Cyro Cyber Achieves NCSC Assured Cyber Security Consultancy Status for Audit & Review and Risk Management 

LONDON, UK – 13th August, 2026

Cyro Cyber, the UK based cyber security professional and managed security services provider, has successfully passed its application to become an NCSC Assured Cyber Security Consultancy (ACSC) for Audit & Review and Risk Management, marking a significant milestone in the development of its award-winning consultancy practice. Cyro Cyber are now one of only 35 ACSCs in the UK. 

The NCSC’s Assured Cyber Security Consultancy scheme is designed for organisations providing independent cyber security consultancy to clients with complex, high risk or nationally significant security requirements. Providers are assessed against the NCSC’s standard for delivering high quality cyber security consultancy and must demonstrate that they can apply NCSC advice and guidance appropriately to their clients’ needs. 

The achievement adds to Cyro Cyber’s growing portfolio of industry leading NCSC assured capabilities. Alongside its ACSC status, Cyro Cyber is also an NCSC Assured Service Provider, supporting its work on the Cyber Assessment Framework with organisations navigating the requirements of the Cyber Resilience Audit Scheme. It also holds NCSC Cyber Incident Exercising (CIE) status, further demonstrating the breadth of specialist capability within its consultancy practice. 

For Cyro Cyber, achieving assurance across both Audit & Review and Risk Management provides independent recognition of the capability, experience and processes underpinning its consultancy services. The NCSC identifies the ACSC scheme as particularly relevant to organisations including operators of essential services, government bodies and organisations facing elevated cyber threats, including targeted, persistent or capable adversaries. 

Cyro Cyber has extensive experience working in these environments, with more than 30 years of collective experience protecting critical IT and OT across the military, Critical National Infrastructure, central government and private sectors. 

Peter Lane, Consultancy Director at Cyro Cyber, said:Passing the ACSC assessment is a significant achievement because it’s an external test of how we actually deliver consultancy, not simply a recognition of the services we offer. The standard requires us to demonstrate that we can provide independent, evidence based advice to organisations facing complex and often high consequence cyber security challenges. For our clients, particularly those operating in CNI, government and other highly regulated environments, that assurance is paramount. It gives them confidence that the advice they receive from Cyro is being delivered against the standard set by the UK’s National Cyber Security Centre.” 

Under the Audit & Review status, assured providers are expected to assess the effectiveness of cyber security policies, standards and controls, review how they are implemented in practice, assess supporting evidence such as system designs and risk analyses, and identify clearly defined remediation actions.

The Risk Management status, assured providers focus on helping organisations develop a realistic understanding of their cyber security risks, assess and prioritise those risks in the context of their business objectives, and make informed decisions about how they should be managed. 

Together, the two offerings strengthen Cyro Cyber’s ability to support clients from understanding their current security position through to making decisions about where risk needs to be reduced, accepted or managed. 

Alec Warriner, Services Director at Cyro Cyber, said: “There is a real difference between producing a risk register or completing an audit and giving an organisation an accurate understanding of the security risks that could genuinely affect its ability to operate. Our clients need advice that reflects their technology, their operational environment, their regulatory obligations and the threats they face. The ACSC assessment has tested the rigour behind the way we deliver that advice. Passing it is a strong endorsement of the team and the standard we hold ourselves to.” 

Shannon Simpson, CEO at Cyro Cyber, said: “We built Cyro around the belief that organisations facing serious cyber risk need more than generic advice. They need people who understand the environment they are operating in, the consequences of getting security wrong and what it takes to make meaningful improvements. Achieving NCSC assured status against Audit & Review and Risk Management is a significant validation of that approach. It demonstrates that the capability we have built at Cyro stands up to independent scrutiny”.  

The NCSC states that its ACSC scheme provides clients with confidence that an assured consultancy has met its standard, has a proven track record of delivering high quality consultancy, understands current and potential cyber threats, and operates with integrity, objectivity and proportionality. 

For Cyro Cyber, the achievement strengthens its ability to support organisations that need independent, trustworthy cyber security advice and further builds its consultancy capability across the sectors where the consequences of cyber risk are greatest. 

About Cyro Cyber:

Cyro Cyber is a UK based cyber security professional and managed security services provider, focused on protecting critical infrastructure, public services and high impact organisations. With 30+ years of experience protecting critical IT and OT across Critical National Infrastructure, central government and private sectors, Cyro Cyber helps security professionals in highly regulated organisations stay protected against evolving cyber threats. Our expertise spans compliance, security assessment, secure system design and MXDR services, backed by a 24/7 UK based Security Operations Centre. 

Media Contact: 

Laura Reilly   
Marketing Manager, Cyro Cyber   
laura.reilly@cyro.uk   

Get in touch

If you’d like to see how we can keep your organisation safe, get in touch with us today!

Next
Next

Cyro Cyber Named Finalist in Three Categories at the National Cyber Awards 2026