Oxford, England
ProjectsIn development

Xcevia: a security consultancy in the making

Xcevia: a security consultancy in the making
Xcevia is a security consultancy I'm building for UK SMEs and scale-ups. These businesses need real security engineering but don't need, or can't afford, a large security firm. The company isn't trading yet. I'm shaping the services, the website, and the delivery approach alongside my full-time role.
  • Cyber Essentials and Cyber Essentials Plus readiness: gap assessment and remediation, then support alongside the IASME-certified assessor during the audit. Xcevia will prepare organisations for certification; it won't issue it.
  • Cloud security: hardening AWS and Azure environments
  • DevSecOps automation: building security checks into CI/CD pipelines
  • ISO 27001 support: preparing policies, controls, and evidence for compliance
  • Technical, not advisory: hands-on engineering rather than a list of recommendations
  • One person delivers the work: the practitioner who scopes the job is the one who does it
  • Clear findings, no filler: plain-language results with practical remediation steps
  • Scoped for SMEs: sized and priced for smaller organisations, not enterprise budgets
Every service draws on work I already do day to day in my full-time role.

Related projects

Penetration testing consultancy
Ongoing

Penetration testing consultancy

Independent penetration testing as a freelance consultant, backed by more than two years of managing and delivering an annual penetration testing programme in-house.
Cutting security tooling costs by 60% while widening coverage

Cutting security tooling costs by 60% while widening coverage

A vendor review at a UK health-tech company. I consolidated onto one platform that covers every operating system and the cloud, then closed the one remaining gap with a dedicated patch management tool.
Incident response and endpoint security in health tech

Incident response and endpoint security in health tech

Owning day-to-day alert handling across a multi-OS estate at a UK health-tech company, correlating cloud activity with endpoint telemetry, and leading the response to a live, high-severity security incident.
Embedding SAST into CI/CD pipelines

Embedding SAST into CI/CD pipelines

Adding static application security testing (SAST) to a health-tech company's delivery pipelines, so developers find code-level vulnerabilities before release rather than after.
Cyber Essentials Plus, ISO 27001 and security governance

Cyber Essentials Plus, ISO 27001 and security governance

Preparing the organisation for Cyber Essentials Plus certification, running the annual penetration testing programme, and keeping security policy, BCP/DR and awareness training aligned with ISO 27001 and GDPR.
EchoCare: a digital complaint management system for home care

EchoCare: a digital complaint management system for home care

An Innovate UK funded feasibility study and proof of concept with PBL Care Limited and Birmingham City University. The system replaces paper-based complaint handling with CQC-standard digital forms, NLP classification, and a live dashboard.