Cyber and Fraud Centre
The Cyber and Fraud Centre – Scotland is an Edinburgh-based social enterprise delivering cyber security and fraud prevention services to private, public, and third sector organisations across Scotland via professional services, the Cyber Skills Academy, and community and membership programmes.
- Company typePrivate
- Founded2015
- HeadquartersEdinburgh, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cyber and Fraud Centre does
The Cyber and Fraud Centre – Scotland is a social enterprise headquartered in Edinburgh (with an additional office in Linlithgow) that delivers cyber security and fraud prevention services to private, public, and third sector organisations across Scotland. Operating since its 2025 transition to a social enterprise model (under the previously known Scottish Business Resilience Centre brand), the organisation structures its offering around three pillars: Professional Services (Cyber MOT, Cyber Advance, vulnerability assessments, penetration testing, risk assessment, phishing resilience exercises, and the newly launched vCISO service), the Cyber Skills Academy (introductory staff training, board-level executive education, incident response plan testing, and NCSC Exercise in a Box workshops), and Community & Membership (threat intelligence alerts, an incident response helpline at 0800 167 0623, the Scottish Cyber Security Network, and the separately established Cyber and Fraud Hub).
The underlying technology is services-led rather than platform-led: assessments and ethical hacking are delivered by practitioners, training is delivered via live webinars, in-person workshops, and bespoke sessions, and member benefits centre on curated threat intelligence and community access. No proprietary AI/ML models, patents, or platform IP are disclosed; differentiation rests on regional positioning (Scotland's only cyber social enterprise), NCSC-affiliated training content, the Abertay University ethical-hacker placement pipeline (over 70 placements since 2020), and trust capital with risk-averse public-sector and charity buyers.
Revenue mechanics combine a freemium distribution layer (free Cyber Byte webinars, free 90-minute CPD-accredited intro sessions, free victim support) with monetised layers of quote-based B2B professional services, paid corporate training programmes (Secure Leaders, Cyber Executive Education, Staff Training Advance), recurring membership subscriptions, and the new monthly/quarterly/annual vCISO engagements. Pricing for the vCISO service includes socially focused tiers for charities, third sector, and start-ups. The organisation reports £3M+ deployed into Scottish cyber projects in the year since the social enterprise transition, £1.4M in training delivered, and over £500,000 in direct incident response support to organisations, alongside assistance to more than 700 cyber-fraud victims with an estimated £1.6M in losses prevented.
Cyber and Fraud Centre firmographics
Firmographics- Name
- Cyber and Fraud Centre
- Legal name
- Cyber and Fraud Centre – Scotland
- Website
- https://cyberfraudcentre.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- The Cyber and Fraud Centre – Scotland is an Edinburgh-based social enterprise delivering cyber security and fraud prevention services to private, public, and third sector organisations across Scotland via professional services, the Cyber Skills Academy, and community and membership programmes.
- Ownership category
- akta.pro rank
Cyber and Fraud Centre industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Training (61142), Technical and Trade Schools (6115), Educational Services (611), Security Systems Services (56162)
- SIC
- Services-Educational Services (8200)
- akta.pro primary industry
- Cybersecurity Training & Awareness Programs (BPAEANAF)
- akta.pro secondary industries
- Cybersecurity (General) (EDAOAIAB), Cybersecurity Learning Platforms (EDAFANAF), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Cybersecurity (Digital Safety, Ethical Hacking Basics) (EDAMACAH)
Keywords
Where Cyber and Fraud Centre is headquartered
LocationHeadquarters
- HQ city
- Edinburgh
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Cyber and Fraud Centre business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Professional Cyber Security Services: B2B cyber security services including vulnerability testing, penetration testing, Cyber MOT, Cyber Advance, Risk Assessment, and vCISO services. Profits from these services are reinvested to support community initiatives as part of the social enterprise model.
- Training and Skills Academy: Cyber Skills Academy providing training sessions including Introduction to Cyber Security, Cyber Executive Education, Incident Response Plan Testing, and bespoke corporate training
- Membership Programme: Membership subscriptions providing access to training, resources, threat intelligence alerts, incident response support, and community networking
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Introduction to Cyber Security sessions - Free entry-level training |
| Freemium | Pay-as-you-go | Cyber Byte webinars - Free educational sessions |
| Subscription | Monthly | vCISO Service - Flexible engagement options |
| Other | Multi-year contract | Professional Services - B2B cyber security services |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels9 records
Cyber and Fraud Centre product offering
Product offeringCore offering
The Cyber and Fraud Centre – Scotland delivers professional cyber security services, skills training, and a community membership programme to organisations across Scotland. Paid services (Cyber MOT, Cyber Advance, vulnerability assessments, penetration testing, risk assessment, vCISO retainers) subsidise free training, threat intelligence, incident response support, and victim assistance as part of a social enterprise model.
Product overview
The Cyber and Fraud Centre – Scotland is a social enterprise providing a comprehensive portfolio of cyber security services organised into three main pillars: Professional Services (including Cyber MOT, Cyber Advance, Vulnerability Assessments, Penetration Testing, Risk Assessment, Phishing Resilience Exercise, and vCISO), the Cyber Skills Academy (offering training from introductory staff sessions through to executive education and Exercise in a Box workshops), and Community/Membership programmes (including threat intelligence alerts, incident response support, and the Cyber and Fraud Hub). The centre transitioned to a social enterprise model in January 2025, reinvesting profits from B2B cyber services into community support initiatives. Services are delivered across Scotland to private, public, and third sector organisations with a focus on making cyber security accessible and affordable.
Differentiator
Problem solved
Functional benefit
Brands
- Cyber and Fraud Hub: A separate resource established by Centre employees where individuals can get support and advice for cyber enabled crime.
Products and services
- Cyber MOT Entry-level cyber security health check service that assesses an organisation's current security posture and identifies basic vulnerabilities and areas for improvement. Designed for SMEs and third sector organisations.
- Cyber Advance Year-long cyber improvement service focused on technical uplift, continuous improvement, and staff training to provide sustained and progressive cyber security enhancement.
- Vulnerability Assessments Technical assessment service that identifies and evaluates security weaknesses in networks and web applications to help organisations understand their exposure to potential attacks.
- Penetration Testing Ethical hacking service that simulates real-world cyber attacks to test an organisation's defences and identify exploitable vulnerabilities before malicious actors can leverage them.
- Risk Assessment Comprehensive evaluation service that identifies, analyses, and prioritises cyber security risks specific to an organisation's operations, assets, and threat landscape.
- Phishing Resilience Exercise Training exercise that tests and improves staff awareness of phishing attacks through simulated campaigns and educational feedback.
- vCISO (Virtual Chief Information Security Officer) Flexible senior-level cyber security leadership service providing governance, risk management, compliance guidance, and strategic oversight without the cost of a full-time executive hire. Offers monthly, quarterly, and annual engagement options.
- Incident Response Plan Testing Service that helps organisations build, test, and refine their cyber incident response plans through practical exercises and scenario-based training.
- Intro to Cyber Security for Staff CPD-accredited 90-minute entry-level training session for non-technical employees covering securing devices, identifying phishing, and responding to cyber incidents.
- Secure Leaders: Cyber Security for Boards and Senior Executives Executive-level training programme equipping CEOs, Directors, and Non-Executive Directors with frameworks and best practices to manage cyber security-related risks.
- Cyber Executive Education Educational programme designed to build senior leadership cyber knowledge and competency across Scottish organisations.
- Exercise in a Box NCSC-developed cyber exercising tool delivered in partnership with the Cyber and Fraud Centre, helping organisations test and practise response to cyber attacks in a safe environment, with micro exercises covering password security, phishing identification, secure remote working, and ransomware response.
- Membership Organisational membership programme providing access to training, expert insights, threat intelligence alerts, and a community of organisations facing similar cyber security challenges.
- Incident Response Helpline Emergency helpline service (0800 167 0623) providing immediate support and guidance to organisations experiencing active cyber incidents.
- Threat Intelligence Alerts Real-time alerts and updates on emerging cyber threats and vulnerabilities provided to members and the wider community.
- Cyber and Fraud Hub Online resource platform where individuals can access support and advice for cyber-enabled crime, established by Centre employees in 2024.
Quantifiable outcome
- £1.6 million in fraud losses prevented for over 700 individuals
- +2 more outcomes
Companies that use Cyber and Fraud Centre
Customer profileNamed customers5 records
Segments5 records
Ideal customer profiles6 records
Cyber and Fraud Centre technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Cyber and Fraud Centre partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- HIT ScotlandcorePartnership to support delivery of HIT Scotland's new Code of Trust: Executive Strategy, helping hospitality leaders put cyber resilience on the agenda.
- The Gannochy TrustminorCollaboration for Third Sector and Public Sector Cyber Roadshow in Perth, supporting cyber security awareness for local organisations.
- Third Sector Interface (Perth & Kinross)minorCollaboration for Third Sector and Public Sector Cyber Roadshow in Perth, supporting cyber security awareness for third sector organisations.
- Abertay University (Dundee)corePartnership established to offer paid placements to aspiring ethical hackers. Over 70 individuals have found direct employment through this programme since it began in 2020. The partnership also involves hosting events at Abertay cyberQuarter facility.
- Network ROIminorSponsor of Cyber Byte: Threat Intel webinar event, providing expertise on Cyber Essentials 2026 changes.
- Police ScotlandcoreCollaboration on incident response planning webinars and community events. Police Scotland experts participate in educational sessions on cyber security incident response.
- Hanover ScotlandminorHousing association participating as panelist in roundtable on enhancing cyber security in housing associations.
- Scottish Federation of Housing AssociationsminorIndustry body participating as panelist in roundtable on enhancing cyber security in housing associations.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
Cyber and Fraud Centre competitors and assessment
Company assessmentBroad incumbents
- NCC Group: Global cyber security specialist with UK heritage delivering penetration testing, risk assessment, and consulting. Competes with the Centre's professional services line for larger Scottish enterprise and public-sector contracts.
- NCSC (National Cyber Security Centre): UK government authority on cybersecurity whose Exercise in a Box tool the Centre delivers under partnership. NCSC sets national cyber standards and competes indirectly through free tools and guidance aimed at the same SMEs and public-sector buyers the Centre serves.
- Bridewell Consulting: UK-based cyber security consultancy delivering pen testing, managed detection, and vCISO-style services. Overlaps with the Centre's professional services portfolio but operates nationally with significantly larger headcount and broader service breadth.
Emerging players
- CybSafe: UK-based security awareness and human risk management platform. Comparable to the Centre's Introduction to Cyber Security staff training and Phishing Resilience Exercise products, with stronger SaaS delivery model.
- Hack The Box: Cybersecurity upskilling platform with hands-on hacking labs and training content for individuals and enterprises. Comparable to the Centre's ethical hacker talent development pathway and Skills Academy curriculum.
Direct peers
- Immersive Labs: Cyber skills training platform offering exercise-based learning, crisis simulations, and executive training — directly competing with the Centre's Cyber Skills Academy (Incident Response Plan Testing, Executive Education, Exercise in a Box-style workshops) at a national/international scale.
- Cyber Resilience Centre network (UK regional CRCs): Police-led regional cyber resilience centres across the UK (Eastern, North West, West Midlands, etc.) offering similar affordable cyber services to SMEs, charities and public sector — directly comparable in mission, pricing and customer base.
- IASME Consortium: UK-based organisation focused on cyber certification (Cyber Essentials) and assurance for SMEs and third-sector organisations — directly overlapping the Centre's SME/third-sector training and assessment offering.
Regional players
- Police Scotland Cybercrime Unit: Scotland's law enforcement cyber capability and the Centre's named partner. Provides overlapping community cyber awareness, victim support, and incident response guidance — relevant as both collaborator and adjacent public-sector provider.
Others
- Scottish Business Resilience Centre (now merged into Cyber and Fraud Centre): The predecessor entity rebranded into the Cyber and Fraud Centre – Scotland. Historically delivered similar Scottish cyber resilience services to SMEs and public sector; relevant for institutional continuity and legacy positioning.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Cyber and Fraud Centre social profiles
Digital presenceCyber and Fraud Centre financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber and Fraud Centre leadership team
Management profileNumber of profiles
Profiles6 records
Cyber and Fraud Centre funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber and Fraud Centre M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber and Fraud Centre
What does Cyber and Fraud Centre do?
The Cyber and Fraud Centre – Scotland delivers professional cyber security services, skills training, and a community membership programme to organisations across Scotland. Paid services (Cyber MOT, Cyber Advance, vulnerability assessments, penetration testing, risk assessment, vCISO retainers) subsidise free training, threat intelligence, incident response support, and victim assistance as part of a social enterprise model.
Is Cyber and Fraud Centre a public or private company?
Cyber and Fraud Centre is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Cyber and Fraud Centre founded?
Cyber and Fraud Centre was founded in 2015. It employs 11 to 50 people.
Where is Cyber and Fraud Centre based?
Cyber and Fraud Centre is headquartered in Edinburgh, United Kingdom, in the Europe region.
How does Cyber and Fraud Centre make money?
Three revenue lines are on record. Professional Cyber Security Services are the primary driver. The others are training and Skills Academy and membership Programme.
Who are Cyber and Fraud Centre's main competitors?
Broad incumbents on record are NCC Group, NCSC (National Cyber Security Centre) and Bridewell Consulting. Emerging players are CybSafe and Hack The Box. Direct peers are Immersive Labs, Cyber Resilience Centre network (UK regional CRCs) and IASME Consortium. Police Scotland Cybercrime Unit is listed as a regional player. Scottish Business Resilience Centre (now merged into Cyber and Fraud Centre) is listed as an others.
Does Cyber and Fraud Centre have an API?
No public API is recorded for Cyber and Fraud Centre.
What industry is Cyber and Fraud Centre in?
Cyber and Fraud Centre's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEANAF, Cybersecurity Training & Awareness Programs, with a secondary code of EDAOAIAB, Cybersecurity (General). Its NAICS code is 61142 and its SIC code is 8200.