Skip to content
Sectors

The same rigour, whether or not a regulator is watching.

Regulated industries demand evidence, traceability, and resilience. Unregulated ones still need to win enterprise trust and move fast without breaking things. We've worked on both sides of that line, and the discipline travels well.

Regulated

Where evidence, audit, and resilience are non-negotiable.

Financial servicesTesting & inspectionManufacturing & industrialEducation & EdTech
Unregulated

Where speed, scale, and trust win the market.

Software & SaaSConstruction & built environmentProfessional services
Financial services sector
Regulated

Financial services

Money, sensitive data, and a regulator that expects evidence, alongside relentless pressure to ship product and scale. You need technology leadership that keeps delivery moving and a security posture that stands up to scrutiny, from one accountable person.

Where we're brought in

  • Setting technology strategy and an architecture that scales, without stalling delivery
  • Standing up a credible security and risk function the FCA and PRA will recognise
  • Operational resilience: important business services, impact tolerances, and the evidence to prove them
  • Building and hiring an engineering team that ships within change-management and audit expectations

We act as the accountable CTO and CISO, shaping the architecture and roadmap in the morning and speaking to a regulator in the afternoon, building product velocity and the controls, evidence and resilience story together.

Sets the bar:FCAPRAOperational resilience (PS21/3)NIST CSFISO 27001
Talk to us about financial services
Testing & inspection sector
Regulated

Testing & inspection

Accreditation and data integrity are the business, and the systems your results depend on are overdue for modernisation. The opportunity is better software and data products; the obligation is protecting integrity, traceability and impartiality.

Where we're brought in

  • Modernising LIMS, instrumentation and integrations, and the roadmap to get there
  • Protecting data integrity and audit trails end-to-end, from instrument to report
  • Building digital and data services that scale without undermining chain-of-custody
  • Securing OT and lab equipment that was never designed to be networked

We bring architecture and delivery leadership alongside security discipline, modernising the systems your results depend on while hardening the controls your assessors rely on.

Sets the bar:ISO 27001UKAS expectationsCyber Essentials
Talk to us about testing & inspection
Manufacturing & industrial sector
Regulated

Manufacturing & industrial

Production can't simply be rebooted, and much of the technology running it is decades old. You need a plan to modernise and integrate, and the security to keep the line running when an attacker comes knocking.

Where we're brought in

  • Modernising and integrating decades-old plant, ERP and data systems
  • OT/IT convergence: connecting the factory floor without exposing safety-critical systems
  • Turning IoT and production data into value, architecture, platform and roadmap
  • Ransomware resilience where an outage stops the line, not just the email

We own the modernisation and integration roadmap and secure the OT/IT boundary, making pragmatic calls about what to build, modernise, isolate or replace, and planning for the outage you hope never comes.

Sets the bar:NIST CSFISO 27001Cyber Essentials
Talk to us about manufacturing & industrial
Software & SaaS sector
Unregulated

Software & SaaS

Architecture, security maturity, and a credible AI story increasingly decide whether you win the enterprise deal, or stall in the security questionnaire.

Where we're brought in

  • Passing enterprise security reviews and SOC 2 / ISO 27001 without derailing the roadmap
  • Scaling architecture and engineering practice ahead of the next growth stage
  • Turning AI from a demo into a governed, evaluated, production capability
  • Building security in early enough that it's a sales asset, not a retrofit

We give scaling platforms the senior technology and security leadership to ship faster, satisfy enterprise buyers, and make AI bets that actually pay off.

Sets the bar:SOC 2ISO 27001NIST CSFOWASPCyber Essentials
Talk to us about software & saas
Education & EdTech sector
Regulated

Education & EdTech

In EdTech the product is the business, but you're also handling children's data and selling into risk-averse buyers. You have to ship great learning software and be trusted with it: CTO and CISO in one.

Where we're brought in

  • Turning pedagogy and content into a product that scales, architecture, data model and roadmap
  • Shipping AI-powered learning features (tutoring, marking, personalisation) that are genuinely useful
  • Passing the security and data-protection due diligence schools and trusts run, and protecting children's data
  • Integrating cleanly (SSO, MIS/SIS, LTI/OneRoster) and staying reliable through term-start spikes

We've been the CTO building and scaling an EdTech product first-hand, and we own the security side too, so we help with the architecture, AI and integrations and the trust, privacy and controls that unlock school and trust deals.

Sets the bar:Applied AI / LLMsUK GDPR (children)Cyber Essentials
Talk to us about education & edtech
Construction & built environment sector
Unregulated

Construction & built environment

A traditionally analogue industry going digital fast. The prize is joined-up data and better delivery; the risk is a distributed, multi-supplier estate that's easy to get wrong. You need both a technology plan and proportionate security.

Where we're brought in

  • Joining up data across design, site and asset systems that were never meant to talk
  • Getting real value from BIM, IoT and site data without a runaway technology spend
  • Pragmatic security for a distributed, project-based, multi-supplier workforce
  • Protecting commercially sensitive bid and project data across the supply chain

We help built-environment firms digitise deliberately, choosing the few integrations and platforms that move the needle, and keeping security proportionate to a project-based reality.

Sets the bar:Cyber EssentialsISO 27001
Talk to us about construction & built environment
Professional services sector
Unregulated

Professional services

Client trust and confidentiality are the franchise; productising expertise with AI is the opportunity. You need technology leadership to modernise delivery and the security posture that keeps blue-chip clients confident.

Where we're brought in

  • Adopting AI to productise services and lift fee-earner productivity
  • Modernising delivery, knowledge and data platforms without disrupting the business
  • Meeting client and enterprise security expectations to win and keep accounts
  • Governing data and access across partners, contractors and clients

We help firms turn expertise into AI-assisted, productised services, pairing delivery and platform modernisation with the data governance and security that keeps clients confident and accounts intact.

Sets the bar:ISO 27001Cyber EssentialsGDPR / data protectionNIST CSF
Talk to us about professional services

Work in a sector not listed?

The principles, sound architecture, real security, pragmatic AI, apply broadly. Tell us about yours.

Prefer email? phil.baker@amaya.technology