24/7/365 SOC — average triage time 4m 51s

Customer reviews

15 years of clients, in their own words.

Reviews are collected annually from named contacts at every organisation under contract, published with written permission, and never edited for content. Where a client cannot be named, the sector and size are stated instead.

4.9/5

Average rating across 87 verified client reviews

96%

Annual renewal rate, three-year average

71

Net promoter score, most recent survey cycle

6.4yrs

Average tenure of a client relationship

“We had two MSSPs before NCPS. Both sent us dashboards. NCPS sent us an analyst at 3:40 on a Sunday morning who had already isolated the workstation and knew which vendor invoice the phishing email had impersonated. That is the entire difference, and it is not a small one.”
Dana Whitfield-Moss
Chief Operating Officer, Meridian Valley Credit Union · client since 2019

All reviews

Across every practice we run.

5.0 · Feb 2026

Our SOC 2 Type II was a condition of a nine-figure enterprise deal. NCPS took us from "we have a policy folder somewhere" to a clean opinion in seven months, and their evidence library meant our auditor stopped asking us for screenshots halfway through.

Clean SOC 2 Type II · 0 exceptions · deal closed

Rasheed Sultani
VP Engineering, Cartograph Labs
Compliance
5.0 · Nov 2025

The pen-test report was the first one I have read that a non-engineer could follow. It told a story: here is the door we opened, here is what we reached, here is what it would have cost you. Our board approved the remediation budget in one meeting.

14 findings · all remediated and retested in 60 days

Elaine Kowalczyk
CFO, Harbison Precision Manufacturing
Pen test
5.0 · Jan 2026

Our cyber-insurance renewal was going to double until NCPS rebuilt the MFA and backup story and wrote the carrier a technical narrative in their own language. Premium came in under the prior year with a higher limit.

Premium down 11% · coverage limit up $3M

Tomas Beaulieu
CFO, Ardsley Health Partners
vCISO
5.0 · Sep 2025

Eleven years with the same account team. That is the whole review. Nobody in this industry stays eleven years, and the fact that they know our plant floor better than some of our own staff is the reason we have never gone to bid.

Client since 2015 · 0 reportable incidents

Marisol Guzmán
CIO, Delaware Bay Logistics Group
Managed
5.0 · Mar 2026

The NCUA examiner asked for evidence of continuous monitoring. We forwarded the NCPS quarterly pack unchanged. His only comment was that he wished more institutions our size documented this well.

Exam passed · no findings on IT controls

Jordan Pell
CEO, Brandywine Community FCU
Compliance
4.5 · Aug 2025

Onboarding took eleven business days rather than the ten they quoted, which is the only complaint I have in four years. The tuning period was genuinely quiet — we were braced for a month of false alarms that never came.

640 endpoints monitored · 3 false escalations in year one

Henrik Nilsen
IT Director, Sable Ridge School District
Onboarding
5.0 · Jun 2025

A partner's mailbox was compromised nine days before a closing and the wiring instructions were altered. NCPS caught the forwarding rule the hour it was created. The client never knew there had been a problem.

$1.4M funds transfer protected

Claudette Ossei-Bempah
Managing Partner, Ossei & Marchetti LLP
MDR
5.0 · Dec 2025

We are a defense supplier with 90 people and no security staff. CMMC felt impossible. Their enclave design cut the CUI scope to eleven machines, which turned an unaffordable project into a manageable one.

CUI scope cut 84% · Level 2 readiness achieved

Renata Aliyeva
President, Kestrel Aerostructures
CMMC
4.5 · Oct 2025

I wanted a cheaper tier than the one they recommended and they let me have it, then showed me at the quarterly review exactly which two incidents the cheaper tier had slowed down. We upgraded. No pressure, just evidence.

Upgraded at month 8 on measured gaps

Bill Fothergill
Controller, Trenton Mutual Insurance
Managed
5.0 · Apr 2026

Ransomware hit a vendor with a remote-support tunnel into our network on a Friday evening. Containment happened in under four minutes. We were back to normal operations Monday morning having lost one file server.

Contained pre-encryption · 1 server rebuilt · 0 ransom

Sunil Varadarajan
VP Operations, Chesapeake Orthopaedic Group
IR
5.0 · Jul 2025

Their exposure scan found a file-transfer appliance a departed contractor stood up in 2019 that nobody had inventoried. It was internet-facing and unpatched. That single finding paid for the year.

7 unknown internet-facing assets retired

Amara Dieng
Director of IT, Wilmington Housing Authority
Exposure
5.0 · May 2025

We are 55 people and I expected to be the smallest client they had ever taken seriously. Our quarterly review is run by the same CISO who sits with institutions twenty times our size, and she has never once made us feel small.

Client since 2022 · full programme at 55 seats

Grace Tolliver
Executive Director, Riverbend Family Services
vCISO

Outcomes in detail

Three engagements, start to finish.

Financial services · 240 endpoints

From eight examination findings to none

A credit union came to us with eight IT-related findings from its prior NCUA examination and eleven months to fix them. We rebuilt the control set, stood up continuous evidence collection, and rehearsed the examination interview.

  • All eight findings closed and evidenced within nine months
  • Next examination closed with no IT findings
  • Board reporting cut from 40 pages to 6

Manufacturing · 1,150 endpoints

Ransomware stopped at the OT boundary

An intrusion through a vendor's remote-support tunnel reached the IT estate on a Friday night. Automated containment isolated 14 hosts in under four minutes; the production network was never touched.

  • 0 minutes of production downtime
  • 1 file server rebuilt from backup
  • Root-cause timeline delivered to the carrier in 6 days

SaaS · 310 endpoints

SOC 2 Type II in seven months

A data-platform company needed a Type II report to close an enterprise contract. We ran readiness, implemented the controls, automated the evidence, and managed the auditor relationship through the observation window.

  • Clean opinion, zero exceptions
  • Engineering time on the audit cut by an estimated 400 hours
  • Security questionnaire turnaround now under 48 hours

References

Talk to them, not to us.

At the reference stage we will introduce you to two or three current clients in your sector and at your size — including at least one who has been with us for more than five years, and one who has been through an incident with us. We do not screen the conversation.

Request customer references

Next step

See what an attacker sees — in 30 minutes, at no cost.

We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.

  • Findings report delivered in 3 business days
  • No sales engineer required to read it
  • Yours to keep, whether or not you hire us