NCC Group plc

United Kingdom · owned by Independent (publicly listed) (United Kingdom) · www.nccgroup.com · 39 vendors

NCC Group is a global cybersecurity company headquartered in Manchester, United Kingdom, providing a wide range of services including security assessments, penetration testing, managed detection and response, and software escrow. The company serves clients across multiple industries and geographies, helping organizations assess, develop, and manage cyber threats. It is listed on the London Stock Exchange (LSE: NCC).

Resilience scores

Disruption prediction

NCC Group plc has an estimated 11% probability of disruption in the next 6 months.

17 of NCC Group plc's 39 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 39 sub-vendors.

Insights

Last updated 2026-05-24 · revision 8

39 direct vendors, 384 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

NCC Group plc exhibits medium migration readiness. A key strength is its internal tech stack, which heavily leverages modern cloud platforms such as Microsoft Azure, Microsoft Sentinel, Microsoft Defender, and Splunk. This indicates a strong foundation and internal expertise in cloud-native technologies. The company's product offerings also include extensive cloud security services (AWS, Azure, GCP), container security, and AI in cybersecurity, further demonstrating a strategic alignment with modern, migratable architectures. Financial stability, with consistent revenue growth, suggests the company has the capacity to fund significant migration initiatives. However, several factors present considerable challenges. The regulatory environment is complex; while compliant with GDPR, ISO 27001, and UK Cyber Security Regulations, the 'Assessment Required' status for NIS2 and SOC2 means that any migration must carefully consider and integrate these compliance requirements, potentially adding complexity and cost. Data residency requirements are a major hurdle, with mandates from UK GDPR, EU GDPR, client contracts, and national security considerations requiring sophisticated architectural planning for data localization and cross-border transfers. Regarding vendor relationships, the 'Total Vendors: 0' data is unclear, but the presence of 56 vendor services and geographic diversity across 9 unique vendor HQ countries (e.g., US, UK, Norway, France) suggests a potentially diverse vendor ecosystem, which could mitigate vendor lock-in risks during migration. However, the 'Vendor Lock-in Risk' itself is unknown, which is a minor weakness. The presence of Umbraco CMS in the internal tech stack might also represent a legacy component that could require specific migration strategies. In summary, while NCC Group has a strong cloud-oriented tech stack and financial capacity, the intricate regulatory landscape, stringent data residency requirements, and the need to address pending compliance assessments will necessitate careful planning and execution for any large-scale migration.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

As a UK-based company with operations across EU (Netherlands, Belgium, Spain) and processing personal data of EU residents through their cybersecurity services, GDPR compliance is mandatory. Non-compliance could result in fines up to 4% of annual turnover or €20M. Given their global client base and data processing activities, the likelihood of handling EU personal data is very high. The company demonstrates awareness through their privacy policies and data protection frameworks.

Evidence: https://www.nccgroup.com/privacy-notice/, https://www.nccgroup.com/data-privacy/, https://www.nccgroup.com/cookie-policy/, https://www.nccgroup.com/our-office-locations/

NIS2 (source) — Assessment Required

NIS2 applies to Essential and Important Entities in EU. While NCC Group operates in cybersecurity (which could fall under 'ICT service management' for Essential Entities), their primary business is cybersecurity consulting rather than critical infrastructure provision. However, they have EU operations and exceed size thresholds (2000+ employees). The regulatory scope is complex and requires detailed assessment of their specific service offerings to determine if they qualify as Essential or Important Entities.

Evidence: https://www.nccgroup.com/campaign/nis2-prepare-your-organisation-for-compliance/, https://www.nccgroup.com/solutions/compliance-and-regulations/, https://www.nccgroup.com/our-office-locations/

SOC 2 (source) — Assessment Required

As a provider of managed cybersecurity services, cloud security services, and technology solutions to clients, SOC2 compliance would be highly beneficial for demonstrating security controls to clients. The risk is medium because while not legally mandated, SOC2 certification is often required by enterprise clients for service providers handling sensitive data. Non-compliance could impact business opportunities and client trust.

Evidence: https://www.nccgroup.com/managed-services/, https://www.nccgroup.com/solutions/compliance-and-regulations/, https://www.nccgroup.com/

Financials

Three-year financials

Financial Resilience Score: 6/10

NCC Group's financial resilience has materially improved following the 2024 divestment of its Software Resilience (Escrow) business to Iron Mountain for approximately £220m in cash. This transaction transformed the balance sheet, moving the group from a modest net debt position in FY23 to a materially strengthened net cash position, with proceeds used for a ~£30m share buyback and debt reduction. Historically, the company maintained an RCF with NatWest and HSBC providing adequate working capital headroom, and a progressive dividend policy (~4.65p annual). However, resilience is tempered by significant operational challenges. Adjusted operating margins have compressed from ~14% in FY22 to high single digits in FY23-FY24, reflecting weakening demand and elongated sales cycles, particularly in North America. The company now depends almost entirely on the cyclical Cyber Security division following the Escrow disposal, reducing earnings diversification. Significant goodwill from prior acquisitions (Iximus, Fox-IT, IPM) presents impairment risk, and statutory results have been impacted by impairments and restructuring charges. A cost-reduction programme targeting £17-20m in annualised savings was implemented in early 2023, including ~125 redundancies, indicating reactive management of cyclical pressures.

Key strengths: Escrow disposal proceeds of ~£220m materially strengthened balance sheet, Net cash position post-disposal (vs. modest net debt in FY23), RCF facility with NatWest and HSBC syndicate provides liquidity headroom, Progressive dividend policy maintained (~4.65p annual), £30m share buyback announced from disposal proceeds, Diversified customer base with no material single-customer concentration

Risk factors: Earnings volatility in cyber consulting due to project-based revenue, Goodwill impairment risk on prior acquisitions (Fox-IT, Iximus, IPM), Material USD FX exposure, Talent costs in competitive cyber labour market, Execution risk on post-disposal strategy, Reduced earnings diversification post-Escrow sale, Margin compression from ~14% (FY22) to high single digits (FY23-FY24), Tightened dividend cover amid weak trading

Revenue by geography

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report