Skip to content

CyberQ Group

UK-based MSSP delivering CREST-accredited SOC monitoring, penetration testing, and vCISO advisory services to mid-market organizations.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

CyberQ Group is a Birmingham, UK-based managed security services provider founded in 2016 by Chris Woods and Steve Bailey, launched through the Cyber London (Cylon) accelerator. The company runs a CREST-accredited 24/7 SOC-as-a-service offering alongside penetration testing, vulnerability assessments, configuration reviews, and attack surface reviews, plus advisory work including virtual CISO services, cyber maturity assessments, and board-level crisis simulation exercises.

The firm holds ISO 27001 and Cyber Essentials certifications, is a CREST-accredited testing provider, and is listed as a supplier on the UK government’s G-Cloud framework — independently verifiable credentials rather than self-reported claims. It has grown to serve more than 150 client organizations, primarily in logistics, manufacturing, and retail, delivered through a “follow-the-sun” model with offices in the UK, US, and Philippines.

CyberQ has raised roughly £1 million in a mix of equity and UK innovation grant funding (including Innovate UK), positioning it as a modestly funded but operationally credentialed regional MSSP. It is a reasonable fit for mid-market organizations that need outsourced SOC coverage and accredited testing without building an in-house security operations function, though it competes in a crowded MSSP field against larger, better-capitalized rivals.

Innovation Matrix Assessment

Innovation Velocity 5/10

Has expanded from core pentesting into SOC-as-a-service, vCISO, and board crisis-simulation offerings since its 2016 founding, a moderate pace typical of a growing regional MSSP.

Operational Value 6/10

Runs a CREST-accredited 24/7 SOC with follow-the-sun coverage across UK, US, and Philippines offices, serving 150+ client organizations.

Market Momentum 4/10

Modest total funding (~$1.27M, largely grants) and steady rather than explosive client growth; no major recent funding or acquisition events found.

Category Disruption 3/10

A conventional MSSP/pentest service model; differentiation comes from accreditation and delivery model rather than novel technology.

Real-World Efficacy 6/10

CREST accreditation, ISO 27001 certification, and UK G-Cloud supplier status are independently issued/audited credentials that substantiate its technical testing claims.

Enduring Relevance 7/10

Outsourced 24/7 SOC monitoring and accredited penetration testing address persistent, high-demand mid-market needs, particularly for organizations lacking in-house security operations staff.

Why CISOs Should Care

Gives mid-market organizations CREST-accredited testing and 24/7 SOC coverage without the cost of building an in-house security operations function.

What Makes It Different

Combines CREST-accredited technical testing with board-level advisory (crisis simulations, vCISO) under one roof, differentiating from pure-play pentest shops or pure-play SOC vendors.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A credentialed, modestly scaled regional MSSP with genuine accreditation to back its claims; solid execution but not a category disruptor, competing in a crowded outsourced-SOC market.

Editorial Note: Claims vs. Verified Findings

The '150+ clients' figure and follow-the-sun delivery model are vendor-reported; CREST accreditation, ISO 27001 certification, and G-Cloud supplier listing are independently verifiable third-party credentials.

Sources