CyberQ Group
UK-based MSSP delivering CREST-accredited SOC monitoring, penetration testing, and vCISO advisory services to mid-market organizations.
Visit Website ↗ + Add to CompareOverview
CyberQ Group is a Birmingham, UK-based managed security services provider founded in 2016 by Chris Woods and Steve Bailey, launched through the Cyber London (Cylon) accelerator. The company runs a CREST-accredited 24/7 SOC-as-a-service offering alongside penetration testing, vulnerability assessments, configuration reviews, and attack surface reviews, plus advisory work including virtual CISO services, cyber maturity assessments, and board-level crisis simulation exercises.
The firm holds ISO 27001 and Cyber Essentials certifications, is a CREST-accredited testing provider, and is listed as a supplier on the UK government’s G-Cloud framework — independently verifiable credentials rather than self-reported claims. It has grown to serve more than 150 client organizations, primarily in logistics, manufacturing, and retail, delivered through a “follow-the-sun” model with offices in the UK, US, and Philippines.
CyberQ has raised roughly £1 million in a mix of equity and UK innovation grant funding (including Innovate UK), positioning it as a modestly funded but operationally credentialed regional MSSP. It is a reasonable fit for mid-market organizations that need outsourced SOC coverage and accredited testing without building an in-house security operations function, though it competes in a crowded MSSP field against larger, better-capitalized rivals.
Innovation Matrix Assessment
Has expanded from core pentesting into SOC-as-a-service, vCISO, and board crisis-simulation offerings since its 2016 founding, a moderate pace typical of a growing regional MSSP.
Runs a CREST-accredited 24/7 SOC with follow-the-sun coverage across UK, US, and Philippines offices, serving 150+ client organizations.
Modest total funding (~$1.27M, largely grants) and steady rather than explosive client growth; no major recent funding or acquisition events found.
A conventional MSSP/pentest service model; differentiation comes from accreditation and delivery model rather than novel technology.
CREST accreditation, ISO 27001 certification, and UK G-Cloud supplier status are independently issued/audited credentials that substantiate its technical testing claims.
Outsourced 24/7 SOC monitoring and accredited penetration testing address persistent, high-demand mid-market needs, particularly for organizations lacking in-house security operations staff.
Why CISOs Should Care
Gives mid-market organizations CREST-accredited testing and 24/7 SOC coverage without the cost of building an in-house security operations function.
What Makes It Different
Combines CREST-accredited technical testing with board-level advisory (crisis simulations, vCISO) under one roof, differentiating from pure-play pentest shops or pure-play SOC vendors.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A credentialed, modestly scaled regional MSSP with genuine accreditation to back its claims; solid execution but not a category disruptor, competing in a crowded outsourced-SOC market.
Editorial Note: Claims vs. Verified Findings
The '150+ clients' figure and follow-the-sun delivery model are vendor-reported; CREST accreditation, ISO 27001 certification, and G-Cloud supplier listing are independently verifiable third-party credentials.
Sources
Alternatives to CyberQ Group
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Sophos
Sophos is a UK-founded, Thoma Bravo-owned cybersecurity vendor unifying endpoint protection, network firewalls, and managed detection and response…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…