Skip to content
FeatherON · Security · Agentic AI · Engineering

Security that runs itself. AI that ships safely.

FeatherON is an information security, agentic AI and software engineering consultancy. We secure regulated platforms, ship fleets of autonomous agents that investigate, reason and draft while humans commit, and build the software behind both - hands on, in your stack, from 15 years of doing it in production.

Years in information security
15
Customers on platforms secured
15M+
Accreditations delivered hands-on
25+
Annual savings delivered
£2M+

Advisory

What we do

Three practices that belong together, and the disciplines that hold them up. Every engagement is hands-on and engineering-led - built from what has actually shipped in regulated, production environments.

Information Security

Security strategy, architecture and operations for regulated platforms - board reporting, Zero Trust, identity and an autonomous SOC that clears L1 and L2 without a queue.

Agentic AI

Safe autonomous agents designed and shipped end to end - guardrails, human-in-the-loop boundaries, agent identity and adversarial testing, proven on fleets running live.

Software Development

The build, not just the advice - platforms, integrations and automation delivered inside your repositories, secure by construction and handed over with tests and runbooks.

GRC & Accreditations

25+ frameworks delivered hands-on from zero to operational - ISO 27001/42001, SOC 2, FedRAMP High, CMMC, DoD IL4, DORA, NIS2 and the EU AI Act - with zero friction to the business.

Cloud, Identity & Zero Trust

Zero Trust across AWS, Azure and GCP. Identity rebuilt on a single plane with SSO, MFA and just-in-time privileged access, and tooling consolidated on the way through.

Posture & Assurance

Measured improvement rather than a paper exercise - posture scores moved 82% in a quarter, evidence generated by the systems themselves, audits rehearsed before they happen.

Agentic AI & engineering

Software we designed, built and shipped

We do both halves of this: the agents and the engineering underneath them. Autonomous systems in production across security operations, vulnerability management, threat modelling, procurement, sales and the executive office - integrated across 40+ business and IT systems. Every agent holds to one standard: agents investigate, reason and draft; humans commit, approve and release.

Level 1 & 2 security operations

Autonomous SOC

Every alert and incident fully triaged, investigated and resolved - or escalated with the complete evidence chain attached. Six months live, zero false positives.

End-to-end vulnerability lifecycle

Autonomous Vulnerability Manager

Re-classifies severity against CVE, CWE, EPSS and exploitation intel, then sandbox-tests the fix before raising a proven non-breaking remediation PR.

STRIDE on demand

Automated Threat Modeller

Generates STRIDE threat models from architecture, code and cloud config - per-component threats, controls and mitigations, mapped to security requirements.

Phishing response

AI Security Mailbox

Investigates every reported phishing email end to end, reaches a verdict and removes confirmed threats in minutes - borderline cases escalate with an audit trail.

Procurement agent

Penny Pryce

Runs the renewal radar, flags tool overlap and low-usage licences, benchmarks pricing and drafts approval packs. Never commits spend.

Security response agent

Rex Reeves

Triages open cloud security issues worst-first, reasons about blast radius and root cause, and drafts the fixes and PRs. Never deploys.

PAYG lead-dispute agent

Larry Ledger

Automates the monthly PAYG lead-dispute cycle for Sales - extracts, contestation, crediting policy and sign-off packs for account managers.

Chief of staff agent

Callum Chaser

Runs the weekly executive leadership cycle end to end - pre-reads, chasing actions and tracking every decision to closure.

And the platforms underneath

AI routing platform

In-House LLM Gateway

Routing across frontier and self-hosted models with per-task policy plus cost and quality telemetry. Cut AI running costs by up to 80% and absorbed multi-hour provider outages.

Detection and response

Security Automation Pipeline

Continuous breached-credential detection with automated reset and session revocation, plus automated blocking that clears thousands of threats a day with no human in the path.

Identity and access

Unified Identity Platform

Identity rebuilt on one plane: SSO, mandatory MFA, automated joiner-mover-leaver provisioning and just-in-time privileged elevation across cloud and production estates.

Systems integration

Agent Integration Fabric

The connective layer letting agents read and write across 40+ business and IT systems, with credentials scoped per integration, session logging and evidence captured per action.

Track record

Where it was proven

Regulated banking to enterprise software - nine environments where our work had to hold at scale. Sectors and numbers, not name-dropping.

Regulated Banking & Fintech

BaFin-regulated consumer neobank

15M+
Customers
€150B
Assets under mgmt
18
Countries

Proven thereAutonomous SOC and vulnerability management with zero false positives; ISO 27001, SOC 2 and NIST CSF compliant; €1M+ annual savings.

Global Financial Markets

£3bn+ listed interdealer brokerage

£3bn+
Group revenue
6
Security team led
4
Zero Trust domains

Proven thereEnterprise-wide Zero Trust architecture across cloud, network, application and data, plus an AI/ML-enabled target operating model.

Manufacturing & Consumer Goods

£3bn+ NYSE-listed global manufacturer

£5M
Programme
8
Countries
20+
People led

Proven thereGroup security built from first hire: ISO 27001 and Cyber Essentials Plus delivered, M&A security across 8 countries, audited by KPMG, PwC and Gallagher.

Home Services Marketplace

High-growth UK home-services marketplace

150K+
Customers
82%
Posture score lift
5K+
Threats blocked daily

Proven thereSecurity posture raised 41.7 to 75.9 in one quarter; five named production AI agents shipped; £300K annual savings; identity rebuilt end to end.

AI & GovTech Scale-Up

Generative-AI platform for government

12+
Standards
70%+
More contract wins
100%
Critical vulns cut

Proven thereFirst security hire: AI governance programme (AI TRiSM, ISO 42001-aligned) plus ISO 27001/17/18, SOC 2, HIPAA, TX-RAMP, CSA STAR, FedRAMP, DoD IL2/IL4, FIPS 140-3, NIST 800-53 and NIST 800-171.

Elite Professional Services

International legal services firm

CISO
Appointed
3
Frameworks advised
2
Delivery streams

Proven thereSecurity strategy and consultancy function built from the ground up - internal delivery plus client-facing ISO 27001, NIST CSF and NCSC CAF assessments.

Government & Public Sector

Government-contract services group

8
Countries
4
Standards held
100%
Estate red-teamed

Proven thereGroup ISMS across eight countries certified to ISO 27001, Cyber Essentials Plus, SOX and PCI DSS; security architecture function established; red teaming and penetration testing led estate-wide.

Security & Risk Consultancy

Global cyber security consultancy

10+
Sectors advised
CxO
Advisory level
100%
Client-facing

Proven thereConsultancy and architecture across banking, legal, finance, critical infrastructure, retail and education - from ISO 27001 and Cyber Essentials certification to strategy, operating models and penetration testing programmes.

Enterprise Software

Global business & IT transformation software vendor

2
Data centres to Azure
CIS 20
Controls implemented
4
Customer regions

Proven thereISMS built and operated to ISO 27001 and Cyber Essentials Plus; two on-premises data centres migrated hands-on to Azure; group-wide CIS 20 alignment; secure coding, continuous penetration testing and red teaming led from within.

Toolkits

The whole programme, pre-built

The ISO 27001:2022 Complete Toolkit is live in the shop, and it is not a template pack. Every mandatory document written lean enough to adopt as it stands, then the part the template vendors leave out: a twelve-week roadmap, the questions auditors actually ask with model answers, a clause-by-clause evidence index, a map of what your existing tools already prove, and 19 diagrams including an A3 wall poster. 57 files, or 67 with the policies as separate documents. Buy once, own it outright.

ISO 27001:2022 Complete Toolkit

00 - Start Here · 7

README - How To Use This Toolkit
Implementation Roadmap (12 weeks, task by task)
+5 more

01 - Governance · 4

ISMS Governance Manual
Risk Management Procedure (with a worked example)
+2 more

02 - Policies · 6

Information Security Policy (the clause 5.2 policy)
Information Security Policy Set
+4 more

03 - Records · 12

Risk Register and Treatment Plan - 15 worked risks with owners (Excel)
Asset Inventory (Excel)
+10 more

04 - Audit Preparation · 5

Internal Audit Pack (with the full checklist)
Stage 1 Readiness Checklist (Excel)
+3 more

05 - Diagrams (PNG) · 4

19 print-quality PNG diagrams
ISMS on a Page - A3 poster (PDF)
+2 more

06 - Support · 1

Get Expert Support

Recognition

Speaking, awards & board work

Speaking

CyberEdBoard Talks
CISO UK
Fortress Manchester
SANS
(ISC)²
ISACA
Teiss
Cloud Security Alliance
Infosecurity Europe
UK Cyber Week
DTX
The Future of Cybersecurity

Awards & Fellowships

CSO30 Award (CSO UK), 2021
Fellow, British Computer Society (FBCS)
Fellow & Chartered, Chartered Institute of Information Security (FCIIS)

Board & Advisory

Approved Assessor, UK Cyber Security Council
Board Member, Cloud Security Alliance UK Chapter
Board Member, My Family Recovery Plan (MyFRP)
Mentor and contributing writer for information security publications

Work with FeatherON

Bring in a team that ships

Book a focused hour on the problem you are actually facing - agentic AI risk, a compliance wall, a build that has stalled, or a board that needs answers. You will leave with a plan, not a pitch.