Built to make cybersecurity more useful to the organisations that depend on it.

Red Horizon Cyber Group brings together specialist cybersecurity, secure technology and practical education under one organisation. We exist to help businesses understand risk, strengthen the systems they depend on and build lasting security capability.

Reveal Risk. Enable Confidence.

Where Red Horizon began

Red Horizon began with a shared interest in offensive security, vulnerability research and understanding how systems fail under real attack conditions.

What started as hands-on security research developed into a broader ambition: build a cybersecurity organisation capable of not only identifying weaknesses, but helping organisations fix them, validate the improvement and continue becoming more resilient over time.

Why we built Red Horizon differently

Cybersecurity shouldn't end with a report

Finding a vulnerability is useful, fixing it is better. Validating the fix is better again.

Maintaining the improvement is where long-tem security happens.

Security and IT cannot operate independently

Many cyber weaknesses come from ordinary technology decisions:

  • Accounts
  • Cloud Configuration
  • Network Architecture
  • Devices
  • Access
  • Infrastructure

One Group. Connected Capability.

APEX CONSULTANCY

Cybersecurity assessment, offensive security and assurance.

Apex helps organisations understand where they're exposed and what should happen next.

QUADRANT SERVICES

IT, Infrastructure, Systems and Technical Remediation.

Quadrant strengthens the technology businesses depend on and helps turn identified security improvements into implementation.

RED HORIZON CYBER ACADEMY

Cybersecurity education and capability development.

The Academy strengthens the people side of security through practical education and professional development.

RED HORIZON CYBER GROUP

How we think about cybersecurity.

Reveal

Understand the real exposure.

Not assumptions

Not simply whether a product exists.

Prioritise

Not every vulnerability deserves the same attention.

Focus effort where risk and business impact intersect.

Improve

Security assessments should lead to action.

Prove

Validate that changes actually reduced the risk.

ASSESS → SECURE → ASSURE → PROTECT

Understand where risk exists.

Strengthen systems and controls.

Validate improvement and demonstrate security.

Maintain and continually improve the security posture.

Founded by practitioners. Built for the long term.

William Endean

Co-Founder

Offensive Security | Network Security | Infrastructure

CompTIA Security+, CREST CPSA

LinkedIn

Dylan Brownnutt

Co-Founder

Cyber Security | Risk | Resilience

CompTIA Security+, CREST CPSA

LinkedIn

Gavin Viano

Co-Founder

Penetration Testing | Vulnerability Assessments

CompTIA Security+, CREST CPSA

LinkedIn

Graeme Lawson

Co-Founder

Security Engineering | Detection | Research

CompTIA Security+, CREST CPSA

LinkedIn

Our Ambition

Our ambition is to build Red Horizon into one of the UK's most capable and trusted cybersecurity organisations — combining consultancy, secure infrastructure, education and technology in a way that makes security easier for organisations to understand and act upon. As Red Horizon grows, our commitment remains the same: technical integrity, clear advice and security improvement that can be demonstrated. we communicate confidence and seriousness

Technical integrity

We don't exaggerate findings, capability or certainty.

Clarity over complexity

Security advice should enable decisions rather than create confusion.

Evidence over assumption

We test, validate and prioritise based on what we can establish.

Improvement over theatre

The objective isn't to make security look impressive. It's to make the organisation harder to compromise.

Clients may give Red Horizon visibility into systems, vulnerabilities and information that would create serious risk if mishandled. Our approach is therefore built around defined scope, authorisation, confidentiality and responsible handling of security information.

  • Defined Rules of Engagement
  • Non-Disclosure Agreements
  • Secure Evidence Handling
  • Professional Reporting
  • Responsible Disclosure
  • Relevant Qualifications
  • Insurance
  • Company Certifications

Let's talk about your security.