
Cyber & Privacy does not need to be complex
ICA Consultancy has consultants based in London and works with more London organisations than anywhere else. Our clients here include banks and payments firms, investment managers, private equity houses, professional and membership bodies, and charities. Every consultant is an ex-industry practitioner who has done the job, not just advised on it.
Who we work with in London
Professional and membership bodies: an accountancy institute, a financial markets trade association and a fraud prevention membership organisation
Banking, payments and FX: Specialist banks, cross-border payments and FX firms, and digital payments businesses, regulated by the FCA/PRA
Investment management and capital markets: independent investment managers, capital markets platforms and consumer investment research firms
Private equity: London PE firms and their portfolio companies, from security culture programmes to portfolio-wide governance
Recruitment: Regional and International staffing groups
Telecoms and technology: critical communications providers, media technology and software firms
Professional services: Legal group, and sustainability and management consultancies
Charities and faith organisations: a London hospital charity and a large city church
How we help them
01.
Maturity assessments. An independent view of where you stand, for boards, investors, auditors and regulators.
02.
Risk Management. Risk management, policy, and supplier and third-party assurance.
03.
CISO and DPO as a Service. Senior, named security and data protection leadership without a full-time hire.
04.
DORA and Operational Resilience. Scenario testing and DORA for firms with EU entities, clients or providers.
05.
Culture360º. Measurable security culture across offices and hybrid teams, reported to the board.
06.
AI governance and ISO/IEC 42001. Controls for AI use before regulators and clients start asking.
07.
Cryptgility (post-quantum cryptography). A crypto migration roadmap, starting with critical systems.
08.
Cyber incident response exercises. Board and executive scenarios that test decision making.
Why a London-based team matters
We can be in your office for board meetings, workshops and incident exercises at short notice. We know the regulators, trade bodies and supervisory expectations London firms answer to, because many of our clients sit inside them.
What London firms are being asked to prove
FCA and PRA operational resilience
Mapping important business services, setting impact tolerances, scenario testing
DORA
Gap analysis, ICT risk framework, third-party register, testing
UK GDPR and ICO expectations
DPO as a Service, records of processing, DPIAs, breach response
PCI DSS and SWIFT CSP
Readiness, evidence and assessment support
Client and investor due diligence
ISO 27001, Cyber Essentials Plus, questionnaire responses backed by a named CISO
See the results
FRACTIONAL CISO
No in-house security leadership. A board with a need.
No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.
15
risks scored across three phases of the programme
SECURITY & PRIVACY ROADMAP
Two disciplines, one baseline, one roadmap
A listed international recruitment group had security and data protection assessed in the same quarter, with one improvement plan built from both. Both capabilities were then held fractionally rather than hired.
3.24
overall security maturity by 2023, from a baseline of 1.95
MANAGED SECURITY CULTURE
Nine hundred thank-yous
Every phishing report gets an automatic thank-you in Teams. Phishing data and learning data joined into one score, proportionate remediation that escalates with the mistake, and a chase list of the people failing on both.
900+
phishing reports acknowledged automatically
Do you only work with large firms?
No. Most London clients have between 50 and a few thousand staff. We scale the service to the firm.
Can you meet in person?
Yes. Our London consultants work on site as needed, alongside remote delivery.
How quickly can you start?
Usually within weeks. If there is a deadline, such as an audit, a regulatory submission or an insurance renewal, tell us and we plan back from it.
Do you replace our IT provider?
No. We set the security and data protection direction, and hold your IT provider and other suppliers to it.
