# Soteria Cyber and Digital > Soteria is a specialist UK cyber security and digital consultancy. We work with Defence, Government, Critical National Infrastructure (CNI), and regulated private sector organisations — delivering cleared, expert consultancy across cyber security and digital delivery as one integrated team. Soteria was founded by Matt Lomax, a decade-experienced cyber security practitioner, with a clear mission: bridge the gap between deep technical security and real-world business needs. All consultants hold active UK security clearance. Soteria is proudly British and a signatory to the Armed Forces Covenant. **Contact:** contact@soteria.uk | +44 (0)7769 264 693 | Mon–Fri 9:00am–5:00pm **Enquiries:** https://soteria.uk/contact --- ## Services Soteria offers eight core service lines spanning cyber security and digital delivery, designed to be engaged individually or together as one integrated programme. ### Cyber Security Services - [Secure by Design](https://soteria.uk/services/secure-by-design): Embedding security throughout the full capability lifecycle — from concept and threat modelling through procurement, design, implementation, assurance, and disposal. Aligned to Cross-Government Secure by Design Framework, GovAssure, JSP 440, JSP 453, Def Stan 05-138, NCSC CAF, IEC 62443, ISO 27001, and Cyber Essentials. Deliverables include security strategy, secure architecture design, threat modelling, vendor/supply chain security, compliance support, and security testing coordination. - [CISO as a Service](https://soteria.uk/services/ciso-as-a-service): On-demand, virtual Chief Information Security Officer (CISO) leadership. Provides strategic security direction, board-level engagement, security governance, risk management, regulatory compliance oversight, incident escalation support, and stakeholder/supplier management. Engagement from one to three days per week, or full-time on-site if required. Suitable for organisations without a dedicated CISO, those between hires, or enterprises needing specialist augmentation. - [Risk & Compliance](https://soteria.uk/services/risk-compliance): Contextualised risk management and certification support across ISO 27001, Cyber Essentials, IEC 62443, and the NCSC Cyber Assessment Framework (CAF). Translates regulatory requirements into practical, defensible security controls. - [Security Training & Awareness](https://soteria.uk/services/security-training-education-awareness): Expert-led, scenario-based security training to strengthen organisational awareness and resilience. Helps teams identify threats, protect data, and embed a culture of security. - [AI Security](https://soteria.uk/services/ai-security): Specialist guidance for secure AI adoption, deployment, and governance. Covers AI risk assessment and threat modelling (data poisoning, adversarial attacks, prompt injection, model theft, privacy risks, algorithmic bias), AI governance aligned to EU AI Act and UK AI Safety Standards, secure AI architecture, LLM/prompt injection security, Shadow AI detection and management, and AI supply chain risk. Vendor-neutral. - [Security Architecture](https://soteria.uk/services/security-architecture): Expert guidance to design secure, scalable technology architectures from the ground up. Security treated as a foundational design principle, not a retrofit. ### Digital Consultancy Services - [Digital Delivery](https://soteria.uk/services/digital-delivery): Structured, end-to-end delivery of secure digital systems and IT capabilities. Covers requirements through deployment and lifecycle governance, ensuring projects are delivered efficiently, securely, and in line with assurance frameworks. - [Digital Transformation](https://soteria.uk/services/digital-transformation): Supporting secure modernisation across cloud, automation, and emerging technologies. Embeds secure-by-design principles throughout transformation journeys. --- ## Sectors Soteria works exclusively with high-assurance environments where security, resilience, and compliance are non-negotiable: - [Defence & Aerospace](https://soteria.uk/sectors/defence): UK Armed Forces and defence supply chain. Deep expertise in MoD frameworks including JSP 440, JSP 453, and Def Stan 05-138. All consultants hold active UK security clearance. - [Government Organisations](https://soteria.uk/sectors/government): Central and local government. Aligned to GovAssure, Cross-Government Secure by Design Framework, and NCSC guidance. Supports digital transformation under public sector security constraints. - [Critical National Infrastructure](https://soteria.uk/sectors/critical-national-infrastructure): Energy, water, transport, and telecoms operators. Specialist expertise in IEC 62443 (OT/ICS security) and the NCSC Cyber Assessment Framework (CAF). - [Private Sector](https://soteria.uk/sectors/private-sector): Regulated and security-conscious private sector organisations of all sizes. ISO 27001, Cyber Essentials, GDPR, NIS Regulations, and sector-specific compliance. --- ## About - [About Soteria](https://soteria.uk/about): Mission, values, team credentials, and founder background. Soteria's mission is to enable the organisations Britain depends on to operate and deliver securely. **Key credentials:** - 100% security-cleared personnel - 10+ years of hands-on experience - 100% system assurance rate - 100% client satisfaction - 40+ hours of training per consultant per year - Certifications held: CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, ISO/IEC 27005 Risk Manager, ISACA Advanced AI Security Management (AAISM), PRINCE2, City & Guilds Graduateship, NIST **Founder:** Matt Lomax (LinkedIn: https://www.linkedin.com/in/matt-lomax-a24a87a5/) --- ## Why Soteria - **Integrated cyber and digital:** Most consultancies offer one or the other. Soteria delivers both from a single team, eliminating handoff risk between security and delivery. - **Security built in:** Embeds security from concept to operation, reducing costly rework, delay, and late-stage remediation. - **Contextualised risk:** Technical detail translated into clear, mission-aligned insight for decision-makers. - **Framework-led assurance:** Deep expertise across UK MoD JSPs, ISO 27001, Cyber Essentials, IEC 62443, NCSC CAF, and sector-specific frameworks. - **Vendor-neutral:** No product sales or commercial affiliations — advice is grounded in client operational needs. - **Executive-level leadership:** Board-ready communication and CISO-grade strategic direction across cyber and digital. - **Security-cleared:** All consultants hold active UK security clearance. --- ## Optional - [Privacy Policy](https://soteria.uk/privacy) - [Sitemap](https://soteria.uk/sitemap.xml) - [Contact / Request a Consultation](https://soteria.uk/contact)