The engine behind CyPro's consultancy and SOC

CyPro Labs: our market leading innovation and R&D centre

CyPro Labs is where CyPro takes on some of the hardest challenges in cyber security today. It is the engine that drives and accelerates both our consultancy and our security operations centre, and the efficiencies it creates are passed straight to our clients, so they become more secure, faster.

  • Drives CyPro's consultancy and security operations centre
  • Every deliverable owned by a named consultant
  • Designed and run by the CyPro team
3D illustration of the connected challenges CyPro Labs takes on for every engagement

The short version

What CyPro Labs is

CyPro Labs is CyPro's innovation and research and development centre. It is where our consultants and security operations centre analysts turn the problems they meet on client work into new methods, tested structures and purpose built tooling, so that every engagement and every shift starts from the strongest foundation we have rather than from a blank page.

It is not a product. There is no client login, no licence and nothing to buy. What you receive is the result: assessments, registers, plans, reports, detections and briefings, scoped, reviewed and signed by the consultant who owns your engagement, and delivered faster and to a higher standard because of the work done in Labs.

Why we built it

Some of the hardest problems in cyber security are problems of scale and consistency

A gap analysis that needs weeks of workshops. A tenant with thousands of settings that nobody has the hours to review by hand. Vulnerability reports from four sources that no one can prioritise. Alerts that outrun the analysts watching them. None of these are solved by adding another consultant; they are solved by changing how the work is done.

Labs exists to do exactly that. We take a difficult, repetitive or slow piece of security work, work out how to do it consistently and well, then build that method into how CyPro delivers. The time saved goes back to our clients as sharper judgement, quicker turnaround and a lower cost of being secure.

Innovation areas

The challenges we are solving

Each area below starts with a problem our clients and our own teams kept running into, then describes what Labs built in response. Every one is in use on live engagements today, with a named consultant or analyst reviewing what it produces.

3D illustration of the assurance and compliance challenges CyPro Labs is solving

Assurance and compliance

Knowing where you stand against a framework, and what to fix first, without the engagement consuming weeks of your people's time.

Delivering a compliance assessment without weeks of client workshops

The challenge

A gap analysis against ISO 27001 or a similar framework has traditionally meant a run of long workshops, a consultant transcribing answers by hand, and evidence that goes stale between the first session and the final report. Your people lose days, and the write up takes weeks more.

What Labs built

Labs turns a focused set of recorded conversations into a control by control draft: status, findings and recommendations for every control, with the evidence behind each one kept in place. The consultant who ran the sessions reviews and edits every section, and the same method now drives our cyber maturity assessments. Fewer workshops for you, and a report that arrives while the discussion is still fresh.

Reviewing every security control across an entire tenant without hours of engineer time

The challenge

A Microsoft 365 or Google Workspace tenant holds thousands of settings spread across a dozen admin consoles. Reviewing them by hand takes a security engineer days, misses things, and is out of date the moment someone changes a policy.

What Labs built

Labs reads the whole tenant, read only and with your permission, and checks it against CyPro's hardening controls: what is in place, what is not and what to change, scored the same way every time. The review can be repeated as often as you like, so progress is measured rather than assumed. We recommend, you implement.

Rating a new vendor, application or service before it becomes a bottleneck

The challenge

Every new SaaS request, supplier or service needs a risk view before it is approved. Done by hand, each one is a day of research, so requests queue behind the security team and the business either waits or goes ahead without an answer.

What Labs built

A short intake is all it takes. Labs researches the public security, privacy and breach record of the vendor or service, produces a rated assessment with every source cited, and a consultant checks it before it is issued. Decisions that used to take days take hours.

3D illustration of the threat and exposure challenges CyPro Labs is solving

Threat and exposure

Seeing what an attacker sees, understanding who would target you and why, and keeping exposure falling week on week.

Vulnerability data from everywhere, and no way to prioritise it

The challenge

Endpoint protection, network scanners and cloud tooling each produce their own vulnerability reports, in their own formats, with their own scores. The same weakness appears three times, the critical one is buried, nothing reflects what the affected system actually does for the business, and there is no way to prove that fixed means fixed.

What Labs built

Labs brings every source into one governed view. Each finding is enriched with exploitability and exposure, scored consistently per device and per application, and weighted by the business context you give us. Progress is tracked week on week, and what you decide not to fix is captured in a formal risk acceptance register rather than lost in a spreadsheet.

Knowing what an attacker can already see from the outside

The challenge

Your external footprint changes every week as domains, cloud services and suppliers come and go. A yearly penetration test is a photograph of a single day, and the gap between tests is where exposures accumulate unnoticed.

What Labs built

From your domains, address ranges and company names, Labs maps what an attacker would find: subdomains, open services, leaked credentials, exposed storage, look alike domains and exposed secrets, each rated for urgency. Active scanning only ever runs with your permission, and the picture can be refreshed as often as your footprint changes.

Threat assessments about you, not a generic threat report

The challenge

Most threat reports describe the whole world. Working out which threat groups actually target organisations like yours, how they operate and what that means for a specific system used to take a senior consultant weeks of research, so it was rarely done in the depth it deserved.

What Labs built

Labs builds a threat assessment specific to your sector, size and technology in reviewed stages: the scenarios that apply to you, the groups behind them, their techniques and real cases, then an executive summary. For individual systems, your architecture becomes a structured threat analysis mapped to MITRE ATT&CK with attack paths and prioritised mitigations. A consultant approves each stage before the next begins.

3D illustration of the third party and transaction challenges CyPro Labs is solving

Third parties and transactions

The questions your customers ask you, the checks you owe your suppliers, and the scrutiny a contract or acquisition deserves, at the speed deals actually move.

Answering security questionnaires without starting from a blank page every time

The challenge

Every customer and buyer sends a different questionnaire asking largely the same questions. The answers live in policies, certificates and old responses scattered across the business, so each one costs days of an already stretched team, and the answers drift over time.

What Labs built

Labs holds a curated library of your policies, certifications and evidence and answers each question from it, with a source reference against every answer so you can see exactly where it came from. A consultant reviews the whole response before anything goes back. Turnaround drops from weeks to days, and every answer stays consistent with the last one.

Due diligence on suppliers, contracts and counterparties that keeps pace with the deal

The challenge

Supplier reviews, contract clause checks and counterparty screening are all slow when done by hand, so they either hold up the deal or get skipped. Reviews vary with whoever did them, and the evidence trail behind a decision is hard to reconstruct later.

What Labs built

Labs gives each of these a consistent method. Suppliers are assessed against one question set with a rated view and an evidence trail. Contracts are read for unreasonable, unusual or unworkable security clauses, each flagged with plain English commentary and a suggested alternative (commentary, not legal advice). Counterparties are screened against registry data, filed accounts, sanctions and politically exposed person lists in one assessment, with a reviewer's approval on record.

3D illustration of the detection and response challenges CyPro Labs is solving

Detection and response

For clients of CyPro's security operations centre: detection that fits your telemetry, response you can hold us to, and reporting that shows what was found and what was done.

Detection coverage that grows faster than rules can be written by hand

The challenge

Open source detection libraries rarely fit a client's log sources and field names as published, and writing bespoke rules one at a time is slow, specialist work. Coverage gaps stay open for months, and nobody can say with confidence which attacker techniques would actually be caught.

What Labs built

Labs translates community and vendor detection content into rules that fire on your telemetry, tests them, and adds bespoke detections written from real incidents. Coverage is mapped to MITRE ATT&CK so you can see exactly which techniques are watched, and the gaps are worked down in priority order.

Response targets that are met and proven, not just promised

The challenge

Service levels are often checked after the fact, when a missed deadline is already a conversation. Monthly reporting is assembled by hand from ticket exports, arrives late, and tells you what happened without much on why.

What Labs built

Every ticket is watched against its response and investigation targets as it happens. An analyst is assigned before a first response deadline can be missed, escalations go out if it slips, and the shift lead sees a summary each morning. The monthly report is built from the same live record: service level performance, incident volumes and categories, resolution breakdowns and detection coverage against MITRE ATT&CK, reviewed by your service manager before it is issued.

Turning a closed incident into a client ready report without pulling analysts off the queue

The challenge

Writing up an incident properly takes an experienced analyst hours they do not have, so reports arrive late, thin, or inconsistent from one incident to the next.

What Labs built

Alerts reach the SOC as tickets an analyst can act on, with the affected asset and account already resolved and status kept in step with your own service desk. When an incident closes, Labs drafts the report from the full ticket record, with a timeline of what happened and what was done, and the analyst who handled it reviews and signs it before it leaves the SOC.

3D illustration of the advisory and communication challenges CyPro Labs is solving

Advisory and communication

Making sure what leaves CyPro is right, and keeping your people informed about the threats that matter to them rather than every headline.

Quality control on every deliverable before it reaches you

The challenge

Consultancy deliverables are reviewed by whoever has time, against whatever they remember of the brief. House style slips, sections drift from the scope that was agreed, and problems surface when the client reads the document rather than before.

What Labs built

Every deliverable is checked in Labs for quality, house style and coverage of what the engagement promised before a partner signs it off. The review lists problems for the author to answer; it never edits the document itself. What you receive has been challenged before you see it.

Threat intelligence filtered to what matters to you

The challenge

Security news is endless and mostly irrelevant to any one organisation. Generic bulletins get ignored, and the stories that do matter to your sector, suppliers or technology are easy to miss.

What Labs built

Labs gathers cyber news continuously, removes duplicates and triages it against each client's profile, so only the stories relevant to you are researched and written up, with two stages of review before a bulletin goes out. Client newsletters follow the same principle: one master briefing each issue, then rewritten around your own tooling, vendors and priorities.

A challenge that is not on the list?

Most engagements combine several of these, and Labs takes on new problems as client work demands them. Tell us what you are trying to achieve and a consultant will explain how the work would run and what you would receive.

Book a discovery call

Principles

How Labs is run

Five commitments that hold on every engagement and every shift, whichever service you are buying and whoever is delivering it.

Your information stays yours

Each client's engagement data is held separately and handled under CyPro's ISO 27001 certified information security management system. Nothing is visible to, or reused for, any other client.

A person signs everything

Labs supports the consultant and the analyst. It does not replace the named person who reviews the deliverable, presents it and answers for it afterwards.

Consistency by design

The same tested method on every engagement, whoever is delivering it. The report you receive in month twelve is built the same way as the report in month one.

Better with every engagement

The way a control is assessed or a finding is structured improves as we deliver more work. Method carries between engagements; client information never does.

Run by the CyPro team

Labs is designed, operated and improved by CyPro's own UK based team. There is no third party between you and the people doing the work.

CyPro Ltd is ISO 27001 certified, Cyber Essentials Plus certified and a CREST accredited provider. The same management system that governs our client work governs Labs.

About CyPro

The people behind Labs

Built by the people who use it

Labs is shaped by the consultants and analysts who use it on client engagements and in the security operations centre every week. These are the CyPro team members who lead it.

Jonny Pelter, Partner at CyPro

Jonny Pelter

Partner, CyPro

Jonny is a Founding Partner at CyPro and an executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ. Originating from KPMG and Deloitte, he has advised organisations across technology, critical national infrastructure, financial services, insurance, betting, pharmaceuticals and utilities, and is a regular commentator on cyber security for BBC News, the Telegraph and Times Radio. Jonny sets the direction for CyPro Labs: the challenges it takes on and the standard every method it produces is held to.

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc
LinkedIn
Rob McBride, Partner at CyPro

Rob McBride

Partner, CyPro

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001
LinkedIn
Dan Proctor, Senior Security Automations Engineer at CyPro

Dan Proctor

Senior Security Automations Engineer, CyPro

Dan leads the design and day to day running of CyPro Labs. He builds the methods and delivery structures that CyPro's engagements and security operations run through, and works across both client engagements and CyPro's own operations to keep Labs secure, resilient and improving.

  • ISO 42001
LinkedIn
Leonie Witte, Cyber Security Manager at CyPro

Leonie Witte

Cyber Security Manager, CyPro

Joining CyPro from Capgemini, Leonie brings a strong blend of technical insight and consulting expertise to her role as a Cyber Security Manager. Her work spans governance and compliance (including ISO 27001), advanced security operations such as privileged user monitoring and security tooling optimisation, and the security review of new delivery methods before they reach client work.

  • ISO 27001 Implementation
  • ISO 27001 Internal Auditor
  • ISO 42001 Lead Implementer
  • Darktrace internal certifications
  • ISO 42001 Implementation
LinkedIn
Niall Fitzgerald, Senior SOC Analyst at CyPro

Niall Fitzgerald

Senior SOC Analyst, CyPro

Niall joined CyPro from IBM, where he supported enterprise security operations and engineering across endpoint, identity and cloud. At CyPro he works in the security operations centre, analysing alerts, contributing to threat hunting and refining detection logic to improve visibility and reduce false positives, and he brings that front line view to the detection and response work built in Labs.

LinkedIn
Elsie Day, Senior Security Consultant at CyPro

Elsie Day

Senior Security Consultant, CyPro

Elsie holds an MSc in Crime Science with Cyber Crime from UCL and brings a research background in the human factors of cyber security to her consulting work. At CyPro she delivers assurance and bid work for clients, and her hands on reviews of what Labs produces feed directly into how its methods are refined.

  • BA Criminology
  • MSc Crime Science and Cyber Crime
  • ISC2 - Certified in Cyber Security
  • Prince2 Practitioner
LinkedIn

The team holds

  • CIPM
  • CIPP E
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001
  • Prince2
3D illustration of frequently asked questions about CyPro Labs

Good questions

Frequently asked questions

Can we buy, licence or log in to CyPro Labs?

No. CyPro Labs is CyPro's internal innovation and R&D centre, used by our own consultants and security operations centre analysts. There is no client login, no licence and no subscription.

What you receive is the work it produces: assessments, registers, plans, reports and briefings, handed over by the consultant who owns your engagement.

Does Labs mean we get less time with a consultant?

It means the time you get is spent differently. Assembling documents, cross-referencing evidence and formatting deliverables used to take a large share of an engagement. Labs takes that on, so the consultant's time goes into scoping, interpretation, judgement and explaining the findings to you. The efficiency is passed on to you as quicker turnaround and sharper advice.

Every engagement still has a named consultant who scopes the work, reviews every output and answers for it.

Is our information used for other clients?

No. Each client's engagement data is held separately and handled under CyPro's ISO 27001 certified information security management system. Nothing you share is visible to, or reused for, any other client.

What does carry between engagements is method: the way a control is assessed or a finding is structured improves as we deliver more work, without any client's information crossing over.

What do we actually receive at the end?

The same kinds of deliverable you would expect from any consultancy engagement, in formats you can use directly: written reports, risk and control registers, remediation plans, board briefings and presentation decks.

The difference is in the consistency and depth. Every finding traces back to the evidence it came from, and every deliverable follows the same tested structure, so a report in month twelve reads the same as the report in month one.

Which CyPro services benefit from Labs?

Most of them, across both the consultancy and the security operations centre. The challenges above show where: compliance and maturity assessments, tenant hardening reviews and rapid risk assessments; vulnerability governance, attack surface reconnaissance, threat assessments and threat modelling; security questionnaire responses, supplier due diligence, contract review and counterparty checks; detection engineering, alert and incident handling, service level tracking, monthly reporting and incident reports; deliverable quality review, threat bulletins and client newsletters.

If a piece of work you have in mind is not listed, ask. A discovery call is the quickest way to find out how it would run.

See the challenges we are solving

Who is accountable for the work?

A named CyPro consultant, always. Labs supports the consultant and the analyst; it does not replace the person who signs the deliverable, presents the findings and takes your questions afterwards.

That is the reason Labs stays internal. It is a way of raising the standard of our own work, not a product we hand over and step back from.

Meet the team

3D rocket illustration for booking a discovery call with CyPro

Next step

See what Labs means for your engagement

Book a discovery call with a CyPro consultant. Tell us what you are trying to achieve and we will explain how the work would run and what you would receive.