Bridewell
We protect Critical National Infrastructure (CNI) and organisations who want the highest standard of cyber security
Bridewell
To protect your organisation against cyber attacks, you need security experts that understand your business challenges.
Whether this requires achieving 24/7 security operations, securing the Cloud and Operational Technology or meeting regulatory and compliance standards, Bridewell’s highly trusted and accredited services can support any outcome.
A Complete, Cutting-Edge Menu of Security Services
Bridewell’s services are grouped into four main areas, although the options for deployment and customisation are endless and unique to each client. Whether you’re looking to design a cyber security infrastructure from scratch, or want to test your risk, optimise or rethink your current arrangements, the sections below will help you understand the benefits of each area in detail, and its possibilities for your business.
Our Services:
Cyber Security
Managed Services
Penetration Testing
Data Privacy.

Key Specialities
Security Architecture
Security architecture is the design of information systems that have suitable security controls in place to mitigate a given level of risk while supporting business functionality and objectives. Our consultants are experienced in the use of security architecture approaches including SABSA and TOGAF. Our architects are qualified to provide expert guidance under the NCSC Certified Professional Scheme.
Penetration Testing
Penetration Testing enables organisations to identify and address vulnerabilities in their information systems before they are exploited and result in a breach.
We are a specialist, independent provider of penetration testing services, and are a Cyber Essentials Plus certifying organisation.
Services include:
- Web application testing (OWASP)
- Network and infrastructure testing.
- Cloud-based testing, including AWS and Azure
- Compliance testing, including for PSN and PCI DSS
- Vulnerability scanning and monitoring
- Code review
- Social engineering and Red Teaming.
Compliance & Testing
Bridewell are experts at supporting organisations in achieving compliance and certification against key standards including ISO/IEC27001, NIST, SOC2 and the Payment Card Industry Data Security Standard (PCI DSS).
We use principles-based guidance such as the NCSC Cloud Security Principles to assess systems and services and provide reports which can be used to demonstrate how the organisation meets those principles in their own context.
We engage with business and technical stakeholders at all levels to evaluate the governance processes, technical, physical and personnel level security controls. We provide pragmatic support and guidance to build information security management systems that are compliant with ISO/IEC 27001 and can be certified by the chosen certification body.