Secure Impact
Secure Impact is a UK-based cybersecurity consultancy founded in 2021 that delivers expert-led penetration testing, incident response, cloud security and national risk assessment services to enterprise and government clients across 45+ countries, leveraging its SANS instructor network.
- Company typePrivate
- Founded2021
- HeadquartersGloucester, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Secure Impact does
Secure Impact Limited is a UK-based cybersecurity consultancy founded in 2021 that sells expert-driven professional services to enterprise and government buyers. The company delivers SOC maturity assessments, incident response tabletop exercises, national risk assessments for critical national infrastructure (CNI), cloud security reviews, and a full portfolio of advanced penetration testing and adversary simulation services. Its stated differentiator is access to 150+ SANS instructors and a cohort of consultants characterised as the top 1% of cybersecurity practitioners globally, holding 500+ industry certifications including GIAC GSE credentials. Service delivery is led personally by founder James Lyne, a globally recognised SANS instructor, with Giorgia Cacace serving as General Manager; the company reports working with over 200 clients across 45 countries and a 98% customer return rate.
The core technology is human expertise rather than a proprietary platform: engagements are project-based, scoped through a consultative discovery process, and delivered by curated teams of senior practitioners aligned to each client's risk profile. Pricing is quote-based, billed in GBP via Statements of Work, with day-rate billing for consultant time and tiered cancellation terms. The go-to-market is direct enterprise field sales supported by HubSpot-driven meeting booking, supplemented by thought-leadership content, case studies and conference partnerships. The firm holds GIAC, CREST, Cyber Essentials Plus and ISO 9001:2015 accreditations, and lists partnerships with the SANS Institute, GIAC, NCSC-aligned entities, Telenor Software Lab AS, Grey Matter, DWF and Genesys among its commercial relationships. No revenue, funding, or headcount growth figures are disclosed in available materials, and no AI/ML capabilities, proprietary platform, or patent portfolio are evidenced.
Secure Impact is a privately held limited company incorporated in England and Wales (registered number 13172543), with a registered office in Moreton-In-Marsh, Gloucestershire. Ownership appears founder-controlled with no disclosed institutional investment, parent entity, or public listing. The operating posture is active: services are being delivered, new service lines (cloud security, advanced attack simulation, virtual CISO) are being marketed, and the company maintains an online presence via its own website, LinkedIn and X (Twitter) channels.
Secure Impact firmographics
Firmographics- Name
- Secure Impact
- Legal name
- Secure Impact Limited
- Website
- https://secure-impact.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Secure Impact is a UK-based cybersecurity consultancy founded in 2021 that delivers expert-led penetration testing, incident response, cloud security and national risk assessment services to enterprise and government clients across 45+ countries, leveraging its SANS instructor network.
- Ownership category
- akta.pro rank
Secure Impact industry classification
Industry- Product category
- Cybersecurity Consultancy Services
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design and Related Services (5415)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Cybersecurity & Identity Consulting (BPAHAEAG)
Keywords
Where Secure Impact is headquartered
LocationHeadquarters
- HQ city
- Gloucester
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Secure Impact business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- Cybersecurity Consultancy Services: Professional services revenue model based on project-based consultancy engagements. Fees are detailed in Statements of Work with invoicing per agreed terms. The company charges day rates for consultant time, with cancellation fees for client-initiated cancellations with less than 5 business days notice. Expenses are billed separately unless stated as inclusive.
- Penetration Testing Services: Intelligence penetration testing services including web application, mobile application, network infrastructure, wireless infrastructure testing, and advanced attack simulation. Revenue generated through scoped assessments and retained testing services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagements - pricing based on project scope and consultant expertise |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Secure Impact product offering
Product offeringCore offering
Secure Impact is a UK-based cybersecurity consultancy that delivers expert-led security services through a curated network of 150+ SANS instructors and GIAC-certified practitioners. Core offerings span intelligent penetration testing (web, mobile, network, wireless, retained), advanced attack simulation (adversary emulation, phishing, physical, OSINT), security assessments (OT, embedded, AD, code review, vulnerability scanning), cloud security services, SOC maturity assessments, incident response tabletop exercises, national risk assessments, virtual CISO, digital forensics, and red/purple team services. Engagements are scoped and priced via Statements of Work, with day-rate consultant billing and multi-year contract options.
Product overview
Secure Impact is a cyber security consultancy offering a comprehensive portfolio of professional services delivered by world-class experts including SANS instructors and GIAC-certified practitioners. The core offering comprises two main service lines: Consultancy Services (including SOC maturity assessment, incident response tabletop exercises, national risk assessments, strategic advisory, virtual CISO, digital forensics, and red/purple team services) and Intelligent Penetration Testing (encompassing web application, mobile application, network infrastructure, wireless infrastructure, and retained testing services). These are complemented by Advanced Attack Simulation services (adversary emulation, phishing simulations, physical attack simulation, OSINT assessments), Security Assessment services (operational technology, embedded technology, network device configuration, vulnerability scanning, active directory, code review, security design), and Cloud Security Services (infrastructure review, compliance audits, M365 assessments). The company operates globally with access to over 150 SANS instructors and has certifications including GIAC, CREST, Cyber Essentials Plus, and ISO 9001:2015.
Differentiator
Problem solved
Functional benefit
Products and services
- Cyber Security Consultancy Services Bespoke cyber security consultancy delivered by SANS instructors and GIAC-certified practitioners covering SOC design and maturity, incident response tabletop exercises, national risk assessments, security posture maturity, risk assessments, virtual CISO, digital forensics, strategy development, disaster recovery and business continuity planning, infrastructure review, and incident preparedness and response. Targeted at enterprise and government clients requiring outcome-focused, expert-led advisory.
- Intelligent Penetration Testing World-class penetration testing services delivered by GIAC-certified testers using manual, real-world attacker approaches. Scope includes web application, mobile application, network infrastructure, wireless infrastructure, retained vulnerability assessment, and breakout assessments, sold as a unified penetration testing service line to enterprise and technology clients.
- Advanced Attack Simulation Comprehensive attack simulation services including adversary emulation, adversary simulation, targeted phishing simulations, physical attack simulation (black teaming), and OSINT and public exposure assessments, delivered as a standalone service line to organisations seeking realistic adversary testing.
- Security Assessment Services Comprehensive security assessments bundled as a single service line covering operational technology, embedded technology, network device configuration, vulnerability scanning, active directory, code review, and security design assessments for enterprise and technology clients.
- Cloud Security Services Cloud security service line providing cloud security infrastructure review, cloud compliance audits, and M365 security assessments, sold together as a coherent offering for enterprises needing cloud posture uplift and compliance assurance.
- Red and Purple Team Services Offensive security testing through dedicated red team operations and combined red/blue team purple team exercises, sold as a standalone service for organisations testing their defensive capability against real-world attackers.
- Digital Forensics Services Computer forensic examination services including evidence recovery and analysis, delivered as a standalone offering for organisations investigating security incidents.
Companies that use Secure Impact
Customer profileNamed customers10 records
Segments4 records
Ideal customer profiles4 records
Secure Impact technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Secure Impact partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core, flagship and minor.
- SANS InstitutecoreStrategic partnership providing exclusive access to 150+ SANS instructors for consultancy delivery. SANS provides elite cybersecurity training and certifications, and Secure Impact leverages this network to deliver world-class consultancy services. Founder James Lyne is a SANS instructor and the company maintains close ties with SANS programs.
- GIAC (Global Information Assurance Certification)coreGIAC provides cybersecurity certifications and Secure Impact maintains a team certified in over 30 GIAC certifications. The partnership provides credibility and access to certified practitioners for delivering high-quality consultancy services.
- NCSC (UK National Cyber Security Centre)coreNCSC is the UK government authority on cyber security. Secure Impact maintains association with NCSC standards and best practices, positioning the company as aligned with UK national cyber security initiatives.
- Telenor Software Lab ASflagshipSecurity partnership where Secure Impact provides GIAC certified security staff with bespoke scope aligned to client risk model. Telenor requires high-quality security partners due to their industry position and operations. Quote indicates strong satisfaction with SI's differentiated approach.
- OrgVuecorePartnership for Incident Response simulation exercises. Secure Impact designed and delivered an exercise reflecting OrgVue's own environment, significantly increasing business value. Focus on ensuring clients gain maximum value from expertise delivered.
- Grey MatterminorTechnology reseller and distributor partnership. Grey Matter provides IT solutions and cybersecurity products, with Secure Impact services positioned as part of their offerings.
- DWFminorProfessional services firm partnership. DWF is a legal and business services firm, suggesting potential referral or collaborative engagement for clients with combined legal and security needs.
- GenesysminorTechnology company partnership. Secure Impact's logos appear alongside Genesys on the website, suggesting collaborative engagement or mutual promotional activities.
Scale indicators14 records
Recent moves6 records
Expansion highlights5 records
Secure Impact competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-listed cybersecurity consultancy providing penetration testing, incident response, and managed security services. Most direct comparable based on geography, service portfolio, and enterprise/government client mix.
- Bridewell: UK-based cybersecurity consultancy offering penetration testing, managed security, and cyber advisory across CNI sectors. Direct competitor for UK enterprise and regulated-industry work.
- Bishop Fox: US-based offensive security consultancy focused on penetration testing, red teaming, and attack surface management. Closely comparable talent-led, expert-driven delivery model.
- IOActive: Global security consultancy specialising in penetration testing, hardware/embedded security, and application security. Comparable talent-led offensive security model.
- TrustedSec: US-based cybersecurity consultancy specialising in penetration testing, incident response, and adversary simulation. Comparable offensive security services portfolio and expert positioning.
- Pen Test Partners: UK-based penetration testing and cybersecurity consultancy. Direct geographic competitor with similar SME-to-enterprise client mix and similar services scope.
Broad incumbents
- WithSecure (formerly F-Secure): European cybersecurity vendor with a substantial consulting arm offering penetration testing, incident response, and managed detection. Comparable service mix with broader product portfolio.
- Mandiant (Google Cloud): Global incident response and cybersecurity consulting leader, now part of Google Cloud. Direct competitor for high-end IR, threat intelligence, and strategic cyber advisory engagements.
- Optiv: Large US-based cybersecurity solutions integrator and advisory firm offering penetration testing, IR, and managed security. Comparable advisory services with broader portfolio scale.
- Accenture Cyber Security: Global consulting giant's cybersecurity practice, competing for high-end advisory, IR, and CNI engagements. Represents the scale-tier competitor that pressures premium consultancies on multi-million pound enterprise deals.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Secure Impact social profiles
Digital presenceSecure Impact compliance and trust
Trust signalCompliance4 records
Secure Impact financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secure Impact leadership team
Management profileNumber of profiles
Profiles2 records
Secure Impact funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secure Impact M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secure Impact
What does Secure Impact do?
Secure Impact is a UK-based cybersecurity consultancy that delivers expert-led security services through a curated network of 150+ SANS instructors and GIAC-certified practitioners. Core offerings span intelligent penetration testing (web, mobile, network, wireless, retained), advanced attack simulation (adversary emulation, phishing, physical, OSINT), security assessments (OT, embedded, AD, code review, vulnerability scanning), cloud security services, SOC maturity assessments, incident response tabletop exercises, national risk assessments, virtual CISO, digital forensics, and red/purple team services. Engagements are scoped and priced via Statements of Work, with day-rate consultant billing and multi-year contract options.
Is Secure Impact a public or private company?
Secure Impact is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secure Impact founded?
Secure Impact was founded in 2021. It employs 11 to 50 people.
Where is Secure Impact based?
Secure Impact is headquartered in Gloucester, United Kingdom, in the Europe region.
How does Secure Impact make money?
Two revenue lines are on record. Cybersecurity Consultancy Services are the primary driver. The others are penetration Testing Services.
Who are Secure Impact's main competitors?
Direct peers on record are NCC Group, Bridewell, Bishop Fox, IOActive, TrustedSec and Pen Test Partners. Broad incumbents are WithSecure (formerly F-Secure), Mandiant (Google Cloud), Optiv and Accenture Cyber Security.
Does Secure Impact have an API?
No public API is recorded for Secure Impact.
What industry is Secure Impact in?
Secure Impact's product category is Cybersecurity Consultancy Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54151.