SoVael Cybersecurity CYBER

Governing question: What is the threat?

NOW
Phase 1
Assessment
Free external vulnerability scan + Cyber Essentials gap analysis. Convert diagnostics into qualified managed-security leads.
Timeline: Q3 2026 · £15K build
ACTIVE
Phase 2
Managed Security
AI monitoring, weekly scans, threat alerts and board reporting. Core recurring revenue package for trades and SMBs.
Timeline: Q4 2026 · £1,497/mo per client
PHASE 3
Phase 3
Incident Response
Retainer-based response, containment playbooks, forensics and recovery coordination for clients that cannot afford downtime.
Timeline: Q2 2027 · Custom retainer
PHASE 4
Phase 4
Autonomous Defence
Agent-driven patching, isolation and recovery with human-in-the-loop escalation. Self-healing security for unattended endpoints.
Timeline: 2028+ · Self-funded
5
Completed
3
In Progress
1
Ready
Loading live board data...

Next Actions — live from kanban

Loading live tasks...
£14BUK Cyber Market
£3.4BSME Annual Losses
£1,600Avg Breach Cost
3%Hold Cyber Essentials
£180KY1 Revenue
£600KY2 Revenue
£1.5MY3 Revenue
12moBreakeven

Next Steps — What's Happening Now

Research completed — market, threat cost, regulations and competitor pricing
5 research documents with real UK stats from GOV.UK, NCSC/IASME and industry analysts.
DONE
Build Cyber command centre page
Dark theme, cyan accent, live kanban stats, research cards and next-steps checklist.
IN PROGRESS
Deploy to cyber.sovael.ai
Copy cyber_centre.html into sovael-ai container, add nginx rewrite, add Traefik route and verify HTTPS.
NEXT
Set up Firecrawl monitors for threats and pricing
Auto-track NCSC advisories, ICO fines, competitor price moves and CVEs relevant to trades clients.
PENDING
Create Cyber Essentials onboarding playbook
Step-by-step guide to take a client from scan to certification-ready in under 30 days.
PENDING
Sales pilot with 5 trades businesses
Run free scans, close first £1,497/mo managed-security retainers and collect case studies.
BLOCKED

Completed Research — click to expand

UK Cybersecurity Market Size & SME Gap
The UK cybersecurity market is valued at roughly £14–17 billion and growing ~10–12% CAGR. UK SMEs lose an estimated £3.4 billion annually to inadequate cyber defences, while adoption of basic controls remains low.

Market TAM

Industry forecasts put the UK cybersecurity market at ~£14 billion in 2025 and £17–18 billion by 2026 (Mordor Intelligence, Beagle Security / Micro Pro). Globally the market is accelerating well into the hundreds of billions as AI-driven attacks expand the attack surface.

SME Reality

612,000 UK businesses identified at least one cyber breach or attack in the last 12 months (GOV.UK 2025). Despite this, only 3% hold Cyber Essentials certification and only 1% hold Cyber Essentials Plus. Only 27% of businesses have board-level cyber responsibility.

Insurance Uptake

Small-business cyber-insurance adoption jumped from 49% to 62% year-on-year, and 45% of all businesses now have some form of cyber cover. Insurers are increasingly asking for evidence of controls before quoting.

Sources: GOV.UK Cyber Security Breaches Survey 2025; CyberSecStats UK Cybersecurity Statistics 2026; Mordor Intelligence UK Cybersecurity Market Report 2026; NCSC Annual Review 2025
UK Threat Cost & Incident Profile
The average cost of the most disruptive breach for a UK business is £1,600 (including £0 responses); excluding £0 responses it is £3,550. 43% of businesses reported a breach or attack in the last year, rising to 74% among large businesses.

Breach Economics

GOV.UK estimates the mean cost per most-disruptive breach at £1,600 for all businesses and £3,240 for charities. When excluding organisations that reported zero cost, the figure rises to £3,550 for businesses and £8,690 for charities. Mean cost among breaches with a material outcome is £8,260.

Attack Prevalence

Phishing remains the most common breach vector: 35% of micro businesses and 42% of small businesses reported phishing attacks. Overall, 43% of businesses and 30% of charities reported any cyber breach or attack. Ransomware cyber-crime prevalence doubled from under 0.5% to 1% of all businesses (~19,000 businesses) between 2024 and 2025.

Incident Response Maturity

Incident response plans are rare in SMBs. 50% of finance/insurance firms have a plan, but only 27% of businesses overall have board-level cyber accountability. Small businesses improved hygiene in 2025, yet formal response procedures lag.

Source: GOV.UK Cyber Security Breaches Survey 2025
Regulatory Landscape — Cyber Essentials, GDPR & ICO
Cyber Essentials is the UK government-backed baseline certification, with entry-level pricing from £320+VAT. Despite its accessibility, only 3% of UK businesses are certified. ICO enforcement is increasingly focused on security failures and breach notification.

Cyber Essentials

Administered by NCSC and delivered through IASME-accredited bodies. Certification starts at £320+VAT for micro-organisations and scales to ~£600+VAT for larger firms. The technical fail rate is only ~1.1%, yet national uptake sits at just 3% (21% among large businesses). 95% of certified organisations say they would recertify.

Data Protection & ICO

UK GDPR and the Data Protection Act 2018 require appropriate technical and organisational security measures. URM analysis shows two-thirds of ICO monetary penalties in H1 2025 were for UK GDPR security breaches, reflecting a clear enforcement shift away from marketing-consent fines toward actual security failures.

Emerging Rules

NIS2 is reshaping EU/UK cyber obligations. UK suppliers to larger regulated customers, and businesses handling personal data, face rising expectations for documented controls, supply-chain risk reviews and 72-hour breach reporting.

Sources: NCSC Annual Review 2025; CyberLab / IASME pricing guidance; URM Consulting ICO Enforcement Analysis 2025; GOV.UK Cyber Security Breaches Survey 2025
Competitive & Pricing Benchmarks
The UK SME cyber market is split between compliance platforms (CyberSmart), endpoint/MDR vendors (Sophos, Microsoft, Kaspersky), MSPs and specialist consultancies. Managed security typically ranges from £20–120 per user per month, while EDR starts around £8–15 per endpoint.

Key Competitors

CyberSmart positions itself as the leading SME compliance and certification platform, bundling Cyber Essentials tooling, active protection and insurance. Sophos, Microsoft Defender and Kaspersky compete on EDR/XDR and managed detection. Traditional MSPs package M365 security, backups and email filtering into per-user contracts.

Pricing Benchmarks

Published 2025/26 UK price points: Cyber Essentials certification £320–600+VAT by size; managed cybersecurity £20–120/user/month depending on tier; managed EDR £8–15/endpoint/month; full SOC/MDR for a medium business £4,000–12,000/month; incident response £80–120/hour.

SoVael Positioning

Our published prices (£497 one-off scan, £1,497/month Cyber Essentials tier) sit above commodity EDR but below full SOC retainer, aligning with trades businesses that need hands-on help, not just software. AI triage and WhatsApp-led reporting differentiate from MSP helpdesk models.

Sources: CyberSmart.co.uk, Sophos, PC Support Group, Precursor Security, Netnavi, Forge Secure, ISMS.online
Trades & Local Business Opportunity
Trades businesses have limited IT staff, high mobile and cloud usage, customer PII, and growing supply-chain pressure to demonstrate cyber hygiene. This creates a clear niche for a low-friction, AI-assisted managed-security service.

Target Profile

Plumbers, electricians, builders and property services typically operate from phones and vans, share passwords informally, and rely on cloud accounting, scheduling and payment apps. These behaviours raise phishing and account-takeover risk but the sector rarely employs dedicated IT.

Demand Drivers

Insurers are requiring Cyber Essentials or MFA for cyber cover. Larger contractors and housing associations increasingly ask suppliers for security questionnaires. The GOV.UK survey shows cyber-insurance uptake rising fastest among small businesses (49% to 62%).

SoVael Offer

A £497 external scan lowers the entry barrier, the £1,497/month tier delivers continuous monitoring plus incident response readiness, and custom enterprise retainers serve multi-van firms. The AI operator interface removes the need for clients to interpret alerts.

Sources: GOV.UK Cyber Security Breaches Survey 2025; SoVael Cybersecurity landing-page pricing; internal customer research

In Progress

Cyber command centre deployment
Build the dark cyan research page and route cyber.sovael.ai to the sovael-ai container.
External vulnerability scan pipeline
Connect scanner, generate risk-ranked PDF reports and 24-hour turnaround workflow.
Cyber Essentials client playbook
Document gap analysis to certification-ready workflow for trades clients.

Ready — Requires Human Decision

Approve Cyber Essentials go-to-market pricing and pilot target list
Confirm £497 scan / £1,497 Essentials tiers and select 5 pilot trades businesses.
Loading document
⬇ Download this document