AMR CyberSecurity
AMR CyberSecurity is a UK-based accredited cybersecurity consultancy founded in 2019, offering penetration testing, red teaming, OT assurance, incident response, and compliance certification services to defence, finance, government, and critical-infrastructure clients across the UK and increasingly the US. It operates as part of Infinum Group following a December 2025 acquisition.
- Company typePrivate
- Founded2019
- HeadquartersFareham, United Kingdom
- Headcount11–50
- GTM typeB2B
- OfferingServices
What AMR CyberSecurity does
AMR CyberSecurity is a UK-headquartered cybersecurity consultancy founded in 2019 and operating from Fareham and Cheltenham, providing accredited penetration testing, security architecture, intelligence-led red teaming, operational technology assurance, incident response, and governance/risk/compliance services. Its technical scope spans network, web, mobile, cloud, wireless, and physical security testing, with explicit OT/ICS coverage against ISA/IEC 62443 and NIST frameworks, and methodologies that incorporate threat-actor TTPs through a reseller partnership with SecAlliance. The firm has progressively accumulated one of the densest UK regulatory credential stacks in its peer set, including CREST accreditations across penetration testing, vulnerability assessment, application security, STAR, and OVS; NCSC CHECK; one of only four NCSC-certified Cyber Resilience Test Facilities; PCI QSA; Swift CSP Certified Assessor; IASME Cyber Essentials/Gold Certification Body; and full Defence Cyber Certification (DCC) Certification Body status at Levels 0-3.
Commercially, AMR sells professional services on a quote-based, multi-year contract model to enterprise and public-sector buyers across defence and space, finance and banking, government, energy and utilities, retail, and online gambling. UK public-sector access is structured through G-Cloud 13, Digital Outcomes and Specialists 6, and Cyber Security Services 3 frameworks, while US delivery is enabled by 2026 CREST accreditation across four offensive-security disciplines. On 1 December 2025 AMR was acquired by Infinum, a Croatian European tech consultancy with ~400 specialists across eight offices in Europe, the UK, and the US; post-acquisition, cybersecurity is targeted to represent around 10% of Infinum group revenue, with AMR operating as the group's UK and Western Europe cybersecurity platform under continuing leadership from Director Martin Walsham.
AMR CyberSecurity firmographics
Firmographics- Name
- AMR CyberSecurity
- Legal name
- AMR CyberSecurity LTD
- Website
- https://amrcybersecurity.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- AMR CyberSecurity is a UK-based accredited cybersecurity consultancy founded in 2019, offering penetration testing, red teaming, OT assurance, incident response, and compliance certification services to defence, finance, government, and critical-infrastructure clients across the UK and increasingly the US. It operates as part of Infinum Group following a December 2025 acquisition.
- Ownership category
- akta.pro rank
AMR CyberSecurity industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Security Systems Services (56162), Security Systems Services (except Locksmiths) (561621), Computer Facilities Management Services (541513), Electronic and Precision Equipment Repair and Maintenance (811210)
- SIC
- Services-Detective, Guard & Armored Car Services (7381), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Cybersecurity Architecture & Security Integration (BPAEAAAL), OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where AMR CyberSecurity is headquartered
LocationHeadquarters
- HQ city
- Fareham
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
AMR CyberSecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consultancy Services: Professional services revenue from penetration testing, security consulting, red teaming, incident response, and security architecture services. Services delivered by accredited security consultants to enterprise and government clients in defense, finance, CNI, and regulated sectors.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom project-based pricing |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels6 records
AMR CyberSecurity product offering
Product offeringCore offering
AMR CyberSecurity is a UK-based cybersecurity consultancy that delivers accredited penetration testing, red teaming, security architecture, operational technology (OT/ICS/SCADA) assurance, governance risk and compliance, PCI DSS assessment, Swift CSP, Defence Cyber Certification (DCC) and cyber security incident response services to enterprise, government and defence clients. The firm also operates as a certification body for Cyber Essentials, IASME Gold, DCC Levels 0-3 and the NCSC Cyber Resilience Test Facility (CRTF) scheme.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Accredited penetration testing covering internal/external infrastructure, web and mobile applications, wireless, cloud, build review and code review, delivered by CREST- and CHECK-accredited consultants to enterprise and government clients.
- PCI DSS Assessment Payment Card Industry Data Security Standard assessments delivered by an approved QSA company for merchants, acquirers and service providers that handle cardholder data.
- Swift CSP Compliance Tailored consultancy and assessment services helping financial institutions meet the Swift Customer Security Programme (CSP) controls and assurance requirements.
- Governance, Risk and Compliance Consultancy services supporting organisations in identifying, managing and reporting on cyber and information security risk in line with ISO 27001, NIST CSF, NCSC CAF, DORA, TIBER-EU and other frameworks.
- Security Architecture Design and review of security architectures aligned to business needs and security goals, delivered through a five-stage Discovery, Assessment, Design, Implementation and Monitoring/Review methodology.
- Red Teaming Intelligence-led red team engagements that simulate real-world threat actors using their TTPs, with tailored attack scenarios based on client-specific threats and key assets.
- Operational Technology Assurance Security assurance and testing for operational technology, ICS and SCADA systems, covering product design assurance, security testing, system design assurance and compliance audits against ISA/IEC 62443 and NIST.
- Cyber Security Incident Response Specialist incident response service providing rapid scoping, containment and eradication of cyber security incidents for affected organisations.
- Defence Cyber Certification (DCC) Certification body service that independently assesses and certifies suppliers operating within the UK Ministry of Defence supply chain against the Defence Cyber Certification (DCC) scheme at Levels 0, 1, 2 and 3.
- Cyber Resilience Testing NCSC-certified Cyber Resilience Test Facility (CRTF) service providing independent assurance of connected products and services for government and critical national infrastructure clients.
Companies that use AMR CyberSecurity
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles6 records
AMR CyberSecurity technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature4 records
AMR CyberSecurity partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- SecAlliancecoreAMR CyberSecurity partnered with SecAlliance, a cyber threat intelligence company, as an authorized reseller of SecAlliance threat intelligence services. The partnership enables AMR to better support customers for red team engagements and CREST STAR engagements by incorporating threat intelligence based on tools, tactics, and procedures (TTPs) used by threat actors. SecAlliance provides research, analysis, and insights gathered by true intelligence experts with real-world experience.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
AMR CyberSecurity competitors and assessment
Company assessmentDirect peers
- Secarma: UK-based cybersecurity testing and consulting firm offering penetration testing, application security, and managed security services - directly comparable boutique consultancy competing for similar enterprise and public sector work.
- Cyberis: UK cybersecurity consultancy providing penetration testing, vulnerability assessment, red team, and incident response to enterprise clients - comparable specialist boutique competing for the same enterprise and public sector mandates as AMR.
- Pentest People: UK-based penetration testing specialist with CREST and CHECK accreditations serving enterprise and public sector - a like-for-like boutique competitor for AMR's pen testing and red teaming work.
- NCC Group: Largest UK-headquartered cybersecurity consultancy with extensive penetration testing, NCSC CHECK, CREST STAR and incident response capabilities serving defence, finance, and government - directly comparable service menu and target customers to AMR.
- WithSecure (formerly F-Secure): Nordic-rooted cybersecurity consultancy with a UK presence offering penetration testing, managed detection, and incident response - directly comparable offensive security and IR services to AMR's core portfolio.
- Pen Test Partners: UK CREST-accredited penetration testing consultancy focused on web, mobile, infrastructure, and IoT/OT engagements - directly comparable to AMR's pen testing and OT assurance services.
- Bridewell: UK-based cybersecurity consultancy delivering CREST-accredited penetration testing, red teaming, managed security, and compliance services to CNI, finance, and government - a near-twin to AMR on services and verticals.
Broad incumbents
- Trustwave: Global MSSP and cybersecurity services firm offering penetration testing, managed detection, and DFIR as part of a wider portfolio - a broader incumbent where AMR's pen testing and red teaming services overlap.
- Mandiant (Google Cloud): Global incident response, threat intelligence, and security consulting firm (now part of Google Cloud) - broader incumbent serving many of the same large enterprise, finance, and government clients as AMR, often competing for TLPT/IR mandates.
- KPMG UK - Cyber Security Practice: Big Four advisory firm with a UK cyber practice delivering penetration testing, threat-led assessments, and regulatory cyber advisory to FS, defence, and government clients - broader incumbent competing for similar regulated-sector mandates as AMR.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
AMR CyberSecurity social profiles
Digital presenceAMR CyberSecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
AMR CyberSecurity leadership team
Management profileNumber of profiles
Profiles2 records
AMR CyberSecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
AMR CyberSecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about AMR CyberSecurity
What does AMR CyberSecurity do?
AMR CyberSecurity is a UK-based cybersecurity consultancy that delivers accredited penetration testing, red teaming, security architecture, operational technology (OT/ICS/SCADA) assurance, governance risk and compliance, PCI DSS assessment, Swift CSP, Defence Cyber Certification (DCC) and cyber security incident response services to enterprise, government and defence clients. The firm also operates as a certification body for Cyber Essentials, IASME Gold, DCC Levels 0-3 and the NCSC Cyber Resilience Test Facility (CRTF) scheme.
Is AMR CyberSecurity a public or private company?
AMR CyberSecurity is a private company. It is classified as corporate owned and is currently operating.
When was AMR CyberSecurity founded?
AMR CyberSecurity was founded in 2019. It employs 11 to 50 people.
Where is AMR CyberSecurity based?
AMR CyberSecurity is headquartered in Fareham, United Kingdom, in the Europe region.
How does AMR CyberSecurity make money?
One revenue line is on record: cybersecurity Consultancy Services.
Who are AMR CyberSecurity's main competitors?
Direct peers on record are Secarma, Cyberis, Pentest People, NCC Group, WithSecure (formerly F-Secure), Pen Test Partners and Bridewell. Broad incumbents are Trustwave, Mandiant (Google Cloud) and KPMG UK - Cyber Security Practice.
Does AMR CyberSecurity have an API?
No public API is recorded for AMR CyberSecurity.
What industry is AMR CyberSecurity in?
AMR CyberSecurity's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEAAAL, Cybersecurity Architecture & Security Integration. Its NAICS code is 56162 and its SIC code is 7381.