About · Est. 2009 · Duxford
One company.One team.No middlemen.
We started in 2009 as Hedgehog Security, launched our own SOC365 platform in 2022, and became Cyber Defence in 2024. Everything we sell, we run ourselves from The Officers' Mess in Duxford.
CRESTISO 27001 · ISO 9001Cyber Essentials PlusCompany no. 16199391
Detect threats that others miss. Defend systems that others overlook. Disrupt attackers that others fear.
Security should be engineered, measurable and intelligence-led. Our Detect–Defend–Disrupt model unifies monitoring, investigation, engineering and offensive insight into one defensive capability — the result of everything we have learned in more than fifteen years of cyber operations, leading SOCs, responding to crises and testing organisations at scale.
- Founded
- 2009 (as Hedgehog Security)
- Registered
- UK Cyber Defence Ltd · 16199391 · England and Wales
- Base
- The Officers' Mess, Royston Road, Duxford, Cambridge CB22 4QH
- Accreditations
- CREST · ISO 27001 · ISO 9001 · Cyber Essentials Plus · CMMC L3
From the founder
A company that tells the truth
When I founded Hedgehog Security in 2009, my goal was to create a security company that told the truth — clarity, honesty and practical guidance in a world full of noise. Over the years it became clear that organisations did not just need testing; they needed continuous protection, grounded in intelligence and engineered for resilience. That insight shaped SOC365, our Disrupt incident response team and the way intelligence runs through everything we do.
Cyber Defence is built on people who care deeply about their craft: analysts, responders, penetration testers, engineers, researchers and developers. We exist to protect our clients, to disrupt attackers, and to raise the standard of cyber defence for organisations that deserve better than the status quo.
— Peter Bassill, Founder
Principles
What guides the work
Truth over comfort
We give honest assessments, even when the truth is uncomfortable. We sell good mornings, not nightmares: if a risk is small we say so.
Action over theory
Practical, implementable improvements rather than recommendations nobody will act on.
Engineering over paperwork
Real resilience comes from technical change, not from audits alone.
Detection over assumptions
If we cannot see it, we cannot defend it. Logging and monitoring are non-negotiable.
Threat-led over checklist-led
Our work is shaped by how attackers behave, not by arbitrary frameworks.
Continuous improvement
Security must evolve as fast as the threats that target it; point-in-time fixes are not enough.
Timeline
Fifteen years, shaped by real adversaries
Stage 01
2009
Hedgehog Security founded: a penetration testing and offensive security consultancy built on OSSTMM and PTES principles.
Stage 02
2012
Full CREST membership — formal recognition of technical excellence in penetration testing and security assessment.
Stage 03
2014
Incident response practice established, the beginnings of what became the Disrupt team.
Stage 04
2016
Threat intelligence programme launched: phishing analysis, dark-web indexing and adversary infrastructure tracking.
Stage 05
2018
EmilyAI created — our internal SOC analyst assistant.
Stage 06
2019
SOC365 blueprint: a unified MDR platform combining telemetry normalisation, correlation models and threat intelligence.
Stage 07
2022
SOC365 platform launched, delivering cloud, endpoint, identity and OT monitoring as one service.
Stage 08
2024
Rebrand to Cyber Defence; UK Cyber Defence Ltd incorporated in January 2025 as a single UK company.
01
Ethical AIEmilyAI · Human-led
AI that assists. Analysts who decide.
We use artificial intelligence to support analysts, not replace them. EmilyAI accelerates triage, enrichment, correlation and documentation, while every investigative decision, containment action and escalation remains with a qualified human. She runs only inside our own environment, processes the minimum metadata needed, never sees raw client data or credentials, and every interaction is logged and attributable. Reliability, predictability and controllability come first — an approach we borrow from Alan Turing's thinking about what makes a computational system trustworthy.
- Can
- Summarise alerts · Extract indicators · Look up intelligence · Draft case notes · Reduce noise
- Cannot
- Contain · Change client systems · Deploy detections · Suppress alerts · Act unsupervised
- Safeguards
- Internal-only · Minimal data · Change control · Audit logging · Role-based access
Start a conversation
Come and see the SOC.
We are twenty minutes from Cambridge. Visitors welcome by arrangement.