Skip to content
LokalMatch

Cybersecurity Consultants

Cybersecurity Consultants near you

Security consulting in the UK covers a wide range of work sold under one word. At one end is help getting a Cyber Essentials certificate, which is a defined scheme with five controls and a pass or fail outcome. At the other is a framework assessment against the NCSC Cyber Assessment Framework, a penetration test, an incident response retainer or a part-time security lead. These are different jobs with different deliverables, and buying the wrong one is the usual reason a security budget produces nothing anyone can point to.

Tell us what you need and we’ll help you find cybersecurity consultants who serve your area.

Free for homeowners · No obligation to hire

On this page

Nobody needs a licence to call themselves a security consultant here. What does exist is a set of recognised reference points: the NCSC's schemes and guidance, the Network and Information Systems Regulations for operators of essential services and digital service providers, and the ICO's expectations about security of processing. A consultant who cannot place your organisation against those reference points is guessing.

The other thing to get right before any testing starts is authorisation. Accessing a computer system without permission is a criminal matter under the Computer Misuse Act 1990, so the scope and the written consent are not paperwork, they are the legal basis for the work.

The distinct jobs sold as cyber security consulting

  • Certification support: getting an organisation through Cyber Essentials or Cyber Essentials Plus, including remediation of whatever fails first time.
  • Penetration testing: a time-boxed attempt to find exploitable weaknesses in a defined set of systems, ending in a report with evidence.
  • Framework assessment: measuring an organisation against a structured model such as the NCSC Cyber Assessment Framework and producing a prioritised improvement plan.
  • Incident response: retained help for when something has already happened, including containment, forensics and the regulatory notifications that follow.
  • Fractional security leadership: a part-time senior person who owns risk decisions, supplier assurance and board reporting rather than producing a document.
  • Supplier assurance: reviewing the security of the third parties you depend on, which for most organisations is now the larger exposure.

Cyber Essentials certification versus a real security assessment

Cyber Essentials answers a narrow question well: are five specific technical controls in place across the organisation. It is a good floor, it is widely recognised by UK buyers and insurers, and the Plus variant is verified by independent technical testing rather than a questionnaire. It says nothing about whether your staff would notice a fraudulent invoice, whether your backups survive ransomware, or whether your supplier has your customer database.

An assessment asks the wider question and produces a ranked list of things to fix, usually with owners and dates. It has no certificate at the end, which makes it harder to sell internally and easier to ignore. The sensible sequence for most organisations is certification first because it is bounded and demonstrable, then an assessment once the obvious gaps are closed.

The Cyber Assessment Framework and the NIS Regulations

The NCSC describes the Cyber Assessment Framework as a tool for assessing and improving cyber security and resilience and for protecting essential services. It is built around objectives, principles, outcomes and indicators of good practice, and it publishes two profiles: a basic profile setting a baseline against common attacks, and an enhanced profile for organisations facing sophisticated, well-resourced attackers.

The framework matters most to organisations captured by the Network and Information Systems Regulations 2018. Those regulations apply to operators of essential services across sectors including electricity, oil and gas, air, rail, water and road transport, healthcare, drinking water supply and digital infrastructure, and separately to relevant digital service providers, which register with the Information Commissioner. Operators carry security duties and a duty to notify incidents, and the regulations provide for information notices, inspections, enforcement notices and penalties.

If you are in scope, say so in the first conversation. A consultant scoping a generic penetration test for an organisation with CAF obligations is solving a smaller problem than the one you have.

Written authorisation before anyone tests anything

Under section 1 of the Computer Misuse Act 1990 it is an offence to cause a computer to perform a function intending to secure access to programs or data where the access is unauthorised and the person knows it is unauthorised. Testing that you have properly authorised is not unauthorised access. Testing that nobody in your organisation approved may be.

So the authorisation letter needs to name the systems, the IP ranges and domains in scope, the window in which testing may happen, the techniques permitted, and the person signing who has authority to give that permission. Where a system is hosted by someone else, the hosting provider's own terms may require notice as well, and that is your job to establish, not the tester's assumption.

Scoping a test so the report is worth reading

  • Agree what is in scope by asset, not by adjective: named applications, environments and network ranges rather than a phrase like the corporate network.
  • State whether the tester starts with no credentials, with a standard user account, or with documentation, because the three produce very different findings.
  • Decide in advance how a critical finding is escalated mid-test rather than held for the report.
  • Require evidence with each finding, and a retest of the fixes included in the price rather than sold afterwards.
  • Ask for the report to separate what is exploitable now from what is merely untidy, since a flat list of severities buries the urgent items.

Incident response and the reporting clocks that start immediately

During an incident the technical work and the regulatory work run in parallel. If personal data is involved and the breach is notifiable, the ICO expects a report without undue delay and no later than 72 hours after you become aware, with phased detail permitted where the investigation is incomplete. Individuals must be told directly and without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Every breach must be documented internally whether or not it is reported.

A retainer is mostly about not making those decisions from scratch at two in the morning. What it should include is a named contact, an agreed response time, pre-signed authorisation so the responder can act on your systems lawfully, and clarity about who drafts the regulatory notification and who signs it. Organisations under the NIS Regulations have a separate incident notification duty to their competent authority as well.

Signs the engagement will produce nothing

  • The proposal sells a tool subscription rather than an assessment, and the findings all happen to be things that tool detects.
  • The report is an unfiltered scanner export with no attempt to establish which findings are reachable in your environment.
  • Nobody has asked who your suppliers are, although the NCSC's supply chain guidance treats supplier assurance as a core control and notes that very few UK businesses set minimum security standards for their suppliers.
  • There is no named owner or date against any recommendation, so the document ages without anything changing.
  • The consultant will not put the authorisation and scope in writing before starting.

Cybersecurity Consultants: frequently asked questions

Do cyber security consultants need a licence in the UK?

No. There is no statutory licence and no protected title, so anyone may trade under the description. What can be checked is scheme membership and certification: whether the firm is itself Cyber Essentials or Cyber Essentials Plus certified, whether its testers hold recognised assurance scheme credentials, and whether it can describe your obligations under the NIS Regulations or UK GDPR accurately without being prompted.

Are we covered by the NIS Regulations?

Only if you are an operator of an essential service in a listed sector, such as electricity, oil and gas, transport, healthcare, drinking water or digital infrastructure, or a relevant digital service provider meeting the thresholds. Digital service providers register with the Information Commissioner. Most ordinary businesses are outside the regime entirely, but a supplier to an operator may be pulled into its requirements by contract rather than by the regulations themselves.

Is a penetration test the same as a vulnerability scan?

No. A scan is automated and produces a list of things that look wrong from outside. A test uses that as a starting point and attempts to confirm what can actually be exploited and what an attacker would reach next. Both are useful, but a report that lists hundreds of findings with no evidence of exploitation is a scan with a cover page, and it should be priced as one.

How often should testing be repeated?

There is no fixed UK legal interval for most organisations. The practical triggers are change rather than the calendar: a new public-facing application, a significant architecture change, a merger, or a move to a new hosting arrangement. Annual testing plus retesting after material change is a common pattern, and contractual obligations from customers or insurers often set the actual rhythm.

Can a consultant report a breach to the ICO on our behalf?

They can draft it and help you assemble the facts, but the obligation sits with the controller. Because the deadline is measured from when you become aware, agree in advance how the consultant escalates to a named person in your organisation, and make sure that person can be reached outside working hours.

Sources

  1. NCSC: Cyber Assessment Framework
  2. NCSC: Cyber Essentials overview
  3. NCSC: supply chain security guidance
  4. Network and Information Systems Regulations 2018 (SI 2018/506)
  5. Computer Misuse Act 1990, section 1
  6. ICO: personal data breaches, a guide

Written by the LokalMatch editorial team. Last reviewed 22 September 2026. How we write and check our guides

Find cybersecurity consultants by city

England

Show 173 cities

What affects the fees cybersecurity consultants charge

Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:

  • Scope and complexity of the work
  • How the firm bills: hourly, per project or on a monthly retainer
  • Experience of the team
  • Timeline and how urgent the work is
  • Ongoing support after the work is delivered

How to compare cybersecurity consultants before you hire

  • Ask for examples of similar work for clients like you.
  • Read reviews and ask for references you can contact.
  • Make sure the scope, deliverables and timeline are written down before work starts.
  • Ask who will do the work: an in-house team, freelancers or subcontractors.
  • Compare two or three proposals before you decide.

Questions to ask cybersecurity consultants before you hire

  • Have you done work like this before, and can I see examples?
  • Who will work on this, and who is my main contact?
  • How do you charge: hourly, per project or monthly?
  • What is included, and what costs extra?
  • How long is the contract, and how can either side end it?
  • How will you report on progress?
  • Who owns the work, files and accounts you set up for me?

Licences and registration

This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.

Ready to contact cybersecurity consultants?

Tell us what you need in a few sentences.