Login to profile

About us

We were established in the UK in 2006 making this our founding region.

We have grown and developed significantly in the UK over the years, adding members and expanding the range of professional certifications and services we are able to offer.

In the UK, we work closely with regulatory bodies such as the National Cyber Security Centre, part of GCHQ, the UK’s Government Communications Headquarters. The IT Health Check Service, or CHECK, was developed to enhance the availability and quality of the penetration testing services that are provided to Government.

We work with the NCSC to provide a set of penetration testing examinations that underpin the CHECK scheme in the UK. All our examinations used to assess individuals as part of CHECK are reviewed and approved by GCHQ, NCSC.

Over time, interest in the success of our UK activities has grown in other regions that are keen to build on our experience in building capability, capacity, consistency and community in the cyber security industry. We have been able to support the setting up of chapters around the world and to work with governments, regulators, buyers and suppliers to develop and support internationally recognised schemes.

Our experience in the UK and, increasingly, in other global regions is helping to enhance cyber resilience around the world and to open up markets for our member companies and opportunities for CREST qualified individuals.

We offer a full range of disciplines in the UK market:

• Penetration Testing
• Incident Response
• Threat Intelligence
• Security Operations Centres

UK Council Members

The serving UK Council Members are listed below in alphabetical order. Hold your cursor over each for more information.

Dave Allan

CYSIAM Ltd

[Portfolio: Cyber Leaders’ Forum]

Dave joined the British Army as a Royal Signals Operator and served for 10 years, with the latter half of his career focussed on counter terrorism support to HMG overseas. He then joined the Foreign and Commonwealth office in a variety of IT/Security related roles and finished his civil service career as Head of International Cyber Capacity Building. In 2019, Dave co-founded CYSIAM as the CTO and in 2021, moved into the Managing Director role.

CYSIAM works in strategic partnership with public and private sector clients who understand, and are serious about mitigating, the risks that cyber incidents pose to their critical systems and data.

Rob Dartnall

(Chair) Security Alliance Ltd

Rob is the CEO and Director of Intelligence for Security Alliance Ltd, a Cyber Threat Intelligence company. From a military intelligence background, Rob transitioned his intelligence tradecraft into the cyber domain where he is an advocate of ‘Intelligence Preparation of the Cyber Environment’.

Rob’s primary work has been designing intelligence-led resiliency programs, developing intelligence capability, creating intelligence sharing frameworks and initiatives and providing intelligence led consulting engagements. Rob holds the CREST Certified Threat Intelligence Manager qualification, is a CREST TI Assessor and sits of the CTIPs Sub- Committee.

Rob was formally elected as Chair of what was then the GB Executive on 3 March 2021.

Contact: [email protected]

Jed Kafetz

Claranet

[Portfolio: SOC]

Jed spearheads the cyber practice at Claranet, with roots in penetration testing, red teaming, and offensive security management. Having worked at several CREST member companies, he has developed and implemented pentesting and red teaming programs for numerous global organisations. Jed is dedicated to enhancing cybersecurity strategies in collaboration with CREST and its members. He is deeply interested in the integration of generative AI and machine learning into existing processes, aiming to provide customers with a more enriched and insightful service. He is currently leading in-house projects that incorporate generative AI into the scoping process.

Anthony Long

LRQA

Anthony is the VP of Advisory Consulting at LRQA and a senior leader within its Cyber Division. He drives global strategy, business planning, and execution across advisory services, overseeing P&L, service development, talent growth, and operational efficiency. A key force behind LRQA’s expansion in Financial Services and Government sectors, he has extensive experience in talent development and fostering a culture of excellence, innovation, and continuous improvement

 

With 20+ years of experience spanning threat intelligence, fraud, resilience, and cyber strategy, Anthony is a former senior advisor at the Bank of England, where he helped architect and implement the pioneering CBEST framework. He is a trusted global advisor to governments, regulators, and commercial sectors, helping organisations build and sustain robust cyber and operational resilience.

 

Anthony is known for translating complex risk challenges into scalable, business-aligned solutions—driving innovation, cross-functional growth, and long-term client success.

Ian Lovering

DXC Technology (Assessors’ Representative)

Ian has 20 years’ experience in the IT industry latterly as technical lead for DXC managing CHECK, STAR and GBEST penetration testing and long-term vulnerability scanning implementations. He has also been responsible for secure architecture reviews and secure code reviews covering multiple industries including finance, public sector, telecoms, and oil and gas. Ian has been a CREST Assessor since 2015 and is currently running the our exam development group creating our next generation exams.

Boglarka Ronto

Resillion

[Portfolio: Penetration Testing]

Boglarka is Director of Operations at Commissum (Eurofins Cyber Security UK), with a background in penetration testing and UNIX systems administration. In her role she relays a lifelong passion for the security industry, supporting a variety of businesses, both large and small on their journey to a more mature security posture. Boglarka works with young people to help them find a fulfilling career in one of the many areas of cyber security, focusing on challenges associated with niche requirements such as testing mainframes.

Martin Walsham

AMR Cyber Security

Martin is an industry recognised cyber security expert with the business gravitas and presence to lead and deliver at large programme level.

Martin has excellent stakeholder relationships with industry and regulators and has been directly involved in shaping the maturity of the cyber security eco system both on a National and International basis through memberships of working groups, research, the development of new schemes and standards, and through his previous work on the former Executive Board for CREST.

Martin has excellent skills in risk management, security architecture, policy development and security leadership. He is highly proficient in accreditation and in developing information security management systems.

Martin has extensive experience of developing trusted assurance models for hardware and software systems and leading the evaluation of hardware and software systems under trusted assurance scheme models.

Martin has a pragmatic, mature consultative engagement approach. He is committed to providing quality business focused service. His levels of focus and commitment are evident in his unblemished track record for delivery

William Wright

Closed Door Security

William Wright, CEO of Closed Door Security, is Scotland’s first Chartered Cyber Security Professional (ChCSP) and a recognised figure in the cybersecurity industry. With over 20 years of experience focused on security testing across the UK, USA, and Middle East, he brings a broad understanding of the challenges organisations face. He founded Closed Door Security in Stornoway, Scotland, and has grown it into an international company with offices in the UK, USA, and UAE. Despite his leadership role, William remains actively involved in penetration testing and holds several industry certifications. He focuses on building practical, effective security strategies to help organisations protect what matters most.