Metis Security is an independent UK cybersecurity consultancy focused on determining whether your Microsoft cloud security controls genuinely work, not just whether they exist.
Many organisations invest heavily in Microsoft security capabilities. Fewer have independent technical assurance that those controls are properly enforced and operating as intended. We specialise in validating control effectiveness across Microsoft 365 and Azure environments, providing evidence-based clarity on configuration reality and risk exposure.
Alongside Microsoft cloud security assessments, we deliver penetration testing and targeted remediation support to ensure identified weaknesses are properly addressed.
Engage directly with experienced technical leadership for precise, defensible answers about your real security posture.



Engage directly with an experienced security professional with over two decades of senior consultancy experience. You work with the person performing the assessment — not a layered delivery structure involving sales, scoping and separate technical teams.
From initial discovery through assessment, reporting and implementation support, engagements are structured to deliver clear outcomes — not standalone reports that leave you to interpret or action findings alone.
Where appropriate, engagements are defined with fixed scope and agreed outcomes. The focus is on delivering measurable improvements and defensible conclusions — not open-ended consultancy hours.
Focused expertise across Microsoft 365, Entra and Azure ensures depth rather than breadth. Engagements are grounded in real-world control validation and practical understanding of Microsoft security architecture.
Findings are delivered in precise, plain English — technically rigorous yet concise. The objective is clarity and actionability, not lengthy reports filled with unnecessary jargon.
Security assessments can be challenging. Engagements are conducted with respect for both technical and business realities, ensuring findings are delivered constructively and collaboratively.
Engage directly with an experienced security professional with over two decades of senior consultancy experience. You work with the person performing the assessment — not a layered delivery structure involving sales, scoping and separate technical teams.
From initial discovery through assessment, reporting and implementation support, engagements are structured to deliver clear outcomes — not standalone reports that leave you to interpret or action findings alone.
Where appropriate, engagements are defined with fixed scope and agreed outcomes. The focus is on delivering measurable improvements and defensible conclusions — not open-ended consultancy hours.
Focused expertise across Microsoft 365, Entra and Azure ensures depth rather than breadth. Engagements are grounded in real-world control validation and practical understanding of Microsoft security architecture.
Findings are delivered in precise, plain English — technically rigorous yet concise. The objective is clarity and actionability, not lengthy reports filled with unnecessary jargon.
Security assessments can be challenging. Engagements are conducted with respect for both technical and business realities, ensuring findings are delivered constructively and collaboratively.
Independent validation of identity, access, data protection and monitoring controls across your Microsoft 365 tenant. We confirm what is working, identify where controls fall short, and provide clear, prioritised guidance on what to address first.
Learn MoreEvidence-led review of your Azure security architecture, covering identity boundaries, network exposure, governance enforcement and detection readiness. The focus is whether your controls operate as intended under real-world conditions.
Learn MoreStructured adversarial testing of Internet-facing infrastructure and applications, using real-world attack techniques to identify genuine exploitability rather than theoretical risk. Delivered as a standalone engagement or alongside a cloud security assessment.
Learn MoreI had the distinct pleasure of working with David closely on several initiatives at NCC Group in 2021-22 where he gracefully bridged the gap between deeply technical cybersecurity leaders and business-focused sales/operations leaders to develop a global professional services framework that I still regard as truly elegant. He has an exceptional blend of technical and business insight, an infallibly polite demeanour, and an unflinching focus on optimal outcomes. It was certainly enjoyable to work with such capable and steady hands.
David is one of the rare few, he is highly technical yet has the ability to relay technical risk fluently in language that C level can comprehend. He has a fantastic understanding of risk and this is demonstrated in the way he provides sensible risk ratings as part of his deliverables.
He is a very professional individual, understands tactical and strategic drivers, someone it was a pleasure to work alongside as a client.
I had the pleasure of first working with David when I joined NGS Software in 2005, we worked together on many penetration testing engagements. During this time David took me under his wing and helped mentor me by building the foundation of my security knowledge. David has a wealth of experience in the cyber security industry which few can match, he has deep technical understanding networking, cloud computing and infrastructure security which he compliments with excellent communication skills.
Dave is one of a rare breed of highly technical security professionals that can articulate business risk to senior management without getting lost in the technical minutia. A safe pair of hands that I look forward to working with in the future.
David is the consummate professional, he is passionate about pen testing. Over the past two years David has not only been our CHECK team leader delivering numerous complex health checks but has also provided advice and consultancy on a regular basis to me, my team and the project.
I would have no hesitation in recommending David as a CHECK Team leader
I worked with David on a very high profile project for BT, David’s role as CHECK team leader and project leader was a high pressure position. David’s CHECK knowledge is a credit to him and his determination to drive the Pen Testing to a successful conclusion was outstanding. I was always impressed with David’s total dedication and professionalism even under intense pressure.
I have worked with David over the course of many years and he is simply one of the best at what he does. He has a deep technical knowledge that he can convey to all levels in high presure project environments.
This coupled with high integrity and a good sense of humour make David an asset to any company and someone that I would certainly recommend.
David has the ability to turn complex plans and documentation into easy-to-follow instructions within relatively short timescales. He remains professional and approachable throughout each engagement and I feel safe in the knowledge that David knows exactly what he is doing.
His communications are always clear, timely and thorough which makes working with him a pleasure. I too have no reservations whatsoever in recommending David should he ever decide to make tracks elsewhere. He is an asset to be proud of and a force to be reckoned with!
David was retained to provide expert advice to myself and the Head of Security on all Penetration Testing matters. This included scoping, organisation, interpretation of results and recommendations for the appropriate countermeasure or remediation.
David’s level of skill is very high and he is able to take the sometimes complex results and reinterpret them into a more user-friendly format for non-technical management.
I would have no hesitation in hiring David for any CHECK or Penetration Testing work that needed doing and is a considerable asset to his current employer.
In an industry prone to hype it is rare to find a consultant who combines a technical grasp of security issues with an ability to articulate their business impact. I highly valued David’s versatile contributions, ranging from elaborate information gathering tools to expansive client reports. David is a security assessment specialist who can be trusted to produce first-rate consulting deliverables.
We believe in constant training and the maintenance of both our technical and consultative skills and this can be best presented to our clients through formal qualifications, a selection of which are presented below.


