IRM (Information Risk Management)
UK-founded cyber GRC and penetration testing consultancy, now the cybersecurity division of Capgemini Group, built around its SYNERGi GRC software platform.
Visit Website ↗ + Add to CompareOverview
IRM (Information Risk Management) is a UK cybersecurity consultancy founded in 1998 in Cheltenham, built on two lines of business: hands-on penetration testing and PCI-DSS qualified security assessor (QSA) work, and SYNERGi, a governance-risk-compliance (GRC) software platform sold as a standalone product. SYNERGi covers governance, risk, compliance, audit, vendor, and IT security management in one platform, positioned as a single source of truth for board and audit reporting rather than a point tool for one compliance framework.
French engineering and consulting group Altran acquired IRM in 2019 to build out its cybersecurity practice; when Capgemini acquired Altran in 2020, IRM became part of Capgemini Group, operating today as IRM Global Cybersecurity. IRM has retained its own brand, website, and SYNERGi product line rather than being fully folded into generic Capgemini IT services branding, which keeps it distinguishable as a dedicated GRC and testing practice inside a much larger diversified parent.
IRM reports serving over 750 customers across 25 countries, including multiple UK government divisions, built on more than two decades of QSA and penetration testing consulting credibility. Being owned by Capgemini gives IRM access to a much larger global delivery and sales organization than it could support independently, though it also means IRM’s cybersecurity-specific results are not separately broken out in Capgemini’s public financials.
Innovation Matrix Assessment
No major new SYNERGi capability or product launch was found in recent coverage; the platform's module set (governance, risk, compliance, audit, vendor, IT security management) appears stable rather than rapidly expanding.
Over 750 customers across 25 countries and multiple UK government relationships, built on 20+ years of QSA and pen-testing consulting, indicates a genuinely operational and credentialed practice rather than a shell brand.
IRM's trajectory since 2019 has been driven by parent-company M&A (Altran, then Capgemini) rather than IRM's own visible growth signals; no independent recent evidence of accelerating customer wins or headcount growth was found under Capgemini ownership.
GRC platforms and PCI QSA/pen-testing services are a mature, well-established category; SYNERGi competes as a capable but not category-redefining option against dedicated GRC vendors and larger integrated risk platforms.
QSA accreditation and 750+ customers are verifiable credentials, but no independent benchmark or named case study detailing measurable outcomes from SYNERGi deployments was found in public sources.
GRC and PCI compliance remain standing requirements for regulated organizations, and being backed by Capgemini's global delivery network keeps IRM relevant to large multinational clients that a standalone UK consultancy of its original size could not easily serve.
Why CISOs Should Care
Offers a combined GRC-software-plus-consulting model -- SYNERGi for ongoing risk/compliance tracking, backed by IRM's own QSA and pen-testing teams -- useful for organizations that want one vendor for both the platform and the assessment work behind it.
What Makes It Different
Pairs a licensable GRC platform (SYNERGi) with in-house PCI QSA and penetration testing expertise under one roof, rather than selling GRC software alone and outsourcing assessment work to third parties.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A credentialed, operationally sound GRC and compliance testing practice that gained global reach through Capgemini ownership, but shows limited independent evidence of recent product innovation or standalone momentum.
Editorial Note: Claims vs. Verified Findings
The 750-customers-in-25-countries figure and UK government client base are IRM-published and not independently itemized; the Altran and Capgemini acquisition history is independently confirmed via industry press (ADS Advance) and Capgemini's own M&A disclosures.
Sources
Alternatives to IRM (Information Risk Management)
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…