CyberQ Group
UK-based MSSP delivering CREST-accredited SOC monitoring, penetration testing, and vCISO advisory services to mid-market organizations.
Visit Website ↗ + Add to CompareOverview
CyberQ Group is a Birmingham, UK-based managed security services provider founded in 2016 by Chris Woods and Steve Bailey, launched through the Cyber London (Cylon) accelerator. The company runs a CREST-accredited 24/7 SOC-as-a-service offering alongside penetration testing, vulnerability assessments, configuration reviews, and attack surface reviews, plus advisory work including virtual CISO services, cyber maturity assessments, and board-level crisis simulation exercises.
The firm holds ISO 27001 and Cyber Essentials certifications, is a CREST-accredited testing provider, and is listed as a supplier on the UK government’s G-Cloud framework — independently verifiable credentials rather than self-reported claims. It has grown to serve more than 150 client organizations, primarily in logistics, manufacturing, and retail, delivered through a “follow-the-sun” model with offices in the UK, US, and Philippines.
CyberQ has raised roughly £1 million in a mix of equity and UK innovation grant funding (including Innovate UK), positioning it as a modestly funded but operationally credentialed regional MSSP. It is a reasonable fit for mid-market organizations that need outsourced SOC coverage and accredited testing without building an in-house security operations function, though it competes in a crowded MSSP field against larger, better-capitalized rivals.
Innovation Matrix Assessment
Has expanded from core pentesting into SOC-as-a-service, vCISO, and board crisis-simulation offerings since its 2016 founding, a moderate pace typical of a growing regional MSSP.
Runs a CREST-accredited 24/7 SOC with follow-the-sun coverage across UK, US, and Philippines offices, serving 150+ client organizations.
Modest total funding (~$1.27M, largely grants) and steady rather than explosive client growth; no major recent funding or acquisition events found.
A conventional MSSP/pentest service model; differentiation comes from accreditation and delivery model rather than novel technology.
CREST accreditation, ISO 27001 certification, and UK G-Cloud supplier status are independently issued/audited credentials that substantiate its technical testing claims.
Outsourced 24/7 SOC monitoring and accredited penetration testing address persistent, high-demand mid-market needs, particularly for organizations lacking in-house security operations staff.
Why CISOs Should Care
Gives mid-market organizations CREST-accredited testing and 24/7 SOC coverage without the cost of building an in-house security operations function.
What Makes It Different
Combines CREST-accredited technical testing with board-level advisory (crisis simulations, vCISO) under one roof, differentiating from pure-play pentest shops or pure-play SOC vendors.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A credentialed, modestly scaled regional MSSP with genuine accreditation to back its claims; solid execution but not a category disruptor, competing in a crowded outsourced-SOC market.
Editorial Note: Claims vs. Verified Findings
The '150+ clients' figure and follow-the-sun delivery model are vendor-reported; CREST accreditation, ISO 27001 certification, and G-Cloud supplier listing are independently verifiable third-party credentials.
Sources
Alternatives to CyberQ Group
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…