Acumen Cyber
Acumen Cyber is a Glasgow-based cybersecurity firm operating a 24/7 CREST-accredited Security Operations Centre that delivers managed detection and response, threat intelligence, vCISO, and incident response services to UK and Ireland enterprise, education, and public sector clients.
- Company typePrivate
- Founded2024
- HeadquartersGlasgow, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Acumen Cyber does
Acumen Cyber is a Glasgow-headquartered cybersecurity services provider operating a 24/7 CREST-accredited Security Operations Centre (SOC) that delivers managed extended detection and response, cyber threat intelligence, vCISO advisory, and incident response services. The SOC is staffed by security engineers operating a non-tiered, end-to-end ownership model under an "assume breach" methodology, ingesting billions of events daily and driving tens of thousands of alert investigations. The technical stack is anchored on Elastic SIEM with Recorded Future threat intelligence, AWS cloud infrastructure, and SentinelOne and CrowdStrike endpoint platforms, with AI-driven automation used for alert triage, anomaly detection, and investigation summarisation.
The company serves mid-market and enterprise customers primarily in the United Kingdom and Ireland across education, transport, manufacturing, and public sector verticals, alongside MSPs and MSSPs served through a formal Channel Partner Program with Reseller and Introducer models. Education-sector delivery is structured through a strategic partnership with HEFESTIS, a not-for-profit shared service owned by UK universities and colleges, which has produced customer wins at Edinburgh Napier University and Ayrshire College under the SecurEd sub-brand. Revenue is generated predominantly through subscription-based managed services (MXDR Complete covering endpoints, SaaS, cloud, and infrastructure, plus the Enhanced Managed Security Suite and CTI service) with supplementary professional services revenue from vCISO engagements, advisory, and incident response. Pricing is quote-based on annual or multi-year contracts; no public pricing or revenue figures are disclosed. Distribution combines direct enterprise field sales with channel partner enablement and active participation in UK cybersecurity events including Infosecurity Europe, Scot-Secure, and CYBERUK. The company holds CREST SOC accreditation alongside ISO 27001, ISO 9001, ISO 14001, Cyber Essentials Plus, and UK GDPR compliance.
Acumen Cyber firmographics
Firmographics- Name
- Acumen Cyber
- Legal name
- Acumen Cyber Limited
- Website
- https://acumencyber.com
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Acumen Cyber is a Glasgow-based cybersecurity firm operating a 24/7 CREST-accredited Security Operations Centre that delivers managed detection and response, threat intelligence, vCISO, and incident response services to UK and Ireland enterprise, education, and public sector clients.
- Ownership category
- akta.pro rank
Acumen Cyber industry classification
Industry- Product category
- Managed Security Services
- NAICS
- Security Systems Services (56162), Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Computer Facilities Management Services (541513)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
Keywords
Where Acumen Cyber is headquartered
LocationHeadquarters
- HQ city
- Glasgow
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Acumen Cyber business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Security Services (MXDR): Recurring subscription-based managed security services including 24/7 monitoring, threat detection, and incident response delivered through the SOC. Services include MXDR Complete, MXDR for Endpoints, MXDR for SaaS, MXDR for Cloud, and MXDR for Infrastructure.
- vCISO and Advisory Services: Virtual Chief Information Security Officer and security consultancy services providing strategic security leadership, framework benchmarking, risk management, policy development, and incident response planning on a flexible, part-time or project basis.
- Enhanced Managed Security Suite: Portfolio of standalone managed security solutions including Email Security, Secure SD-WAN, Privileged Access Management, DNS Filtering, Dark Web Monitoring, Web Application Firewall, Business Continuity and Disaster Recovery, and Vulnerability Management.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Custom enterprise pricing based on organization size and security requirements |
Go-to-market motion3 records
Distribution channels2 records
Marketing channels3 records
Acumen Cyber product offering
Product offeringCore offering
Acumen Cyber is a UK-based cybersecurity service provider that operates a 24/7 CREST-accredited Security Operations Centre (SOC) delivering managed extended detection and response (MXDR) services, cyber threat intelligence, vCISO advisory, incident response, and an enhanced managed security suite to organisations across the UK and Ireland. The core offering centres on continuous 24/7 monitoring, threat detection, and incident response delivered by a non-tiered team of security engineers, underpinned by Elastic SIEM, Recorded Future threat intelligence, and integrations with SentinelOne, CrowdStrike, and Fortinet.
Product overview
Acumen Cyber is an engineer-powered cyber security service provider operating a portfolio of managed security services anchored by a fully UK-based, CREST-accredited 24/7 Security Operations Centre (SOC). The core offering is MXDR Complete — a unified managed service merging MXDR for Endpoints, MXDR for SaaS Applications, MXDR for Cloud, and MXDR for Infrastructure into a single cohesive platform. MXDR Complete is underpinned by Elastic SIEM and Recorded Future threat intelligence, and integrates SentinelOne and CrowdStrike endpoint platforms. Supporting the core MXDR suite are: Cyber Threat Intelligence (CTI) Service (with an Enhanced tier powered by Recorded Future), the Enhanced Managed Security Suite (covering Email Security, Secure SD-WAN, Vulnerability Management, Dark Web Monitoring, DNS Filtering, PAM, Disaster Recovery, and WAF), Incident Response, Security Posture Benchmarking Assessments, vCISO and Acumen Advisory Services, and SecurEd (an education-sector branded offering). All services are delivered through the CREST-accredited SOC staffed by full-stack security engineers using AI-driven automation.
Differentiator
Problem solved
Functional benefit
Products and services
- MXDR Complete A unified, all-encompassing Managed eXtended Detection and Response (MXDR) service that merges MXDR for Endpoints, MXDR for SaaS, MXDR for Cloud, and MXDR for Infrastructure into a single fully managed security solution. Provides 24/7 SOC monitoring across endpoints, servers, network devices, cloud platforms (AWS, Azure, GCP), and SaaS applications (Microsoft 365), underpinned by Elastic SIEM and Recorded Future threat intelligence.
- MXDR for Endpoints Dedicated MXDR service focused on endpoint security, providing AI-driven threat detection, real-time monitoring, and automated response across all endpoint devices. Integrated with SentinelOne and CrowdStrike platforms.
- MXDR for SaaS Applications Dedicated MXDR service focused on SaaS application security, covering Microsoft 365 and other SaaS platforms, providing monitoring, detection, and response for SaaS-specific threat vectors.
- MXDR for Cloud Dedicated MXDR service focused on cloud security, covering AWS, Azure, and Google Cloud environments. Monitors cloud configurations, workloads, and data for misconfigurations and threats.
- MXDR for Infrastructure Dedicated MXDR service focused on network infrastructure security, monitoring servers, network devices, and on-premises environments for threats and vulnerabilities.
- Cyber Threat Intelligence (CTI) Service Cyber Threat Intelligence service powered by Recorded Future, delivering real-time intelligence on emerging threats. Embedded directly into the MXDR platform and SOC workflows. Includes an Enhanced Threat Intelligence Service with custom alerts, bespoke reports, and strategic guidance.
- Enhanced Managed Security Suite A comprehensive collection of standalone managed cybersecurity services including Email Security, Secure SD-WAN (Fortinet), Continuous Vulnerability Management, Dark Web Monitoring, DNS Filtering, Privileged Access Management (PAM), Business Continuity & Disaster Recovery, and Web Application Firewall (WAF). Each service is fully integrated into the MXDR platform and managed by the SOC team.
- Incident Response Service Incident response services for organisations experiencing a cyber breach, providing swift containment, investigation, remediation, and recovery support 24/7.
- vCISO Service and Acumen Advisory Services Virtual Chief Information Security Officer (vCISO) service providing flexible, part-time executive-level security leadership, strategic guidance, framework benchmarking (NIST CSF, NCSC CAF, ISO 27001), board-level reporting, risk management, policy and governance development, and penetration testing. Advisory services also cover cloud security architecture, compliance and audit support, third-party risk management, and incident response planning.
- Security Posture Benchmarking Assessments Security posture benchmarking assessments that evaluate an organisation's current security posture against recognised standards (NIST, CAF, ISO 27001), identify gaps, and develop a custom roadmap for continuous improvement.
- Security Operations Centre (SOC) Acumen's fully UK-based, CREST-accredited 24/7 Security Operations Centre staffed by security engineers (not tiered analysts). Analyses billions of events daily, investigates tens of thousands of alerts, and drives focused investigations. Uses Elastic SIEM, Recorded Future threat intelligence, and AI-driven automation. Non-tiered model where engineers own incidents end-to-end.
- SecurEd Enterprise-grade cybersecurity service tailored for the further and higher education sector, delivered through a single comprehensive service model that eliminates coverage gaps and provides predictable fixed-price support. Every aspect of the environment is continuously monitored, secured, and managed by experts.
- Channel Partner Program Partnership program for MSPs, VARs, and consultancies to resell or refer Acumen Cyber's managed security services. Partners gain access to a Partner Portal with customer insights, service performance data, security posture visibility, co-branded marketing materials, and training. Two models: Reseller and Introducer.
Quantifiable outcome
- Billions of events processed daily across client environments
- +1 more outcomes
Companies that use Acumen Cyber
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
Acumen Cyber technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability5 records
Feature3 records
Acumen Cyber partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and supporting.
- AttackIQcoreStrategic partnership combining Acumen Cyber's engineering-led SOC capabilities with AttackIQ's adversary-informed Continuous Threat Exposure Management (CTEM) platform. Enables organizations to continuously validate defenses, map viable attack paths, and measure reduction in adversary opportunity over time. Engineers will emulate MITRE ATT&CK techniques to help customers identify exploitable attack paths.
- Recorded FuturecoreThreat intelligence partnership powering Acumen Cyber's CTI service. Recorded Future provides real-time threat feeds from open web, dark web, and other sources. Integrated into MXDR platform for dynamic detection rules, proactive threat hunting, and continuous optimization of security strategies.
- ElasticcoreElastic SIEM platform forms the backbone of Acumen Cyber's SOC operations, providing log ingestion, event correlation, and real-time analytics across cloud, on-premises, and container environments.
- SentinelOnecoreAI-driven endpoint protection platform integrated into MXDR services, providing real-time threat intelligence, automated detection and remediation, and rollback capabilities for affected systems.
- CrowdStrikecoreEndpoint security platform integrated into MXDR services, delivering AI-driven detection, real-time threat intelligence, and rapid response capabilities across all endpoints.
- AWScoreCloud infrastructure powering Acumen Cyber's security analytics platform, client portal, and hyper-automation solutions with scalable, secure cloud operations.
- FortinetsupportingSecure SD-WAN solutions integrated into Enhanced Managed Security Suite, providing security-forward networking for distributed enterprise environments.
- HEFESTIScorePartnership with HEFESTIS, a not-for-profit shared service organization owned by UK universities and colleges, to deliver cybersecurity services to the higher and further education sector. Combines HEFESTIS's sector knowledge with Acumen's SOC capabilities for comprehensive education security.
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
Acumen Cyber competitors and assessment
Company assessmentDirect peers
- Arctic Wolf: Large pure-play MDR provider offering 24/7 managed detection and response via a SOC-concierge model. The most direct competitor to Acumen Cyber's MXDR / SOC offering, with overlapping customer target of mid-market and enterprise needing outsourced security operations.
- Bridewell: UK-based cybersecurity services firm operating a CREST-accredited 24/7 SOC alongside MXDR, vCISO, and advisory services. Closest UK-headquartered direct peer given shared focus on mid-market and enterprise UK customers with a sovereignty-led SOC offering.
- Expel: US-headquartered MDR provider delivering 24/7 transparent SOC services with strong integrations into leading SIEM, EDR, and cloud platforms. Comparable in being a platform-aggregating, integrations-heavy MDR rather than a single-vendor stack.
- eSentire: Pure-play MDR provider operating a 24/7 SOC and a proprietary XDR platform, with strong exposure to mid-market and enterprise customers. Comparable in product scope (MDR, threat intelligence, incident response) and reliance on multi-vendor telemetry ingestion.
- Alert Logic: Managed detection and response provider delivering 24/7 SOC monitoring, threat detection, and incident response across cloud and on-premises environments. Comparable service scope (SOC, MDR, compliance reporting) and similarly mid-market-focused go-to-market.
- Quorum Cyber: UK-based cybersecurity services firm operating a Microsoft-focused 24/7 SOC alongside incident response and advisory. Closely comparable as a UK-headquartered, mid-sized, multi-sector MDR/MSP with strong Microsoft ecosystem ties.
Broad incumbents
- Sophos Managed Detection and Response: Established global cybersecurity vendor that has built a 24/7 MDR service on top of its own endpoint, network, and email products, plus third-party integrations. Competes head-on with Acumen in the mid-market segment, particularly with MSP channel distribution.
- CrowdStrike (Falcon Complete): Endpoint security incumbent whose Falcon Complete MDR service directly competes with Acumen's MXDR-for-Endpoints product while also serving as a key underlying technology partner for Acumen. Unique in being both a competing vendor and a partner ecosystem reference.
- NCC Group: UK-headquartered global cybersecurity consultancy with managed detection, incident response, and advisory services. Relevant UK-based incumbent peer with overlapping services (MXDR-style managed SOC, CTI, advisory) and broader enterprise/government reach.
Regional players
- WithSecure (formerly F-Secure): European-origin cybersecurity vendor offering managed detection and response through a 24/7 SOC, with strong presence in Northern Europe. Comparable as a SOC-as-a-service provider selling into mid-market customers, though geographically weighted toward continental Europe rather than the UK.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Acumen Cyber social profiles
Digital presenceAcumen Cyber compliance and trust
Trust signalCompliance7 records
Acumen Cyber financial estimates
Financial estimateRevenue estimate
Valuation estimate
Acumen Cyber leadership team
Management profileNumber of profiles
Profiles3 records
Acumen Cyber funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Acumen Cyber M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Acumen Cyber
What does Acumen Cyber do?
Acumen Cyber is a UK-based cybersecurity service provider that operates a 24/7 CREST-accredited Security Operations Centre (SOC) delivering managed extended detection and response (MXDR) services, cyber threat intelligence, vCISO advisory, incident response, and an enhanced managed security suite to organisations across the UK and Ireland. The core offering centres on continuous 24/7 monitoring, threat detection, and incident response delivered by a non-tiered team of security engineers, underpinned by Elastic SIEM, Recorded Future threat intelligence, and integrations with SentinelOne, CrowdStrike, and Fortinet.
Is Acumen Cyber a public or private company?
Acumen Cyber is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Acumen Cyber founded?
Acumen Cyber was founded in 2024. It employs 11 to 50 people.
Where is Acumen Cyber based?
Acumen Cyber is headquartered in Glasgow, United Kingdom, in the Europe region.
How does Acumen Cyber make money?
Three revenue lines are on record. Managed Security Services (MXDR) is the primary driver. The others are vCISO and Advisory Services and enhanced Managed Security Suite.
Who are Acumen Cyber's main competitors?
Direct peers on record are Arctic Wolf, Bridewell, Expel, eSentire, Alert Logic and Quorum Cyber. Broad incumbents are Sophos Managed Detection and Response, CrowdStrike (Falcon Complete) and NCC Group. WithSecure (formerly F-Secure) is listed as a regional player.
Does Acumen Cyber have an API?
No public API is recorded for Acumen Cyber.
What industry is Acumen Cyber in?
Acumen Cyber's product category is Managed Security Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 56162 and its SIC code is 8700.