
Managed Cyber Security, CREST Penetration Testing and 24/7 SOC-Led Detection
Claranet Cyber Security is the security practice of Claranet, a London-headquartered managed services provider founded in 1996 by Charles Nasser that now employs roughly 2,200 people across the UK, Europe and Brazil. The security arm was assembled in part through acquisitions of the UK testing firm Sec-1 in 2017 and the training-focused NotSoSecure in 2018. It targets mid-market and sub-enterprise organisations that need offensive testing, monitoring and compliance work handled by a single provider.
Engagements follow a four-phase defence-in-depth model — Prepare, Test, Protect, Improve — that begins by mapping critical threats and budget priorities, then continuously assesses the attack surface before layering preventive and detective controls. Managed detection and response runs from three UK security operations centres monitoring around 58TB of data a month, built on SentinelOne, Microsoft Defender and Microsoft Sentinel, with SAP-specific monitoring available. Testing spans CREST penetration tests, continuous security testing, external attack surface monitoring, and red and purple team exercises.
Scale on both sides of the discipline is the main differentiator: more than 200 engineers covering offensive, defensive and compliance work, and roughly 10,000 days of penetration testing delivered annually by in-house specialists. Accreditations include CREST, Cyber Essentials Plus, NCSC certification and ISO 27001, 27017 and 22301. Alongside the technical services sit governance offerings — ISO 27001 implementation, PCI DSS, GDPR consultancy and ransomware readiness assessments — plus hands-on hacking courses inherited from the NotSoSecure business.



