Cyber Security Consultant · Copthorne, West Sussex
I spent 21 years building — and securing — the IT and network systems that kept the oil and gas industry running. Then I learned how to break into them, and found that the businesses easiest to attack were the ones least able to survive it.
That’s the short version of why Systems Secure exists.
The longer version is that I got very good at protecting organisations that could afford to be protected, and then noticed that the eight-person firm down the road was facing exactly the same attackers with none of the same defences — and, unlike a global corporation, wouldn’t still be trading six months after a bad week.
I didn’t quit on the spot and call it a leap of faith. I started this in 2010 on evenings and weekends, kept the day job, and spent six years proving it worked before I let go of the salary. It’s the same way I’d advise you to make a decision that size.
Nobody sets out to be a cyber security consultant. Here’s the honest route.
I started in the oil and gas industry in 1995 and stayed twenty-one years, doing IT, networks and cyber security for global corporations.
I led multi-million dollar projects that spanned the globe, and spent a good deal of those years travelling across America and Europe designing and implementing them. Remote sites where “I’ll call IT in the morning” isn’t an available option. Big budgets, long timescales, and no forgiveness for anything that didn’t work.
I picked up the Microsoft engineering certifications along the way — Microsoft Certified Systems Engineer and Microsoft Certified Professional. Those are the qualifications of that era rather than this one, and I’d not lean on them today. What they left behind is the useful part: I can look at a network and see how it was actually put together, rather than how the diagram says it was.
Two things came out of it that I still use every day. How large organisations genuinely decide what to protect and what to accept — not what the brochures say, what actually happens in the room. And a working knowledge of what enterprise-grade security looks like when somebody is properly paying for it.
In 2010 I set up Systems Secure, and I kept the day job.
It was an IT company then. Not what it is now — the ordinary work, done properly, for small businesses around West Sussex.
For six years it was evenings, weekends and holidays. Real clients, real work, but built alongside a career rather than instead of one. I wanted to know it worked before I asked my family to live on it.
That’s not the story a marketing department would write. It’s the true one, and I’d rather you had it, because it’s exactly the advice I’d give you about a decision that size: prove it small before you bet the house on it.
By then I’d spent two decades defending systems. In 2016 I sat the Certified Ethical Hacker exam, which is the opposite discipline — a formal qualification in attacking them. You learn what someone breaking in actually tries, in what order, and how little of it is clever.
What I found wasn’t sophisticated attacks against well-defended companies. It was open doors. Passwords reused across a dozen sites. Ex-employees who still had access. Backups nobody had ever tested. Almost none of it needed a genius to exploit, and almost all of it would have been cheap to fix.
And the businesses standing behind those open doors weren’t the global corporations. They were the small firms I was already looking after in the evenings.
That’s the year the two halves of my working life finally met.
By day I was doing serious security for organisations that could afford it. By night I was doing IT for small businesses who couldn’t — and who needed it just as badly, because they face the same attackers with none of the same defences, and far more to lose. A bad enough week doesn’t cost them a quarter’s profit. It costs them the business.
So after twenty-one years I left. The salary, the benefits, the travel, all of it. I went full time on Systems Secure and pointed it at security instead of IT.
That wasn’t a marketing decision. Security was the weakness I could see in nearly every small business I walked into — and ten years later, it still is. Plenty of firms will keep your computers running. Far fewer are watching to see whether somebody has got into them, and the businesses that need that watching most are the least likely to have it.
Systems Secure has been trading since 2010 — sixteen years, the last ten of them full time. QuantumCare is how the work is packaged now: a proper security programme with the price printed on the website, for businesses from a one-person operation up to a couple of hundred people.
A small number of clients, deliberately. One person who knows your business well enough to be useful at short notice.
When you ring, you get me.
Check you have the right company
There is another UK cyber security firm with a name almost identical to ours, and we have no connection with them. Every detail below can be checked independently — nothing here asks you to take our word for it.
Ring the number you already have — the one in your phone or on an old invoice — rather than one from a search result, an email signature or a text message.
Never change payment details on the strength of an email. If you receive anything saying our bank details have changed, they have not. Ring and check. That goes for every supplier you use, not just us.
When in doubt, forward it. There is no charge for asking, and we would far rather look at ten things that turn out to be fine than miss the one that isn’t.
Most security advice comes from someone who has only ever sat in one of these. That’s why so much of it is either unaffordable or useless.
Twenty-one years doing IT and security inside global corporations, leading multi-million dollar projects across America and Europe, and watching how enterprise security is really decided — including how much of it is theatre, and which parts genuinely earn their cost. I know what the expensive version looks like from the inside, which is what tells me what can safely be left out of yours.
Formally trained in the techniques attackers use. It’s very difficult to defend against methods you’ve never seen from the other side. It also stops you selling fear — once you know how the common attacks actually work, you stop being impressed by them.
I run a small business. Same cash flow, same month where something unexpected lands, same instinct to put off a bill that isn’t urgent yet. Every price I set, I’ve had to imagine paying myself.
The three together are what make it possible to give a small business protection built to enterprise standards without an enterprise invoice attached.
The main ones that come up on almost every call, answered here so you don’t have to book one to find out.
James Batt is the founder of Systems Secure Ltd, a cyber security firm based in Copthorne, West Sussex, trading since 2010. From 1995 he spent 21 years in the oil and gas industry, running IT, networks and cyber security for global corporations and leading multi-million dollar projects across America and Europe. He qualified as a Certified Ethical Hacker in 2016, the year he moved into cyber security full time. He holds CISSP, C|CISO, C|EH, NIST NCSP Practitioner and CompTIA Security+ certifications. Systems Secure won Cybersecurity Company of the Year at the West Sussex Business Awards 2025.
You'll be dealing with James. That's the reason the client list is deliberately small — Business Pro is capped at twenty clients. On the packages that include the Direct Security Line, when you ring, you get him.
Fair question, and it deserves a straight answer. The tools doing the monitoring are the same enterprise-grade platforms used by much larger providers — they cost the same whoever buys them. What a small firm changes is who answers the phone and how well they know your business. What it can't offer is a large team standing behind it, which is exactly why the client list is capped and why the honest advice above 250 people is to go elsewhere.
Yes, and it's worth being straight about it. Systems Secure was started in 2010 as a sideline while James was still working in oil and gas, and ran that way for six years before he moved to it full time in 2016. Clients in that period got real work done properly — but the honest version is that it was built slowly and deliberately rather than launched in one go. It's the same approach he'd recommend to any business owner weighing up a decision of that size.
No — though it used to be. Systems Secure began in 2010 as an IT company and moved into cyber security in 2016, because security was the gap James kept finding in small businesses and still is. Today it provides cyber security only: monitoring, response, hardening, certification and reporting. It does not provide IT support, a helpdesk, printer support or device setup, and it works alongside your existing IT provider rather than replacing them.
You describe the business, how many people, what you use, and what's worrying you. James tells you which package fits, what it costs, and — if nothing fits — says so. No presentation, no proposal document three weeks later.
The next step
You don’t have to decide anything on the call. We tell you what’s exposed, and you keep the findings either way — even if we’re not the right fit.
No obligation · No sales script · You keep the findings either way
James Batt · CISSP, C|CISO Founder, Systems Secure Ltd
Your IT team keeps the business running. We check it is protected — finding the risks, telling your IT team what to fix, and showing you the proof every month in plain English.
Per computer, sole trader. Excludes VAT.
Three packages, sized by how many people you have — £35, £204 and £710 a month. Every price is on this page.
Systems Secure Ltd is an independent cyber security company based in Copthorne, West Sussex, run by James Batt and working with businesses across the UK. Its managed service, QuantumCare, works alongside your existing IT support rather than replacing it — finding the risks, telling your IT team what to fix, and checking that important protections are still working.
This is cyber security, not IT support. Prices are published on this site, starting at £35 a month. Cyber security should give you clear answers — not long reports, confusing alerts or guesswork.
There's a reason a company's accounts are prepared by one firm and audited by another. It isn't that accountants can't be trusted — it's that nobody, however good, is well placed to check their own work.
Keeps your systems, users and everyday technology running. In-house or outsourced, they stay involved throughout — and receive clear, specific actions from us whenever their help is needed.
Finds the cyber risks, strengthens protection, and checks that important security controls are still working. You get an independent view of what's protected, what has changed, and what should happen next.
Good IT teams tend to welcome this. An independent report is often the evidence they've been trying to get budget on for months.
One person, one computer
From £35
per computer, per month
Priced per Microsoft 365 or Google account
From £204
per month
Priced per Microsoft 365 or Google account
From £710
per month
No setup fees. No minimum contract. No penalty for changing your mind. All prices exclude VAT. Compare all packages side by side
QuantumCare CISO is the mirror image of the packages above — all people, no software. A qualified security officer for a business of 10 to 250 people, from £1,200 a month. Five published prices, and no quote to ask for.
See CISO pricesOne-off work with James at a fixed price agreed before anything starts. £450 to review one system — your Microsoft 365, your firewall, your backups. £795 for the whole business. Got a question first? There's no charge for finding out whether you need us.
See consulting pricesNo form to fill in first, and no sales call needed to find out the number.
Three QuantumCare packages, sized by how many people you have, from £35 a month. Every price is published on this site.
A conversation, not a pitch. We confirm which package fits — and if the honest answer is that you don't need us, we'll say so.
We install it, configure it and check it is working — usually inside a week from agreement, and mostly without you noticing.
Monitoring, updates applied in the background, and problems dealt with rather than just flagged up. Micro Business and Business Pro add a plain-English summary each month.
Month to month on 30 days' notice, no setup fee and no penalty for changing your mind. A 12-month option is there if you'd rather freeze your price — a choice, not a requirement.
If your business is compromised while you're following the agreed security plan, you get three months' fees back. No security company can promise you'll never be attacked, and we don't.
The managed security list is capped at 20, so the person checking your security is actually paying attention — and you deal with the same person every time.
We will not take on a direct competitor of an existing client, and every price on this site is the price you pay.
In IT, networks and cyber security since 1995
Systems Secure trading, full time on cyber security since 2016
Defences strengthened, risk reduced, peace of mind delivered
Trained to spot threats, stop breaches and protect businesses
The gold standard in cyber security, recognised worldwide.
Certified to run a security programme — governance, risk and reporting to a board.
Qualified to think like a hacker and find your weaknesses first.
Certified in structured cyber risk management using the NIST framework.
Globally recognised qualification in cyber security best practice.
Most cyber security experts talk in acronyms. I talk like a business owner — because I am one.
I went into the oil and gas industry in 1995, doing IT, networks and security for global corporations, and led multi-million-dollar projects across America and Europe. Twenty-one years of it — and security was part of the job from the first day. I'm not an IT man who retrained into it later.
In 2010 I started Systems Secure as a sideline and ran it alongside the day job for six years. By 2016 it had outgrown the evenings and weekends, so I sat the Certified Ethical Hacker exam, left a good salary and better benefits behind, and turned the company from IT to cyber security — because security was, and still is, the weakness most smaller businesses have.
Sixteen years on, I've helped 200+ UK organisations strengthen their defences, pass compliance audits, and sleep easier knowing their data — and their reputation — are protected. You deal with me, not a rotating support desk.
Written for the person who owns the business, not the person who runs the servers. No acronyms, no scare stories, and nothing you need a technical background to act on.
We'll email you the PDF. The button opens a short form — one name, one email address.
Send me the guide In a hurry? The ten-point checklist is on the site already, with nothing to fill in.The main ones that come up on almost every call, answered here so you don't have to book one to find out.
Systems Secure managed cyber security starts at £35 per computer per month for a sole trader, £204 per month for a business of one to nine people, and £710 per month for a business of ten or more. All prices exclude VAT and there are no setup fees.
What you pay depends on how many people you have. The Sole Trader package is priced per computer. Micro Business and Business Pro are priced per Microsoft 365 or Google account, so the cost scales with your team rather than a fixed licence block. Every price is published on the website — you don't need to sit through a sales call to find out the number.
QuantumCare is Systems Secure's cyber security service: three managed packages priced by how many people you have — Sole Trader from £35 a month, Micro Business from £204 and Business Pro from £710 — plus QuantumCare CISO, a separate service from £1,200 a month for businesses of 10 to 250 that need a qualified security officer rather than more software.
It is cyber security, not IT support — it works alongside whoever runs your systems rather than replacing them, finding the risks, telling your IT team what to fix, and checking that important protections are still working.
No. Every Systems Secure package runs on a rolling monthly basis with 30 days' notice and no cancellation penalty. There is no minimum term.
A 12-month option is available if you'd rather freeze your price, which saves £2 per account per month. It's a choice, not a requirement.
No. There are no setup fees and nothing to pay upfront on any Systems Secure package. You pay monthly, starting from the month the service begins.
No. All Systems Secure prices are quoted excluding VAT. VAT is added to your invoice at the prevailing UK rate.
Yes. Fixed-price consulting is available with no ongoing commitment: £150 for a single question answered in writing within two working days, £250 for a second opinion, £450 for a review of one system, and £795 for a full review of your business. All prices exclude VAT.
These prices are built for businesses of up to 25 staff. Above that, the price rises with headcount.
No. Systems Secure is designed to work alongside your existing IT support, not replace it. Whether your IT is outsourced or in-house, they carry on running your systems, users and everyday technology, and receive clear, specific actions from us whenever their help is needed.
The two roles are different jobs. Your IT team keeps the business running; Systems Secure checks that it's actually protected. You get an independent view of what's protected, what has changed and what should happen next — without disrupting a relationship that's already working.
Usually yes — and it tends to help them rather than undermine them. An in-house IT manager is responsible for keeping everything running, which means security competes with a hundred other urgent things every week. It also means they would be reporting on the quality of their own work, which isn't a fair position to put anyone in.
Systems Secure gives your IT manager a specialist to escalate to and a second pair of eyes on the things that matter, and gives you a view that doesn't depend on one person's workload or judgement.
IT support keeps your technology working: fixing problems, setting up new starters, keeping systems online. Cyber security is a separate job — finding weaknesses before an attacker does, strengthening protection, and checking that important controls are still working months after they were switched on.
Good IT teams, in-house or outsourced, do handle parts of security — including updates, backups and access control. What they rarely provide is independent oversight: someone whose only job is to look for the gaps, and who has no reason to report that everything is fine.
Possibly not — and Systems Secure will tell you honestly if that's the case. But two things are worth knowing: nobody is well placed to audit their own work, and IT providers are themselves a target for attackers looking for a route into their customers' networks.
In a joint advisory, the UK's National Cyber Security Centre — alongside CISA, the NSA, the FBI and their Australian, Canadian and New Zealand counterparts — warned that managed service providers are granted privileged access to a customer's network, which can create opportunities for attackers.
That isn't hypothetical. In July 2021 attackers exploited a flaw in Kaseya VSA, remote management software used by IT providers, and reached an estimated 800 to 1,500 businesses through around 60 providers. None of those businesses did anything wrong. They were reached through a supplier they trusted.
So the question worth asking isn't "do you handle security?" It's "when did you last check that it's working, and can I see the evidence?"
No. In the last 12 months, 46% of UK small businesses and 42% of micro businesses identified a cyber security breach or attack, according to the Government's Cyber Security Breaches Survey 2025/26.
Most attacks aren't personally chosen — they're automated. Software scans the internet looking for weaknesses and takes whatever it finds. A business with three staff and a website nobody visits still gets probed daily. Phishing remains by far the most common method, experienced by 38% of businesses.
No. Antivirus catches known threats, but most modern attacks don't rely on a recognisable file. Phishing, stolen passwords and misconfigured settings all bypass antivirus entirely.
Proper protection needs several layers: monitoring that spots unusual behaviour, multi-factor authentication, patching, backups you've actually tested, and staff who can recognise a convincing fake email.
No. Most cyber insurance policies require you to prove you took reasonable precautions — multi-factor authentication, staff training, patch management. If you can't demonstrate those, a claim can be reduced or refused entirely.
Insurers increasingly expect standards such as Cyber Essentials before they'll offer cover or renew it. Insurance is worth having, but it pays out after the damage. It doesn't prevent it.
No security company can promise you'll never be attacked, and Systems Secure doesn't make that promise. What it does offer is a three-month refund guarantee: if your business is compromised while you're following the agreed security plan, you get three months' fees back.
The realistic goal is fewer incidents, caught earlier and contained faster.
Every package includes round-the-clock monitoring, automatic updates, protection against viruses and ransomware, blocking of dangerous websites, and staff training. Larger packages add cloud backup, alerts when a login is stolen, regular checks for weak spots, firewall and network reviews, written security policies and a quarterly review.
Micro Business and Business Pro also include a short monthly summary showing what's protected, what changed and what needs attention — written in plain English rather than as a long technical report.
From sole traders up to businesses of around 250 staff. There are three packages: Sole Trader for one person, Micro Business for one to nine people, and Business Pro for ten to 250. Business Pro has a minimum of ten accounts.
No. Systems Secure is based in Copthorne, West Sussex, and works with businesses across the UK. Almost all of the work is done remotely, so your location doesn't affect the service or the price.
On-site visits are available and charged separately: £240 for a visit of up to two hours, £400 for a half day and £760 for a full day.
Yes. Cyber Essentials readiness support is included in the Business Pro package. That means reviewing your current setup against the requirements, telling you what needs to change, and getting you to the point where you can pass.
Worth knowing: Cyber Essentials reflects the day of assessment, not a permanent state. Ongoing patching, access reviews and vulnerability checks are what keep the certificate meaningful between renewals.
James Batt. Systems Secure deliberately caps its managed security client list at 20, so you deal with the same person every time rather than a rotating support desk.
Systems Secure will also never take on a direct competitor of an existing client.
James Batt holds CISSP, C|CISO (Certified Chief Information Security Officer), CEH (Certified Ethical Hacker), NCSP Practitioner and CompTIA Security+.
Behind those: 21 years designing multi-million-dollar IT systems for the oil and gas industry, and 16 years running Systems Secure. The company was named Cybersecurity Company of the Year at the West Sussex Business Awards 2025, and Security Solution Specialists of the Year at the E2 Media Awards 2025.
Because security oversight is only worth paying for if someone is genuinely paying attention. Capping the list at 20 clients means each one gets real scrutiny rather than an automated dashboard nobody reads.
It also means Systems Secure can be honest about capacity rather than selling a service it can't properly deliver.
A conversation, not a pitch. We'll confirm which package fits — and if the honest answer is that you don't need us, we'll say so.

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.