Somniac Security
Somniac Security is a London-based cyber security advisory firm delivering consulting across cloud security, compliance, Virtual CISO, and operational technology (IACS/SCADA) for UK enterprises, SaaS companies, financial services firms, and government bodies.
- Company typePrivate
- Founded2022
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Somniac Security does
Somniac Security (legal entity Somniac Group Ltd) is a London-based cyber security advisory firm founded in 2022 that delivers professional services rather than packaged software. The portfolio spans cloud security (with GCP, Azure and AWS qualified experts), independent security architecture, compliance advisory for ISO 27001, NCSC Cyber Essentials, PCI DSS, SOC 2 Type 2 and HIPAA, a subscription Virtual CISO service, risk and assurance management, cyber maturity assessment, cloud migration services, and a dedicated operational technology (IACS/SCADA/PLC) security practice. Underlying capabilities are structured as discrete tactical deliverables or longer-term strategic transformation programmes rather than a unified platform, and the firm maintains partner relationships with Microsoft Azure, Zscaler, Plerion, Westcon and Add Value Machine to support delivery.
Revenue is generated through a mix of project-based professional services engagements and recurring Virtual CISO subscriptions, with Zscaler and IACS specialist work delivered as contract engagements. Pricing is not publicly disclosed; engagements are scoped per project. The go-to-market is sales-led, combining direct outreach via phone and email with public sector channel access through G-Cloud 13 and Crown Commercial Service framework listings.
The firm is privately held and founder-led by directors Stephen Jones and Malcolm Duncanson, each with over 25 years of cyber and IT security experience. Documented clients include enterprise financial services firm HCFX (cloud migration), a mid-market boutique financial company (Microsoft M365 modernisation), a SaaS security provider (SOC 2 Type 2 and HIPAA compliance), and UK government departments (modernisation programme support). Operating geography is the United Kingdom, with public sector reach through government procurement frameworks.
Somniac Security firmographics
Firmographics- Name
- Somniac Security
- Legal name
- Somniac Group Ltd
- Website
- https://somniacsecurity.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Somniac Security is a London-based cyber security advisory firm delivering consulting across cloud security, compliance, Virtual CISO, and operational technology (IACS/SCADA) for UK enterprises, SaaS companies, financial services firms, and government bodies.
- Ownership category
- akta.pro rank
Somniac Security industry classification
Industry- Product category
- Cyber Security Advisory & Consulting
- NAICS
- Computer Systems Design and Related Services (5415), Management, Scientific, and Technical Consulting Services (5416), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG)
- akta.pro secondary industries
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF), Network Security Services (Firewall/VPN/ZTNA/SASE Integration) (BPAEAEAG), Security Training & Compliance (Guard Training, SOPs, Drills) (BPABAMAN)
Keywords
Where Somniac Security is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
Somniac Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Cyber Security Consulting: Advisory and consulting services delivered for tactical discrete solutions or longer-term strategic transformation programmes. Engagements include security architecture, cloud migration, compliance certification, and cyber risk assessments.
- Virtual CISO Subscription: Subscription-based virtual CISO service providing ongoing cyber security leadership, board-level expertise, and advisory. Service flexes and scales with business demands, billed on a recurring subscription basis.
- Zscaler Implementation Services: Project-based implementation of Zscaler solutions including design, deployment, testing, documentation, and client training. Quoted and delivered as a discrete contract engagement.
- IACS Specialist Contract: Contract role for IACS specialist delivering design, implementation and maintenance of industrial control systems cyber security. Billed as a contractor/contract engagement.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Somniac Security product offering
Product offeringCore offering
Somniac Security is a cyber security advisory firm that delivers consulting services across cloud security (GCP, Azure, AWS), security architecture, compliance (ISO 27001, NCSC Cyber Essentials, PCI DSS, SOC 2, HIPAA), virtual CISO subscriptions, risk and assurance management, and cyber maturity assessment. The firm also specialises in Industrial Automation and Control Systems (IACS/SCADA/PLC) security and Zscaler zero-trust implementation services, serving clients through discrete tactical projects and longer-term strategic programmes.
Product overview
Somniac Security is a cyber security advisory firm offering a portfolio of consulting services rather than a unified software product. The core offerings include Cloud Security Services (with GCP, Azure, and AWS certified experts), Security Architecture Services, Compliance Services (ISO 27001, Cyber Essentials, PCI), a Virtual CISO subscription service, Risk and Assurance Management, and Cyber Maturity Assessment. Supporting advisory services include Cloud Migration Services, SOC 2 Compliance Advisory, HIPAA Compliance Advisory, IACS Specialist Services (covering industrial control systems and SCADA/PLCs), and Zscaler Implementation Engineer engagements. Services are consumed either as discrete tactical deliverables or as part of longer-term strategic transformation programmes.
Differentiator
Problem solved
Functional benefit
Products and services
- Cloud Security Services Advisory and consulting service delivering cloud-based security controls and DevSecOps techniques aligned to client objectives and security posture, with GCP, Azure and AWS qualified security experts supporting clients from the earliest days of cloud adoption.
- Security Architecture Services Independent security architecture consulting helping clients achieve their organisational vision, strategy and goals across internal and external stakeholders; consumed as either tactical discrete solutions or longer-term strategic transformational programmes such as cloud migrations and process optimisations.
- Compliance Services Compliance mapping and certification support for ISO 27001, NCSC Cyber Essentials, and PCI DSS, providing guidance through the compliance journey tailored to each organisation's requirements.
- Virtual CISO (vCISO) Service Cost-effective subscription-based alternative to a full-time CISO providing board-level cyber security leadership, covering cyber incident response, cyber strategy, cyber resilience, cyber risk and assurance, and cyber training and awareness.
- Risk and Assurance Management Risk management service comprising threat modelling, product and vendor assessments, and solution appraisal using a component-driven risk management approach.
- Cyber Maturity Assessment Holistic, evidenced-based framework to evaluate an organisation's security posture, providing a clear understanding of true security posture and enabling focused investment where it is needed most.
- Cloud Migration Services End-to-end cloud migration advisory including discovery workshops, planning, training, hands-on technical delivery, project direction and oversight, supporting migration to Microsoft M365 and other cloud environments.
- SOC 2 Compliance Advisory Guided clients through SOC 2 Type 2 certification including gap analysis, policy optimisation, control remediation, and external audit management, with a publicly claimed 100% track record on SOC 2 Type 2 audits.
- HIPAA Compliance Advisory HIPAA compliance assessment and remediation support for healthcare-adjacent clients, building on SOC 2 groundwork to achieve HIPAA compliance at minimal additional cost.
- IACS Specialist Services Industrial Automation and Control Systems (IACS) cyber security specialist service covering design, implementation and maintenance of industrial control systems including PLCs and SCADA, and IACS Cyber Security Management System (CSMS) development covering risk management, asset registers, policies, processes, incident response, patching, access control, physical and remote access, and secure disposal.
- Zscaler Implementation Service Professional service designing, implementing and maintaining Zscaler services including ZIA, ZPA, and ZDX, encompassing client and app connectors, dedicated Zscaler tenants, and client training.
Quantifiable outcome
- 100% SOC 2 Type 2 compliance track record for clients going through external audit
- +2 more outcomes
Companies that use Somniac Security
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles5 records
Somniac Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
Feature6 records
Somniac Security partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- Microsoft AzurecoreMicrosoft Azure Partner. Somniac Security leverages Microsoft Azure as a cloud platform for delivering security solutions. The company's team includes Azure-qualified security experts who have worked with cloud from its earliest days. Somniac has also delivered Microsoft M365 cloud migration projects for clients.
- ZscalercoreZscaler is featured as a partner on Somniac's website, with the company actively recruiting a Zscaler Implementation Engineer role. Somniac designs, implements, and maintains the Zscaler service for clients, including client and app connectors and dedicated Zscaler tenants.
- Add Value MachineminorAdd Value Machine, focused on Generative AI in Enterprise, is shown as a partner on Somniac's website, indicating a strategic working relationship around AI-driven enterprise security topics.
- WestconminorWestcon, a technology distributor, is shown as a partner on Somniac's website. Westcon operates in the UK as Westcon Comstor, suggesting a channel distribution relationship for technology resale.
- ZscalercoreSomniac actively designs and implements Zscaler solutions (ZIA, ZPA, ZDX) for clients. The company is actively hiring for Zscaler Implementation Engineers, indicating a dedicated Zscaler practice. Somniac works directly with clients to configure Zscaler tenants based on their environment and security requirements.
Scale indicators1 record
Recent moves6 records
Expansion highlights6 records
Somniac Security competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Global cyber security consulting, incident response and managed defence firm now part of Google Cloud; broader incumbent serving many of the same enterprise and public-sector cyber advisory needs (GRC, IR, risk assessments) but at significantly greater scale than Somniac.
- KPMG UK Cyber Security Services: Big Four advisory practice offering cyber strategy, risk, compliance and security transformation to large UK enterprise and public sector; broader incumbent that overlaps significantly with Somniac's GRC, ISO 27001 and regulatory compliance work but at much larger scale.
Direct peers
- Bridewell: UK-headquartered cyber security consultancy delivering advisory, penetration testing, GRC and managed security services to enterprise and public sector clients; closest direct competitor to Somniac given matching UK focus, advisory-led GTM and similar service catalogue around cyber risk and compliance.
- Cyberis: UK-based cyber security consultancy providing penetration testing, red teaming, threat intelligence and security advisory; closely comparable in size, geography and service offering to Somniac's advisory and offensive security practice.
- NCC Group: UK-listed cyber assurance and consulting firm providing penetration testing, risk consulting, managed detection and response, and GRC advisory; competes head-to-head with Somniac for enterprise and public-sector cyber mandates in the same UK market.
- Optiv: Large US-headquartered cyber security solutions and advisory provider delivering consulting, integration, managed services and risk advisory; competes with Somniac for advisory/GRC engagements, with a much larger bench and broader portfolio.
- Sapphire (Risk & Advisory): UK-based information and cyber security consultancy offering GRC, ISO 27001, SOC 2 advisory, penetration testing and vCISO services; highly comparable to Somniac's compliance and advisory practice with similar mid-market to enterprise UK client profile.
- Pentest Limited: UK-based penetration testing and cyber security consultancy offering pen testing, SOC services, compliance (ISO 27001, Cyber Essentials) and managed security; highly comparable in size, customer type (UK enterprise/mid-market/SaaS) and service mix to Somniac.
- Falanx Cyber: UK cyber security services firm delivering penetration testing, managed security, GRC advisory and virtual CISO; operates in the same niche as Somniac with closely aligned offerings including subscription-based CISO/cyber leadership.
- WithSecure (formerly F-Secure Cyber Security Consulting): European-headquartered cyber security consultancy offering attack-surface management, managed detection, and strategic advisory; comparable to Somniac in delivering technical cyber advisory and managed security consulting to enterprise clients.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Somniac Security social profiles
Digital presenceSomniac Security compliance and trust
Trust signalCompliance4 records
Somniac Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Somniac Security leadership team
Management profileNumber of profiles
Profiles2 records
Somniac Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Somniac Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Somniac Security
What does Somniac Security do?
Somniac Security is a cyber security advisory firm that delivers consulting services across cloud security (GCP, Azure, AWS), security architecture, compliance (ISO 27001, NCSC Cyber Essentials, PCI DSS, SOC 2, HIPAA), virtual CISO subscriptions, risk and assurance management, and cyber maturity assessment. The firm also specialises in Industrial Automation and Control Systems (IACS/SCADA/PLC) security and Zscaler zero-trust implementation services, serving clients through discrete tactical projects and longer-term strategic programmes.
Is Somniac Security a public or private company?
Somniac Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Somniac Security founded?
Somniac Security was founded in 2022. It employs 1 to 10 people.
Where is Somniac Security based?
Somniac Security is headquartered in London, United Kingdom, in the Europe region.
How does Somniac Security make money?
Four revenue lines are on record. Professional Cyber Security Consulting is the primary driver. The others are virtual CISO Subscription, zscaler Implementation Services and IACS Specialist Contract.
Who are Somniac Security's main competitors?
Broad incumbents on record are Mandiant (Google Cloud) and KPMG UK Cyber Security Services. Direct peers are Bridewell, Cyberis, NCC Group, Optiv, Sapphire (Risk & Advisory), Pentest Limited, Falanx Cyber and WithSecure (formerly F-Secure Cyber Security Consulting).
Does Somniac Security have an API?
No public API is recorded for Somniac Security.
What industry is Somniac Security in?
Somniac Security's product category is Cyber Security Advisory & Consulting. Its primary akta.pro industry code is BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory, with a secondary code of BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC). Its NAICS code is 5415 and its SIC code is 8700.