Turn this list into pipeline.
Threat Intelligence Companies in London: 71 Active Firms (2026)
Threat intelligence companies in London collect, analyse and operationalise cyber risk signals for organisations across the capital.
Security, risk and technology buying centres dominate this market: chief information security teams need external signals for detection and response, risk functions want reporting that can be taken to boards, and public-sector buyers often require intelligence-led monitoring around sensitive operations. Engagements tend to sit between specialist advisory work and recurring managed-service or platform subscriptions, with buyers expecting analysts to turn raw threat signals into prioritised actions. The London fit is therefore less about generic cyber tooling and more about suppliers that can combine collection, enrichment, workflow and reporting for business, government and regulated-sector customers.
Read more
London has 71 actively trading threat intelligence companies in this cohort. The revenue profile is not only early-stage: 17 companies report turnover above £5M, while 11 have been incorporated since 2022, giving the market both established operators and a recent formation tail. Reported employment totals 1,362 people, which points to a specialist labour footprint rather than a mass-employment software segment. For researchers, that makes the list most useful as a view of commercially active cyber-risk suppliers clustered around the capital, rather than a proxy for the whole cyber security labour market.
Government and regulated-sector demand shapes the operating context, even where the supplier itself is not licensed in the way a financial institution or utility would be. Buyers tend to test how intelligence is collected, how sensitive information is handled, and whether reporting can support audit, incident escalation and procurement scrutiny. Market structure is also partly services-led: threat feeds and monitoring tools still need analysts who can explain relevance, false positives and response priority. That keeps many London providers close to security operations, risk management and incident-response budgets rather than pure software procurement.
The London cohort appears to be split between specialist providers serving mature security teams and younger firms still proving repeatable commercial demand. Buyers tend to favour suppliers that can show how intelligence changes response decisions, not only how many signals they ingest. That may keep pressure on firms with broad monitoring claims but limited operational workflows. Consolidation remains plausible where managed security providers want intelligence capability in-house, while independent specialists may retain room where they serve regulated or government-facing customers with higher confidentiality and reporting expectations.
71
Active firms
2026
17
Above £5M
Revenue threshold
11
New since 2022
Recent incorporations
Key facts
About 23% of the trading cohort reports turnover above £5M (17 of 71 firms) — the rest sits below that revenue band.
15% of the cohort was incorporated since 2022 (11 firms), so a sizeable share is in its first few filing cycles.
Threat intelligence work in London tends to combine cyber-risk signal collection, analyst review and operational reporting for enterprise security teams.
Buyers usually assess these suppliers on source coverage, alert quality, analyst depth and how easily findings can be turned into security actions.
London’s financial-services and professional-services base gives the segment a local buyer pool with relatively high exposure to fraud, account takeover and supplier-risk monitoring.
Top London threat intelligence companies
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsProvides cyber threat intelligence software and services, including a SaaS platform that collects and analyses data on threat actors, vulnerabilities, breaches and underground marketplaces to support…
Serves B2B security teams and cyber risk leaders at organisations with exposure to advanced cyber threats, including teams managing threat intelligence, threat hunting, attack surface exposure and…
Financial Health
HealthyHealthy · -8% CAGR over 2y
Location
ESENTIRE UK LIMITED
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsProvides managed detection and response cybersecurity services including 24/7 security operations centre monitoring, threat hunting, incident response and digital forensics. Develops an AI‑driven…
Serves mid-market businesses and public sector organisations needing managed cybersecurity, including finance, insurance, legal, healthcare, manufacturing, retail, construction, private equity, food…
Financial Health
HealthyHealthy · 0% CAGR over 1y
Location
FIVECAST UK LIMITED
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops open‑source intelligence software that collects and analyses data from the surface, deep, and dark web. Provides AI‑driven platforms used by government, law enforcement, defence, and…
Serves government intelligence, border security, defence and law enforcement agencies, plus corporate security, financial crime and insurance teams in large organisations.
Financial Health
StrongStrong · Hiring · 50% CAGR over 2y
Location
Develops and provides cybersecurity software and managed services, including managed detection and response (MDR), SIEM, vulnerability management, attack surface monitoring, cloud security tools, and…
Serves security and IT teams at mid-market and enterprise organisations globally, including finance, logistics, professional services and other businesses with cloud, hybrid and digital environments.
Location
Babel Street
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops AI-powered risk intelligence software that ingests and analyses global multilingual data to identify threats, resolve identities, detect relationships, and support supply chain risk…
Serves national defense and law enforcement agencies, global enterprises and FinTech firms, targeting analysts, security, compliance and risk teams managing identity, threat, vendor and supply-chain…
Financial Health
StrongStrong · Hiring · 11% CAGR over 4y
Location
ELEMENDAR LTD
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsDevelops AI-powered cybersecurity threat intelligence software that analyses threat reports, identifies threat actors, maps cyber threats to organisational risks, and supports automated risk…
Serves security teams and cyber threat intelligence analysts in businesses and public-sector organisations, including healthcare providers, government bodies, and retail/e-commerce companies.
Financial Health
DistressedDistressed · -40% CAGR over 1y
Location
FS-ISAC UK, LTD.
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsProvides a member-based platform for financial institutions to share cyber threat intelligence, collaborate on security issues, conduct incident response exercises, and access research, events, and…
Serves global financial services institutions, including banks, credit unions, insurers, payments firms, investment and securities firms, exchanges, critical private-sector providers, and public…
Financial Health
HealthyHealthy · Hiring · 9% CAGR over 4y
Location
Bluevoyant
Trajectory
2y · 2023–NowFinancial sub-scores
Computed from 2 filingsProvides managed cybersecurity services including managed detection and response, third‑party risk management, and digital risk protection. Monitors networks, vendors, and online assets for threats,…
Sells to B2B cybersecurity, IT, risk and compliance teams at mid-market and enterprise organisations managing networks, third-party vendors and digital brand exposure, including users of Microsoft,…
Financial Health
HealthyHealthy · Hiring · 20% CAGR over 1y
Location
Develops and provides cybersecurity software and managed security services, including threat detection and response (MDR), SIEM, vulnerability management, attack surface and exposure management,…
Serves security and IT teams at global businesses, including finance, banking, logistics, infrastructure and services organizations, requiring enterprise cybersecurity operations support.
Location
Tadaweb UK Limited
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops software for open‑source intelligence (OSINT) and publicly available information (PAI) analysis, providing an operating system that aggregates and analyses small data from online sources to…
Financial Health
StableStable · Hiring · 16% CAGR over 4y
Location
TRM Labs UK Ltd
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops blockchain intelligence software used by financial institutions, crypto businesses and law enforcement to monitor cryptocurrency transactions, screen wallets, detect fraud and sanctions…
Serves government agencies, law enforcement, national security teams, regulators, tax authorities, financial institutions, fintechs and crypto businesses involved with digital assets.
Financial Health
StrongStrong
Location
Cyber Defence Alliance Limited
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsProvides cyber threat intelligence services for member financial institutions, including analysis and sharing of information on cyber threats. Works with banks, law enforcement, telecommunications…
Serves member financial institutions, especially banks, alongside their clients and communities, cyber security agencies, law enforcement, intelligence and security agencies, regulators, trade…
Financial Health
StrongStrong · Growing · 7% CAGR over 1y
Location
OBRELA SECURITY INDUSTRIES LIMITED
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsProvides managed detection and response cybersecurity services, cyber risk and compliance management, and digital forensics and incident response. Operates the Swordfish platform to monitor threats,…
Serves B2B organisations with complex digital operations, including manufacturing, shipping, banking and finance, energy and utilities, healthcare, telecommunications, oil and gas, and retail…
Financial Health
HealthyHealthy · Hiring · 18% CAGR over 2y
Location
Trajectory
4y · 2023–NowFinancial sub-scores
Computed from 4 filingsProvides identity threat protection software that uses recaptured breach and malware data from the dark web to detect exposed credentials, session cookies and personal data, helping organisations…
Sells to businesses and enterprises with employee, consumer, and vendor identity exposure risks, including security, fraud, and IT teams. Also serves financial services organisations and cybercrime…
Financial Health
StrongStrong · Hiring · 20% CAGR over 3y
Location
Claritas Insight Services Ltd
Trajectory
3y · 2022–NowFinancial sub-scores
Computed from 3 filingsProvides cyber security and intelligence services including open‑source intelligence analysis, digital footprint monitoring, virtual CISO support, and incident response. Distributes digital forensics…
Serves UK Government, NATO/public-sector buyers and private-sector organisations, including investigators and businesses managing staff, supplier and online security risks.
Financial Health
HealthyHealthy · 0% CAGR over 2y
Location
Truesec
Trajectory
4y · 2022–NowFinancial sub-scores
Computed from 4 filingsProvides cybersecurity services including managed detection and response, incident response, digital forensics, threat exposure management, and security consulting. Advises on cloud, identity and…
Serves public sector and government bodies, small and medium businesses, and enterprises across industries, including organizations running mission-critical operations, complex IT environments, and…
Financial Health
StrongStrong · Hiring · 23% CAGR over 3y
Location
COUNTERCRAFT LTD
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops cybersecurity software that uses deception technology to create decoy environments within networks, generating threat intelligence, detecting attackers, and monitoring lateral movement and…
Serves enterprise CISOs and security teams, public infrastructure operators, governments and national security organisations, with focus on energy, financial services, healthcare, manufacturing,…
Financial Health
StableStable · Hiring · 26% CAGR over 4y
Location
Integrity360
Provides cyber security services including managed detection and response, threat monitoring, incident response, penetration testing, vulnerability management, and security operations. Also offers…
Serves organisations in the public sector and regulated industries including banking, fintech, healthcare, education, utilities, manufacturing, professional services and media across Europe.
Financial Health
Insufficient historyInsufficient history
Location
Orpheus Cyber Limited
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsProvides cyber risk assessment and intelligence services, including external attack surface monitoring, third‑party risk management, vulnerability management, security testing, and regulatory…
Serves B2B and financial-sector buyers, including CISOs, cyber leaders, IT and infrastructure teams, DPOs, procurement and risk leaders, MSSPs, investment managers, and cyber insurers and brokers.
Financial Health
WeakWeak · -6% CAGR over 2y
Location
Provides cyber security and digital risk services including penetration testing, incident response, digital forensics, threat intelligence, and social engineering assessments. Also offers compliance…
Sells to businesses, UK government and public sector bodies, international government organisations, NGOs, online platforms, and defence-sector suppliers needing cyber security, compliance, digital…
Location
ANOMALI LIMITED
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops cybersecurity software platforms that aggregate security data and threat intelligence for security operations teams. Provides tools for threat detection, investigation and response,…
Sells to enterprise security operations and cyber threat intelligence teams, including SOC analysts, incident responders and threat hunters in organisations managing complex cybersecurity programmes.
Financial Health
DistressedDistressed · -31% CAGR over 2y
Location
Pen-Link Technologies Uk Ltd.
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops digital intelligence and investigation software that aggregates and analyses communications, open‑source, and other data. Provides tools for data analytics, link analysis, reporting, and…
Serves public-sector security and investigation teams, including law enforcement, national security, government, defense and public safety agencies, plus financial services and enterprise…
Financial Health
StableStable · Hiring · 155% CAGR over 2y
Location
Trajectory
3y · 2020–NowFinancial sub-scores
Computed from 3 filingsDevelops cybersecurity software that monitors and analyses organisational IT activity to detect and investigate threats. Provides an AI-driven security operations platform with automated alert…
Serves B2B security operations teams at organisations with legacy SIEM or MDR setups, especially lean or resource-constrained SOCs across industries.
Financial Health
StrongStrong · Growing · 3% CAGR over 2y
Location
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops network detection and response (NDR) software and appliances that monitor and analyse network traffic to detect cyber threats. Provides sensors, analytics, intrusion detection, packet…
Serves enterprise and public-sector security teams, including SOCs in energy, federal government, financial services, healthcare, transport, state/local government and education.
Financial Health
HealthyHealthy · Hiring · 10% CAGR over 2y
Location
Chainalysis
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops blockchain analytics software and data services used to trace cryptocurrency transactions, assess wallet and exchange risk, monitor transactions for compliance, and support investigations by…
Serves government agencies, law enforcement, regulators, tax authorities, crypto exchanges, financial institutions, insurance firms, cybersecurity companies and web3 businesses operating in digital…
Financial Health
WeakWeak · -10% CAGR over 2y
Location
Trajectory
3y · 2024–NowFinancial sub-scores
Computed from 3 filingsProvides managed detection and response cybersecurity services, including 24/7 security monitoring, threat detection, investigation, and incident response. Develops a security operations platform…
Serves B2B security teams and SOC leaders at organizations of any size across industries, including those operating cloud, email, endpoint, identity, network and SaaS environments.
Financial Health
HealthyHealthy · Hiring · 11% CAGR over 2y
Location
Credentious Ltd
Trajectory
5y · 2020–NowFinancial sub-scores
Computed from 5 filingsProvides cyber and human threat intelligence and investigative services for organisations and individuals. Focuses on cybercrime, intellectual property theft and reputational or financial threats,…
Serves senior executives, CISOs, legal teams, law firms, police and cyber-attack victims at organisations and high-net-worth individuals concerned with intellectual property, financial and…
Financial Health
DistressedDistressed · -16% CAGR over 4y
Location
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops network visibility and security software that analyses network traffic to detect threats, support incident investigation, and monitor performance. Provides network detection and response,…
Serves enterprise IT security, SOC and network operations teams in education, defence and intelligence, financial services, healthcare, retail, and public sector organisations.
Financial Health
StableStable · 2% CAGR over 2y
Location
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops cybersecurity software and services for managing cyber risk. Provides attack surface management, vulnerability scanning, digital risk protection, penetration testing, and threat intelligence…
Sells to B2B security, IT and risk teams at organisations needing cyber risk management, attack surface visibility, application security testing, threat intelligence and PCI compliance support.
Financial Health
StableStable · Hiring · 6% CAGR over 4y
Location
Trajectory
4y · 2023–NowFinancial sub-scores
Computed from 4 filingsDevelops cybersecurity software for security operations, providing a platform that combines SIEM, network detection and response (NDR), automation and case management to detect cyber threats, analyse…
Serves MSSPs and in-house SOC/security teams in organisations with data residency needs, especially education, public administration, financial services, critical infrastructure, healthcare, retail,…
Financial Health
WeakWeak · -26% CAGR over 3y
Location
Develops cybersecurity software and services including extended detection and response (XDR), endpoint protection, and threat monitoring tools. Provides managed detection and response, incident…
Serves enterprise security teams, IT leaders and incident-response buyers across sectors, including organisations with on-prem or air-gapped environments, plus resale, managed service and technology…
Location
Whiteblueocean Ltd.
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsProvides digital security services focused on monitoring the open web and dark web for exposed personal and business data. Offers tools and reports that help detect compromised credentials, manage…
Serves both businesses and individual consumers concerned with digital identity, fraud and exposed personal data, including organisations managing cyber risks for their own customers.
Financial Health
HealthyHealthy · 0% CAGR over 1y
Location
Deltaflare Limited
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops cybersecurity software for operational technology environments. Its Phoenix platform provides monitoring, threat detection and compliance management for critical infrastructure operators in…
Serves operators of essential services and critical national infrastructure, especially asset owners in energy, water, electricity and transport, plus system integrators, OEM partners, government…
Financial Health
StrongStrong
Location
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsDevelops cybersecurity analytics software for maritime fleets and other operational assets. Provides monitoring of shipboard IT, IoT and OT systems, asset inventory, threat detection, cyber risk…
Serves maritime fleet operators and critical national infrastructure asset operators managing remote IT, IoT and OT systems, with buyers responsible for cybersecurity, cyber risk and compliance.
Financial Health
HealthyHealthy · Hiring · 44% CAGR over 1y
Location
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsProvides cybersecurity consulting and services including incident response, threat hunting, managed detection and response (MDR), cyber readiness assessments, red and purple team testing, threat…
Serves global enterprises and CISOs, including organisations in crypto, retail, financial services, healthcare, law, logistics and transportation, industrial systems, telecoms and technology.
Financial Health
WeakWeak · -13% CAGR over 2y
Location
CYPFER LIMITED
Trajectory
2y · 2024–NowFinancial sub-scores
Computed from 2 filingsProvides cybersecurity incident response and ransomware recovery services. Conducts digital forensics, breach and cloud investigations, dark web monitoring, and cyber risk assessments, and offers…
Serves businesses, critical infrastructure operators and organisations with legal/eDiscovery needs worldwide, targeting security, IT, risk and legal teams responding to cyber incidents or managing…
Financial Health
StableStable · Hiring · 122% CAGR over 1y
Location
Integrity360
Provides cyber security services including managed detection and response, threat monitoring, vulnerability management, incident response, penetration testing, and governance, risk and compliance…
Serves organisations across Europe, including public sector bodies and businesses in banking, financial services, fintech, healthcare, education, utilities, manufacturing, professional services and…
Financial Health
Insufficient historyInsufficient history
Location
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops cyber risk management software that analyses organisations’ internet‑facing assets and supply chains to identify vulnerabilities and exposures. Provides data and analytics tools used by…
Serves B2B organisations of any size and industry, including cyber insurance brokers, underwriters, financial services firms, public entities, and teams managing internal, supplier, client, or…
Financial Health
HealthyHealthy · Hiring · 28% CAGR over 4y
Location
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops AI‑driven cybersecurity software that monitors network, cloud and identity activity to detect and respond to cyberattacks. Provides network detection and response (NDR) platforms, threat…
Sells to enterprise security, SecOps and SOC teams, including organisations in finance, healthcare, higher education, public sector and critical infrastructure that manage network, cloud and identity…
Financial Health
StrongStrong · Hiring · 10% CAGR over 4y
Location
Trajectory
4y · 2022–NowFinancial sub-scores
Computed from 4 filingsProvides cloud‑native cybersecurity deception software that deploys and manages honeypots and decoy data across IT environments. The platform monitors interactions with these traps to detect…
Serves organisations with cloud infrastructure, selling to CISOs, heads of information security, SOC teams and security operations leaders in businesses facing data loss, insider threat and detection…
Financial Health
DistressedDistressed · -7% CAGR over 3y
Location
RELIANCE CYBER LIMITED
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsProvides managed cyber security services including monitoring and management of IT security infrastructure, managed detection and response, threat intelligence and vulnerability management. Also…
Serves businesses and organisations across the UK and Ireland, especially those with security teams, critical digital infrastructure, compliance needs, or exposure to cyber threats.
Financial Health
DistressedDistressed · -64% CAGR over 5y
Location
NetSecurity.IO Limited
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsDevelops cybersecurity software and provides services including endpoint threat detection and response, ransomware and data breach forensic investigations, incident response, managed detection and…
Serves enterprises, government agencies, MSSPs, and law enforcement/intelligence teams with endpoint security, incident response, digital forensics, SOC, and cyber risk needs.
Financial Health
StrongStrong · Growing, Hiring · 11% CAGR over 4y
Location
CyberOne Limited
Trajectory
5y · 2022–NowFinancial sub-scores
Computed from 5 filingsProvides managed cyber security services including 24/7 threat monitoring, managed detection and response (MXDR), incident response, penetration testing, cloud and Microsoft security consulting, and…
Serves growth-focused B2B organisations using Microsoft security, especially in finance, banking and insurance, professional services, healthcare and life sciences, technology, retail, and…
Financial Health
WeakWeak
Location
Develops and provides cybersecurity software and managed services, including a unified platform for threat detection and response, vulnerability and exposure management, SIEM, cloud security…
Serves security and IT teams at mid-market and enterprise organisations globally, including finance, logistics, infrastructure and professional services firms with complex cloud, endpoint and hybrid…
Location
Refute Ltd
Trajectory
1y · 2025–NowDevelops data analysis software that detects and tracks online disinformation campaigns. Aggregates and analyses multi‑channel data to identify coordinated narratives, model threat behaviour over…
Serves businesses and other organisations exposed to disinformation campaigns, particularly teams responsible for reputation, risk, communications, security, and organisational resilience.
Financial Health
Insufficient historyInsufficient history
Location
HEIMDAL SECURITY UK LIMITED
Trajectory
4y · 2023–NowFinancial sub-scores
Computed from 4 filingsDevelops and provides a unified cybersecurity platform offering endpoint, network and email security, vulnerability and patch management, privileged access management, and threat detection and…
Sells to businesses and public sector organisations needing cybersecurity, including SMBs and enterprises in critical infrastructure, education, engineering, energy, government, healthcare,…
Financial Health
WeakWeak · 0% CAGR over 3y
Location
Develops software and analytics platforms for risk, compliance and supply chain management. Provides tools for third‑party due diligence, financial crime detection, and supply chain risk monitoring…
Serves large enterprises, banks and government agencies, including Fortune 500 firms and public sector bodies in automotive, critical infrastructure, defense, energy and healthcare.
Location
Threat Limited
Trajectory
5y · 2021–NowFinancial sub-scores
Computed from 5 filingsProvides cybersecurity and managed IT services including continuous penetration testing, red team exercises, managed threat detection and response, vulnerability scanning, cloud and infrastructure…
Serves B2B customers, from fast-moving scale-ups to multinational enterprises, especially organisations with complex IT, cybersecurity and compliance requirements across cloud, endpoint, network and…
Financial Health
WeakWeak
Location
Vambrace
Provides cybersecurity consulting and managed security services, including compliance support for standards such as ISO 27001, Cyber Essentials and PCI DSS, penetration testing, vulnerability…
Sells to businesses seeking cybersecurity, compliance and risk management support, including teams responsible for security operations, compliance and supplier risk. Serves organisations needing…
Location
SECURITYGEN LTD
Trajectory
3y · 2023–NowFinancial sub-scores
Computed from 3 filingsDevelops cybersecurity products and services for telecommunications networks, including breach and attack simulation platforms, signaling and GTP firewalls, and intrusion detection systems. Provides…
Serves B2B telecom customers, including mobile network operators, network owners and private 5G stakeholders, targeting security, fraud, compliance and network operations teams managing 4G and 5G…
Financial Health
DistressedDistressed · -18% CAGR over 2y
Location
Unlock all 71 leads
Showing 50 of 71 — +21 more with verified decision-maker contacts, live data, and CRM sync.
How London threat intelligence companies work and how to sell to them
What they do
Threat intelligence providers usually earn revenue through annual platform subscriptions, managed-service retainers and scoped advisory work, rather than perpetual software licences. The product shape is a mix of data collection, enrichment, analyst workflow and customer-facing reporting; the service layer matters because raw indicators are rarely useful without triage and context. Pricing often follows the breadth of monitored sources, number of users or teams served, service levels, and access to analysts for briefings or investigations. Ad-supported and marketplace models are unusual. A smaller buyer may start with monitoring and alerting, while larger regulated customers often pay for tailored intelligence, executive reporting and response support.
Who they sell to
Most sellers in this market target organisations with an existing security, risk or resilience function: regulated operators, public-sector bodies, technology companies, critical suppliers and larger commercial groups with exposed digital operations. The economic buyer is commonly a chief information security officer, head of security operations, risk director or CTO, with procurement, legal and sometimes board-level risk committees involved before contract signature. Smaller engagements can be sold through direct discovery and technical validation; government or regulated-sector work is more likely to involve frameworks, RFPs and supplier-assurance checks. Sales cycles tend to lengthen when the buyer needs evidence on collection methods, confidentiality, analyst access and integration with existing security operations.
What they buy
Threat intelligence firms tend to buy tools and services that improve collection, analysis, delivery and trust. Common spending areas include cloud infrastructure, data pipelines, enrichment tooling, search, case management, customer portals, API management and secure collaboration. Commercial teams need CRM, proposal management, subscription billing and customer success systems as repeat revenue becomes more important. Security spend is also internal: identity management, access control, logging, vulnerability management and audit support matter because customers will scrutinise how intelligence and sensitive information are handled. Professional services buyers may need specialist legal advice, public-sector bid support, technical recruitment, analyst training and content production for briefings or board reporting.
Why and how to sell to them
Commercial intent often appears when a provider moves from bespoke consultancy towards repeatable subscriptions, adds managed-service capacity, or starts selling into more scrutinised public-sector and regulated accounts. Those moments create pressure around evidence, onboarding, service levels, reporting templates and integration with customer security operations. Outbound messages tend to work better when they map to that operating model: reducing analyst time spent on low-value triage, shortening procurement responses, improving handover between sales and delivery, or making executive reporting easier to evidence. Claims about broad cyber risk will sound generic; buyers in this segment usually respond to specific operational constraints, confidentiality expectations and customer-assurance requirements.
How this list is built
Data sources
This list is built from UK Companies House filings, XBRL accounts data, and semantic analysis of each company's public website. Revenue and headcount figures come from the most recent filed accounts; where the company has not filed, values are estimated using a model trained on filed history and peer benchmarks and are labelled as estimates.
Classification
Rather than relying solely on SIC codes, Firmbase classifies each company semantically: the company's website is crawled, an AI model reads what the company actually sells, and the company is placed into the relevant industry and subsectors. SIC codes are used as one signal but not the only one. This means a company that registered under a generic SIC code but pivoted into (for example) fintech is correctly identified as fintech, not as its original SIC category.
Freshness
The underlying company data is refreshed from Companies House continuously; filings appear in the list within days of submission. The curated list ordering is regenerated when the underlying data moves meaningfully (company count changes by more than 5%, a new company enters the top-ranked segment, or the filed-revenue numbers for the top firms change). You can see the last-updated timestamp near the top of the page.
Also in London
Related directories
Frequently asked questions
How many threat intelligence companies are there in the London?↓
What counts as a threat intelligence company in this list?↓
Which are the largest threat intelligence companies in the London?↓
What do threat intelligence companies in the London actually do?↓
How does London threat intelligence compare internationally?↓
How is this list built and how fresh is the data?↓
How big are the typical threat intelligence companies in the London?↓
Are these mostly new or established threat intelligence companies?↓
What SIC codes does this use?↓
What buying signals should I look for?↓
Push these 71 companies into your pipeline.
Find the right decision-makers, see verified company data, and export your list in seconds.

















































