About

About Cybertomic

Health-sector digital assurance covering information security, clinical safety, and AI governance.

Cybertomic cybersecurity consulting approach

Our Story

When an accounting officer, board member, or senior responsible owner has to decide whether to proceed with NHS data access, a procurement award, or a major digital programme, another checklist is not what they need. They need an independent view of whether the risk is defensible.

Cybertomic was set up to provide exactly that. We do two kinds of work: readiness, where we help suppliers build and evidence what the NHS requires; and independent assurance, where we give decision makers a clear written opinion on whether a control environment, supplier, or deployment is defensible. In assurance mode that means checking whether controls are meaningful, finding the residual risk that survives a technically passing submission, and producing an opinion that holds up in front of audit, regulators, or an assurance committee.

We keep the two separate. Where we have built or prepared evidence for a client, we do not also sell that client an independent assurance opinion on the same work. Independence is only worth anything if it is real, so we protect it rather than blur it.

The organisations we work with operate where accountability is real: healthtech suppliers that have to prove they are safe to sell into the NHS, and the NHS bodies that have to decide whether to trust them. Our assurance is proportionate to that. It is clinically informed, grounded in how organisations actually run, and never written to help someone simply pass.

Credentials

Our work is led by a practitioner who holds:

  • Registered Pharmacist - General Pharmaceutical Council (GPhC)
  • MBA
  • ISO/IEC 27001:2022 Lead Implementer (BSI)
  • ISO/IEC 42001 Lead Implementer - AI Management Systems
  • BCS Practitioner Certificate in Data Protection
  • Clinical Safety Officer - trained in DCB0129 / DCB0160
Cyber Essentials certified

Cybertomic holds Cyber Essentials as an organisation.

Readiness and assurance, kept separate

Where we have built or prepared evidence for a client, we do not also sell that client an independent assurance opinion on the same work. Independence is only worth anything if it is real, so we protect it rather than blur it.