Skip to content

Capita

Large publicly traded UK outsourcing group whose managed security division runs 24/7 SOCs for public and private sector clients, a division whose own 2023 breach drew a £14m ICO fine.

Visit Website ↗ + Add to Compare
42/100Emerging / Unranked

Overview

Capita is a large, publicly traded UK business-process-outsourcing and technology group (LSE: CPI) with a dedicated cybersecurity services division rather than a single security product. That division runs 24/7 security operations centres in the UK and India offering tiered managed SIEM (Bronze/Silver/Gold), vulnerability assessment, security infrastructure management, and incident response, serving both public-sector clients (UK central and local government) and private-sector customers such as PD Ports.

Founded in 1984 and now employing roughly 34,000 people group-wide (the cybersecurity practice is a fraction of that total), Capita’s security business is best understood as an outsourced SOC/MSSP offering aimed at organizations that don’t want to build 24/7 monitoring capability in-house. It is a traditional managed-services model rather than a technology-differentiated platform, competing largely on scale, coverage, and existing outsourcing relationships with UK public bodies.

Capita itself suffered a serious cyberattack in March 2023, in which an attacker who gained access via a malicious file was not contained for 58 hours despite an early security alert, ultimately exfiltrating nearly a terabyte of data and exposing personal information on 6.6 million people across 325 pension schemes administered by Capita Pension Solutions. In October 2025, the UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions a combined £14 million for the resulting UK GDPR failures — a directly relevant, independently adjudicated data point for a company that also sells cybersecurity monitoring services to others.

Innovation Matrix Assessment

Innovation Velocity 4/10

Capita's managed security services evolve through incremental additions to its SIEM service tiers and infrastructure-management offerings rather than fast-moving product releases typical of a dedicated security vendor.

Operational Value 6/10

Running three 24/7 security operations centres across the UK and India for large public- and private-sector clients demonstrates real operational scale, independent of the 2023 incident's outcome.

Market Momentum 4/10

Continued public-sector contract wins (e.g., PD Ports) show the security business remains active, but the 2023 breach and subsequent 2025 ICO fine have been a reputational headwind for the division during this period.

Category Disruption 3/10

A traditional outsourced SOC/MSSP model competing on scale and existing government relationships rather than introducing new detection technology or a materially different security architecture.

Real-World Efficacy 3/10

Capita's own March 2023 breach, in which a compromised device was not contained for 58 hours after an alert fired and nearly a terabyte of data was exfiltrated, resulted in a £14m ICO fine in October 2025 for UK GDPR failures — a serious, independently adjudicated efficacy concern for a company selling security monitoring and incident-response services to others.

Enduring Relevance 5/10

Outsourced 24/7 SOC and managed SIEM services remain relevant for public-sector and mid-market organizations that lack in-house monitoring capability, though buyers should weigh Capita's own incident-response track record.

Why CISOs Should Care

Offers an established, at-scale outsourced SOC option for organizations without in-house 24/7 monitoring capability, but Capita's own 2023 breach and resulting ICO fine are directly relevant due-diligence context.

What Makes It Different

Distinguished mainly by scale and long-standing UK government outsourcing relationships rather than by differentiated security technology; its 2023 breach and £14m ICO fine are a distinguishing negative data point relative to category peers.

The Matrix Verdict

42/100 — EMERGING / UNRANKED

A large-scale, publicly traded managed security provider whose own well-documented 2023 breach and subsequent regulatory fine materially undercut confidence in its security practice, even as its SOC infrastructure continues to operate at meaningful scale.

Editorial Note: Claims vs. Verified Findings

The March 2023 Capita data breach, the 58-hour containment delay, the 6.6 million affected individuals, and the £14m combined ICO fine (October 2025) are independently confirmed by the UK Information Commissioner's Office, Wikipedia, and multiple law-firm analyses (Mayer Brown, Clifford Chance, Burges Salmon). Capita's own marketing claims about its SOC capabilities are vendor-stated and are presented alongside, not in place of, this independently verified incident.

Sources