Skip to content

Arco Cyber

Arco Cyber is a UK-based cybersecurity assurance company, founded in 2022 and led since inception by CEO Matt Helling, a 19-year veteran of infrastructure…

+ Add to Compare
63/100Incremental Innovator

Overview

Arco Cyber is a UK-based cybersecurity assurance company, founded in 2022 and led since inception by CEO Matt Helling, a 19-year veteran of infrastructure provider Softcat. The company operates a continuous cyber risk and control assurance platform that consolidates data across a customer’s security stack to show control effectiveness, surface exposures, and prioritize remediation using risk-based metrics, rather than relying on point-in-time audits.

Sophos acquired Arco Cyber in February 2026 as the foundation of Sophos CISO Advantage, a new initiative combining agentic AI, integrated platforms, and human expertise — delivered through Sophos’s MSP and MSSP partner network — to give organizations without a dedicated CISO access to CISO-level security judgment and compliance guidance. Terms were not disclosed.

Innovation Matrix Assessment

Innovation Velocity 7/10

Built a continuous control-assurance platform and became the centerpiece of a major acquirer's new CISO-as-a-service strategy within roughly four years of founding.

Operational Value 7/10

Converts scattered security-stack data into ongoing, risk-scored control effectiveness metrics that security teams and partners can act on directly rather than waiting for periodic audits.

Market Momentum 7/10

Acquired by Sophos in February 2026 specifically to anchor its new Sophos CISO Advantage initiative -- a strong strategic endorsement from a major security vendor.

Category Disruption 5/10

Continuous control assurance is an incremental evolution of established GRC and security-posture-management approaches rather than a wholly new category.

Real-World Efficacy 5/10

No independent customer benchmarking is publicly available; efficacy rests on Sophos's acquisition due diligence and the founding team's industry background rather than published third-party validation.

Enduring Relevance 7/10

Compliance pressure and the shortage of CISO-level talent at small and mid-sized organizations make continuous, partner-deliverable assurance durably relevant.

Why CISOs Should Care

Gives resource-constrained security teams -- and organizations with no dedicated CISO at all -- continuous, risk-scored visibility into control effectiveness across their stack, turning point-in-time compliance audits into an ongoing assurance process.

What Makes It Different

Built specifically as a continuous control-assurance layer that consolidates evidence across the existing security stack into risk-based metrics, rather than as a GRC questionnaire tool or a standalone audit product.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

A young (2022) UK assurance platform whose acquisition by Sophos to anchor a flagship new CISO-as-a-service initiative is a strong momentum signal; Meaningful Innovator given the speed of that validation for a four-year-old company.

Editorial Note: Claims vs. Verified Findings

The acquisition, founding date, and CEO background are corroborated across Sophos's own press release and independent trade coverage (BankInfoSecurity, Techzine); deal financial terms were not disclosed by either party.

Sources