IT and security for NewSpace.

A young space company moves fast: an ESA contract to meet, a UK Space Agency grant to report against, a Series A round to close, and a small in house team running real time operations on expensive hardware. Each carries its own security expectation, and they all land on the same few people.

We run, secure, build, and prove the technology behind the work, so an ISO 27001 clause or a grant condition has an answer ready rather than slowing a launch. UK-based, certified to ISO 27001 by a UKAS-accredited body, an appointed Cyber Essentials certification body, twenty minutes from Harwell.

A satellite subassembly on a workbench in a clean room, with an engineer in protective dress
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher
Space Tech / 01 · The context

Where the security pressure comes from.

In space tech the security pressure is not an abstract policy. It arrives as a clause in an ESA contract, a cyber hygiene condition on a grant, an investor diligence checklist in a Series A, and export control sitting over a stack full of US technology.

For a company of ten to a hundred people with one or two holding IT and security together, that is a lot. We build the posture and the evidence without pulling your engineers off the mission.

ESA supplier security ISO 27001 Cyber Essentials and Plus UKSA and Innovate UK grant terms ITAR and EAR aware Investor diligence
ESASupplier security attestationESA contracts expect ISO 27001 and supplier side security evidence, with Cyber Essentials Plus often the practical stepping stone. We prepare you for each step.
UKSAGrant cyber conditionsUK Space Agency and Innovate UK grant terms increasingly carry cyber hygiene and reporting conditions. We put the controls and reporting behind them.
A+Investor diligenceSeries A and later rounds surface cyber and IT governance as a diligence item. We get the evidence in order before the data room opens.
Space Tech / 02 · On your doorstep

Reading to Harwell is twenty minutes.

Our base is in Reading, twenty minutes from the Harwell campus and the cluster around the UK Space Agency, the European Space Agency's UK presence, and RAL Space, so when a ground station rig needs a hands on look, or a launch window is close, we can be on site rather than in a ticket queue. The other clusters we support securely and remotely, the way modern IT already works.

01HarwellTwenty minutes from our Reading base. On site when it counts.
02GlasgowLaunch and small satellite manufacturing, the Scottish cluster.
03BristolPropulsion and ground segment, the south west cluster.
04SurreySatellite heritage and the spinouts that came from it.
Space Tech / 03 · The pressures

What we hear from space companies.

01Stretch further

One or two people holding it all

A small in house team runs real time operations on costly hardware and keeps the office working, with nothing left for security. Things get missed through load, not carelessness. We take that weight off them.

02Protect the IP

Payload designs and mission data

Payload designs, mission data, control links, and export controlled components are what a capable adversary, or a partner with more access than they need, could reach. The work has to be defended, segmented, recoverable, and evidenced as such.

Space Tech / 04 · How we help

Managed IT, certification, software, and evidence.

01Run it

Managed IT and cloud for heavy compute

UK-based support and UK-hosted infrastructure for the systems we manage, from a team that knows simulation, image processing, and mission operations. We run the cloud the heavy compute leans on, with Managed Detection and Response (MDR) included as standard.

02Secure it

Cyber Essentials and certification

We are an appointed Cyber Essentials certification body, so we know what a grant or contract naming the standard is asking for; we prepare you for it, and formal assessment is scoped separately. Email and endpoint security harden the systems an attacker reaches for first.

03Build it

Software, secure by design

Custom software, integration, and applied AI for the tooling around your mission systems, with UK-hosted deployment and an audit trail behind it, built by the team that also runs and secures it.

04Prove it

ISO 27001 and the evidence funders want

We are certified to ISO 27001 by a UKAS-accredited certification body, and we take growing companies through the same standard: the policies, controls, and audit trail an ESA assessor or investor expects, produced as you go rather than before a review.

We name the sector, not the client. In space and defence especially, the detail that would identify a client, or help an attacker, stays behind closed doors.
Space Tech / 05 · Export control and residency

British owned and UK based.

US technology components are everywhere in a modern space stack, so ITAR, EAR, and UK export controls are normal compliance rather than an edge case. We build and run the access controls that keep restricted material away from unauthorised foreign access. The legal interpretation stays with your export control advisers; the technology that enforces it is ours.

01StaffUK-based support and escalation.
02DataUK-hosted cloud and backups for the systems we manage.
03AccessNeed to know controls around export controlled material.
04ITAR and EARWe build the controls; export control law stays with your advisers.
FAQ

Common questions

Our ESA contract asks for ISO 27001 and we have nothing in place. Where do we start?

With a clear read of what the contract requires, which is often ISO 27001 with Cyber Essentials Plus as a practical first step. We are certified to ISO 27001 by a UKAS-accredited certification body and an appointed Cyber Essentials certification body, so we can take you from a standing start to ready for assessment on the contract's timeline. Preparation and formal assessment are distinct pieces of work.

A UK Space Agency or Innovate UK grant has cyber conditions attached. Can you handle that?

Yes. Grant terms in this sector increasingly carry cyber hygiene and reporting conditions, and what they need depends on the wording, which we will read with you. Usually Cyber Essentials or Cyber Essentials Plus, with the controls and reporting in place behind it, satisfies the condition, and we keep producing the evidence the funder expects.

We are a small team raising a round. How do we get ready for the cyber side of diligence?

Series A and later rounds routinely surface cyber and IT governance as a diligence item, and the time to get it in order is before the data room opens. We assess where you stand, close the obvious gaps, and assemble the policies, controls, and evidence an investor will ask for, so the question is answered with a document. It is the same groundwork that supports ISO 27001.

We are right by Harwell. Where is your team based?

Our base is in Reading, around twenty minutes from the Harwell campus, so when a ground station rig or a test setup needs a hands on look, or a deadline is close and you want someone on site, that is straightforward. For space companies elsewhere in the UK we work securely and remotely, with on-site visits where they help.

We handle ITAR or export controlled technology. Can you support us?

We build and run the IT environment designed to keep restricted material away from unauthorised foreign access, with a UK-based team, UK-hosted infrastructure for the systems we manage, and need to know access controls. ITAR, EAR, and UK export control compliance is a legal and procedural matter, so we work alongside your export control advisers rather than replacing them.

Talk to us about your programme.

Send us the clause in your contract, the conditions on your grant, or your investors' diligence list. We will tell you where you stand and what it takes to close the gap.

Reading, Berkshire, twenty minutes from Harwell  /  ISO 27001 certified via a UKAS-accredited body  /  reply within one working day