Security should not be a luxury.
We started CMS InfoSec because the people with the most to lose from a cyber attack are the ones the security industry serves worst.
Our mission
To give every UK household and small business the security that, until now, only a company with an IT department could buy. Not a watered down version of it. The same controls, the same proof, the same standards, explained in words you already know and priced so that saying yes is easy.
Why we exist
Cyber security grew up serving big companies, and it still talks that way. Standards are written for people who read standards. Tools are sold per seat to buyers who have a budget line for them. Advice turns up as a forty page PDF that assumes somebody has time to read it.
The attacks moved down to smaller targets years ago. Scam email kits, stolen password lists and ready made ransomware do not check the size of your company, or the age of the person holding the phone, before they run.
That gap is the whole reason we are here. The people least able to take the hit get the least help avoiding it, and nobody was going to close that gap by writing another standard.
Who and what we build for
UK households
The people scammers target most are the ones security products serve least: parents, grandparents, anyone whose phone is their whole digital life. They are not a smaller version of a corporate customer and they should not be sold one.
UK small businesses
A firm with five staff and a firm with five thousand get the same scam email. Only one of them has somebody whose job it is to spot it. We build for the one that does not.
What happens afterwards
Most of the industry stops at prevention. The hours after a scam are where people are most alone and where the least has been built: what to do first, who to tell, how to prove it, how to get the money back.
Proof you can hand over
Being safe and being able to show it are two different jobs. The second one is what wins contracts and settles claims. Everything our products do should leave behind something a customer, an insurer, an auditor or a bank will accept.
Our research
Every number our products show somebody is a judgement one of us made, and we treat it that way. The figures we build against are published on our research page, each one sourced and dated.
Risk is shown in pounds, taken from published data. The cost ranges in Cyber Made Simple are built from the Government's Cyber Security Breaches Survey and from what the ICO has fined people. The working is always one tap away. We would rather show an honest number and say where it came from than show a reassuring chart with nothing behind it.
Our scoring is written down, with the reasoning. CMS SecureMe scores six areas by how well each one predicts real harm, not by how easy it is to measure. Data breaches carry the most weight, because we check them against a real list rather than asking you. Signing up to the Telephone Preference Service carries the least, because criminals ignore it, and a control that does not cut your risk should not carry weight that says it does. Both of those decisions sit in the code next to the number they produce.
We remove things that do not measure what they claim. Two scoring categories were cut from SecureMe in 2026 after a review. One measured the app's own permissions rather than anything about your security. The other counted how many times you had opened a tool. Neither predicted harm. Cutting a feature is cheaper than shipping a number that means nothing.
We check our own claims and correct them in public. A 2026 review of SecureMe found four security claims in our own documentation that the code did not back up, including certificate pinning, which had never been built. All four were corrected rather than quietly dropped, and the app's privacy notice now names the thing we donot do. If you find another, we want the email.
What we believe
Plain words are a security control
If someone cannot understand the advice, they cannot follow it, and advice nobody follows protects nobody. Jargon is not rigour. We write things the way we would explain them to a friend who runs a business, because that is usually who we are explaining them to.
Small steps beat big projects
Security programmes fail because they are built as programmes. Ours are built around the time you actually have, usually minutes a week, and they keep working when a busy month means you do nothing at all.
"We cannot tell" is a real answer
When a check cannot work out whether something is safe, our products say so instead of guessing. A confident wrong answer from a security tool is worse than no answer, because the person acts on it.
We stay on our side of the line
We do not put software on your computers, ask for admin access to your email, or connect to your systems. Everything we do is advice, questions you answer yourself, documents we write for you, and checks against information that is already public. It is a limit we chose, and it means a break-in at our end can never become a break-in at yours.
The people behind it
Our products are built and run in the UK by CMS InfoSec Ltd. We are security practitioners, not a marketing company that licensed a scanner. We have sat on the other side of this: writing the policies, filling in the supplier questionnaires, explaining to a director at 9pm why the invoice they just paid went to the wrong bank account.
That is where the passion comes from, and it is not an abstract one. Every breach we help someone avoid is a business that keeps trading, a family that keeps its savings, a person who does not spend the next six months untangling their identity. We find that worth getting up for.
Holding us to it
A security company asking for your trust should expect to be checked. Our privacy notices and terms set out what each product does with your data, in detail rather than in general, including the things we would rather not have to write down.
If you find a security problem in anything we run, write to security@cmsinfosec.com. We report problems the way we would want ours reported to us, and we will treat yours the same way.
