9001Cyber Essentials PlusCompany no. 16199391

00Mission

Detect threats that others miss. Defend systems that others overlook. Disrupt attackers that others fear.

Security should be engineered, measurable and intelligence-led. Our Detect–Defend–Disrupt model unifies monitoring, investigation, engineering and offensive insight into one defensive capability — the result of everything we have learned in more than fifteen years of cyber operations, leading SOCs, responding to crises and testing organisations at scale.

Founded
2009 (as Hedgehog Security)
Registered
UK Cyber Defence Ltd · 16199391 · England and Wales
Base
The Officers' Mess, Royston Road, Duxford, Cambridge CB22 4QH
Accreditations
CREST · ISO 27001 · ISO 9001 · Cyber Essentials Plus · CMMC L3

From the founder

A company that tells the truth

When I founded Hedgehog Security in 2009, my goal was to create a security company that told the truth — clarity, honesty and practical guidance in a world full of noise. Over the years it became clear that organisations did not just need testing; they needed continuous protection, grounded in intelligence and engineered for resilience. That insight shaped SOC365, our Disrupt incident response team and the way intelligence runs through everything we do.

Cyber Defence is built on people who care deeply about their craft: analysts, responders, penetration testers, engineers, researchers and developers. We exist to protect our clients, to disrupt attackers, and to raise the standard of cyber defence for organisations that deserve better than the status quo.

— Peter Bassill, Founder

Principles

What guides the work

01

Truth over comfort

We give honest assessments, even when the truth is uncomfortable. We sell good mornings, not nightmares: if a risk is small we say so.

02

Action over theory

Practical, implementable improvements rather than recommendations nobody will act on.

03

Engineering over paperwork

Real resilience comes from technical change, not from audits alone.

04

Detection over assumptions

If we cannot see it, we cannot defend it. Logging and monitoring are non-negotiable.

05

Threat-led over checklist-led

Our work is shaped by how attackers behave, not by arbitrary frameworks.

06

Continuous improvement

Security must evolve as fast as the threats that target it; point-in-time fixes are not enough.

Timeline

Fifteen years, shaped by real adversaries

  1. Stage 01

    2009

    Hedgehog Security founded: a penetration testing and offensive security consultancy built on OSSTMM and PTES principles.

  2. Stage 02

    2012

    Full CREST membership — formal recognition of technical excellence in penetration testing and security assessment.

  3. Stage 03

    2014

    Incident response practice established, the beginnings of what became the Disrupt team.

  4. Stage 04

    2016

    Threat intelligence programme launched: phishing analysis, dark-web indexing and adversary infrastructure tracking.

  5. Stage 05

    2018

    EmilyAI created — our internal SOC analyst assistant.

  6. Stage 06

    2019

    SOC365 blueprint: a unified MDR platform combining telemetry normalisation, correlation models and threat intelligence.

  7. Stage 07

    2022

    SOC365 platform launched, delivering cloud, endpoint, identity and OT monitoring as one service.

  8. Stage 08

    2024

    Rebrand to Cyber Defence; UK Cyber Defence Ltd incorporated in January 2025 as a single UK company.

01

Ethical AIEmilyAI · Human-led

AI that assists. Analysts who decide.

We use artificial intelligence to support analysts, not replace them. EmilyAI accelerates triage, enrichment, correlation and documentation, while every investigative decision, containment action and escalation remains with a qualified human. She runs only inside our own environment, processes the minimum metadata needed, never sees raw client data or credentials, and every interaction is logged and attributable. Reliability, predictability and controllability come first — an approach we borrow from Alan Turing's thinking about what makes a computational system trustworthy.

Can
Summarise alerts · Extract indicators · Look up intelligence · Draft case notes · Reduce noise
Cannot
Contain · Change client systems · Deploy detections · Suppress alerts · Act unsupervised
Safeguards
Internal-only · Minimal data · Change control · Audit logging · Role-based access

Start a conversation

Come and see the SOC.

We are twenty minutes from Cambridge. Visitors welcome by arrangement.