Who we are
Built for the UK, backed by a group defending national infrastructure.
UK financial institutions, government and critical enterprise now have access to a security practice that defends a national judiciary, the government body holding a country's workforce data and the region's largest telecommunications group. Our group architects security operations centres for banks under Singapore's financial regulator, one of the most rigorous in the world, authors the hardening standards other organisations secure their infrastructure against, and has never lost a client. Simply Data International delivers it here.
The UK operation
Delivered in the UK, to UK expectations.
Client data remains within the UK and EEA, processed and retained under UK data protection obligations. The detection engineering, threat intelligence and automation behind the service carry the same standard applied to national infrastructure, engineered into your environment rather than built for the first time on it.
Security operations as a managed service
Continuous monitoring, detection and response across your entire estate.
Observability as a service
Application and infrastructure performance monitoring, because availability failures and security failures are frequently the same incident seen from different angles.
Security consultancy
Structured assessment, framework design and roadmaps a board can approve and a regulator can accept.
Our history
Where the group has been tested.
Simply Data International Ltd is a UK-registered company, staffed in the UK and operating under UK law, with all client data held within the UK and EEA. It sits within the Simply Data group, and the service is run from the same engineering practice that defends national infrastructure across the region. What follows is the group's record, which is the practice now operating here.
Singapore
Singapore is one of the most demanding financial services environments in the world, with a regulator that expects operational resilience to be evidenced rather than asserted. It is where our reputation with financial institutions was built.
We have architected and built security operations centres for financial institutions there, and for the region's largest telecommunications group. These are not monitoring contracts. They are engagements where the client asked us to design the capability itself, which is a materially different level of trust, and we remain selective about them because each one demands our most senior engineers.
For a UK financial services buyer, that record answers the question that matters. Our security engineering has been examined, tested and accepted by institutions operating under one of the most rigorous financial regulatory regimes in Asia, and the controls, the evidence standards and the operational discipline transfer directly.
Malaysia
We run security operations at national scale for organisations where failure is not a commercial inconvenience.
A national judiciary, where we deliver full managed security across the applications and infrastructure underpinning national legal services.
A government-linked corporation responsible for national workforce data, where our threat hunters identified an active intrusion that had already passed through four existing layers of security. The attacker held valid administrative credentials, had accessed sensitive files and had begun deleting their own access logs.
A multi-business-unit conglomerate, where monitoring of Microsoft 365 authentication and file activity surfaced both compromised accounts and internal data exfiltration ahead of any material loss.
Across the wider client base we monitor central banking subsidiaries, government agencies, universities, logistics operators running nationwide site estates, and financial institutions.
These engagements share something that matters more than their scale. In every case the client already had security controls in place. What they did not have was anyone continuously examining what those controls were failing to catch.
Taiwan
We secure manufacturing customers in Taiwan, including organisations among the largest manufacturers in the world.
Manufacturing estates carry a large operational technology surface alongside conventional IT. We cover both. An OT device that is unmonitored is an entry point into the same environment the business runs on, and treating the two as separate problems leaves the join unwatched.
Retention
We have delivered security operations and observability across dozens of client estates, and penetration testing to more than twice that number, without losing a single client.
Recognition
In 2025 the group was named Cybersecurity Project of the Year at the Malaysia Cybersecurity Awards, for the Malaysia Nationwide Cyber Defence SOC Monitoring project.
The award is presented by CyberSecurity Malaysia, the national cybersecurity specialist agency operating under the Ministry of Digital. It recognises the delivery of a nationwide monitoring programme rather than a product launch, and it was awarded for work already in production protecting Malaysian organisations at scale.
Engineering
Built, not assembled.
The group has engineered its own unified security platform rather than assembling a service from other vendors' products, and that engineering capability is the foundation everything else rests on.
Telemetry from across the estate is normalised to a consistent schema and enriched with asset criticality, user risk and threat intelligence before an analyst sees it. That is what makes genuinely vendor-agnostic detection possible without losing context between tools, and it is why an alert reaching a human already carries what is needed to decide.
An agentic investigation layer runs across a three-tier model, where autonomous agents close low-severity noise and draft full investigation packets with documented evidence, and senior analysts direct threat hunting through a chat-driven workbench. Every automated decision is written to independent audit pipelines, because a decision a machine made and nobody can reconstruct is not a decision a regulated organisation can defend.
Automation is written rather than configured, with custom scripting across alert triage, enforcement, application resilience and compliance evidence collection, engineered against each client environment rather than adapted from a template.
Research
We publish original threat research drawn from what we observe across our monitored estate rather than from secondary sources. Our annual threat report examines telemetry across more than ten monitored industries, covering which attack surfaces are genuinely being exploited, how raw alert volume translates into real incidents, and what credential and dark web activity signals about the year ahead. The 2025 edition identified Microsoft 365 as the single largest attack surface across the estate we monitor, which is as true of UK organisations as it is anywhere else.
Credentials
Held by the group.
The credentials below are held by Simply Data Sdn Bhd, the group entity. Simply Data International Ltd is the UK company and is working towards its own UK accreditations. We set that out clearly because accreditation matters and should always be verifiable.
CREST accreditation
The internationally recognised standard in offensive security, and the one UK procurement teams and regulators already recognise. Accreditation is assessed rather than self-declared, covering methodology, technical competence and conduct.
ISO/IEC 27001:2022
Certification against the international standard for information security management, which means data handling across the group is governed by an audited framework rather than by intention.
CIS Benchmark authorship
Our engineering team co-authored Center for Internet Security configuration benchmarks in 2024, the hardening standards other organisations use to secure their own infrastructure. Contributing to a global hardening standard is a different position from being certified against one.
Elastic subcontractor status
One of eight across Asia Pacific and three in ASEAN, where we are the largest. Elastic underpins a substantial share of the world's security and observability workloads, and subcontractor status reflects engineering capability assessed by the vendor rather than a reseller agreement purchased from them.
National licences
Licensed by Malaysia's National Cyber Security Agency for both security operations and penetration testing, and certified as a Penetration Test Service Provider by the Information Security Certification Body under CyberSecurity Malaysia. These are national government licences, which means our operational standards have been examined and approved by a state regulator.
Strategic partnership
Strategic Partner under the CyberSecurity Malaysia Collaboration Programme.
Acquisition
The group acquired Helios, adding specialist deployment and professional services capability.
Leadership
Eric Leong, Co-Founder and Vice President of Engineering.
Eric runs engineering and technical operations across the group, covering security architecture, technical delivery and the detection and response engineering practice. He has spent over a decade building and defending enterprise networks across financial services, telecommunications and government, and that is the background that shaped how the group approaches detection engineering.
His technical credentials run unusually deep. The CCIE in Enterprise Infrastructure is among the most demanding certifications in networking and security, and holding it alongside CISSP and CEH v12 means the same person is credible on how a network is built, how it is governed and how it is attacked. He is also a certified ISO/IEC 27001:2022 Internal Auditor, which is why compliance is treated here as an engineering discipline rather than a documentation exercise.
He is a published CIS Benchmark author. That work is peer-reviewed and used worldwide, and it is the clearest external evidence that the engineering judgement behind our detection logic holds up outside our own environment.
In 2026 he earned Anthropic's Claude Certified Architect credential, covering the design of systems built on large language models. That is the discipline behind our agentic investigation layer, and the reason the AI in our platform is audited and constrained rather than bolted on.
- CCIE Enterprise Infrastructure, Cisco
- CISSP, ISC2
- CEH v12, EC-Council
- ISO/IEC 27001:2022 Internal Auditor
- Claude Certified Architect Foundations, Anthropic
- CIS Benchmark Author, Center for Internet Security
Why this matters
For a UK buyer.
The UK entity is new. The practice behind it is not. The engineers who will build your detection logic have built it for financial institutions in Singapore and for national infrastructure in Malaysia, on a platform written by the people who operate it. Our work has been examined and recognised by a national cyber security agency, and our retention record is the thing we are least willing to compromise by taking on work we cannot deliver properly.
Bring enterprise-grade defence to your organisation.
Our team is here to answer your questions and show how a fully managed SOC keeps your organisation protected around the clock, from continuous monitoring to threat hunting and machine-speed response.