Risk Crew
Risk Crew is a UK-based information security consultancy that provides governance, risk, and compliance services, security testing, and training to mid-market and regulated UK enterprises, delivered by CREST and NCSC CHECK-accredited practitioners and supported by proprietary eRiskology and 3PA platforms.
- Company typePrivate
- Founded2010
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Risk Crew does
Risk Crew is a UK-headquartered information security governance, risk, and compliance (GRC) consultancy serving mid-market and regulated enterprises across the United Kingdom. The firm, based in Aylesbury, was founded in 2010 and now operates as a subsidiary of Red Helix following a 2025 acquisition. It sells a broad service catalogue organised across three pillars: Risk Management (AI risk and impact assessment, information security risk assessment, policy development, incident response, security awareness training, cyber supply chain risk management, ransomware readiness, virtual CISO, and DPO-as-a-Service); Security Testing (red team, application, blockchain, web, mobile, network, cloud, IoT, physical, and social engineering penetration testing plus vulnerability assessments); and GRC/Compliance (ISO 27001, ISO 42001, SOC 2, DORA, NIS 2, Cyber Essentials, Data Protection Act, and PCI). Delivery is grounded in credentialed practitioners holding CISSP, CISA, CRISC, CISM, GIAC, CEH, and other certifications, with the firm itself accredited by CREST, NCSC CHECK, IASME Cyber Assurance Gold, Cyber Essentials Plus, and ISO 27001.
The underlying technology estate is light on proprietary platform infrastructure; the firm runs as a consultancy whose primary deliverable is experienced practitioner time, supported by two proprietary software assets: eRiskology (an annual-subscription security awareness and training platform priced at £9.99 per user per month) and 3PA / 3PA Triage (a hosted platform for automated third-party cyber supply chain risk assessments). The 3PA tooling is positioned as a productised, scalable layer on top of the manual C-SCRM practice.
Risk Crew's commercial model is predominantly professional services revenue from project-based and retainer engagements, with custom quoting for all testing, advisory, vCISO, DPO, and incident response work, and a small but recurring contribution from eRiskology subscriptions. Go-to-market is sales-led and consultative: enterprise field sales supported by an inside sales function, content-driven demand generation through SEO, LinkedIn, YouTube, email, and webinars, and direct client engagement across UK-based regulated industries including legal, financial services, healthcare, pharmaceuticals, and logistics. Only one named customer (DRPG) is publicly disclosed as a case study, and there is no self-serve product channel beyond eRiskology.
Risk Crew firmographics
Firmographics- Name
- Risk Crew
- Legal name
- Risk Crew
- Website
- https://riskcrew.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Risk Crew is a UK-based information security consultancy that provides governance, risk, and compliance services, security testing, and training to mid-market and regulated UK enterprises, delivered by CREST and NCSC CHECK-accredited practitioners and supported by proprietary eRiskology and 3PA platforms.
- Ownership category
- akta.pro rank
Risk Crew industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Security Systems Services (except Locksmiths) (561621), Investigation and Personal Background Check Services (561611), Testing Laboratories and Services (54138)
- SIC
- Services-Detective, Guard & Armored Car Services (7381), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance (BPAEAPAG)
- akta.pro secondary industries
- Risk, Compliance & Internal Controls Consulting (BPAHACAJ), Risk Management (ERM), Operational Risk & Business Continuity (BPAEAPAJ)
Keywords
Where Risk Crew is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Risk Crew business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Professional Services – Security Assessments & Advisory: Core revenue stream from deliverable professional services engagements including penetration testing, red team exercises, security risk assessments, incident response, vCISO services, DPO-as-a-Service, and compliance gap assessments. engagements are project-based and typically quoted on a per-assessment or retainer basis. This constitutes the majority of Risk Crew's commercial activity.
- eRiskology Online Training Subscription: Annual subscription to the eRiskology security awareness training platform, sold on a per-user, per-month basis at £9.99/month. Delivered digitally with automated learner management. Provides a recurring revenue component complementing the one-time project-based services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Online Security Awareness Training – Annual Subscription |
| Other | Multi-year contract | All Other Services – Custom Quoting |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels8 records
Risk Crew product offering
Product offeringCore offering
Risk Crew is a practitioner-led information security governance, risk and compliance (GRC) consultancy delivering cybersecurity risk management, accredited security testing (penetration testing, red team, vulnerability assessments), compliance advisory (ISO 27001, ISO 42001, SOC 2, DORA, NIS 2, PCI, GDPR), and fractional executive services (vCISO, DPO-as-a-Service). The firm also sells two proprietary software products: the eRiskology security awareness training platform (subscription) and the 3PA/3PA Triage automated third-party cyber supply chain risk assessment platform.
Product overview
Risk Crew is an elite group of information security governance, risk and compliance (GRC) experts offering a comprehensive portfolio of cybersecurity services and software solutions. The core offering spans three main service areas: Risk Management (covering AI Risk Assessment, Information Security Risk Assessment, Information Security Policies, Incident Response Management, Security Awareness Training, Cyber Supply Chain Risk Management, Ransomware Readiness Assessment, Virtual CISO Services, and DPO as a Service); Security Testing (including Red Team Testing, Application Security Testing, Blockchain Security Testing, Web Application Penetration Testing, Physical Penetration Testing, Network Penetration Testing, Social Engineering Testing, Security Vulnerability Assessment, Mobile Application Security Testing, IoT Penetration Testing, and Cloud Penetration Testing); and GRC/Compliance Services (covering ISO 27001, ISO 42001, SOC 2, DORA, NIS 2, Cyber Essentials, Data Protection Act 2018, and PCI Compliance). The company also offers proprietary software products including the eRiskology training and awareness programme and the 3PA/3PA Triage automated supply chain risk management solutions.
Differentiator
Problem solved
Functional benefit
Products and services
- AI Risk & Impact Assessment
Quantifiable outcome
- 100% client satisfaction commitment
Companies that use Risk Crew
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
Risk Crew technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature2 records
Risk Crew partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Red HelixcoreRed Helix, a UK-based cybersecurity specialist, acquired Risk Crew in 2025. Simon Michie was appointed Managing Director of Risk Crew as part of the acquisition. The acquisition integrates Risk Crew's penetration testing, security risk management, and GRC capabilities into the Red Helix group, while Risk Crew retains its brand identity and operational delivery. The relationship is treated as a strategic parent-subsidiary partnership with significant impact on Risk Crew's go-to-market scale and cross-selling opportunities.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Risk Crew competitors and assessment
Company assessmentDirect peers
- A-LIGN: Cybersecurity and compliance firm specialising in SOC 2, ISO 27001, HITRUST, and penetration testing with proprietary compliance automation software. Comparable in service mix and software-enabled GRC positioning.
- Secarma: UK cybersecurity consultancy specialising in penetration testing, red team, and managed detection. Smaller boutique peer with overlapping security testing services and UK mid-market focus.
- Bulletproof (GardaWorld Security & Risk): UK-based cybersecurity consultancy offering penetration testing, compliance, and managed security services, now part of GardaWorld. Direct comparable in UK mid-market positioning and GRC/testing service mix.
- Coalfire: US-headquartered cybersecurity advisory specialising in GRC, penetration testing, and compliance services (SOC 2, ISO 27001, FedRAMP). Comparable practitioner-led model and service portfolio, though predominantly serving the US market.
- Bridewell: UK-based cybersecurity consultancy offering GRC advisory, penetration testing, managed security services, and threat intelligence. Most direct comparable to Risk Crew in size, UK mid-market/enterprise focus, and service portfolio breadth.
- Schellman: Top US compliance and cybersecurity firm offering SOC 2, ISO 27001, penetration testing, and vCISO services. Closely comparable practitioner-led GRC model, primarily serving US-based technology companies.
Broad incumbents
- NCC Group: Large UK-listed cybersecurity and assurance firm offering penetration testing, GRC consulting, and managed detection. Directly comparable service lines but at significantly larger scale and broader geographic reach than Risk Crew.
- WithSecure (formerly F-Secure): European cybersecurity vendor with a consulting arm delivering security assessments, GRC, and penetration testing services. Comparable service offerings with deeper international delivery than Risk Crew.
- Trustwave: Global cybersecurity firm offering penetration testing, GRC consulting, MDR, and threat intelligence. Overlaps with Risk Crew's security testing and advisory lines but at much larger scale and breadth.
- BSI (British Standards Institution): Standards body and consulting firm offering ISO 27001, ISO 42001, and broader GRC advisory and certification services. Direct overlap with Risk Crew's compliance practice at much larger scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Risk Crew social profiles
Digital presenceRisk Crew compliance and trust
Trust signalCompliance12 records
Risk Crew financial estimates
Financial estimateRevenue estimate
Valuation estimate
Risk Crew leadership team
Management profileNumber of profiles
Profiles1 record
Risk Crew funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Risk Crew M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Risk Crew
What does Risk Crew do?
Risk Crew is a practitioner-led information security governance, risk and compliance (GRC) consultancy delivering cybersecurity risk management, accredited security testing (penetration testing, red team, vulnerability assessments), compliance advisory (ISO 27001, ISO 42001, SOC 2, DORA, NIS 2, PCI, GDPR), and fractional executive services (vCISO, DPO-as-a-Service). The firm also sells two proprietary software products: the eRiskology security awareness training platform (subscription) and the 3PA/3PA Triage automated third-party cyber supply chain risk assessment platform.
Is Risk Crew a public or private company?
Risk Crew is a private company. It is classified as corporate owned and is currently operating.
When was Risk Crew founded?
Risk Crew was founded in 2010. It employs 11 to 50 people.
Where is Risk Crew based?
Risk Crew is headquartered in London, United Kingdom, in the Europe region.
How does Risk Crew make money?
Two revenue lines are on record. Professional Services – Security Assessments & Advisory is the primary driver. The others are eRiskology Online Training Subscription.
Who are Risk Crew's main competitors?
Direct peers on record are A-LIGN, Secarma, Bulletproof (GardaWorld Security & Risk), Coalfire, Bridewell and Schellman. Broad incumbents are NCC Group, WithSecure (formerly F-Secure), Trustwave and BSI (British Standards Institution).
Does Risk Crew have an API?
No public API is recorded for Risk Crew.
What industry is Risk Crew in?
Risk Crew's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAEAPAG, Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance, with a secondary code of BPAHACAJ, Risk, Compliance & Internal Controls Consulting. Its NAICS code is 561621 and its SIC code is 7381.