Clarity in cyber risk.
Capability statement
Current as at 19 September 2026
Cairn Cyber Advisory Ltd
Independent security architecture advisory for regulated organisations adopting AI, agentic systems and emerging technology. The practice designs the controls, standards and evidence that let a regulated business approve new technology without waiting for its control framework to catch up.
Led by Gary Johnston, Principal Security Architect (CISSP, CCSP), with fifteen years in security and infrastructure architecture across institutional banking, asset management, legal services and telecommunications. Engagements are contracted business-to-business and are intended to operate outside IR35.
Service lines
- AI & agentic AI security architecture
- Threat modelling, gateway controls and governance for organisations putting AI into production under regulatory scrutiny.
- Cloud & hybrid security architecture
- Security architecture for cloud migration, platform build and post-merger integration in regulated environments.
- Security standards & governance
- Standards, control frameworks and governance processes that survive contact with an audit and with delivery teams.
- Architecture review & assurance
- Independent security review of designs, platforms and third-party systems before they reach production.
- Blockchain & digital asset security
- Security standards and architecture for blockchain, tokenisation and crypto-custody in regulated institutions.
Engagement shapes
- Discovery · 1 to 2 weeks
- Written assessment, prioritised risk picture, and a costed recommendation on what to do next.
- Architecture review · 2 to 4 weeks
- Threat model, findings rated by risk, and an approve / approve-with-conditions / reject recommendation.
- Embedded advisory · 3 to 12 months, part or full time
- Target-state architecture, design decisions and their rationale, and capability left behind in your team.
- Retained advisory · Ongoing, defined days per month
- Agreed availability for reviews, escalations and design input, with a standing point of contact.
Rates on application against a defined scope. Fixed-price where the scope supports it, otherwise a day rate.
Capability
AI & emerging technology
- AI and LLM security
- Generative and agentic AI
- AI gateways
- Blockchain and crypto-custody
- Zero trust architecture
Frameworks
- NIST CSF v2
- NIST AI RMF
- MITRE ATLAS
- OWASP Top 10 for LLMs
- ISO 42001
- ISO 27001
- DORA
- TOGAF
- GDPR
- PCI-DSS
Platforms
- AWS
- Azure
- GCP
- VMware private cloud
- Kubernetes
- Terraform
Sectors
Institutional banking and custody · Asset and investment management · Legal services · Telecommunications and media · Managed IT and network services
Company and contracting
- Registered name
- Cairn Cyber Advisory Ltd
- Company number
- SC902675
- Place of registration
- Scotland
- Registered office
- 49 Bonaly Wester, Edinburgh, EH13 0RQ, United Kingdom
- VAT registration
- Not VAT registered
- ICO registration
- CSN0579447
- Professional indemnity
- Arranged per engagement, to £5m
- Public liability
- Arranged per engagement, to £5m
- Principal
- Gary Johnston, Principal Security Architect
- Certifications
- CISSP, CCSP
- Enquiries
- hello@cairncyberadvisory.co.uk
- Security contact
- security@cairncyberadvisory.co.uk
- Website
- cairncyberadvisory.co.uk
- Contracts business-to-business on the client's standard terms or the practice's own. NDA available before any detail is discussed.
- Completes standard financial services screening, including BPSS, credit and criminal record checks and employment referencing.
- Work is delivered personally. No subcontracting or associate model, and no client is named as a reference without written permission.
- Insurance certificates available on request; higher limits arranged where a framework requires it.