Cyber security company · Bristol · UK wide

Cyber Security Audits, Accreditation and Monitoring

Fourarmed started with an insurance broker's frustration.

Castlemead had spent years arranging cyber cover for UK businesses and kept seeing the same story play out. A client would buy a policy, tick the boxes they believed mattered, then get hit anyway and lose far more time and money than they needed to. The security advice they had been given beforehand was usually too technical to act on, or too generic to be worth acting on.

So, we built the firm we wished had existed. Fourarmed is a cyber security company, Bristol based and working UK-wide, shaped by what goes wrong in real businesses. We price so you know the cost before you commit, and we report in language your board can act on in an afternoon.

Our office is in Southville, a mile south of Bristol city centre, and we work with organisations across the country.

Company
Fourarmed Cyber Ltd, trading as Fourarmed
Office
St Johns Road, Southville, Bristol BS3 1AL
Area served
United Kingdom, most engagements include a site visit
Method
Audit · Accredit · Monitor · Develop
Pricing
Fixed per engagement, agreed in writing before work starts
Origin
Founded out of Castlemead, an insurance broker and ADS Group member
01

Audit

A fixed-price cyber security audit of your systems, controls, software and people. We visit the site, look at what is actually running, and give you a prioritised action plan plus a board summary.

Cyber security audit

For most businesses, this is the sensible first step.

02

Accredit

Cyber Essentials and Cyber Essentials Plus certification, from gap analysis through remediation to the assessment itself. Increasingly, this is the price of entry for government work, defence supply chains and larger corporate tenders.

Cyber Essentials Plus

Including the April 2026 scheme changes.

03

Monitor

Ongoing network monitoring and phishing tests, plus help scoping and running penetration testing. An audit tells you where you stood in June. Monitoring tells you where you stand today.

24/7 monitoring

Monthly reports you can use at renewal.

04

Develop

Cyber security training that treats your staff as a control, because they are one. Interactive workshops, phishing simulations and scenario exercises, built around your business instead of a generic e-learning module.

Cyber security training

Results aggregated. We do not hand over lists of names.

Fixed price. In writing. Before we start.

We scope the work, give you a single figure, and that is what you pay. Cyber security has a reputation for open-ended bills and we would rather not add to it.

Why Fourarmed?

The difference an underwriter makes

Most cyber security firms start with an IT-focus. We came from insurance, which changes what we look at.

Underwriters spend their working lives on the wrong end of breaches. They see which controls held, which ones were technically present but practically useless, and which claims fell apart because a business could not provide evidence of what it said it was doing. This knowledge sits behind every audit we run.

A certification indicates a business met a defined standard on a particular day. What an insurer wants to know is whether your business would still be in operation in a fortnight.

These are separate tests, and the gap between them is where most organisations are exposed.

What that means in practice

  • We quote fixed prices. We scope the work, give you a single figure, and that is what you pay.
  • We write reports people read. Every audit comes with a short board-level summary in plain English alongside the technical detail for whoever runs your systems, and we talk it through with you instead of simply emailing it over.
  • We give advice you can act on. We tell you what to fix first, what can wait and why. Ninety undifferentiated findings is not a plan, and handing something like this over is really handing over the work.
  • There is no lock-in. You own your audit report and are free to act on it however you like, with us or without us.
  • We do not sell products. We are not resellers and we take no commission on tooling.

The picture, in numbers

Published sources only
46%

of small businesses identified a cyber breach or attack in the previous 12 months. For medium-sized businesses it is 65%.

Cyber Security Breaches Survey 2025/26
38%

were hit by phishing, the most common attack type reported by UK businesses by a wide margin.

Cyber Security Breaches Survey 2025/26
5%

of UK businesses hold Cyber Essentials certification, so it still works as a differentiator as well as a requirement.

Cyber Security Breaches Survey 2025/26
£197m

paid out on UK cyber claims in 2024, up 230% on the previous year. Ransomware and malware accounted for 51%.

Association of British Insurers

Who We Help

Serious about security, no security department

We work with organisations that take security seriously but do not have a security department, which describes a large share of UK businesses.

Small and medium businesses

A large share of our work. The government's 2025/26 Cyber Security Breaches Survey found 46% of small businesses and 65% of medium-sized ones had identified a breach or attack in the previous 12 months, while only 5% of UK businesses hold Cyber Essentials certification.

Insurance brokers and their clients

Our roots. We speak both languages, and we know what a broker needs their client to be able to show evidence of at renewal. Our guide to what cyber insurers require covers the details.

Professional services firms

Solicitors, accountants and consultancies come to us because they hold client data that is valuable to someone else, usually under a regulator's eye.

Aerospace, defence and advanced engineering

Where our sector knowledge is deepest, because Castlemead is a member of ADS Group, the UK trade body for aerospace, defence, security and space. If MOD contracts or a prime such as BAE, Leonardo or Rolls-Royce sits at the top of your supply chain, the cyber security requirements cascade down to you.

Aviation, engineering and manufacturing

These businesses face critical national infrastructure obligations due to operational technology running alongside IT, and their possession of intellectual property worth stealing.

Anyone answering security questionnaires

If your customers have started sending you security questionnaires, that is not going to stop. Cyber Essentials Plus usually answers the questions for you.

Working with Castlemead

Two halves of the same proposition

Fourarmed and Castlemead work as two halves of the same proposition. We assess and improve your security, while Castlemead arranges cover that reflects the improved position.

You can use either without the other, and plenty of clients do. However, handing an underwriter a current audit report from a firm that understands underwriting tends to make renewal conversations go better. There is more on the two businesses and how they fit together in about Fourarmed, and on the method itself in our approach.

Fourarmed
Assesses, certifies, trains and monitors
Castlemead
Arranges cover reflecting the improved position
Obligation
None. We will work with any broker you are happy with.
Why it helps
Our recommendations are written to satisfy underwriters as well as auditors

Common Questions

Six questions
Where should we start?
A cyber security audit is the place to start for most businesses. It establishes where you stand and produces a plan you can work through at your own pace.
How much does it cost?
Every engagement is quoted as a single fixed price, which must be agreed to in writing before any work begins. This ensures there is no hourly meter and no scope creep.
Do we need Cyber Essentials?
If you sell to the government, defence, healthcare or large corporations, you almost certainly do. Only 5% of UK businesses hold it, so it still works as a differentiator as well as a requirement.
We already have an IT provider. Does that matter?
Not at all, and it is the usual situation. We are independent of whoever runs your systems, which is most of the point of an external audit.
Do you work outside Bristol?
Yes, across the UK. Most of our work involves attending sites and we travel for it.
Will this help with our cyber insurance?
Yes. Our recommendations are written to satisfy underwriters as well as auditors.
Free initial conversation

Ready to Secure Your Business?

Most people who call us have had a prompt of some kind. This may be a client questionnaire they cannot answer confidently, an insurance renewal coming up, or a near miss. Some just want to know where they stand. Either way, we will tell you what we would look at and what it would cost, in writing, before you commit to anything.