Bristol based, working UK wide

About Fourarmed Cyber

Fourarmed Cyber Ltd, trading as Fourarmed, is a cyber security company based in Bristol and working with businesses across the UK.

We audit, certify, train and monitor, and we do it from an unusual starting point, because we came out of the insurance industry and not the IT industry.

Legal name
Fourarmed Cyber Ltd
Trading as
Fourarmed
Office
St Johns Road, Southville, Bristol BS3 1AL
Founded out of
Castlemead, an insurance broker and ADS Group member
Method
Audit · Accredit · Monitor · Develop
Team size
Small, on purpose

Our Story

The reason was frustration

Fourarmed was founded out of Castlemead, an insurance broker and a member of ADS Group, the UK trade body for aerospace, defence, security and space. The reason was frustration.

Castlemead had arranged cyber cover for UK businesses for years, which meant seeing the aftermath of a lot of incidents. A pattern kept repeating. A client would believe they were reasonably well protected, then something would happen, and it would become clear the protection was thinner than anyone had realised. This was not through negligence, but because the advice they had been given was either too technical to act on or too generic to be worth acting on.

The gap between "we have security" and "our security would hold" was where clients kept getting hurt.

You cannot fix that from the brokering side. Brokers can advise on cover, but they cannot audit a network or train a workforce. As a result, Castlemead built the security business that had been missing.

That is why Fourarmed does things in a particular way. Our recommendations are written to satisfy an underwriter as well as an auditor, because we know which controls hold up when tested by events. Our reports are written for boards, because the person who approves the budget is not usually someone who understands the technology. Our prices are also fixed, because open-ended security bills are one of the main reasons businesses put this off.

01

Audit

A fixed-price cyber security audit of your systems, controls, software and people. We visit the site, look at what is actually running, and give you a prioritised action plan plus a board summary.

02

Accredit

Cyber Essentials and Cyber Essentials Plus certification, from gap analysis through remediation to the assessment itself. Increasingly, this is the price of entry for government work, defence supply chains and larger corporate tenders.

03

Monitor

Ongoing network monitoring and phishing tests, plus help scoping and running penetration testing. An audit tells you where you stood in June. Monitoring tells you where you stand today.

04

Develop

Cyber security training that treats your staff as a control, because they are one. Interactive workshops, phishing simulations and scenario exercises, built around your business instead of a generic e-learning module.

What We Focus On

A sequence, not a menu

We focus on four pillars, which are set out in full on our services page, and meant to be used in sequence, not picked from a menu.

Alongside these four pillars, we work on the areas where our clients keep encountering risk: supply chain cyber security, IoT and connected device security, and incident response planning.

Our sector strength follows Castlemead's. The full picture of how the insurance background shapes our method is in our approach.

The sectors we work in

  • Aerospace, defence and advanced engineering. Where our sector knowledge is deepest, because Castlemead is a member of ADS Group, the UK trade body for aerospace, defence, security and space. If MOD contracts or a prime such as BAE, Leonardo or Rolls-Royce sits at the top of your supply chain, the cyber security requirements cascade down to you.
  • Engineering and manufacturing. Critical national infrastructure obligations, operational technology running alongside IT, and intellectual property worth stealing.
  • Aviation. Regulated, interconnected, and highly dependent on third-party platforms, with the supply chain scrutiny that follows from all three.
  • Insurance brokers and their clients. Our roots. We speak both languages, and we know what a broker needs their client to be able to show evidence of at renewal.
  • Professional services. Solicitors, accountants and consultancies come to us because they hold client data that is valuable to someone else, usually under a regulator’s eye.
  • Small and medium businesses. A large share of our work: organisations that take security seriously but do not have a security department, on fixed prices they can plan around.

Our Team

Small on purpose

We are a small but perfectly formed team. Here is just a snapshot of our senior leadership team, but we could not do it without our support team working hard in the background to deliver the right results.

Richard Ingleby

Richard Ingleby

Managing Director

Dan Carter

Dan Carter

Tech Lead

Niki Featherstone

Niki Featherstone

Marketing

Why Choose Fourarmed

Six things that follow from where we came from
  • We come from insurance, which means we have seen what happens after the breach, not only before it, and our advice reflects that.
  • Our prices are fixed and quoted in writing. You know the cost before we start and it does not move.
  • Our reports are written for the board, with a plain-English summary and the technical details attached. If a director cannot read it, it will not get acted on.
  • Our advice arrives prioritised. This includes what to fix first, what can wait, and why.
  • We are Bristol-based and work UK-wide. Our office is in Southville and we have clients across the country. For most engagements, someone comes to you.
  • There is no lock-in. You own your audit report and are free to act on it however you like, with us or without us.
Free initial conversation

Talk to Us

Call, email, or send us a message. Every conversation starts free and without obligation, and we will give you an honest view of what you need, including where that is less than you expected.