top of page
Photo of Tower Bridge, article about demysterfying cyber security in London

Cyber security and data protection for London's regulated organisations

Cyber & Privacy does not need to be complex

ICA Consultancy has consultants based in London and works with more London organisations than anywhere else. Our clients here include banks and payments firms, investment managers, private equity houses, professional and membership bodies, and charities. Every consultant is an ex-industry practitioner who has done the job, not just advised on it.

Who we work with in London

Professional and membership bodies: an accountancy institute, a financial markets trade association and a fraud prevention membership organisation

Banking, payments and FX: Specialist banks, cross-border payments and FX firms, and digital payments businesses, regulated by the FCA/PRA

Investment management and capital markets: independent investment managers, capital markets platforms and consumer investment research firms

Private equity: London PE firms and their portfolio companies, from security culture programmes to portfolio-wide governance

Recruitment: Regional and International staffing groups

Telecoms and technology: critical communications providers, media technology and software firms

Professional services: Legal group, and sustainability and management consultancies

Charities and faith organisations: a London hospital charity and a large city church

How we help them

01.

Maturity assessments. An independent view of where you stand, for boards, investors, auditors and regulators.

02.

Risk Management. ​Risk management, policy, and supplier and third-party assurance.

03.

CISO and DPO as a Service. Senior, named security and data protection leadership without a full-time hire.

04.

DORA and Operational Resilience. Scenario testing and DORA for firms with EU entities, clients or providers.

05.

Culture360º. Measurable security culture across offices and hybrid teams, reported to the board.

06.

AI governance and ISO/IEC 42001. Controls for AI use before regulators and clients start asking.

07.

Cryptgility (post-quantum cryptography). A crypto migration roadmap, starting with critical systems.

08.

Cyber incident response exercises. Board and executive scenarios that test decision making.

Why a London-based team matters

We can be in your office for board meetings, workshops and incident exercises at short notice. We know the regulators, trade bodies and supervisory expectations London firms answer to, because many of our clients sit inside them.

What London firms are being asked to prove

FCA and PRA operational resilience

Mapping important business services, setting impact tolerances, scenario testing

Banks, insurers, payments and investment firms

DORA

Gap analysis, ICT risk framework, third-party register, testing

UK firms with EU entities, clients or ICT providers

UK GDPR and ICO expectations

DPO as a Service, records of processing, DPIAs, breach response

Every organisation handling personal data

PCI DSS and SWIFT CSP

Readiness, evidence and assessment support

Every organisation handling personal data

Client and investor due diligence

ISO 27001, Cyber Essentials Plus, questionnaire responses backed by a named CISO

PE portfolio companies, suppliers to regulated firms

See the results

FRACTIONAL CISO

No in-house security leadership. A board with a need.

No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.

15

risks scored across three phases of the programme

SECURITY & PRIVACY ROADMAP

Two disciplines, one baseline, one roadmap

A listed international recruitment group had security and data protection assessed in the same quarter, with one improvement plan built from both. Both capabilities were then held fractionally rather than hired.

3.24

overall security maturity by 2023, from a baseline of 1.95

MANAGED SECURITY CULTURE

Nine hundred thank-yous

Every phishing report gets an automatic thank-you in Teams. Phishing data and learning data joined into one score, proportionate remediation that escalates with the mistake, and a chase list of the people failing on both.

900+

phishing reports acknowledged automatically

Do you only work with large firms?

No. Most London clients have between 50 and a few thousand staff. We scale the service to the firm.

Can you meet in person?

Yes. Our London consultants work on site as needed, alongside remote delivery.

How quickly can you start?

Usually within weeks. If there is a deadline, such as an audit, a regulatory submission or an insurance renewal, tell us and we plan back from it.

Do you replace our IT provider?

No. We set the security and data protection direction, and hold your IT provider and other suppliers to it.

Frequently Asked Questions

Based in London and need a security or data protection lead?

bottom of page