Skip to content
Cyber Security Firms

Editorial policy

What the checks are, what fails them, and how a correction gets made.

Last updated

Resources

Every resource answers one question and finishes it. Where a topic is genuinely contested, the page says so and gives the trade-off rather than picking a side and hiding the argument. Every statistic carries a link to its primary source. If a number has no primary source, it is cut.

Anything a reader could act on that depends on order, direction or a number is a coded diagram with the facts set by hand, never a generated image. Illustrations are for scenes and objects. Every page carries a reviewer byline and the date it was last checked.

Firm rankings: the checks

  1. What they actually do.Services are taken from the firm’s own published scope and cross-checked against what it is known for. A firm that lists every service a website template offers, with nobody who does each one full time, fails.
  2. Attestations that can be checked. SOC 2, ISO 27001, CREST, CMMC registered provider status and similar, recorded only where the firm publishes them or the certifying body lists them.
  3. Track record. Years in operation, named sector experience, and independent recognition where it exists. A firm we cannot find any independent record of fails.
  4. The response test. We contact every firm the way a prospective client would, with a normal enquiry, and note who replies, how fast, and whether the answer addresses the question.
  5. Clarity on scope and price. Firms that say what an engagement includes and where pricing starts outrank firms that only offer a call.
  6. Re-check. Every list carries the date it was last checked. Firms change hands, teams leave, standards slip. Nobody keeps a place by default.

Rank one is the best firm overall. Ranks two to four are the best firm for one buyer each, in a fixed order: small business, managed detection and response, and compliance. The rest of the shortlist cleared the same checks. The rank is an order, not a score: a low rank on a list is not a warning.

Breach reports: sourcing and status

A report is built from primary sources in this order of preference: the organization’s own statement or notification letter, a regulator filing or breach portal entry, a verified breach database, then reporting by named journalists. Every figure on the fact grid traces to a source listed at the foot of the report. Where a figure is not disclosed, the grid says so rather than estimating.

Status is the field that matters most. Confirmed means the organization, a regulator or a court record has acknowledged the incident, or a verified breach database such as Have I Been Pwned has confirmed that leaked data is genuine. Claimed means the only evidence is a listing by a criminal group, and the report says so in its first line, because such listings are sometimes exaggerated, duplicated or wrong. Disputed means the organization has denied it. A report is updated when its status changes, and the update moves its date.

Corrections

Substantive corrections change the page and move its last-checked date. We do not quietly rewrite a page and pretend it always said that. A firm that disagrees with its rank can send us facts; if something we published is wrong we correct it the same week. If it is accurate, the rank stands until the next re-check. Send a correction.

Commercial relationships

The one commercial statement on the site is on the advertising disclosure page and repeated under every ranked list.