
Cyber & Privacy does not need to be complex
ICA Consultancy has consultants based on the South Coast, serving organisations across Portsmouth, Southampton, Hampshire, Surrey, Dorset and Sussex. Our clients here range from software and fintech firms to education providers and automotive manufacturers. Every consultant is an ex-industry practitioner, so you get advice grounded in running security, not just auditing it.
Who we work with across the region
Software and technology: Hampshire and Dorset software companies, including firms selling into regulated customers
Financial services: a securities and trading technology firm in Surrey
Education: a national tutoring and education provider headquartered in Surrey
Automotive: an electric vehicle manufacturer in Surrey
How we help them
01.
Maturity assessments. An independent view of where you stand, for boards, investors, auditors and regulators.
02.
ISO 27001 and Cyber Essentials Plus. From gap analysis, implementation, to certification
03.
CISO and DPO as a Service. Senior, named security and data protection leadership without a full-time hire.
04.
Culture360º. Measurable security culture across offices and hybrid teams, reported to the board.
05.
Cyber incident response exercises. Board and executive scenarios that test decision making.
Why a South Coast team matters
Our consultants live and work in the region, so on-site workshops, audits and exercises don't carry London travel time or cost. We understand the mix of businesses here: technology and defence supply chains, education, and fast-growing firms selling into larger, regulated customers.
What South Coast firms are being asked to prove
Customer security requirements
ISO 27001, Cyber Essentials Plus and security questionnaire responses backed by a named CISO
UK GDPR and the ICO Children's code
DPO as a Service, DPIAs, privacy notices and breach response
Automotive supplier assessments
ISO 27001-aligned readiness for TISAX and customer audits
Cyber insurance renewals
A named security lead, evidenced controls and a tested incident plan
Investor and acquirer due diligence
Maturity assessment and a remediation roadmap investors can rely on
See the results
FRACTIONAL CISO
No in-house security leadership. A board with a need.
No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.
15
risks scored across three phases of the programme
SECURITY & PRIVACY ROADMAP
Two disciplines, one baseline, one roadmap
A listed international recruitment group had security and data protection assessed in the same quarter, with one improvement plan built from both. Both capabilities were then held fractionally rather than hired.
3.24
overall security maturity by 2023, from a baseline of 1.95
MANAGED SECURITY CULTURE
Nine hundred thank-yous
Every phishing report gets an automatic thank-you in Teams. Phishing data and learning data joined into one score, proportionate remediation that escalates with the mistake, and a chase list of the people failing on both.
900+
phishing reports acknowledged automatically
Do you only work with large firms?
No. From around 50 staff upwards, or smaller where a client or regulator demands it. We scale the service to the firm.
Which areas do you cover?
Portsmouth, Southampton, Winchester, Basingstoke, Guildford, Bournemouth, Chichester and the wider South Coast, with on-site support as needed.
How quickly can you start?
Usually within weeks. If there is a deadline, such as an audit, a regulatory submission or an insurance renewal, tell us and we plan back from it.
