EN / ES

Our Story

From 2009 to today — a journey shaped by attackers, driven by innovation, and dedicated to defending organisations across the UK and beyond.

A journey built on real-world cyber defence

Cyber Defence began life in 2009 as Hedgehog Security — a specialist penetration testing and cyber assurance firm delivering high-impact testing for organisations across Europe. From the beginning, our focus was on meaningful results, clear reporting, and an uncompromising standard of technical quality.

As the threat landscape evolved, so did we. We expanded from offensive security into threat intelligence, incident response, and eventually a full modern Security Operations capability. In 2024, Hedgehog Security formally rebranded as Cyber Defence, reflecting our mission to protect organisations through continuous monitoring, defensive engineering, and proactive threat disruption.

Today, Cyber Defence integrates intelligence, SOC365 monitoring, penetration testing, security engineering, and incident response into a unified, intelligence-led cyber defence service — trusted by organisations across critical industries and regulated sectors.

Why we exist

The cyber landscape has changed radically since 2009. Attackers have become faster, quieter, and more adaptive. Traditional defences — signature antivirus, perimeter firewalls, and outsourced alert-handling — cannot keep up.

Cyber Defence exists to solve this problem. Our mission is simple:

Detect threats that others miss. Defend systems that others overlook. Disrupt attackers that others fear.

We believe security should be engineered, measurable, and intelligence-led. Our Detect–Defend–Disrupt model unifies monitoring, investigation, engineering, and offensive insight into one cohesive defensive capability. It is the culmination of everything we have learned over 15 years of cyber operations.

A message from our founder

Cyber Defence is the outcome of many years working on the front line of security: leading SOCs, responding to crises, testing organisations at scale, and learning from real attackers. When I founded Hedgehog Security in 2009, my goal was to create a security company that told the truth — providing clarity, honesty, and practical guidance in a world full of noise.

Over the years, it became clear that organisations did not just need testing — they needed continuous protection, grounded in intelligence and engineered for resilience. This insight shaped the evolution of our SOC365 platform, our Disrupt Incident Response team, and the integration of threat intelligence into everything we do.

Cyber Defence is built on people who care deeply about their craft: analysts, responders, penetration testers, engineers, researchers, and developers. We exist to protect our clients, to disrupt attackers, and to raise the standard of cyber defence for organisations that deserve better than the status quo.

— Peter Bassill, Founder

Principles that guide us

Over fifteen years of defending organisations, we have developed a set of principles that shape how we work and what we deliver:

Truth over comfort — We give honest assessments, even when the truth is uncomfortable.
Action over theory — We focus on practical, implementable security improvements.
Engineering over paperwork — Real resilience comes from technical change, not audits alone.
Detection over assumptions — If we cannot see it, we cannot defend it. Logging and monitoring are non-negotiable.
Threat-led over checklist-led — Our work is shaped by how attackers behave, not arbitrary compliance frameworks.
Continuous improvement over point-in-time fixes — Security must evolve as fast as the threats that target it.

Our timeline

Over fifteen years of continuous evolution, shaped by real adversaries and real operational experience:

  1. 2009

    Hedgehog Security founded

    A penetration testing and offensive security consultancy built on OSSTMM and PTES principles.

  2. 2012

    Achieved full CREST membership

    Formal recognition of our technical excellence in penetration testing and security assessment.

  3. 2014

    Incident Response practice established

    The beginnings of what would become the Disrupt team — responding to breaches and major incidents.

  4. 2016

    Threat Intelligence programme launched

    Development of internal TI capabilities including phishing analysis, dark web indexing, and adversary infrastructure tracking.

  5. 2018

    EmilyAI created

    Our internal SOC analyst assistant, enhancing triage efficiency, detection insight, and operational workflow.

  6. 2019

    SOC365 blueprint created

    The beginning of our unified MDR platform combining telemetry normalisation, correlation models, and threat intelligence.

  7. 2022

    SOC365 platform launched

    Operational, cloud, endpoint, identity, and threat intelligence monitoring delivered as a unified service.

  8. 2024

    Rebrand to Cyber Defence

    Reflecting our evolution into a modern, intelligence-led cyber defence company supporting critical organisations.

Today

Cyber Defence today

We are a modern cyber defence company combining technology, intelligence, and human expertise:

24/7 SOC365 operations

Continuous detection, investigation, and threat disruption powered by engineered detections and high-fidelity telemetry.

Dedicated Disrupt Incident Response unit

Qualified responders, forensics analysts, and threat specialists ready to assist when incidents occur.

Advanced Threat Intelligence

Internal intelligence holdings enriched by phishing analysis, dark web monitoring, infrastructure tracking, and deception sensors.

Offensive Security excellence

Penetration testers and red team specialists performing scenario-driven testing across IT, cloud, OT, and IoT environments.

Security Engineering

Identity, cloud, network, OT/IoT, and logging architecture improvements based on real-world attack paths.

Cross-industry expertise

Supporting organisations across finance, legal, healthcare, maritime, energy, logistics, and government.

Work with a team shaped by real adversaries

Whether you need monitoring, testing, engineering, intelligence, or incident response, Cyber Defence brings 15+ years of practical, operational security experience to your organisation.