Cyber Security Consultant · Copthorne, West Sussex

Hey, I’m James

I spent 21 years building — and securing — the IT and network systems that kept the oil and gas industry running. Then I learned how to break into them, and found that the businesses easiest to attack were the ones least able to survive it.

That’s the short version of why Systems Secure exists.

The longer version is that I got very good at protecting organisations that could afford to be protected, and then noticed that the eight-person firm down the road was facing exactly the same attackers with none of the same defences — and, unlike a global corporation, wouldn’t still be trading six months after a bad week.

I didn’t quit on the spot and call it a leap of faith. I started this in 2010 on evenings and weekends, kept the day job, and spent six years proving it worked before I let go of the salary. It’s the same way I’d advise you to make a decision that size.

Add photo here

James Batt · Founder, Systems Secure Ltd

Connect on LinkedIn

How I ended up doing this

Nobody sets out to be a cyber security consultant. Here’s the honest route.

1995

Building it, and securing it

I started in the oil and gas industry in 1995 and stayed twenty-one years, doing IT, networks and cyber security for global corporations.

I led multi-million dollar projects that spanned the globe, and spent a good deal of those years travelling across America and Europe designing and implementing them. Remote sites where “I’ll call IT in the morning” isn’t an available option. Big budgets, long timescales, and no forgiveness for anything that didn’t work.

I picked up the Microsoft engineering certifications along the way — Microsoft Certified Systems Engineer and Microsoft Certified Professional. Those are the qualifications of that era rather than this one, and I’d not lean on them today. What they left behind is the useful part: I can look at a network and see how it was actually put together, rather than how the diagram says it was.

Two things came out of it that I still use every day. How large organisations genuinely decide what to protect and what to accept — not what the brochures say, what actually happens in the room. And a working knowledge of what enterprise-grade security looks like when somebody is properly paying for it.

2010

Starting it on the side, as an IT company

In 2010 I set up Systems Secure, and I kept the day job.

It was an IT company then. Not what it is now — the ordinary work, done properly, for small businesses around West Sussex.

For six years it was evenings, weekends and holidays. Real clients, real work, but built alongside a career rather than instead of one. I wanted to know it worked before I asked my family to live on it.

That’s not the story a marketing department would write. It’s the true one, and I’d rather you had it, because it’s exactly the advice I’d give you about a decision that size: prove it small before you bet the house on it.

2016

Learning the other side of it

By then I’d spent two decades defending systems. In 2016 I sat the Certified Ethical Hacker exam, which is the opposite discipline — a formal qualification in attacking them. You learn what someone breaking in actually tries, in what order, and how little of it is clever.

What I found wasn’t sophisticated attacks against well-defended companies. It was open doors. Passwords reused across a dozen sites. Ex-employees who still had access. Backups nobody had ever tested. Almost none of it needed a genius to exploit, and almost all of it would have been cheap to fix.

And the businesses standing behind those open doors weren’t the global corporations. They were the small firms I was already looking after in the evenings.

2016

Changing what the company was

That’s the year the two halves of my working life finally met.

By day I was doing serious security for organisations that could afford it. By night I was doing IT for small businesses who couldn’t — and who needed it just as badly, because they face the same attackers with none of the same defences, and far more to lose. A bad enough week doesn’t cost them a quarter’s profit. It costs them the business.

So after twenty-one years I left. The salary, the benefits, the travel, all of it. I went full time on Systems Secure and pointed it at security instead of IT.

That wasn’t a marketing decision. Security was the weakness I could see in nearly every small business I walked into — and ten years later, it still is. Plenty of firms will keep your computers running. Far fewer are watching to see whether somebody has got into them, and the businesses that need that watching most are the least likely to have it.

Now

Where it is today

Systems Secure has been trading since 2010 — sixteen years, the last ten of them full time. QuantumCare is how the work is packaged now: a proper security programme with the price printed on the website, for businesses from a one-person operation up to a couple of hundred people.

A small number of clients, deliberately. One person who knows your business well enough to be useful at short notice.

When you ring, you get me.

I’ve sat in three chairs, and it matters

Most security advice comes from someone who has only ever sat in one of these. That’s why so much of it is either unaffordable or useless.

The corporate chair

Twenty-one years doing IT and security inside global corporations, leading multi-million dollar projects across America and Europe, and watching how enterprise security is really decided — including how much of it is theatre, and which parts genuinely earn their cost. I know what the expensive version looks like from the inside, which is what tells me what can safely be left out of yours.

The attacker’s chair

Formally trained in the techniques attackers use. It’s very difficult to defend against methods you’ve never seen from the other side. It also stops you selling fear — once you know how the common attacks actually work, you stop being impressed by them.

The owner’s chair

I run a small business. Same cash flow, same month where something unexpected lands, same instinct to put off a bill that isn’t urgent yet. Every price I set, I’ve had to imagine paying myself.

The three together are what make it possible to give a small business protection built to enterprise standards without an enterprise invoice attached.

STILL NOT SURE?

Questions you're probably asking

The main ones that come up on almost every call, answered here so you don’t have to book one to find out.

Who is James Batt?

James Batt is the founder of Systems Secure Ltd, a cyber security firm based in Copthorne, West Sussex, trading since 2010. From 1995 he spent 21 years in the oil and gas industry, running IT, networks and cyber security for global corporations and leading multi-million dollar projects across America and Europe. He qualified as a Certified Ethical Hacker in 2016, the year he moved into cyber security full time. He holds CISSP, C|CISO, C|EH, NIST NCSP Practitioner and CompTIA Security+ certifications. Systems Secure won Cybersecurity Company of the Year at the West Sussex Business Awards 2025.

Will I be dealing with James, or with an account manager?

You'll be dealing with James. That's the reason the client list is deliberately small — Business Pro is capped at twenty clients. On the packages that include the Direct Security Line, when you ring, you get him.

Why should I trust a one-person firm with something this important?

Fair question, and it deserves a straight answer. The tools doing the monitoring are the same enterprise-grade platforms used by much larger providers — they cost the same whoever buys them. What a small firm changes is who answers the phone and how well they know your business. What it can't offer is a large team standing behind it, which is exactly why the client list is capped and why the honest advice above 250 people is to go elsewhere.

Wasn't this a part-time business to begin with?

Yes, and it's worth being straight about it. Systems Secure was started in 2010 as a sideline while James was still working in oil and gas, and ran that way for six years before he moved to it full time in 2016. Clients in that period got real work done properly — but the honest version is that it was built slowly and deliberately rather than launched in one go. It's the same approach he'd recommend to any business owner weighing up a decision of that size.

Is Systems Secure an IT support company?

No — though it used to be. Systems Secure began in 2010 as an IT company and moved into cyber security in 2016, because security was the gap James kept finding in small businesses and still is. Today it provides cyber security only: monitoring, response, hardening, certification and reporting. It does not provide IT support, a helpdesk, printer support or device setup, and it works alongside your existing IT provider rather than replacing them.

What happens on a first call?

You describe the business, how many people, what you use, and what's worrying you. James tells you which package fits, what it costs, and — if nothing fits — says so. No presentation, no proposal document three weeks later.

The next step

One conversation, and you’ll know where you actually stand

You don’t have to decide anything on the call. We tell you what’s exposed, and you keep the findings either way — even if we’re not the right fit.

No obligation · No sales script · You keep the findings either way

James Batt · CISSP, C|CISO Founder, Systems Secure Ltd

Image

Innovation

Fresh, creative solutions.

Excellence

Excellence

Copyright 2026. Systems Secure. All Rights Reserved.