CYBERSECURITY CONSULTING — CITY OF LONDON · City of London (EC1-EC4)

Cybersecurity Consulting — City of London (EC1-EC4)

The City of London is the UK's densest cluster of FCA-regulated firms: investment managers, brokers, banks, fintech, professional services, insurance. ICO + FCA operational resilience + PRA SS2/21 overlap creates a unique regulatory matrix. Gridisys delivers City-specific managed SOC, FCA-aligned posture, and ICO breach notification retainer to City firms.

FCA operational resilience aligned PRA SS2/21 aware ICO retainer + 72-hour clock MiFID II / DORA aware Solvency II / TC operational aware

EC1-EC4

the Square Mile — concentrated FCA-regulated firm base

FCA Ops Res.

FCA PS21/3 operational resilience — in-force compliance regime

24/7

Gridisys managed SOC for City of London firms — no contract

1,500

estimated local SME fintech / insurance / advisory firms in City cluster

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

Managed SOC for City firms

24/7 monitoring of M365 / Entra across deal teams, compliance function, compliance. Targets: dealing-rule email compromise, OAuth grant abuse on multi-vendor portfolio systems, after-hours admin sign-ins on trading platforms.

FCA operational resilience mapping

PS21/3 obligations: identify important business services, set impact tolerances, test scenarios, document remain-within-tolerance evidence. We map technical controls to FCA deliverables — and document in FCA audit-ready format.

ICO breach notification retainer + 72-hour clock sprint

FCA-regulated firms face per-second regulatory pressure for breach notification. Our retainer covers the 72-hour ICO clock sprint + parallel FCA notification (PS21/3) + customer comms (Art. 34). Fixed-price retainer + activation fee.

MiFID II / DORA preparedness

FCA-regulated firms providing investment services in scope of MiFID II / DORA (in force 2025): ICT risk management, incident reporting, digital operational resilience testing. We scaffold alignment evidence.

Cloud + third-party risk management

FCA SYSC 8.1 third-party outsourcing rules + EBA guidelines on outsourcing: materiality assessment, risk assessment, exit strategy, contract clauses. We document the TPRM pack for FCA inspection.

Senior Managers Regime + SM&CR cyber accountability

SM&CR makes individual senior managers accountable for cyber-resilience (operational resilience is a prescribed responsibility). We design SMF-friendly governance: monthly pack for the SMF24 / SMF3 (Operations) covering monitoring, incidents, training.

How we work

1

Scoping (Week 1)

Confirm FCA / PRA status, MiFID II / DORA scope, SM&CR structure, key outsourcing vendors, current M365 / Entra posture.

2

Deploy (Week 1-2)

Connect M365 / Entra to Gridisys SOC. Conditional access: MFA everywhere, dealing / compliance mailboxes restricted, portfolio system OAuth grants monitored.

3

FCA + ICO evidence (Week 2-3)

Document FCA operational resilience mapping. ICO breach response retainer in place. SMF-friendly monthly pack designed.

4

Operate (ongoing)

24/7 monitoring + monthly SMF reporting + ICO clock retainer active + DORA / MiFID II report preparation.

Sectors we protect

FCA-regulated investment managers Stock broking firms Specialist insurance brokers Mortgage / consumer credit firms Lloyd's market participants Wealth managers Specialist fintech (payments, EMIs) Professional services (legal / audit / actuarial) supporting FS
FREE CONSULTATION

Cybersecurity consulting built for City of London regulatory reality

Free 30-minute consultation for SMFs, COOs and IT leads at City firms. We assess FCA operational resilience evidence, ICO retainer alignment, and outsourcing posture.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.