Jonny Pelter
Partner, CyPro
Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.
- CIPM
- CIPP/E
- CISSP
- CISM
- CRISC
- ISO27001
- Prince2
- MSc
- BSc
The platform behind every CyPro engagement
CyPro Labs is the in-house platform our consultants deliver client work through. You never log in to it. You see it in the consistency, depth and evidence behind everything you receive.
The short version
CyPro Labs is the platform CyPro's consultants use to deliver client work. It holds the methods we assess against, the structures our deliverables follow and the evidence trail behind every finding, so that each engagement starts from the same tested foundation rather than from a blank page.
It is not a product. There is no client login, no licence and nothing to buy. What you receive is the work: assessments, registers, plans, reports and briefings, scoped, reviewed and signed by the consultant who owns your engagement.
Why we built it
Two consultants assessing the same control can structure the finding differently. Evidence gathered in week one gets reassembled in the final week. A large share of any engagement goes into collating, cross-referencing and formatting rather than into the judgement you are paying for.
Labs exists to remove that variation. Every engagement follows the same method, evidence is captured as the work happens, and the consultant's time goes into interpretation, prioritisation and explaining what the findings mean for you.
What it enables
Most CyPro engagements run through Labs. Each area below lists the work it delivers, what goes in, what comes out and who reviews it before you see it.
Where you stand against a framework, how mature each capability really is, and what to fix first. Built from your own workshops, interviews and tenant configuration rather than a generic checklist.
Workshop transcripts become a control by control gap analysis against ISO 27001:2022 or another chosen framework, with a status, findings and recommendations for every control. A consultant reviews each section before it reaches you.
Branded presentation deck
Interview transcripts become a maturity assessment across every capability area: current state, observations and recommendations, scored and approved by the consultant who ran the interviews.
Branded presentation deck
A read only review of your Microsoft 365 and Entra tenant against CyPro's hardening controls, reporting what is in place, what is not and what to change. We recommend, you implement.
PDF report and dashboard
A short intake form is all it takes to start a rated risk assessment of a vendor, application or service, researched from its public security, privacy and breach record, with every source cited.
Rated report with citations
Who is likely to target you, how they would do it, and what an attacker can already see from the outside. Then the discipline to keep the exposure coming down week on week.
A client specific threat assessment built in reviewed stages: the scenarios that apply to you, the threat groups behind them, their techniques and real case studies, then an executive summary. A consultant approves each stage before the next begins.
Branded presentation deck
Your application architecture becomes a structured threat analysis mapped to MITRE ATT&CK, with attack paths, known weaknesses in the technologies you use and prioritised mitigations. Held for expert review, then versioned each time it is updated.
Versioned report, PDF on request
From your domains, addresses and company names we map what an attacker can see: subdomains, open services, leaked credentials, exposed storage, look alike domains and exposed secrets, each rated. Active scanning only ever runs with your permission.
Attack surface report
Your vulnerability data, whether from your endpoint protection or a scanner export, enriched and scored consistently, tracked week on week so fixed means fixed, with a formal risk acceptance process for what you choose not to remediate.
Dashboard, reports and exception register
The questions your customers ask you, the questions you should ask your suppliers, and the checks that belong around any contract or acquisition.
When a customer or buyer sends you a security questionnaire, every question is answered from your own curated library of policies, certifications and evidence, with a source reference against each answer. A consultant reviews before anything goes back.
Completed questionnaire, ready to return
A consistent question set and evidence trail for the suppliers you depend on, combined with the rapid risk assessment above for a rated view of each one.
Rated assessment per supplier
A contract is read for unreasonable, unusual or operationally unworkable cyber security clauses. Each flagged clause comes back with plain English commentary and a suggested alternative. Commentary, not legal advice.
Clause by clause review
Before a new relationship begins: registry data, filed accounts, sanctions and politically exposed person screening and public research, combined into one assessment with a reviewer's approval on record.
PDF assessment
For managed detection and response clients: rules that fit your telemetry, alerts that arrive as usable tickets, response times you can hold us to, and reporting that shows what was found and what was done.
Open source detection libraries translated into rules that actually fire on your log sources and field mappings, plus bespoke rules written from incidents, so coverage grows faster than writing each rule by hand.
Importable rule bundles and coverage analysis
Alerts from your security tooling reach the SOC as tickets an analyst can act on, with the affected asset and account resolved consistently, and incident status kept in step between your tenant and ours.
Service desk tickets
Every ticket is watched against its response and investigation targets in near real time. The on shift analyst is assigned before a first response deadline can be missed, escalations go out if it slips, and a daily summary lands each morning.
Escalations and daily summary
Service level performance, incident volumes and resolution breakdowns, incident categories and detection coverage mapped to MITRE ATT&CK from your own rule export, reviewed by your service manager before it is issued.
Branded presentation deck
A closed incident becomes a client ready report drafted from the ticket record, with a timeline of what happened and what was done, reviewed and edited by the analyst before it leaves the SOC.
Branded Word report with timeline
The written work around an engagement: bids, quality control, and keeping your people informed about the threats that matter to them.
An inbound tender or request for proposal is broken into its questions, each answered as a grounded first draft from CyPro's knowledge base, then edited, regenerated where needed and accepted by a reviewer before export onto the buyer's own template.
Completed response on the buyer's template
Every deliverable is checked for quality, house style and coverage of what the contract promised before a partner signs it off. The review reports problems for the author to answer; it never edits the document itself.
Findings answered before sign off
Cyber news is continuously gathered, de-duplicated and triaged so only the stories relevant to you are researched and written up, with two stages of review before a bulletin is sent.
Client bulletin emails
One master briefing each issue, then rewritten for each client around their own tooling, vendors and priorities. Your edits come back in plain prose and are applied individually before publication.
Newsletter per client
Most engagements combine several of these, and new areas are added as the work demands them. Tell us what you are trying to achieve and a consultant will explain how the work would run and what you would receive.
Labs changes how the work is produced, not who is responsible for it. Three stages, and a named person at every one.
Every engagement starts with a conversation. A CyPro consultant agrees what you need, what evidence you can give us and what the deliverable has to do for you, and stays your point of contact throughout.
The work runs through Labs to a fixed method. Evidence is captured as the work happens rather than assembled at the end, every finding keeps its trail, and the deliverable follows the same tested structure each time.
Your consultant reviews every output, adds the judgement only a person can, and signs it. You receive the finished deliverable in a format you can use, and the same person presents it and takes your questions.
Principles
Five commitments that hold on every engagement, whichever service you are buying and whoever is delivering it.
Each client's engagement data is held separately and handled under CyPro's ISO 27001 certified information security management system. Nothing is visible to, or reused for, any other client.
Labs supports the consultant. It does not replace the named person who reviews the deliverable, presents it and answers for it afterwards.
The same tested method on every engagement, whoever is delivering it. The report you receive in month twelve is built the same way as the report in month one.
The way a control is assessed or a finding is structured improves as we deliver more work. Method carries between engagements; client information never does.
Labs is designed, operated and improved by CyPro's own UK based team. There is no third party between you and the people doing the work.
CyPro Ltd is ISO 27001 certified, Cyber Essentials Plus certified and a CREST accredited provider. The same management system that governs our client work governs Labs.
About CyProThe people behind Labs
Labs is shaped by the people who use it on client engagements every week. These are the CyPro team members who lead it.
Partner, CyPro
Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.
Partner, CyPro
Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.
Senior Security Automations Engineer, CyPro
Dan leads the design and day to day running of CyPro Labs. He builds the methods and delivery structures that every CyPro engagement runs through, and works across both client engagements and CyPro's own operations to keep the platform secure, resilient and improving.
Cyber Security Manager, CyPro
Joining CyPro from Capgemini, Leonie brings a strong blend of technical insight and consulting expertise to her role as a Cyber Security Manager. Her work spans governance and compliance (including ISO 27001), advanced security operations such as privileged user monitoring and security tooling optimisation, and the security review of new delivery methods before they reach client work.
The team holds
Good questions
No. CyPro Labs is an internal platform used by CyPro's own consultants. There is no client login, no licence and no subscription.
What you receive is the work it produces: assessments, registers, plans, reports and briefings, handed over by the consultant who owns your engagement.
It means the time you get is spent differently. Assembling documents, cross-referencing evidence and formatting deliverables used to take a large share of an engagement. Labs takes that on, so the consultant's time goes into scoping, interpretation, judgement and explaining the findings to you.
Every engagement still has a named consultant who scopes the work, reviews every output and answers for it.
No. Each client's engagement data is held separately and handled under CyPro's ISO 27001 certified information security management system. Nothing you share is visible to, or reused for, any other client.
What does carry between engagements is method: the way a control is assessed or a finding is structured improves as we deliver more work, without any client's information crossing over.
The same kinds of deliverable you would expect from any consultancy engagement, in formats you can use directly: written reports, risk and control registers, remediation plans, board briefings and presentation decks.
The difference is in the consistency and depth. Every finding traces back to the evidence it came from, and every deliverable follows the same tested structure, so a report in month twelve reads the same as the report in month one.
Most of them. The catalogue above lists them by area: compliance gap analysis, maturity assessments, tenant hardening reviews and rapid risk assessments; threat assessments, threat modelling, attack surface reconnaissance and vulnerability governance; security questionnaire responses, supplier due diligence, contract review and counterparty checks; detection engineering, alert handling, service level tracking, monthly service reports and incident reports; tender responses, deliverable quality review, threat bulletins and client newsletters.
If a piece of work you have in mind is not listed, ask. A discovery call is the quickest way to find out how it would run.
A named CyPro consultant, always. Labs supports the consultant; it does not replace the person who signs the deliverable, presents the findings and takes your questions afterwards.
That is the reason Labs stays internal. It is a way of raising the standard of our own work, not a product we hand over and step back from.
Next step
Book a discovery call with a CyPro consultant. Tell us what you are trying to achieve and we will explain how the work would run and what you would receive.