Cyber risk management
CRMG is a London-headquartered cyber risk management consultancy and GRC SaaS provider founded in 2018, offering proprietary platforms (Risk Genie, Compliance Genie) and advisory services in regulatory compliance, third-party risk, and AI assurance to enterprise and mid-market clients globally.
- Company typePrivate
- Founded2018
- HeadquartersLondon, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Cyber risk management does
CRMG (Cyber Risk Management Group Limited) is a London-headquartered cyber risk management consultancy and GRC SaaS provider founded in January 2018 by Nick Frost and Simon Rycroft, both former PwC senior practitioners. The company delivers a hybrid platform-plus-services offering to enterprise and mid-market clients across financial services, legal, hospitality, government, and critical infrastructure sectors, with operations spanning EMEA, the Americas, APAC, and the Middle East. Its service portfolio spans AI Assurance, Third Party Risk Management, Cyber Risk Assessment, Cyber Security Programme Support, National Projects, and regulatory compliance advisory for DORA, NIS2, and ISO 27001.
CRMG's core technology comprises four proprietary assets: Risk Genie, a practitioner-built cyber risk assessment SaaS platform with a 6-stage guided process, heatmaps, and 'what/if' scenario modelling; Compliance Genie, a SaaS compliance management platform mapping controls to DORA, NIS 2, ISO 27001, and FedRAMP; the Threat/Control Matrix (TCM), a proprietary mapping of 160+ cyber security controls against 40+ threats that underpins Risk Genie; and the Harmonised Control Library, a consolidated framework integrating NCA, SAMA, UAE IAS, DESC, and ISO controls for Middle East clients. Data Services, launched in 2024, monetises risk data, DORA/NIS2 datasets, and control libraries as standalone subscriptions or one-time licences.
The business operates on a hybrid revenue model combining bespoke professional services engagements (typically multi-year, quote-based, scope-driven) with recurring SaaS subscriptions for Risk Genie, Compliance Genie, and Data Services. Go-to-market is direct and consultative, led by senior consultants leveraging Big Four networks, with a top-of-funnel content marketing engine (website, LinkedIn, X/Twitter, industry events) feeding a 'Book A Demo' conversion action. CRMG has disclosed no external funding rounds and remains privately held by its co-founders.
Cyber risk management firmographics
Firmographics- Name
- Cyber risk management
- Legal name
- Cyber Risk Management Group Limited
- Website
- https://crmg-consult.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CRMG is a London-headquartered cyber risk management consultancy and GRC SaaS provider founded in 2018, offering proprietary platforms (Risk Genie, Compliance Genie) and advisory services in regulatory compliance, third-party risk, and AI assurance to enterprise and mid-market clients globally.
- Ownership category
- akta.pro rank
Cyber risk management industry classification
Industry- Product category
- Cyber Risk Management Consultancy
- akta.pro primary industry
- CRM Strategy & Consulting (BPAFAFAA)
Keywords
Where Cyber risk management is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Cyber risk management business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Consultancy Services: CRMG generates revenue primarily through bespoke cyber security consultancy engagements. Services include cyber risk assessments, third-party risk management, AI assurance, cyber security programme support, and national projects. Engagements are typically scoped and delivered by senior consultants, with pricing based on project scope and team composition.
- Risk Genie Platform Subscription: CRMG offers access to Risk Genie, its proprietary cyber risk assessment platform, on a subscription basis. Clients can access the platform directly or via facilitated workshops led by CRMG practitioners. The platform supports both self-service and assisted delivery models.
- Compliance Genie SaaS Platform: Compliance Genie is offered as a SaaS subscription enabling organisations to map controls to global and regional standards. Pricing is likely tiered by organisation size or module access.
- Data Services and Control Libraries: CRMG provides data libraries, TCM data tables, and regulatory-specific data sets (DORA, NIS2) as standalone or integrated solutions, sold as subscriptions or one-time data licences to GRC platform providers and end-user organisations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Bespoke consultancy engagement — scope and pricing tailored to client requirements |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels5 records
Cyber risk management product offering
Product offeringCore offering
CRMG provides cyber security and risk management solutions combining proprietary SaaS platforms (Risk Genie, Compliance Genie, Data Services, Harmonised Control Library) with senior-led consultancy services covering cyber risk assessments, third-party risk management, AI assurance, and regulatory compliance support for DORA, NIS2, and ISO 27001. The firm operates as a people-led, risk-based consultancy that builds in-house technology to deliver pragmatic GRC outcomes for organisations across EMEA, Americas, and APAC.
Product overview
CRMG offers a platform-plus-services architecture combining proprietary SaaS products with expert consultancy. The core product portfolio includes Risk Genie (cyber risk assessment platform) and Compliance Genie (compliance management platform), supplemented by Data Services and the Harmonised Control Library (for Middle East markets). These are complemented by a comprehensive range of consulting services including AI Assurance, Cyber Risk Assessment, Third Party Risk Management, Cyber Security Programme Support, and National Projects, plus compliance services for DORA, NIS2, and ISO 27001. The products work together as an integrated GRC ecosystem: Risk Genie and Compliance Genie serve as the technology platforms, Data Services provides the underlying risk and control data libraries, and the consulting services offer implementation and advisory support.
Differentiator
Problem solved
Functional benefit
Brands
- Risk Genie: A cutting-edge cyber risk assessment platform designed to provide actionable, risk-based insights that help organisations strengthen their cyber security posture. Developed in-house by CRMG's own practitioners.
- Compliance Genie
- Data Services
- Harmonised Control Library
Products and services
- Risk Genie A proprietary SaaS cyber risk assessment platform that walks organisations through a 6-stage process of criticality assignment, threat selection, control identification, and action prioritisation. Built on CRMG's proprietary Threat/Control Matrix covering 160+ controls against 40+ threats, it provides heatmaps, what/if scenario modelling, and compliance assessments for ISO 27001, NIST CSF v2.0, and DORA.
- Compliance Genie An all-in-one SaaS compliance management platform that maps cyber security controls to global and regional standards including DORA, NIS 2, ISO 27001, and FedRAMP. Features automated control mapping, real-time updates, and region/industry-specific templates accessible from a central interface for organisations of all sizes.
- Data Services Comprehensive risk data services providing DORA and NIS2-specific data sets with suggested evidence and control effectiveness questions, a Threat/Control Matrix highlighting the effectiveness of 160+ cyber security controls against 40+ specific cyber threats, and audit-friendly control libraries aligned to ISO 27001 and NIST CSF v2.0.
- Harmonised Control Library A consolidated control framework solution that integrates controls from multiple regulatory standards including NCA, SAMA, UAE IAS, DESC, and ISO frameworks into a single unified, domain-tagged library. Designed to eliminate duplication and streamline audit processes for organisations operating in Saudi Arabia and the UAE.
- AI Assurance Consulting service that assesses AI systems for security, compliance, and ethical standards, including data management practices, algorithm fairness, and security protocols. Supports compliance with GDPR, ISO 27001, EU AI Act, and other emerging AI regulations.
- Third Party Risk Management A four-stage triage consulting service that identifies cyber risk implications of working with third parties based on product/service type, data sharing requirements, and contract terms. Delivers tailored supplier questionnaires, assessment reports, and remediation recommendations.
- Cyber Risk Assessment Pragmatic, outcome-focused cyber risk assessment delivered via the Risk Genie platform, guiding organisations through a 6-stage process of criticality assignment, threat selection, protection measure identification, and action prioritisation.
- Cyber Security Check-Up High-level assessment evaluating existing cyber security strategy to establish the true risk profile, with delivery of a bespoke implementation plan addressing gaps, strengthening security posture, and ensuring alignment with regulatory standards.
- Cyber Security Programme Support Tailored support for implementing and maintaining risk-based cyber security programmes, including strategy development, policy and standards creation, ISO 27001 certification support, cyber exercises, data protection support, and staff training.
- National Projects Strategic cybersecurity consultancy for large-scale governmental projects, including the development of national cyber security standards, assurance frameworks, and approaches to protect citizens and critical national infrastructure.
- DORA Compliance
Quantifiable outcome
- CRMG helped a financial data provider assess the cyber maturity of its critical suppliers to determine ransomware preparedness and exposure.
- +2 more outcomes
Companies that use Cyber risk management
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles5 records
Cyber risk management technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature4 records
Cyber risk management partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- DiligentcoreCRMG has an established partnership with Diligent, a governance software platform. CRMG's content appears on the Diligent platform/news section, and CRMG embeds its harmonised control libraries into Diligent's GRC systems. This partnership enables CRMG to reach Diligent's customer base of governance, risk, and compliance professionals and integrate CRMG's proprietary data libraries into the Diligent platform.
- ISF (Information Security Forum)coreCRMG became official partners of the Information Security Forum (ISF) upon formation in January 2018. The ISF is a global, independent, not-for-profit organisation focused on cyber security research, benchmarking, and best practice. CRMG's co-founders have backgrounds with ISF (Simon Rycroft was formerly Head of Consulting at the ISF), creating a deep strategic relationship.
- ISO Certification BodiescoreCRMG works with certification partners to guide clients through the ISO 27001 certification process. CRMG states it works 'with our certification partner to ensure everything goes smoothly' when guiding clients through ISO 27001 certification, and can also support internal/external audit teams.
Scale indicators8 records
Recent moves7 records
Expansion highlights5 records
Cyber risk management competitors and assessment
Company assessmentBroad incumbents
- Diligent: Diligent is a large governance, risk, and compliance (GRC) software platform serving boards and executives globally. It is both a CRMG strategic partner and a broader incumbent offering overlapping GRC capabilities including risk management, compliance tracking, and audit workflows that compete with CRMG's Risk Genie and Compliance Genie offerings.
- OneTrust: OneTrust is a large trust intelligence platform offering GRC, privacy, ethics, and ESG solutions to enterprises. It competes with CRMG in third-party risk management, regulatory compliance (DORA, NIS2), and cyber risk governance, with broader scale and deeper enterprise penetration.
- ServiceNow GRC: ServiceNow's Integrated Risk Management (IRM/GRC) module is a major enterprise platform for risk, compliance, and audit workflows. It competes with CRMG's Compliance Genie and Risk Genie in mid-to-large enterprises that standardise GRC on a single vendor platform.
- Optiv: Optiv is a large US-based cyber security solutions integrator and advisory firm serving enterprise clients across risk, compliance, and security operations. It competes with CRMG in delivering cyber risk advisory, GRC advisory, and regulatory compliance programmes to mid-market and enterprise buyers.
Direct peers
- LogicGate: LogicGate is a GRC workflow automation platform that lets organisations build risk and compliance programmes using a no-code framework. It directly overlaps with CRMG's Risk Genie and Compliance Genie SaaS products in helping enterprises operationalise cyber and regulatory risk management.
- MetricStream: MetricStream is a dedicated GRC platform providing cyber risk quantification, regulatory compliance management, and audit solutions. It directly competes with CRMG in serving regulated enterprises needing structured cyber and IT risk management programmes.
- Resolver: Resolver is a GRC and risk management software platform offering integrated risk, compliance, audit, and incident management. It is comparable to CRMG's Compliance Genie in delivering multi-framework compliance tracking and risk assessment capabilities for mid-market and enterprise customers.
- SAI360: SAI360 provides enterprise GRC software covering risk management, regulatory compliance, ethics, and learning. It overlaps with CRMG in cyber risk quantification and regulatory compliance (ISO 27001, NIST) workflows for medium-to-large organisations.
- Riskonnect: Riskonnect is an integrated risk management platform combining enterprise risk, compliance, and third-party risk management. It is comparable to CRMG in offering risk assessment and compliance workflow tooling to regulated and mid-market enterprises.
- NCC Group: NCC Group is a UK-based cyber security and risk advisory firm offering consultancy and managed services across EMEA, Americas, and APAC. It is comparable to CRMG as a competitor in cyber risk consulting and third-party risk assessments for enterprise clients.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Cyber risk management social profiles
Digital presenceCyber risk management compliance and trust
Trust signalCompliance7 records
Cyber risk management financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber risk management leadership team
Management profileNumber of profiles
Profiles9 records
Cyber risk management funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber risk management M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber risk management
What does Cyber risk management do?
CRMG provides cyber security and risk management solutions combining proprietary SaaS platforms (Risk Genie, Compliance Genie, Data Services, Harmonised Control Library) with senior-led consultancy services covering cyber risk assessments, third-party risk management, AI assurance, and regulatory compliance support for DORA, NIS2, and ISO 27001. The firm operates as a people-led, risk-based consultancy that builds in-house technology to deliver pragmatic GRC outcomes for organisations across EMEA, Americas, and APAC.
Is Cyber risk management a public or private company?
Cyber risk management is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber risk management founded?
Cyber risk management was founded in 2018. It employs 11 to 50 people.
Where is Cyber risk management based?
Cyber risk management is headquartered in London, United Kingdom, in the Europe region.
How does Cyber risk management make money?
Four revenue lines are on record. Consultancy Services are the primary driver. The others are risk Genie Platform Subscription, compliance Genie SaaS Platform and data Services and Control Libraries.
Who are Cyber risk management's main competitors?
Broad incumbents on record are Diligent, OneTrust, ServiceNow GRC and Optiv. Direct peers are LogicGate, MetricStream, Resolver, SAI360, Riskonnect and NCC Group.
Does Cyber risk management have an API?
No public API is recorded for Cyber risk management.
What industry is Cyber risk management in?
Cyber risk management's product category is Cyber Risk Management Consultancy. Its primary akta.pro industry code is BPAFAFAA, CRM Strategy & Consulting.