Information Security & Privacy Consultancy
Expert support, built around your organisation.
Why it matters
Most organisations know they need better security. Few know where to start.
The pressure to demonstrate security and privacy compliance has never been greater — from regulators, clients, insurers, and supply chains. But most consultancy either produces paperwork that doesn’t reflect operational reality, or recommends products rather than solving the underlying problem.
Principle Defence was founded to do something different. We provide risk-based, justifiable guidance that fits your organisation — not a generic framework applied without thought. Our team has backgrounds in the British Army, Big 4 consultancies, boutique firms, and in-house security roles. We’ve worked across central and local government, legal, logistics, oil and gas, media, financial services, software development, and telecoms.
When security and privacy are done properly, they decrease costs, enable opportunity, and build trust. That’s what we help you achieve.
What Good Looks Like
- Risk-based, not checkbox-driven
- Proportionate to your size and sector
- Grounded in operational reality
- Aligned to your business objectives
- Independently verified credentials
- Delivered by practitioners, not account managers
- Ongoing support, not one-and-done reports
What we do
Our Consultancy Services
ISO 27001 & Security Frameworks
- ISO 27001:2022 gap analysis & readiness reviews
- ISMS design and implementation
- Internal audit support
- Governance, Risk & Compliance (GRC)
- IT audit and supplier security
- Security engineering support
Privacy & GDPR Compliance
- GDPR compliance reviews & gap analysis
- Data Protection Impact Assessments (DPIAs)
- Privacy by Design & Privacy by Default
- Records of Processing Activities (RoPA)
- Privacy engineering & audit
- Subprocessor and third-party reviews
Cyber Essentials, IASME & Risk
- Cyber Essentials & CE Plus certification
- IASME Cyber Assurance (Level 1 & 2)
- Cyber risk assessments
- Threat intelligence
- Open Source Intelligence (OSINT)
- Incident response planning
Virtual CISO & Virtual DPO
- Virtual Chief Information Security Officer (vCISO)
- Virtual Data Protection Officer (vDPO)
- Security strategy development
- Privacy strategy & competitive advantage
- Board-level reporting and advisory
- Helping win new business through security
How we work
Flexible engagement, on your terms.
01
Discovery
We start by understanding your organisation — its size, sector, risk appetite, existing controls, and compliance obligations. No assumptions. No generic frameworks applied blindly.
02
Recommendation
We produce a clear, prioritised view of what needs to happen, why, and in what order — with honest guidance on effort, cost, and realistic timescales.
03
Delivery
We get to work alongside your team, taking as much or as little ownership as you need. We don’t hand over a report and disappear.
Client Feedback
We recently worked with Principle Defence on our ISO 27001 audit, and the experience was outstanding from start to finish. Jim and the team demonstrated deep knowledge of the standard, guiding us through each stage with clarity and professionalism. Their practical approach made the audit feel like a genuine opportunity for improvement rather than just a compliance exercise.
Our credentials
We hold the certifications we help you achieve.
Sector experience
We've worked across your industry.
Our team has delivered engagements across central and local government, new space, legal, logistics, oil and gas, media, financial services, software development, telecoms, critical national infrastructure, and more.
- Legal
- Technology
- Financial Services
- Education
- Critical National Infrastructure
- Healthcare
- Farming & Agriculture
- Charity
- Start-Ups & Scale-Ups