Quarterlytics / Technology / Information Technology Services / ECSC Group plc

ECSC Group plc

ecsc · LSE Technology
Claim this profile
Ticker ecsc
Exchange LSE
Sector Technology
Industry Information Technology Services
Employees 51-200
← All annual reports
FY2020 Annual Report · ECSC Group plc
Sign in to download
Loading PDF…
ECSC Group plc
Annual Report Year Ended 31 December 2020

This page has been left deliberately blank.

Page 2

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Contents

4 Company Information

7 Chairman’s Statement

8 Chief Executive Officer’s Review

12 Chief Operating Officer’s Review

14 What We Do

17 ECSC Story

18 Typical Client Journey

19 Client Challenges

20 Client Perspective

21 Research and Development

22 Evolving Threats

23 Market Opportunities

24 Strategic Report

35 Board of Directors

37 Directors’ Report

43 Remuneration Committee Report

50 Statement of Directors Responsibilities

“I’m pleased to note that we have maintained 
a stable team throughout these difficult times, 
with staff retention at an improved rate of 91%.

On behalf of the board, I would like to thank 
all of our clients, partners, team, advisors, 
and investors for their continued support 
throughout a challenging year for us all.

ECSC is well-positioned in the growing 
cyber security marketplace, and we are now 
resuming our organic growth strategy and 
related recruitment activities. ”

David Mathewson
Non-Executive Chairman

51 Independent Auditor’s Report to the Members of ECSC Group plc

59 Consolidated Statement of Comprehensive Income

60 Consolidated Statement of Financial Position

61 Company Statement of Financial Position

62 Consolidated Statement of Changes in Equity

63 Company Statement of Changes in Equity

64 Consolidated Cash Flow Statement

65 Company Cash Flow Statement

66 Notes to the Financial Statements

Page 3

ECSC Group plcAnnual Report Year Ended 31 December 2020Nominated Advisor & Broker to the Company
Allenby Capital Limited
5 St. Helen’s Place
London
EC3A 6AB

Auditors to the Company
BDO LLP
Central Square
29 Wellington Street
Leeds
LS1 4DL

Financial Press and Investor Relations
Yellow Jersey PR
ecsc@yellowjerseypr.com
0203 004 9512

Solicitors to the Company
Freeths LLP
1 Vine Street
Mayfair
London
W1J 0AH

Registrar
Equiniti Group plc
Sutherland House
Russell Way
West Sussex
RH10 1UH

Company Information

Directors
David Mathewson (Non-Executive Chairman)
Ian Mann (Chief Executive Officer)
Lucy Sharp (Chief Operating Officer)
Gemma Basharan (Chief Financial Officer )*
Ian Castle (Chief Technical Officer)*
Elizabeth Gooch (Non-Executive Director)

*Appointed on 25 March 2020

Registered Office
28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR

Telephone Number
01274 736 223

Company Secretary
David Mathewson

Website
www.ecsc.co.uk

Page 4

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Highlights

22%

6%

Managed Detection & 
Response (MDR) 
recurring revenue 
growth of 22%
 to £2.42m
(2019: £1.98m)

MDR revenue up 
6% to £2.73m
(2019: £2.59m)

£0.4m
PROFIT

£5.66m

Adjusted EBITDA* 
profit £0.4m
 (2019: break-even)

Revenue of £5.66m 
(2019: £5.91m)

£1.12m

90

Cash at period end 
£1.12m**
The Group’s bank facility 
remains unutilised
(31 Dec 2019: £0.35m)

90 new Assurance 
clients secured
(2019:118)

* Adjusted EBITDA excludes one-off charges and share based charges
** Including £0.42m of COVID-19 related medium-term government support relating to VAT and PAYE deferral 

Page 5
Page 5

ECSC Group plcAnnual Report Year Ended 31 December 2020MDR

ASSURANCE

VENDOR

OTHER

Track Record Of Organic Growth

£6,000,000

£5,000,000

£4,000,000

£3,000,000

£2,000,000

£1,000,000

0

2014-2015

2016*

2017**

2018

2019

2020

* Adjusted for 12 months
** Restated for IFRS 15

Global Offering

General Office

Security Operations Centre

Incident Response

Page 6

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020The Group’s successful £0.5m (before costs) 
fundraise in April 2020 demonstrated the continued 
support from our institutional investors and reduced 
our risk exposure during the uncertain months 
of 2020. As a result of the growth in profitability 
and cash generation, the Group did not utilise this 
additional funding.

I am pleased to note that we have maintained a 
stable team throughout these difficult times, with 
staff retention at an improved rate of 91%.

On behalf of the board, I would like to thank all of 
our clients, partners, team, advisors, and investors 
for their continued support throughout a challenging 
year for us all.

ECSC is well-positioned in the growing cyber 
security marketplace, and we are now resuming our 
organic growth strategy and related recruitment 
activities. 

David Mathewson
Non-Executive Chairman
23 March 2021

Chairman’s Statement

These results demonstrate solid growth in the 
Group’s adjusted EBITDA profitability and cash 
generation.  The encouraging progress we have 
seen in our Managed Detection and Response 
(MDR) division has been driven by continuing 
market demand and increasing awareness 
of ECSC’s expertise in both the development 
of technologies and in the area of Artificial 
Intelligence (AI).  This highlights the ongoing 
requirements for all organisations to maintain their 
cyber security defences, and we have emerged from 
the most difficult period imaginable in a strong 
position.

Despite the ongoing uncertainty caused by the 
pandemic and the economic risks associated with 
Brexit, the Group has continued to demonstrate 
resilience and financial progress based on quality 
of delivery and unrivalled client reputation and 
retention. I am proud of the way the team has 
adapted in order to achieve a very credible set 
of results throughout a period of unprecedented 
economic turmoil.

The confirmation of the multi-million-pound fines 
related to the UK and European General Data 
Protection Regulation (GDPR) substantiate the 
new regulatory environment that all organisations 
have to acknowledge; building resilience into their 
cyber security protection, detection and response 
capabilities.  ECSC remains the trusted partner to 
help organisations of all sizes achieve this.

The continued growth in 24/7/365 detection services, 
delivered through the Security Operations Centres 
(SOCs) in the UK and Australia, supported by the 
ECSC Kepler Artificial Intelligence (AI), shows the 
importance of early breach detection to contain the 
incident and limit damaging consequences.  For all 
but the largest global organisations, the outsourcing 
of this critical function continues to be the logical 
choice, and ECSC has the technology, people, and 
certified processes to deliver.

Page 7

ECSC Group plcAnnual Report Year Ended 31 December 2020Chief Executive Officer’s Review

The direct revenue impact of COVID-19 was most 
evident in two areas:

Firstly, the Assurance division, comprising mainly 
consultancy type services, was impacted with client 
cancellations and delays to confirmed projects.  
Having seen Assurance growth in Q1 2020 of just 
over 4% compared with the 2019 average quarterly 
revenue, Q2 2020 saw revenue drop by over 50% 
against the same comparator.

However, Q3 2020 demonstrated a rapid recovery to 
only 4% down on average 2019 quarterly revenues, 
with Q4 returning to growth of over 6% against the 
same comparator.

£800,000

£700,000

£600,000

£500,000

£400,000

£300,000

£200,000

£100,000

0

ASSURANCE 
REVENUE

2019 AV.

Q120

Q220

Q320

Q420

Secondly, client chargeable expenses declined from 
£53k in Q1 2020 to only £8k in Q2 2020, and only £21k 
combined in Q3 2020 and Q4 2020 as remote working 
continued.

The combined reductions in revenue for the 
Assurance division in Q2 and expenses for the year 
came to over £400k. This compares with the overall 
Group revenue reduction of £242k for the year, 
showing the reduced revenue was due to the short-
term impact of COVID-19.

The Group made solid progress during the 2020 
financial year, and we are particularly pleased to 
report growing adjusted EBITDA profitability and 
cash generation.

The £3m of Group revenue in H2 illustrates the 
recovery in the Assurance division following the 
COVID-19 related impact seen in Q2. The continued 
growth in recurring MDR revenue demonstrates 
the resilience of this service line, and our effective 
strategy of winning consulting clients and 
converting them into long-term managed services 
clients.

COVID-19 Impact
One year ago, at the time of publishing our annual 
results, the potential impact of the pandemic was 
beginning to emerge.  As such, we led our Annual 
Report with our strategy of managing the situation.  
This included:

1.  Re-engineering services traditionally delivered 
on-site with clients to enable remote and home 
working, ensuring the safety of our clients and 
our team.

2.  Ensuring the continued delivery of off-site 24/7 

managed services with uninterrupted compliance 
with all agreed Service Level Agreements (SLAs).
3.  Making use of government support and reducing 
costs to a break-even level during the short-term 
period of revenue loss.

The management team, and the efforts of all 
employees, ensured we met the first two objectives 
and exceeded the third.

To reduce the overall risk to the Group, in April 
2020 we conducted a fully subscribed £0.5m (before 
costs) fundraise from existing and new institutional 
investors to strengthen our cash position, and 
reduce the risks of either an extended lockdown, or 
potential long-term disruption without the uncertain 
government support.

Page 8

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Chief Executive Officer’s Review cont.

£60,000

£50,000

£40,000

£30,000

£20,000

£10,000

0

CLIENT 
EXPENSES

2019 AV.

Q120

Q220

Q320

Q420

Return to Profitability
The combination of the strong recovery in the 
Assurance division in Q3, the continued recurring 
revenue growth in the MDR division of 22%, and 
careful control of costs, saw Group Adjusted EBITDA 
profit of £0.4m (2019 break-even).

Growth Strategy
We are confident that the organic growth strategy of 
ECSC remains appropriate.  Despite the challenges 
of 2020, we added 90 new Assurance division clients. 
In addition, we expanded the Partner Programme 
to over 150 partners, contributing to 4% of revenue 
(2019: 2%) and 13% of the new client wins.

Key Performance Indicators
The Key Performance Indicators below were 
established in 2018 to enable meaningful 
measurement of the Group’s performance.  See page 
10.

Outlook
ECSC is well-positioned in the growing cyber 
security marketplace and looks forward with 
confidence to delivering improved operating results 
and shareholder value.

Ian Mann
Chief Executive Officer
23 March 2021

Page 9

ECSC Group plcAnnual Report Year Ended 31 December 2020Key Performance Indicator Table

Key Performance Indicator Table

Performance 
Indicator

Rationale

2020

2019

2018

Management Comment

Revenue Growth

Measurement of the 
success of the organic 
growth strategy

(4%)

10% 35%

Managed Detection 
and Response 
Recurring Revenue 
Growth

Visibility of the success of 
increasing the percentage 
of revenue from long-term 
recurring revenues

Managed Detection 
and Response 
Recurring Revenue 
Proportion

Visibility of the success of 
increasing the percentage 
of revenue from long-term 
recurring revenues

Managed Detection 
and Response 
Order Book

Combined measurement 
of new client contracts 
together with renewals of 
existing client contracts

22% 27% 46%

43% 34% 29% In line with the strategy to 
increase this proportion

£2.6m £2.6m £2.5m

Managed Detection 
and Response 
Gross Margin

Delivery efficiency 
measurement

73% 68% 53%

Assurance Repeat 
Revenue

Quasi-recurring from 
longer-term consulting 
clients

73% 73% 78%

Assurance Gross 
Margin

Delivery efficiency 
measurement

58% 54% 57%

Research and 
Development
 (of revenue)

Continued investment in 
technology and intellectual 
property development

14% 13%

8%

Page 10

The Group saw a decline 
in Assurance revenue 
and rechargeable 
expenses due to COVID-19 
pandemic. Assurance 
revenues returned to 
growth in Q4

Continued growth due to 
new contract wins and 
contract expansions, 
building on the 2017 
investment.

The management team’s 
favoured overall measure 
of progress in managed 
services

Indicative of increased 
leveraging of IPO 
investment in capacity

Indicative of strong client 
retention and continued 
trust in ECSC quality

A reflection on capacity 
required for growth and 
management of consultant 
workload

A new measure introduced 
to show continued 
investment in technologies 
for the future

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Ian Mann, CEO, Security Operations Centre, Yorkshire

Page 11

ECSC Group plcAnnual Report Year Ended 31 December 2020Chief Operating Officer’s Overview

Our in-house recruitment strategy continues to 
serve us well to ensure we attract and recruit the 
best people across all teams, guaranteeing the right 
mix of skills and diversity that complement and 
enhance the current team.  Despite the pandemic, 
we have still been able to leverage our student 
placement, graduate and apprenticeship schemes, 
working closely with local universities, to ensure an 
appropriate pipeline of talent, so we have the right 
people in the right positions, for now and also with 
succession planning in mind for the future.

We are very proud of the way in which everyone has 
navigated through these challenging times, with 
minimal detrimental impact on our ability to both 
engage and retain our people, to successfully deliver 
our services, to maintain quality in what we do, as 
well as introduce new members across the business 
in support of our growth plans.

I am pleased to be resuming recruitment activities 
and have every confidence in the team to continue to 
deliver the excellent service we are known for.

Lucy Sharp
Chief Operating Officer
23 March 2021

Whilst the last 12 months have been challenging for 
everyone due to the COVID-19 pandemic, the Group 
has not lost sight of the importance of our people 
and this has been at the forefront when considering 
plans to navigate through these unusual times.  

As clients came to terms themselves with working 
remotely and therefore halting their own security 
projects, we saw a reduction in consultancy in Q2 
of the year.  For the Assurance division, historically 
delivering consultancy services predominantly on 
client sites, our teams had to adapt very quickly, 
switching to delivering all our services remotely. 
The team has responded remarkably well and this 
is reflected in the excellent client feedback we have 
received.  After re-engineering our service offering 
to be delivered remotely, we were able to bring 
consulting delivery back up to pre-COVID numbers 
through Q3 and Q4, finishing the year in a strong 
position. 

We are delighted to report that we have maintained 
a stable team through these difficult times as seen 
from our 91% staff retention rate.  Our most recent 
Employee Engagement Survey showed that the team 
continues to feel their contribution is valued and 
morale and commitment is as strong as ever.  This is 
testament to our continued people-focused strategy, 
and in turn protects the strong, positive culture we 
have built at ECSC – one of continual development, 
learning and communication.

Professional development across all teams has 
continued throughout the last 12 months, meaning 
individuals feel equipped to be the best they can 
be and are on the front foot in this ever-changing 
cyber landscape.  Within the Assurance division for 
example, this enables individuals to contribute to 
multiple service lines to increase their experience 
and skills, while also increasing utilisation levels, 
promoting innovation and our ability to respond to 
market demand. 

Page 12

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Employee Engagement Survey 2020

“I really enjoy 
working at ECSC and 
hope to for many 
years to come”

“I have never felt so 
appreciated in a role 
as I do at ECSC”

“The Senior 
Management Team 
are awesome, 
always willing to 
help and support”

97%
have faith in the 
Senior Management 
Team to deliver on 
their objectives
97%

feel proud of ECSC

98%

have a good working 
relationship with 
their team

97%
want to make a 
difference in helping 
the Company 
succeed

Sample response to our latest Employee Engagement Survey

Page 13

ECSC Group plcAnnual Report Year Ended 31 December 2020What We Do

Incident response 
‘emergency’ service

Remotely manage client 
cyber security devices 
from ECSC’s Security 
Operations Centre (SOC)

Cyber security reviews

Consultancy to help 
clients achieve ISO 27001 
information security 
certification

Technical penetration 
testing of cyber security

Advise and assess clients 
for certification to the 
Payment Card Industry 
Data Security Standard 
(PCI DSS)

Develop Artificial 
Intelligence (AI)

Cyber Essentials
Certifications

Page 14
Page 14

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020What We Do

For most organisations, understanding their cyber security responsibilities is often complex and 
challenging, with new threats discovered daily.  The priority given by organisations to cyber security 
has changed significantly since we started 20 years ago, helped most recently by the introduction of the 
General Data Protection Regulation (GDPR), the mandatory reporting of breaches to the Information 
Commissioner’s Office (ICO) and increased fines.  Given the legal responsibility now placed on 
organisations to protect personal data, the sensible approach for most is to seek external help.

Despite the complexities of cyber security, a consultative approach remains at the heart of ECSC’s offering.  
All communications are carried out in a format and language that is easy to be understood by all.

ECSC’s range of services can be broken down into three basic categories.

Despite regular scaremongering by certain product vendors, press releases from 
organisations that have suffered a breach, and at times the media, all breaches are 
preventable.  We confidently make this statement based on 20 years experience in 
incident response.

An organisation’s primary strategy should be breach prevention.  ECSC helps in a 
number of ways.  The most common is to test cyber security using similar techniques 
to those used by hackers.  In the industry, this is referred to as penetration testing or 
ethical hacking.  Finding the vulnerabilities before a hacker does and remedy accordingly.

Although it may be possible to prevent all breaches, it is also sensible to have an ability 
to detect breaches.  Done correctly, this means that incidents can usually be contained 
before expensive data-loss occurs.  Additionally, under GDPR, there is a requirement to 
be able to detect breaches.

ECSC’s full 24/7/365 cyber security monitoring, alerting, and analysis from the both UK 
and Australian Security Operations Centres provides our managed service clients with 
peace of mind.

Although it makes little sense for all but the largest organisations to build, and try 
and retain, an internal incident response capability, it does makes sense to have a 
relationship with external experts that can respond 24/7. 

ECSC’s 20 years of incident experience mean that we can assist our clients from 
the smallest and simplest event, to the most complex incident requiring extensive 
investigation, an on-site team, and guidance with external stakeholder and regulator 
communications.

Page 15
Page 15

ECSC Group plcAnnual Report Year Ended 31 December 2020ECSC Group plc, Security Operations Centre, Yorkshire

Page 16

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020The ECSC Story

“I’ve got to say what a great piece of 
work your team have produced - really 
impressed with the quality of the 
document and the people. I am confident 
that this will be the start of a long and 
illustrious relationship with ECSC”.

The ECSC story begins in the 
dotcom boom of the late 1990s.  
Ian Mann was conducting 
government consultancy and 
running one of the first UK Cisco 
training academies, teaching 
the first generation of Internet 
engineers.  Having just completed 
an MBA, Ian was looking to start 
his own business.  He noticed 
that the security element of the 
network training was the biggest 
challenge for most students and 
therefore concluded that this 
would be a growing need for 
organisations as they began to 
fully utilise the Internet. 

With the financial help of his credit 
cards, two re-mortgages, the 
backing from family and friends, 
and a few work colleagues, ECSC 
was born.  ECSC’s second recruit 
was Lucy Sharp (now COO) who 
Ian employed as a school leaver.

Initially testing the security of 
organisations’ new connections 
to the Internet, and responding 
to security incidents, very quickly 
clients began to enquire whether 

ECSC could manage this critical 
area.  In 2001, the Group’s 
managed services division began; 
taking internally developed 
technologies originally for ECSC’s 
own use, and applying them to 
client environments.

As the industry began to mature, 
and international standards began 
to emerge, ECSC then started 
supporting clients efforts to 
achieve and manage a range of 
certifications.

Although focusing fully on ECSC, 
Ian continued to do some advisory 
work for the UK’s GCHQ, and 
more recently trained their new 
cyber security recruits in the art of 
people hacking (having authored 
two books on the subject of social 
engineering).

The next significant appointment 
was Ian Castle, who joined in 2003 
as CTO to co-ordinate the research 
and development that forms 
the foundation of the already 
award winning ECSC proprietary  
technology and managed services.

Senior Support Analyst
Major Utilities Supplier 

The next current senior 
management appointments came 
in 2007, when Paul Lambsdown 
took charge of the Group’s sales 
function, with Gemma Basharan 
later joining the finance team 
in 2011, and Clare Macdonald 
establishing the marketing team 
in 2013.

Despite numerous offers to 
buy the business, in 2016 
ECSC decided to raise the first 
institutional investment via 
an initial IPO on the London 
Stock Exchange AIM market.  
This investment enabled the 
establishment of new Security 
Operations Centres in the UK and 
Australia, giving true 24/7/365 
‘eyes on glass’ cyber security 
monitoring, without the need for 
engineers to work night shifts.

Today, the senior management 
team has over 80 years combined  
experience within ECSC.

Page 17

ECSC Group plcAnnual Report Year Ended 31 December 2020Typical Client Journey

A client journey with ECSC tends to start from one of three starting points:

HELP, WE THINK WE’RE 
IN THE MIDDLE OF A 
BREACH!

THE OWNERS/DIRECTORS 
NEED TO KNOW IF 
THEIR ORGANISATION IS 
SECURE?

WE NEED TO 
DEMONSTRATE OUR 
CAPABILITY THROUGH 
A RECOGNISED 
CERTIFICATION

Incident response call-outs can 
happen at any time (although 
they are more common outside of 
business hours).  

The priority here is to help contain 
the breach, understand how to 
prevent re-occurrence and then 
deal with any ongoing impact.  
Following this, a longer-term view 
can be developed to help prevent 
a repeat breach and enable the 
organisation to function efficiently 
with an appropriate level of 
security.

The ECSC Cyber Security Reviews 
are often a good place to start, as 
they give non-technical managers 
and owners a clear picture of 
the risks and a pragmatic route 
to risk reduction and ongoing 
management.

Where a technical person asks 
the same question, a more 
‘traditional’ penetration test 
may be the best solution.  By 
duplicating the approach of a 
hacker, we help a client uncover, 
and address, their vulnerabilities 
before a breach occurs.

The emergence of a number of 
UK and international standards, 
means that clients have an 
opportunity to demonstrate 
competence and develop 
trust with their stakeholders. 
Increasingly, this is becoming 
essential to doing business in 
some sectors, and taking part in 
sales tenders.

Although the initial objective may 
be ‘get the badge’, the process of 
certification usually does lead to 
organisational learning, and real 
enhanced security.

Although it is rare that a fully 24/7 managed solution is a starting point, it is increasingly the destination.  
Clients recognise that it is almost impossible to recruit and retain this level of expertise in-house, but do 
require the benefits associated with a 24/7 managed solution.

The ECSC approach has always been to understand the client’s requirements, give honest, practical advice, 
and deliver effective solutions that contribute to building long-term partnerships based on trust and value.

Page 18

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Typical Client Challenges

Cyber security brings many and varied new challenges for organisations of all sizes and complexities.  
They cut across vertical sectors and traditional competencies.

There are some common features in the challenges that we help our clients to solve:

DIFFICULTY IN RECRUITING 
AND RETAINING SPECIALIST 
SKILLS IN CYBER SECURITY

THE RATE OF 
COMMUNICATION AND 
INFORMATION
TECHNOLOGY CHANGE

UNDERSTANDING 
THE COMMON MYTHS 
PROPAGATED BY SOME 
VENDORS AND/OR THE MEDIA  

This may be due to the cost of 
funding a specialist role, or not 
having the right environment 
to attract them.  With a general 
skills shortage, qualified and 
experienced people have the 
choice of roles and will tend to 
be attracted by the variety and 
challenge, plus the chance to 
further develop their skills, not 
just by the money.  

However, it can also be a case that 
organisations won’t need some 
skills full-time, only at specific 
times.  For example, it makes little 
sense for most organisations to 
try and recruit people skilled in 
emergency incident response - an 
organisation may only need this 
once a year.

The increasing pace of change can 
nearly always be associated with 
new cyber security vulnerabilities.  

Despite what they say, technology 
providers do not make security a 
priority over their profits.  

For example, in the last 
12-months, people migrating 
IT systems into the cloud have 
accounted for 90% of the breaches 
we have been called out to resolve.

These include the belief that 
breaches cannot be prevented 
(in 20 years of incident response, 
we have never seen or heard of a 
breach that was not preventable). 

Another common myth is that 
hackers target organisations 
because they are looking for 
specific targets.  The reality is 
that most breaches are a result 
of organisations making technical 
or people mistakes that are then 
spotted and exploited by malicious 
hackers.

Page 19

ECSC Group plcAnnual Report Year Ended 31 December 2020Client Perspective

It is fair to say that all ECSC clients want to prevent cyber security breaches.  However, they also want 
more than this.  They usually require a range of services that have some common elements:

EASY TO UNDERSTAND DELIVERY OUTPUTS THAT 
EXPLAIN CYBER SECURITY IN A LANGUAGE THEY 
UNDERSTAND

Easy to understand delivery outputs that explain 
cyber security in a language they understand. 

This may be an ECSC Cyber Security Review that 
maps and grades technical weaknesses into 
a language that non-technical executives can 
understand.  This custom ECSC approach is now 
proven to be the best way for non-technical senior 
managers to understand current risks, and measure 
progress towards a more defendable position.

Another example is where we summarise complex 
penetration testing (ethical hacking) into a simple 
Pass/Fail result that managers and business owners 
can understand, with prioritised findings - each 
graded by risk.  This allows clients to address 
findings in order of priority.

AN ONGOING PARTNERSHIP
 BUILT ON TRUST

It is common for our partnership with a client to 
develop over many years.  Their requirements evolve 
as their technology usage changes, new threats 
emerge and they recognise the value that our 
expertise can bring to their organisation.  

In most cases, small initial engagements develop, 
and in many cases these evolve into full 24/7/365 
outsourced managed services.

VALUE

EMERGENCY RESPONSE

Delivering the intended outcomes efficiently and 
professionally.  Clients value the benefits of 20 years 
experience across the range of consulting, managed 
services and incident response.  An unrivalled mix 
for any UK provider.  This means less risk for clients 
than selecting new entrants. 

If the worst happens, ECSC clients (and non clients) 
benefit from an experienced and calm response 
by an expert team.  Early expert involvement in 
potential breaches means that incidents can usually 
be contained before expensive data-loss or system 
disruption occurs.  

If an incident does escalate, ECSC helps in all 
aspects of response management from the 
technical response and investigation to stakeholder 
and regulator communications.

Page 20

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Research and Development

Our continued investment in Research and Development takes many forms, all of which are of crucial 
importance to our continued success:

WHAT THE HACKERS ARE 
DOING

MANAGED SYSTEMS

INTERNAL SYSTEMS 

Each day, globally, there are about 
40 new technical ‘vulnerabilities’ 
discovered and published.  
Keeping track of these, and how 
they relate to an organisation’s 
IT system, is complex.  In reality 
only a small number of these are 
critical but extensive experience is 
needed to recognise the important 
trends and developments.  

Within ECSC we review new 
vulnerabilities formally every 8 
hours, 365 days a year and relate 
them to our systems, systems 
managed for clients, and wider IT 
environments.  We do this, so that 
our clients do not need to.

Whilst technology continues to 
advance, most new offerings 
are designed to be pioneering 
and functional with security 
taking a back-seat. This means, 
new IT developments, such as 
cloud services, have introduced 
significant new vulnerabilities, 
resulting in an increased need for 
our incident response services.  

With managed security devices 
deployed since 2001, ECSC has a 
long track record of intellectual 
property development, and 
delivering systems that work for 
our clients.  

The release of our Kepler Artificial 
Intelligence (AI) technology is an 
example, where we can process 
billions of pieces of security 
information from client’s IT 
systems and allow our Security 
Operations Centres to operate 
with efficiency and speed.  

Although some people over hype 
AI, we see this as enhancing the 
effectiveness of real experts, but 
not yet replacing the need for 
skilled, experienced people.

Given the sensitivity of our client 
data, ECSC does not allow any 
third-parties to store or process 
our information.  

Therefore, continued development 
of our internal systems is 
important to allow us to refine 
processes and enhance our 
effectiveness.

Our integrated management 
systems mean that we have 
complete process control from the 
start of our marketing activities 
through to assurance delivery and 
fully managed services.

Page 21

ECSC Group plcAnnual Report Year Ended 31 December 2020Evolving Threats

Cyber security has evolved, as have the risks to every organisation.  There is now the recognition that 
personal data has value, and with that comes a legal requirement to keep it secure.

Organisations also recognise that an increasing reliance on information technology means that a breach can 
have immense impact on day-to-day operations.

Originally, before the term ‘cyber security’ was invented, most hacking was conducted by enthusiasts - often 
with no malicious intent.  For example, the first computer virus was actually an experiment in a university 
that worked too well and spread globally.

However, as more and more organisations and individuals connected to the Internet, criminals recognised 
the potential to exploit technology weaknesses, knowing the law enforcement agencies would have 
difficulties catching them.

As a result, we have seen huge increases in hacking that results in criminal behaviour.  The most common 
being:

RANSOMWARE.  Where the hacker encrypts data and demands a ransom to give you 
access to your own data.  For an individual this may be their photo collection, whereas for 
an organisation it may be to cripple their whole IT system.

STEALING DATA.  Information has value, as it can form the basis of fraud.  Therefore, 
credit card information and other personal data will always be a target as it can be sold 
on.

More recently, nation state hackers have gained significant media coverage, and, quite rightly, attention 
from the areas of government tasked with protecting critical national infrastructure.  However, for most 
organisations they are not a target for this activity.  The reality remains that hacking is not targeted, rather 
it exploits mistakes and weaknesses identified by scanning the Internet for known vulnerabilities and also 
tricking IT users into causing breaches.

Therefore, organisations need help in keeping up-to-date with the continually changing threat landscape, 
and understanding and controlling the potential impact of users being caught out.  ECSC remains at the 
leading edge of both these critical areas.

Page 22

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Market Opportunities

The EU General Data Protection Regulation (GDPR), 
enacted in the UK in May 2018 by a new Data 
Protection Act (DPA) represents the most significant 
legal protection to personal data in more than a 
decade.  This new legislation impacts the cyber 
security market place in three main ways:

In addition, the GDPR states that third-party 
‘processors’ must apply cyber security in relation to 
the risks present, not in proportion to their charges.  
This means all IT outsourcing organisations have to 
re-examine their approach to cyber security risk.

1.  Mandatory Reporting
Organisations now have to report breaches of 
personal data to the Information Commissioner’s 
Office (ICO) within 72 hours of being made aware.

This means that breaches can no longer be hidden 
and kept ‘in-house’.  Organisations should seek 
expert assistance to ensure that they have responded 
appropriately to avoid substantial fines.

2.  New Maximum Fines
Increased from the previous £500,000 maximum to 
10m Euros or 2% of total worldwide turnover.  

3.  Direct ICO Liability for Third-Parties
Previously IT providers could hide behind their 
agreed terms and conditions, with liability limits, if 
they caused a cyber security breach.  The advent of 
GDPR gives them an independent liability to the ICO 
with the same maximum fines.

Other factors are also driving more market 
opportunities, including:

•  The uptake of cloud IT services, where applying 
‘traditional’ cyber controls can be difficult 
or impossible, and providers often lack the 
expertise to design security into their cloud 
offerings.

•  Ongoing skills shortages in cyber security 

make more clients seek external help, either 
to test their security, help implement specific 
projects, or to outsource their cyber security 
management.

•  The pace of IT system changes and new 

developments shows no sign of slowing. History 
shows that the quicker technology changes, 
the more cyber security vulnerabilities are 
introduced and the more breaches occur. 

UK cyber security market 
estimated at over £8 billion

Proliferation of breaches 
making cyber security a 
strategic governance issue 
for company boards

UK legislation (GDPR) now 
in force making immediate 
breach reporting 
mandatory and fines up to 
2% of global turnover

Page 23

ECSC Group plcAnnual Report Year Ended 31 December 2020 
Cyber Security Experts
Annual Report Year Ended 31 December 2020

Page 24

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Review

Principal Activities

The principal activity of the Group during the year continued to be the provision of professional cyber security 
services, including Assurance, MDR and the sale of Vendor Products.

Comparative Financial Information

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

Revenue

Assurance

MDR

Vendor Products

Other

Gross Profit

Assurance

MDR

Vendor Products

Other

Adjusted EBITDA*

Other Income

Sales & Marketing Costs

Administration Expenses

EBITDA**

Share Based Payments

Exceptional Items

Depreciation and Amortisation

Adjusted Operating Loss*

Operating Loss

2,724

2,732

125

82

5,663

1,576

1,994

25

(47)

3,548

297

(1,713)

(1,757)

375

(101)

(65)

(209)

(480)

(105)

(271)

* Adjusted Operating Loss and Adjusted EBITDA excludes one-off charges and share based charges. 
* * EBITDA is defined as Earnings before Interest, Tax, Depreciation and Amortisation

(As defined in note 25 in the Financial Statement).

2,922 

2,585

162

236

5,905

1,574

1,745

29

12

3,360

263

(1,958)

(1,664)

1

(105)

(6)

(110)

(594)

(593)

(704)

Page 25

ECSC Group plcAnnual Report Year Ended 31 December 2020Financial Review (continued)

Revenue & Organic Growth

controls. 

Total revenue in the year ended 
31 December 2020 was £5.66m, 
down 4% on the comparable prior 
period (revenue in the 12 months 
ended 31 December 2019 was 
£5.91m). Within this, Assurance 
revenue fell by 7% to £2.72m 
(2019: £2.92m).

EBITDA & Operating Loss

Adjusted EBITDA for the year, 
which excludes one-off charges 
and share based charges, was 
£0.4m (2019: Break-even). EBITDA 
for the year was a profit of £0.21m 
(2019: loss of £0.11m). 

MDR division revenue rose by 
6% in the year to £2.73m (2019: 
£2.59m). This includes recurring 
revenue which rose to £2.42m 
(2019: £1.98m) and Incident 
Response revenues which fell to 
£0.31m (2019: £0.60m).

Adjusted Operating Loss for 
the year, which excludes one-
off charges and share based 
charges, was £0.11m (2019: loss 
of £0.59m). The Operating Loss in 
the year was £0.27m (2019: loss of 
£0.70m).

of £0.29m from HMRC in respect 
of a surrender of R&D Tax Credits 
from earlier periods.

Tangible Asset

Property, plant and equipment 
(PPE) cost has remained at 
£0.95m (2019: £0.95m). This is 
offset by depreciation of £0.81m. 
The Group’s capital expenditure 
for the year was £0.01m. The Net 
Book Value of Tangible Assets as 
at 31 December 2020 was £0.15m 
(2019: £0.28m).

Trade and Other Receivables

Trade and other receivables 
decreased to £0.81m (2019: 
£0.89m) as at 31 December 2020. 
This includes £0.61m of Trade 
receivables.

Trade and Other Payables

Trade and other payables 
increased to £2.09m (2019: 
£1.82m) as at 31 December 2020. 
This includes £0.88m of deferred 
income (2019: £0.87m).

Cash Flow

Cash and cash equivalents 
increased by £0.77m to £1.12m 
as at 31 December 2020 primarily 
due to improved margins across 
the Assurance and MDR divisions, 
£0.29m of COVID-19 related 
Government grants, and the 
proceeds from the fund raise 
undertaken during the year which 
raised £0.5m (before costs). 

Intangible Asset

Key Performance Indicators

The Key Performance Indicators 
are set out on page 10.

Intangible asset costs have 
increased to £1.28m (2019: 
£1.09m). This is offset by 
amortisation of £0.82m. The 
Group’s development cost for the 
year was £0.19m. The Net Book 
Value of Intangible Assets as at 
31 December 2020 was therefore 
£0.46m (2019: £0.43m). During the 
year, the Group received a refund 

Vendor Products revenue in the 
year fell by 23% to £0.13m (2019: 
£0.16m).

Margin Generation

Gross Profit for the year was 
£3.55m, yielding a 63% margin 
(2019: £3.36m, yielding a 57% 
margin). This was due to improved 
margins across the Assurance, 
MDR and Vendor divisions.

The Assurance margin rose to 
58% in the year (2019: 54%). This 
was due to cost controls over the 
period.  The Board expects the 
Assurance margin to continue at a 
similar level in the future.

The MDR margin rose to 73% 
(2019: 68%), with the increase 
being a direct result of new 
contracts utilising the capacity 
built in previous years and cost 

Page 26

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Review (continued)

These factors give the Directors 
confidence in relation to going 
concern.

For further information please see 
pages 69.

Dividend

The Board has not declared a 
dividend for the year ended 31 
December 2020 (2019: £nil).

Gemma Basharan
Chief Financial Officer
23 March 2021

Balance Sheet

The Group’s Balance Sheet 
as at 31 December 2020 had 
Net Assets of £0.65m (2019: 
£0.37m). Retained Earnings and 
Distributable Reserves as at 31 
December 2020 were a cumulative 
loss of £5.94m (2019: cumulative 
loss of £5.67m).

Going Concern 

The Directors have assessed 
the going concern status of the 
Group by reference to a number 
of factors.  In particular, the 
Directors have considered the 
strong rate of growth in the cyber 
security market; the fact that 
business continues to attract new 
clients and is not overly dependent 
on any single client; the fact that 
the business continues to retain 
key staff, and that the Group has 
a secured invoicing discounting 
facility of £0.5m, which remains 
unused. The facility was renewed 
in August 2020 for a minimum 12 
months period with a three month 
notice period. 

The Board expects to renew 
the facility for a further 12 
months following the annual 
review expected in August 2021. 
However, if it is not renewed, the 
cash-flow forecast demonstrates 
that the facility is for prudence 
only and is not relied upon. The 
Board is positive about the future 
EBITDA trajectory of the Company 
and continues to manage the cash 
position of the Company carefully. 

Page 27

ECSC Group plcAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties

ECSC Group plc (‘ECSC’ or ‘the Company’ or ‘the Group’) is exposed to a number of Macro, Business and 
Financial risks.  The Board is responsible for ensuring that the Group has taken a proactive approach to the 
identification and mitigation of these risks in a timely manner.

Summary of Risks

The most significant risks to the Group are summarised in the table below. These risks are explained in 
further detail following the summary. The table does not include all the potential risks associated with Group 
activities and are not in any order of priority.

Principal Risks

Economic conditions

Rapid technological change

Competition

Cyber security breach

Reputation

Dependence on key personnel

Ability to recruit and retain skilled personnel

Reliance on key systems

Client acquisition

Client retention

Future funding requirements

Mitigating Actions/Factors

Expenditure on cyber security has become non-
discretionary in nature and is less sensitive to economic 
fluctuations

Investment in proprietary intellectual property

Maintaining a broad, full-service offering

Certifications to ISO 27001, PCI DSS and Cyber 
Essentials; avoidance of technologies associated with 
common security breaches

Consistent focus on legal, financial, regulatory and 
technological compliance

Board and Senior Management structure and 
remuneration is designed to reduce the risks associated 
with the loss of any single person

Ongoing development of a wide range of employee 
benefits and incentives, career progression and technical 
development

Disaster recovery and business continuity plans

Sales team training and development, partner 
programme, and expanded marketing activities.

Expanded service delivery function and service 
management layer

Flotation on the Alternative Investment Market of the 
London Stock Exchange

Page 28

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)

Macro Risks

Economic Conditions and 
uncertainty including Brexit and 
COVID-19 

demand for cyber security 
services are expected to increase 
in the future

Geopolitical Risks

The Group could be affected 
by national and international 
economic factors outside its 
control, including an economic 
slowdown, changes in the 
monetary and fiscal policies of 
the Government, exchange rate 
fluctuations, commodity price 
volatility, inflation, increases in 
interest rates and banking sector 
conditions.

The Group’s operations now or 
in the future may be adversely 
affected by factors outside the 
control of the Group, including 
election results, changes in 
Government policy, terrorist 
activities, labour unrest, civil 
disorder and political upheaval, 
war, subversive activities and 
sabotage, fires, floods, natural 
disasters and epidemics.

Any UK economic downturn, 
either globally or locally, may have 
an adverse effect on the demand 
for the Group’s services. A more 
prolonged economic downturn 
may lead to an overall decline 
in the volume of the Group’s 
activities and sales, restricting the 
Group’s ability to realise a profit. 

However, given the proliferation of 
cyber security breaches and the 
damage caused, in financial and 
reputational terms, expenditure 
by corporates on cyber security is 
increasingly of a non-discretionary 
nature, such that demand has 
become less sensitive to general 
economic fluctuations.

The recent COVID-19 global 
pandemic has brought additional 
challenges to the business 
environment. However during 
2020 UK businesses saw an 
increase in cyber attacks and 

Business Risks

Technology 

The markets in which the Group 
operates are characterised by 
rapid technological change, 
changes in client requirements, 
frequent product and service 
introductions employing new 
technologies, and the emergence 
of new industry standards and 
practices that could render the 
Group’s existing technology and 
services obsolete. 

In order to compete successfully, 
the Group will need to continue 
to improve its services, and to 
develop and market new products 
that keep pace with technological 
change. This may place strain 
on the Group’s capital resources, 
which may adversely impact the 
revenues and profitability of the 
Group.

The success of the Group depends 
on its ability to anticipate and 
respond to technological changes 
and client requirements in a 
timely and cost-effective manner. 
There can be no assurance 
that the Group will be able to 
effectively anticipate and respond 
to technological changes and 
client needs in the future.

Intellectual Property

In order to mitigate Technology 
risk and maximise its competitive 
advantage, the Group seeks to 
protect its intellectual property. 
Much of the Group’s intellectual 
property is not of a nature 
that is capable of registration, 
so protection of intellectual 
property relies on maintaining 
the confidentiality of know-how, 
methodologies and processes 
which, in turn, are largely 
dependent on people. There is a 
risk that if the confidentiality of 
the Group’s intellectual property 
were compromised, this could 
lead to a loss of competitive 
advantage. To mitigate this risk, 
the Group employs strict terms 
of confidentiality in its standard 
terms of employment.

The Group’s software is largely 
developed in-house. However, 
some aspects of it are based 
on open-source licences such 
as the General Public License 
(a widely used form of license 
within the free and open-source 
code software domain), which 
oblige ECSC to provide access to 

Page 29

ECSC Group plcAnnual Report Year Ended 31 December 2020 
Principal Risks and Uncertainties (continued)

the source code of the relevant 
software package if a client 
requests it. There is a limited risk 
that ECSC could be pursued by 
way of enforcement action in this 
area, which may have a material 
adverse effect on the Group’s 
performance.

Competition 

There can be no guarantee that 
the Group’s current competitors 
or new entrants to the market will 
not bring superior technologies, 
products or services to the 
market, or equivalent products 
at a lower price, which may have 
an adverse effect on the Group’s 
business. Such companies may 
also have greater financial and 
marketing resources than the 
Group. These competitive risks 
are mitigated by maintaining a full 
service offer, spanning Consulting 
and Managed Services, with a 
strategic focus on expanding 
the recurring revenue base from 
retained clients, underpinned by 
a proactive account management 
process.

Cyber Security Breach 

As with all providers in this sector, 
the potential embarrassment and 
reputational impact of a major 
cyber security breach for ECSC 
itself is significant. However, 
ECSC manages this risk in a 
number of ways:

•  External certification to 
international security 

standards, such as ISO 27001 
and PCI DSS. 

•  Avoidance of technologies 

commonly targeted for attack 
– ECSC makes extensive use 
of Linux-based technologies, 
including all operational 
desktop PCs and laptops, and 
does not support Bring Your 
Own Device (BYOD) policies 
for any company business, 
including for Associate 
Consultants. 

•  The Company directs the 
same level of security 
expertise at its own security 
as to that of its clients, 
avoiding the common issue 
with IT companies that their 
own internal IT is managed 
by a less capable internal 
team than their client-facing 
delivery team.

Reputation

The Group’s reputation, in terms 
of the services it provides, the 
manner in which it conducts 
its business and the financial 
performance it achieves, are 
central to the Group’s success. 

The Group’s services, and the 
software on which they are based, 
are complex and may contain 
undetected defects when first 
introduced. Such defects could 
damage the Group’s reputation, 
ultimately leading to an increase 
in the Group’s costs or reduction 
in its revenues. 

Other issues that may give rise 

to reputational risk include, but 
are not limited to, failure to deal 
appropriately with legal and 
regulatory requirements in any 
jurisdiction (which may result in 
the issuance of a warning notice 
or sanction by a regulator or an 
offence being committed by a 
member of the Company or any 
of its employees or Directors), 
money-laundering, bribery and 
corruption, factually incorrect 
reporting, staff disputes, 
fraud (including on the part of 
clients), technological delays 
or malfunctions, the inability to 
respond to a disaster, lack of data 
privacy, and poor record-keeping.

In addition, failure to meet the 
expectations of clients, suppliers, 
employees, shareholders, 
regulators and other business 
partners may have a material 
adverse effect on the Group’s 
reputation.

To mitigate these varied risks, the 
Group has adopted a strict and 
thorough approach to compliance, 
investing resources to meet 
relevant legal, financial, regulatory 
and technological standards and 
requirements.

Dependence on Directors and 
Senior Management 

The Group’s performance is 
substantially dependent on 
the continued services and 
performance of its Directors 
and senior management. 
Although certain Directors and 

Page 30

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)

key personnel have entered into 
Service Agreements or Letters of 
Appointment with the Group, there 
can be no assurance that the 
Group will retain their services. 
The loss of the services of any of 
the Directors or key personnel 
may have a material adverse 
effect on the business, operations, 
relationships and/or prospects of 
the Group. 

The risk of loss of a Director or 
member of senior management 
is mitigated by offering market 
competitive remuneration for 
key roles, including appropriate 
levels of equity incentivisation via 
the share option schemes of the 
Group. 

Ability to Recruit and Retain 
Skilled Personnel

The Group believes that it has 
the appropriate incentivisation 
structures to attract and 
retain the calibre of employees 
necessary to ensure the growth 
and development of the Group. 
However, any difficulties 
encountered in hiring appropriate 
employees and the failure to do 
so may have a detrimental effect 
upon the trading performance 
of the Group. The ability to 
attract new employees with the 
appropriate expertise and skills 
cannot be guaranteed. 

Reliance on Key Systems

The Group’s dependency 
upon technology exposes it to 

significant risk in the event that 
such technology or the Group’s 
systems experience any form of 
damage, interruption or failure. 

The Group’s systems are 
vulnerable to damage or 
interruption from events 
including:
•  power loss and infrastructure 

failure; 

•  fire or physical destruction;
•  computer hacking activities; 

and

•  acts of criminal damage or 

terrorism.

Any malfunctioning of the Group’s 
technology and systems, or those 
of key third parties, even for a 
short period of time, could result 
in a lack of confidence in the 
Group’s services, the termination 
of client contracts and potential 
claims for damages, with a 
consequential material adverse 
effect on the Group’s operations 
and performance.

The Group has a well-considered, 
certified and regularly rehearsed 
disaster recovery and business 
continuity plan to mitigate this 
risk.

New Client Acquisition and 
Retention of Existing Clients 

The Group’s future success 
depends on its ability to increase 
sales of its services and products 
to new clients, increase sales to 
its existing clients, and maintain 
existing client contractual 

relationships. 

The rate at which new and 
existing clients purchase services 
and existing clients renew their 
contracts depends on a number 
of factors, including the efficacy of 
the Group’s services and the utility 
of the Group’s new offerings, as 
well as factors outside of the 
Group’s control, such as clients’ 
perceived need for security 
solutions, the introduction 
of services by the Group’s 
competitors that are perceived 
to be superior to the Group’s 
services, end clients’ IT budgets 
and general economic conditions. 
A failure to increase sales as a 
result of any of the above could 
materially adversely affect the 
Group’s financial performance and 
position. 

Failure to Develop, Launch and 
Market New Services

The Group’s long-term growth and 
profitability is dependent on its 
ability to develop and successfully 
launch and market new services. 
The Group’s revenues and market 
share may suffer if it is unable 
to successfully introduce new 
products in a timely fashion or if 
any new or enhanced products 
or services are introduced by its 
competitors that its customers 
find more advanced and/or better 
suited to their needs. 

While the Group continuously 
invests in research and 
development to develop products 

Page 31

ECSC Group plcAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)

in line with client demand and expectations, if it is not able to keep pace with product development and 
technological advances, including shifts in technology in the markets in which it operates, or to meet client 
demands, this could have a material adverse effect on the Group’s financial performance and position. 

Financial Risks

Future Funding Requirements

Although not presently anticipated by the Directors, the Group may need in the future (more than twelve 
months) to raise equity or additional debt capital to fund future acquisitions, expansion and/or business 
development. There can be no guarantee that the necessary funds will be available on a timely basis, on 
favourable terms, or at all, or that such funds, if raised, would be sufficient. If the Group is not able to 
obtain additional capital on acceptable terms, or at all, it may be forced to curtail or abandon acquisition 
opportunities, expansion and/or business development. The Board anticipates to renew the £0.5m invoice 
discounting facility it currently has with Barclays in August 2021. There is no guarantee that the Group will 
be able to renew the facility. However if it not renewed the cash-flow forecast demonstrates that the facility is 
not reliant upon but for prudence only.

This risk is partially mitigated by the Group’s quotation on the Alternative Investment Market of the London 
Stock Exchange, which provides a conduit to equity investors.

Page 32

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Statement by the Directors

Statement by the Directors in 
performance of their statutory 
duties in accordance with s172(1) 
Companies Act 2006

• 

high standards of business 
conduct; and
the need to act fairly as 
between shareholders of the 
Company.

The Board of Directors of 
ECSC Group plc consider that, 
individually and together, they 
have acted in the way which in 
good faith would be most likely 
to promote the success of the 
company for the benefit of its 
members as a whole (having 
regard to the stakeholders and 
matters set out in s172(1)(a-
f) of the Act) in the decisions 
taken during the year ended 31 
December 2019.

The Board looked to promote the 
success of the Company, having 
regard to the long term, whilst 
taking into account the interests 
of all stakeholders. It is designed 
to secure the long-term financial 
viability of the Company to the 
benefit of its members and all 
stakeholders, and in doing so have 
regard (amongst other matters) 
to:

• 

• 

• 

• 

• 

the likely consequence of any 
decisions in the long-term;
the interests of the company’s 
employees;
the need to foster the 
company’s business 
relationships with suppliers, 
customers and others;
the impact of the company’s 
operations on the community 
and environments;
the desirability of the company 
maintaining a reputation for 

The following paragraphs 
summarises how the Directors 
fulfil their duties:

Risk management

We provide business-critical 
service to our clients. As we 
grow, our business and our risk 
environment also becomes more 
complex. It is therefore vital that 
we effectively identify, evaluate, 
manage and mitigate the risks 
we face and that we continue 
to evolve our approach to risk 
management.

For details on our principal risks 
and uncertainties and how we 
manage our risk environment, 
please see page 28.

Our People

The Board recognises that our 
employees are fundamental to 
the delivery of our plan. We aim 
to be a responsible employer 
in our approach to the pay and 
benefits our employees receive. 
The health, safety and well-being 
of our employees is of primary 
concern in the way we do business 
and is monitored extensively by 
the Board and taken into account 
in all major decision-making.

For further information please see 

page 12.

Business Relationships

Our strategy prioritises organic 
growth, driven by cross-selling 
and up-selling services to 
existing clients and bringing 
new clients into the Group. To 
do this we need to continue to 
develop and maintain strong client 
relationships. 

We also aim to act responsibly 
and fairly in how we engage 
with our clients and suppliers, 
co-operate with our regulators 
and act on feedback received 
from these stakeholders. All of 
these considerations are taken 
into account by the Board when 
making strategic decisions for the 
Company.

Community and environment

Our plan considered the impact of 
the company’s operations on the 
community, the environment and 
our wider social responsibilities. 
The Group wants to positively 
impact the lives of the people we 
work with and for, providing long-
term benefits to its employees, 
customers, suppliers and 
individuals in our local and wider 
community.  We will do this by 
acting in a socially responsible 
way; and encouraging our staff 
and business partners to strive 
for matching performance; 
encouraging our staff to be 
mindful of the effect of their 
actions on any natural resource.

Page 33

ECSC Group plcAnnual Report Year Ended 31 December 2020Statement by the Directors

Shareholders
The Board is committed to openly engaging with its shareholders, as we recognise the importance of 
effective dialogue, whether with major institutional investors, private or employee shareholders.  It is 
important to us that shareholders understand our strategy and objectives, so these must be explained 
clearly, feedback heard and any issues or questions raised properly considered.

For further information on how we engage with our shareholders please see page 37.

As the Board of Directors, our intention is to behave responsibly with all stakeholders and to ensure 
that management operates the business in a responsible manner, operating within the high standards 
of business conduct and good governance expected for a business such as ours.  Acting in this way will 
contribute to the delivery of our plan and we intend to maintain our reputation within the industry for 
responsible and compliant behaviour.

As the Board of Directors, our intention is also to make decisions which lead to the long-term success of 
the company whilst behaving responsibly toward our shareholders, treating them fairly and equally, so they 
benefit from the successful delivery of our strategy and plan.

Gemma Basharan
Chief Financial Officer
23 March 2021

Page 34

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Board of Directors

The Board of ECSC Group plc comprises four Executive Directors and two Non-Executive Directors. The 
Board has considered its independence and effectiveness, and is satisfied to the degree of competence and 
efficiency in place.

The Board is responsible for the formulation of business strategy, operational execution, financial 
performance and compliance. The Executive Directors are responsible for day-to-day operational and 
financial management, whilst the Non-Executive Directors are responsible for delivering effective corporate 
governance.

The profile of each Director is as follows:

David Mathewson | Non-Executive Chairman 
David is a Chartered Accountant who has spent most of his career in merchant banking and as a non-
executive director. He was an Executive Director of Noble Grossart Limited, Scotland’s premier merchant 
bank, for many years. Previous non-executive roles include Chairman of Sportech Plc and he was also a 
Director of Playtech Group plc. During his tenure at Playtech, he was appointed Chief Financial Officer 
and oversaw the company move from AIM to the Main Market of the London Stock Exchange. He is 
currently a Non-Executive Director of AIM traded SEC Newgate SPA, an Italian company, also traded on 
AIM, and Chairman of Scram Group Ltd. The Board has reviewed David’s time commitment from his other 
directorships and has concluded that they average six to seven working days per month. The Board is 
therefore comfortable that David has sufficient available capacity to carry out his duties as a Non-Executive 
Chairman of ECSC Group plc.

Ian Mann | Chief Executive Officer
Ian has over 19 years of experience in the cyber-security sector, having founded ECSC. He was previously 
an advisor for GCHQ, and established a Cisco Networking Academy for Dixons City Technology College. Ian’s 
professional certifications include CISSP, PCI QSA, and ISO Lead Auditor. Ian holds a B.Eng. in Electrical and 
Electronic Engineering from the University of Nottingham, and an MBA from the Open University.

Lucy Sharp | Chief Operating Officer
Lucy has over 19 years of experience in the cyber-security sector, having joined ECSC at its inception. Lucy 
worked as an ISO 27001 consultant, leading this area prior to taking the position of Operations Director 
in 2012. Lucy has held a number of professional certifications, including CISSP, PCI QSA, and ISO Lead 
Auditor. Whilst working at ECSC, Lucy completed a Masters in Business Management at Leeds Metropolitan 
University.

Elizabeth Gooch MBE | Non-Executive Director
Elizabeth Gooch is an award-winning UK tech entrepreneur, having started her career in industry, joining 
Forward Trust (a subsidiary of Midland Bank) and then Birmingham Midshires Building Society, before 
establishing eg solutions in 1988. She pioneered the introduction of industrial production management 
methodologies into the service sector and invented the eg operational intelligence ® software suite to 
embed these techniques into businesses. eg was listed on the Alternative Investment Market and was 
acquired by a major US Software Company in 2017. Elizabeth was named as one of The Telegraph’s Most 
Disruptive Entrepreneurs and West Midlands Woman of the Year for her Outstanding Contribution to 

Page 35

ECSC Group plcAnnual Report Year Ended 31 December 2020Board of Directors

Technology. She was made a Member of the Order of the British Empire in the Queens Jubilee Birthday 
Honours 2012, in recognition of her achievements in delivering significant benefits for clients with the 
products she designed. Elizabeth is now CEO of The Tech Growth Factory; a company she established to 
assist the founders of small technology companies achieve their growth potential.

Ian Castle | Chief Technology Officer
Ian joined ECSC in 2003 and has been involved in the design and implementation of all technical aspects of 
ECSC’s service lines and is now focused on managed services. Ian ensures the smooth and secure running 
of our own systems and heads up our research and development efforts.

Gemma Basharan | Chief Financial Officer
Gemma is a Chartered Accountant who has over 14 years of financial experience both in the private and 
charity sector. Gemma joined ECSC in 2011 as a management accountant before taking the position of 
Financial Controller in 2016, and to Chief Financial Officer in April 2020.

BOARD OF DIRECTORS

DAVID MATHEWSON
Non-Executive Chairman

IAN MANN
CEO

LUCY SHARP
COO

IAN CASTLE
CTO

GEMMA BASHARAN
CFO

ELIZABETH GOOCH
Non-Executive Director

Page 36

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

The Directors present their report 
and financial statements for the 
year ended 31 December 2020.

Principal Activities and Review of 
the Business

The principal activity of the Group 
during the year continued to 
be the provision of professional 
cyber security services. Future 
developments of the Group have 
been reviewed as part of the 
Strategic Report.

Principal Risks and Uncertainties

For information on the principal 
risks and uncertainties of the 
Group, please see pages 28 to 32 
of the Strategic Report.

Statements).  

Research and Development

Research and development 
activities are grouped into three 
broad areas: 

•  Proprietary software, 
operating systems, 
applications, tools and 
documentation used to provide 
Managed Services.

•  Proprietary software, tools and 
techniques used to provide 
Consulting Services.
•  Core internal business 

systems to support revenue 
generating activities.

Chairman Corporate Governance

Results and Dividends

Overview

The loss for the period, after 
taxation, amounted to £269k 
(2019: loss of £776k). The Board 
has not declared a dividend for 
the year ended 31 December 2020 
(2019: £nil).

Going Concern
The Directors are satisfied that 
the Group has sufficient financial 
resources to continue to operate 
for the foreseeable future, which 
is considered to be at least the 12 
months from the date of approval 
of the financial statements. For 
this reason, the going concern 
basis is considered appropriate 
for the preparation of the financial 
statements (for more information 
see note 4.2 to the Financial 

As Chairman of the Board 
of Directors of ECSC Group 
plc it is my responsibility to 
ensure that ECSC has both 
sound corporate governance 
and an effective Board. As 
Chairman, my responsibilities 
include leading the Board 
effectively, overseeing the 
Company’s corporate governance 
model, communicating with 
shareholders, and ensuring that 
good information flows freely 
between Executives and Non-
Executives in a timely manner. 

ECSC Group plc has adopted the 
QCA Corporate Governance Code 
in line with the London Stock 
Exchange’s recent changes to the 

AIM Rules, requiring all AIM-listed 
companies to adopt and comply 
or explain non-compliance with a 
recognised corporate governance 
code. The Board considers that 
the Group complies with the QCA 
Code so far as it is practicable 
having regard to the size, nature 
and current stage of development 
of the Company, and will disclose 
any areas of non-compliance in 
the text below. The Board believes 
that corporate governance is 
a framework which underpins 
the core values for running the 
business in which we all believe, 
including a commitment to open 
and transparent communications 
with stakeholders.  Further details 
on Corporate Governance is on 
the Group’s website at https://
investor.ecsc.co.uk/governance/
corporate-governance.html.

QCA Principles

1.  Establish a strategy and 
business model which 
promotes long-term value for 
shareholders

The Board has concluded that 
the highest medium and long-
term value can be delivered to 
its shareholders by a focused 
strategy for the Company.  Details 
of Business Strategy  can be found 
on pages 8-9. 

2. 

 Seek to understand and 
meet shareholder needs and 
expectations

The Group is strongly committed 

Page 37

ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

to the maintenance of good 
investor relations and seeks, 
wherever possible, to build 
a relationship of mutual 
understanding with both 
its institutional and private 
client investors. The Company 
communicates how it is 
governed and is performing 
through its Annual Report and 
Accounts, full-year and half-
year announcements, regulatory 
announcements and its website: 
https://investor.ecsc.co.uk/. The 
Group have a dedicated email 
address investor@ecsc.co.uk  for 
shareholder enquiries.

3.  Take into account wider 
stakeholder and social 
responsibilities and their 
implications for long-term 
success.

The Board recognises that the 
long-term success of the Group 
is reliant upon the efforts of the 
employees of the Group and its 
suppliers, regulators and other 
stakeholders. The Group prepares 
an annual strategic plan and 
detailed budget which considers 
a wide range of key resources and 
stakeholders. Everyone within 
the Group is a valued member 
of the team, and our aim is to 
help every individual achieve 
their full potential. We offer 
equal opportunities regardless 
of race, gender, gender identity 
or reassignment, age, disability, 
religion or sexual orientation. See 
employee survey, (page 12).

4.  Embed effective risk 

6. 

management, considering 
both opportunities and 
threats, throughout the 
organisation.

 Ensure that between 
them the Directors have 
the necessary up-to-date 
experience, skills and 
capabilities.

The Board attaches considerable 
importance to the Company’s 
system of internal control and 
risk management. An ongoing 
process has been established 
for identifying, evaluating, and 
managing the significant risks 
faced by the Group. Details of key 
risks to the business can be found 
on page 28.

5.  Maintain the board as a well-

functioning, balanced team 
led by the Chair.

ECSC is controlled by the Board 
of Directors. There are two 
independent Directors; David 
Mathewson and Elizabeth Gooch. 
Their time commitment to ECSC 
are as follows:

•  David Mathewson: devotes at 
least two full working days 
in each calendar month to 
perform the duties of office; 
and

•  Elizabeth Gooch: reasonable 
endeavours to attend all 
meetings of the Board and/
or committees of the Board of 
which she is a member and to 
attend all general meetings of 
the Company. 

Details of the Board and the roles 
can be found on pages 35-36.

The Directors have both a breadth 
and depth of skills and experience 
to fulfil their roles and deliver 
the strategy of the Group for the 
benefit of the shareholders over 
the medium to long-term. The 
Group believes that the current 
balance of skills in the Board as a 
whole, reflects a very broad range 
of commercial and professional 
skills. The Directors continue to 
develop their skill set and keep up 
to date with current regulations in 
their prospective markets.

Details of the Directors’ 
experience and areas of expertise 
are outlined on pages 35-36.

7.  Evaluate board performance 
based on clear and relevant 
objectives, seeking 
continuous improvement.

The Board informally review board 
performance as part of the day 
to day running of the business. 
ECSC Group plc has yet to carry 
out a formal assessment of board 
effectiveness and the Board will 
keep this under consideration and 
put in procedures when it is felt 
appropriate.

The Company has adopted a code 
for Directors’ and employees’ 
dealings in securities which is 
appropriate for a company whose 

Page 38

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

securities are traded on AIM, 
and is in accordance with the 
requirements of the Market Abuse 
Regulation which came into effect 
in 2016.

8. 

 Promote a corporate culture 
that is based on ethical values 
and behaviours.

The company has clearly defined 
values upon which our culture and 
behaviours are based. These are 
outlined in the Chief Operating 
Officer’s Overview on pages 12.

9.  Maintain governance 

structures and processes 
that are fit for purpose and 
support good decision-
making by the board.

The Board is committed to, 
and ultimately responsible for, 
high standards of corporate 
governance, and has chosen to 
adopt the QCA Code. We review 
our corporate governance 
arrangements regularly and 
expect to evolve these over 
time, in line with the Group’s 
growth. The Board delegates 
responsibilities to Committees 
and individuals as it sees fit, with 
the Chairman being responsible 
for the effectiveness of the Board, 
and the Executive Directors being 
accountable for the management 
of the Company’s business and 
shareholder liaison.

10. Communicate how the 

Committee Responsibilities 

company is governed and is 
performing by maintaining a 
dialogue with shareholders 
and other relevant 
stakeholders.

The Board is strongly committed 
to the maintenance of good 
investor relations and to having 
constructive dialogue with its 
shareholders.  Executive Directors 
and Chair seek to meet with 
shareholders and other investors/
potential investors at regular 
intervals during the year.

Committee Chairman

This report sets out information 
about the remuneration of the 
Directors of the Company for the 
year ended 31 December 2020.  As 
a company admitted to AIM, ECSC 
Group is not required to prepare 
a Directors Remuneration report.  
However, the board supports 
the principle of transparency 
and has prepared this report 
in order to provide information 
to shareholders on Directors 
remuneration arrangements. 

THE REMUNERATION 
COMMITTEE

Committee Composition

Elizabeth Gooch MBE was 
appointed chair of the Committee 
on 16 April 2018.  The other 
member of the committee is David 
Mathewson.

The Remuneration Committee’s 
primary purpose is to ensure 
that the remuneration packages 
of the senior and most highly 
rewarded team at ECSC Group 
are both aligned to the company’s 
purpose and values and linked 
to the successful delivery of the 
company’s long-term strategy.

Committee Meetings

The Remuneration Committee 
met at least four times in the 
period, with other board members 
in attendance as appropriate. The 
Committees main activities during 
the year included: 

•  Approved proposals for 

changes in the remuneration 
of Directors for the 
forthcoming period.  

•  Agreed individual share option 

awards;

•  Agreed targets and 

performance measures for 
bonus payments for the 
forthcoming financial period; 
and

•  Administered the group’s 

share schemes.

In determining the Directors 
remuneration for the year, the 
Committee consulted Ian Mann, 
Chief Executive and Lucy Sharp, 
Chief Operating Officer about its 
proposals.

Page 39

ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

“As a Bradford based technology 
company, we’re were very happy 
to help this local school and to 
support the students continued 
learning during these difficult 
times. After all these children 
might be our apprentices in the 
future!” 

supplies to ensure a steady 
reduction in consumption.

Directors’ Interests and 
Remuneration

The Directors who held office 
during the period were as follows:

Charities are given discounted 
rates when engaging our services 
and where practicable we seek to 
support charities and/or clients 
in their CSR efforts e.g. providing 
prizes for raffles, raising money 
for their causes and attending 
charity functions. 

David Mathewson
Ian Mann
Lucy Sharp
Elizabeth Gooch 
Ian Castle
Gemma Basharan

Audit Committee

Environmental

ECSC Group plc recognises that 
it has a responsibility to the 
environment above and beyond 
regulatory requirements. Action 
on all parts of this policy will be 
the responsibility of all staff. The 
Management Team are committed 
to continuous improvements in 
our environmental performance.

Environmental regulations, laws 
and code of practice will be 
followed to ensure the continuous 
awareness of environmental 
issues and to maintain good 
practice in our operations.

Monitoring environmental 
performance will be part of our 
yearly board review.  We will 
monitor our energy consumption 
for improved environmental 
performance We will monitor 
our use of paper and other office 

The duties of the Audit Committee 
are to consider the relationship 
with the Company’s auditor 
(appointment, re-appointment and 
terms of engagement), to review 
the integrity of the Company’s 
financial statements, to keep 
under review the appropriateness 
of the Company’s accounting 
policies, and to review the 
effectiveness and adequacy 
of the Company’s internal 
financial controls. In addition, 
it will receive and review such 
reports as it from time to time 
requests from the Company’s 
management and auditor. The 
Audit Committee meets at least 
twice a year and has unrestricted 
access to the Company’s auditor. 
The Audit Committee comprises 
David Mathewson and Elizabeth 
Gooch and is chaired by David 
Mathewson.

Social Responsibility

ECSC Group plc’s commitment 
to the continuous improvement 
of our Corporate and Social 
Responsibility (CSR) strategy is 
an integral part of our company’s 
vision and values. We want ECSC 
Group plc to positively impact 
the lives of the people we work 
with and for, providing long-
term benefits to its employees, 
customers, suppliers and 
individuals in our local and 
wider community. We do this by 
acting in a socially responsible 
way; encouraging our staff and 
business partners to strive for 
matching performance; and, 
encouraging our staff to be 
mindful of the  effect of their 
actions on any natural resource. 

ECSC is a sponsor of the 
GiveBradford 100 Club which 
is a network of like minded 
organisations wanting to 
address the challenges facing 
the district. The GiveBradford 
scheme have distributed over £3.8 
million in grants to date across 
the Bradford District, enabling 
positive change in the lives of 
hundreds of thousands of people 
in our communities. 

During the 2020 ECSC supported 
a local secondary school by 
supplying wifi dongles to students 
who did not have internet at home 
and therefore could not continue 
their studies from home during 
lockdown or if they were forced 
to isolate. Lucy Sharp, COO said 

Page 40

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

Nomination Committee 

The duties of the Nomination Committee are to consider the structure, size and composition of the Board 
and make recommendations to the Board with regard to any changes. It is also responsible for identifying 
and nominating candidates to fill Board vacancies as and when they arise. The Nomination Committee 
also makes recommendations to the Board concerning, among other things, plans for succession for both 
Executive and Non-Executive Directors. It meets at least twice a year. The Nomination Committee comprises 
Elizabeth Gooch and David Mathewson and is chaired by David Mathewson.

Disclosure Committee

The Disclosure Committee is the first point of contact with the NOMAD for all routine and non-routine 
matters which the NOMAD wishes to discuss with the Board and shall carry out duties to ensure the 
Company’s compliance with the AIM Rules and Market Abuse Regulations. The Disclosure Committee meets 
twice a year and comprises David Mathewson and Elizabeth Gooch and is chaired by David Mathewson.

Attendance at Board and Committee meetings
There were 12 Board meetings held during the year, all of which were attended by Ian Mann, Lucy Sharp, 
David Mathewson and Elizabeth Gooch. Gemma Basharan attended 11 Board meetings and Ian Castle 
attended 7 Board meetings during the year. 

The Audit Committee had two meetings during the year at which both Elizabeth Gooch and David Mathewson 
attended.

The following Directors had interests in the ordinary shares of the Company as at 31 December 2020:

David Mathewson

Ian Mann

Lucy Sharp

Elizabeth Gooch

Ian Castle

Gemma Basharan

Number of 
Ordinary 
Shares

35,419

2,300,948

242,635

50,000

237,441

4,214

% of Issued 
Share
Capital

0.35%

22.99%

2.42%

0.50%

2.37%

0.04%

Details of the Directors remuneration are included in the Remuneration Report on pages 43-49.

Substantial Interests

At 31 December 2020, the Company had been notified, under the Disclosure guidance and Transparency 
Rules, of the following major shareholdings and the percentages of voting rights represented by such 
holdings, excluding the shareholdings and associated voting rights of the Directors noted above, as follows:

Page 41

ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020

Unicorn Asset Management

Ravinder Bahra

Hargreaves Lansdown

Artemis Investment Management

Phil McLear

Malcolm Hoare

John Leach

Annual General Meeting

Number of 
Ordinary 
Shares

% of Issued 
Share
Capital

1,448,946

1,069,068

343,721

294,733

472,290

300,300

283,920

14.48%

10.68%

3.43%

2.95%

4.72%

3.00%

2.84%

The next Annual General Meeting will take place on 23 June 2021.

Statement of Disclosure of Information to Auditor

The Directors of the Company who held office at the date of approval of this Annual Report as set out above 
each confirm that:

•  so far as each Director is aware, there is no relevant audit information of which the Company’s auditors 

are unaware; and

•  each Director has taken all the steps that they ought to have taken as a Director in order to make 

themselves aware of any relevant audit information and to establish that the Company’s auditors are 
aware of that information.

Auditor

BDO LLP has indicated its willingness to continue as auditor. Accordingly a resolution proposing its 
reappointment as auditor will be put to the members at the next Annual General Meeting.

On behalf of the Board

David Mathewson
Non-Executive Chairman
23 March 2021

Page 42

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report

As an AIM listed company ECSC Group plc is not required to comply with schedule 8 of the Large and 
Medium-sized Companies and Groups (Accounts and Reports) Regulations 2008. Nor is it required to comply 
with the principles relating to Directors remuneration in the UK Corporate Code 2018 (“the code”). The 
content of this report is unaudited unless stated.

Remuneration Policy

The objectives of the remuneration policy are to ensure that the overall remuneration of Executive 
Directors is aligned with the performance of the Group and preserves an appropriate balance of reward and 
shareholder value.  

The Company’s policy is to remunerate Directors appropriately such that they are sufficiently rewarded 
and incentivised for their level of responsibility, the complexity of their role and to reflect their skills and 
experience. The use of Annual Performance Bonuses and equity-based incentives, linked to Company 
performance, helps to align the interests of the Directors and Shareholders. 

The Remuneration Committee sets the level of basic pay and other benefits for Executive Directors and 
other Senior Managers. It does this in line with its assessment of the appropriate market rate for the roles, 
wishing to be able to attract and retain good candidates for these roles. In addition, the Company operates 
an Executive Annual Performance Bonus Scheme covering the Executive Directors. The criteria for payment 
of bonuses (which are not pensionable if paid) are set by the Remuneration Committee at the beginning of 
each financial year. The award of any bonus is decided by the Remuneration Committee at the end of the 
year by reference to the objectives set for the year, the corresponding performance of the Company, and by 
using its discretion. The Company also operates a share based incentive scheme as outlined below.

The Company’s policy is also that a substantial proportion of the remuneration of the Executive Directors 
should be performance related in order to encourage and reward improving business performance and 
shareholder returns.  In determining remuneration arrangements for Executive Directors, the Committee 
is sensitive to pay and employment conditions elsewhere in the Cyber Security and general IT Software and 
Services markets, especially when determining base salary increases.

The committee has reviewed the Remuneration Policy for the forthcoming year and has concluded that it 
remains appropriate for the forthcoming three year period. 

Page 43

ECSC Group plcAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)

The main components of the remuneration arrangements for Executive Directors are as follows:

Purpose & Link to Strategy

Operation

Maximum Opportunity

Performance Conditions

Base Salary
To provide fixed competitive 
remuneration that will attract 
and retain key employees and 
reflect their experience and 
position in the Group.

Reviewed annually taking into 
account industry-standard 
executive remuneration and 
pay levels elsewhere within the 
sector.

Benefits
To provide market levels of 
benefits on a cost-effective 
basis.

Private health cover for the 
executive and their family, life 
insurance cover of one-times 
salary and a company car.

Pension
Providing post-retirement 
benefits.

The Group contributes to 
individual’s personal pension 
schemes

Annual incentive
Recognises achievements 
of annual objectives which 
support the short to medium 
term strategy of the Group

Performance targets are set by 
the Remuneration Committee 
at the start of the year with 
input, as appropriate, from the 
Executive Directors

Executive Share Options Plan
Setting value creation 
through share growth as a 
major objective for Executive 
Directors and senior 
managers. Alignment of option 
holder interests with those of 
shareholders through delivery 
of shares.

The Group introduced a Share 
Option scheme during 2020. 
All the Executive Directors, 
participates in the EMI 
scheme. See below.

Salaries for the year ended 31 
December 2020 are set out 
below.

None.

Private healthcare benefits are 
provided through third-party 
providers and therefore the 
cost to the Company may vary 
from year to year.

None.

10% of base salary

None.

The bonus related Key 
Performance Indicators for 
this period were Revenue 
and EBITDA, and they were 
appropriately weighted.

The Executive Directors Annual 
Performance Bonus Scheme 
for 2021 was structured so 
as to pay up to 25% of basic 
salary for the Chief Executive 
Officer and Chief Operating 
Officer 20% of basic salary for 
the Chief Technology Officer 
and Chief Financial Officer 
based on the achievement of 
stretching targets in certain 
key performance indicators 
aligned with the Group’s 
strategy.

N/A

N/A

The committee reviewed the performance of the Executive Directors against the performance for the 
Annual Incentive scheme and concluded that the stretching targets agreed for the period had not been met. 
However, in recognition of achievements made with establishing a successful Partner Programme and other 
key objectives, the committee recommended payment of modest bonuses as detailed below.

Page 44

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)

The annual incentive paid to Executive Directors for the year ended 31 December 2020 was 7% of the basic 
salary of the Chief Executive, 8% of the basic salary of the Chief Operating Officer, 7% of basic salary of the 
Chief Technology Officer and 6% of basic salary of the Chief Financial Officer.

An Annual Performance Bonus Scheme for the Executive Directors is structured so as to pay up to 25% of 
basic salary for both the Chief Executive and Chief Operating Officer and 20% of basic salary for both the 
Chief Technology Officer and Chief Financial Officer. For the forthcoming period payment will continue to be 
based on the achievement of stretching targets in weighted Key Performance Indicators linked to the Group’s 
strategy.

The committee introduced a Long-Term Incentive Plan (“LTIP”) for the Executive Directors during 2020:

Vesting Period

Target Price

Ian Mann

Lucy Sharp

Ian Castle

Gemma Basharan

I Year

167 Pence

25,000

25,000

20,000

20,000

2 Years

200 Pence

25,000

25,000

20,000

20,000

3 Years

225 Pence

25,000

25,000

20,000

20,000

4 Years

250 Pence

Total Ordinary 
Shares

25,000

25,000

20,000

20,000

100,000

100,000

80,000

80,000

Remuneration for Non – Executive Directors

Remuneration of the Non-Executive Directors is determined by the Board within the limits set by the 
Company’s Articles of Association and is based on fees paid in similar companies, the skills required, 
and the expected time commitment required of each individual.  Non-Executive Directors are not entitled 
to pensions, annual bonuses or employee benefits. They are entitled to participate in share option 
arrangements relating to the Company’s shares and both were allocated 100,000 options on 20 April 
2018. The options had an exercise price of 78 pence and are subject to a three year vesting period and the 
performance condition that the Company’s closing mid-market share price must exceed 200 pence for 10 
consecutive business days following the vesting date. The grant represented 2% of the current issued share 
capital of the company. 

Each of the Non-Executive Directors has a letter of appointment stating his/her annual fee and that his/her 
appointment is initially for a term of three years, subject to re-appointment at the AGM and renewable for 
further periods of three years. Their appointment may be terminated with three months written notice at any 
time.

Page 45

ECSC Group plcAnnual Report Year Ended 31 December 2020 
Remuneration Committee Report (continued)

Annual Bonus Payments for 2020

Following the success of the financial year ended 31 December 2020, the committee resolved to pay modest 
bonuses (as set out in the table below) in recognition of the performance of the Executive Directors during 
the year. The bonuses were paid after the financial year end. 

Name of Director

Ian Mann

Lucy Sharp

Ian Castle

Gemma Basharan

David Mathewson

Elizabeth Gooch

Total

Salary or 
Fees Paid
£’000

Benefit-in-
Kind
£’000

Pension
£’000

Annual 
Bonus
£’000

Share Based 
Payments
£’000

200

125

100

80

65

40

610

2

14

1

-

-

-

17

20

13

10

4

-

-

47

13

10

7

5

-

-

35

4

58

38

4

8

8

120

Year ended 
31
 December 
2020
£’000

Year ended 
31 
December 
2019
£’000

239

220

156

93

73

48

829

214

181

-

-

89

48

532

Notes:
•  Benefits-in-Kind includes the provision of Company Cars and Private Medical insurance; and
•  Share Based Payments are stated at the cost of the award recognised in the financial period.

Ian Mann, Chief Executive is the highest paid Director. 

Employee Benefit Expense (including Directors) during the periods amounted to:

Wages and Salaries - Gross

Government Grants

Wages and Salaries

Social Security Costs

Pension Contributions

Share Based Payments

GROUP
Year ended
31 December
2020
£’000

GROUP
Year ended
31 December 
2019
£’000

COMPANY
Year ended
31 December
2020
£’000

COMPANY
Year ended
31 December
2019
£’000

4,269

(292)

3,977

452

179

101

4,709

4,091

-

4,091

440

153

105

4,789

4,033

(203)

3,830

404

161

101

4,496

3,944

-

3,944

392

134

105

4,575

During 2020 the Group has benefited from £0.2m of Coronavirus Job Retention Scheme (CJRS) and £0.1m of 
Australia grants. (see note 4.5)

Page 46

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)

Directors Interests

Details of the Directors Shareholdings are included in the Director’s Report on page 41.

Share Incentives

The Company operates an Enterprise Management Incentive (‘EMI’) Scheme. The EMI Scheme provides 
the opportunity for eligible Directors and employees to buy ECSC ordinary shares at a future date in 
accordance with the scheme rules. The options are subject to the option holder’s continuing employment, 
are not transferable, and have a life of 10 years. All grants under the scheme are subject to approval by the 
Remuneration Committee.

In August 2020 the Company cancelled over 588,040 Ordinary Share options to 20 employees, following 
the cancellation the Company granted options over 588,040 new Ordinary Shares to the same Company 
employees, at an exercise price of 65 pence per share. The exercise price was set by reference to the 
average mid-market share price being the closing market price on 20 August 2020 in accordance with HMRC 
guidelines. There was a performance condition attaching to this grant, ordinary shares trade at a mid-
market minimum price of 167 pence per share over 10 consecutive business days.

The Company also granted over 450,000 new Ordinary Shares to 32 employees, at an exercise price of 
69 pence per share, subject to a 1- 4 year vesting period. The exercise price was set by reference to the 
average mid-market share price being the closing market price on 27 August 2020 in accordance with HMRC 
guidelines. There was a performance condition attaching to this grant, ordinary shares trade at a mid-
market minimum price of 167 pence per share over 10 consecutive business days.

Page 47

ECSC Group plcAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)

Outstanding Share Based Awards

The outstanding Share Based Awards of the Directors as at 31 December 2020 are:

Name Of Director

Type Of 
Reward

Date Of 
Grant

Granted In 
Year

Vested In 
Year

Not Vested 
End Of Year

Lucy Sharp

Lucy Sharp

Lucy Sharp

Share Option

19 May 2017

Share Option

16 July 2019

69,758

50,000

Share Option

Lucy Sharp

Share Option

Lucy Sharp

Ian Mann

Ian Castle

Ian Castle

Ian Castle

Ian Castle

Ian Castle

Ian Castle

Gemma Basharan

Gemma Basharan

Gemma Basharan

Gemma Basharan

Gemma Basharan

Gemma Basharan

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

Share
Option

5 Feb 
2020

21 Aug
2020

28 Sept
2020

28 Sept
2020

19 May
2017

7 Aug
2018

16 July
2019

5 Feb
2020

21 Aug
2020

28 Sept
2020

19 May
2017

7 Aug
2018

16 July
2019

5 Feb
2020

21 Aug
2020

28 Sept
2020

Cancelled/
Lapsed 
In Year

69,758

50,000

25,000

25,000

144,758

100,000

100,000

-

-

-

18,602

18,602

50,000

50,000

15,000

15,000

20,000

20,000

103,602

80,000

-

-

4,651

4,651

25,000

25,000

15,000

15,000

20,000

20,000

64,651

80,000

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

Market 
Price At 
Grant

497.5p

78.0p

1.08p

Exercise 
Price

167.0p

78.0p

108.0p

-

-

-

144,758

0.65p

0.65p

100,000

0.69p

0.69p

100,000

0.69p

0.69p

-

-

-

-

497.5p

167.0p

0.93p

93.0p

78.0p

78.0p

1.08p

108.0p

103,602

0.65p

65.0p

80,000

0.69p

69.0p

-

-

-

-

497.5p

167.0p

0.93p

93.0p

78.0p

78.0p

1.08p

108.0p

64,651

0.65p

65.0p

80,000

100,000

100,000

0.69p

79.0p

79.0p

69.0p

78.0p

78.0p

Elizabeth Gooch

Share Option

18 Apr 2018

100,000

David Mathewson

Share Option

18 Apr 2018

100,000

The closing mid-market price of the Group’s shares at 31 December 2020 was 67.5 pence. During the 
financial year the share price reached a high of 145.0 pence and a low of 60.0 pence.

Page 48

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)

Directors Service Contracts 

The Service contracts and letters of appointment of Directors include the following terms:

Executive Directors

Ian Mann

Lucy Sharp

Ian Castle

Gemma Basharan

Date of Appointment

13 April 2018

02 November 2012

25 March 2020

25 March 2020

Non-Executive Directors

Date of Appointment

David Mathewson

Elizabeth Gooch

18 April 2018

16 April 2018

Statement of Voting at General Meeting

Notice Period

6 months

6 months

6 months

6 months

Notice Period

3 months

3 months

At the Annual General Meeting of the Company held (last years date 30 June 2020), all resolutions, except 
resolution 7, were passed. The Board notes that resolution 7, which would have enabled the Board to issue 
up to 20% of the Company’s issued share capital for cash, was not passed.

Approval

This report was approved by the Directors and signed by order of the Board. 

Elizabeth Gooch MBE
Chairman of the Remuneration Committee
23 March 2021

Page 49

ECSC Group plcAnnual Report Year Ended 31 December 2020 
Statement of Directors’ Responsibilities

The Directors are responsible for preparing the Annual Report and the financial statements in accordance 
with applicable law and regulations.

Company Law requires the Directors to prepare financial statements for each financial year. Under that law 
the Directors have elected to prepare the financial statements in accordance with International accounting 
standards in conformity with the requirements of the Companies Act 2006 .  Under Company Law the 
Directors must not approve the financial statements unless they are satisfied that they give a true and 
fair view of the state of affairs of the Company and the Group and of the profit or loss of the Group for the 
reporting period. In preparing these financial statements, the Directors are required to:

•  select suitable accounting policies and then apply them consistently;
•  make judgments and estimates that are reasonable and prudent;
•  state whether applicable accounting standards have been followed, subject to any material departures 

disclosed and explained in the financial statements; and

•  prepare the financial statements on the going concern basis unless it is inappropriate to presume that 

the Company will continue in business.

The Directors are responsible for keeping adequate accounting records that are sufficient to show and 
explain the Company’s transactions and disclose with reasonable accuracy at any time the financial position 
of the Company and enable them to ensure that the financial statements comply with the Companies Act 
2006.  They are also responsible for safeguarding the assets of the Company and hence for taking reasonable 
steps for the prevention and detection of fraud and other irregularities.

Financial information is published on the Company’s website. The maintenance and integrity of this website 
is the responsibility of the Directors. The work carried out by the Company’s auditors does not involve 
consideration of these matters and, accordingly, the auditors accept no responsibility for any changes that 
may occur to the financial statements after they are initially presented on the website.

It should be noted that legislation in the United Kingdom governing the preparation and dissemination of 
financial statements may differ from legislation in other jurisdictions.

By order of the Board

David Mathewson
Non-Executive Chairman
23 March 2021

Page 50

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Cyber Security Experts
Annual Report Year Ended 31 December 2020

Page 51

ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

Opinion on the financial statements

In our opinion:

• 

• 

• 

• 

the financial statements give a true and fair view of the state of the Group’s and of the Parent Company’s 
affairs as at 31 December 2020 and of the Group’s loss for the year then ended;
the Group financial statements have been properly prepared in accordance with international accounting 
standards in conformity with the requirements of the Companies Act 2006;
the Parent Company financial statements have been properly prepared in accordance with international 
accounting standards in conformity with the requirements of the Companies Act 2006 and as applied in 
accordance with the provisions of the Companies Act 2006; and
the financial statements have been prepared in accordance with the requirements of the Companies Act 
2006.

We have audited the financial statements of ECSC Group plc (the ‘Parent Company’) and its subsidiaries 
(the ‘Group’) for the year ended 31 December 2020 which comprise the Consolidated Statement of 
Comprehensive Income, the Consolidated and Company Statements of Financial Position, the Consolidated 
and Company Cash Flow Statements, the Consolidated and Company Statements of Changes in Equity and 
notes to the financial statements, including a summary of significant accounting policies. 

The financial reporting framework that has been applied in the preparation of the financial statements is 
applicable law and international accounting standards in conformity with the requirements of the Companies 
Act 2006 and, as regards the Parent Company financial statements, as applied in accordance with the 
provisions of the Companies Act 2006.

Basis for opinion

We conducted our audit in accordance with International Standards on Auditing (UK) (ISAs
(UK)) and applicable law. Our responsibilities under those standards are further described in the
Auditor’s responsibilities for the audit of the financial statements section of our report. We believe that the 
audit evidence we have obtained is sufficient and appropriate to provide a basis for our opinion. 

Independence

We remain independent of the Group and the Parent Company in accordance with the ethical requirements 
that are relevant to our audit of the financial statements in the UK, including the FRC’s Ethical Standard as 
applied to listed entities, and we have fulfilled our other ethical responsibilities in accordance with these 
requirements. 

Conclusions relating to going concern

In auditing the financial statements, we have concluded that the Directors’ use of the going concern basis of 
accounting in the preparation of the financial statements is appropriate. 

Page 52

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

As a result of the significant assumptions and judgements made by management in assessing going 
concern, which were based on their best estimates and analyses of the current market conditions, including 
the potential impacts of COVID-19, going concern was considered to be a key audit matter. 

Our evaluation of the Directors’ assessment of the Group and the Parent Company’s ability to continue to 
adopt the going concern basis of accounting included:

•  Obtaining and examining the Board’s Going concern paper, alongside supporting forecasts for the next 

two years.

•  Challenging management’s assumptions, such as revenue pipeline, as used in the forecast period 
through review of the historic forecast accuracy, comparing forecasts to post year end results, cost 
performance, current business trends and pipeline/contract analysis.

•  Considering the Board’s probable scenarios of sensitivities, including COVID-19 potential impact, to 

understand the robustness of the forecast trading model and the headroom available to the Group and 
Parent Company. 

•  Review of the available cash and financing facilities within the Group, and evaluation of management’s 

downside sensitivities on cash flow headroom, incorporating a review of financial covenants compliance 
and headroom analysis throughout the forecast period.

•  Review of the disclosures made in the financial statements and in the strategic report. We assessed 
whether these adequately disclose the basis of the judgements taken and the view formed by the 
Directors with respect to going concern. 

Based on the work we have performed, we have not identified any material uncertainties relating to events 
or conditions that, individually or collectively, may cast significant doubt on the entity’s ability to continue as 
a going concern for a period of at least twelve months from when the financial statements are authorised for 
issue. 

Our responsibilities and the responsibilities of the Directors with respect to going concern are described in 
the relevant sections of this report.

Coverage

Key audit matters

100% (2019: 100%) of Group loss before tax
100% (2019: 100%) of Group revenue
100% (2019: 100%) of Group total assets

Going concern assessment 

2020

x

2019

x

Materiality

Group financial statements as a whole

£108k (2019: £97k) based on 1.85% (2019: 1.65%) of revenue - refer to ‘Our application 
of materiality’ section below for details.

Page 53

ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

An overview of the scope of our audit

Our Group audit was scoped by obtaining an understanding of the Group and its environment, including 
the Group’s system of internal control, and assessing the risks of material misstatement in the financial 
statements.  We also addressed the risk of management override of internal controls, including assessing 
whether there was evidence of bias by the Directors that may have represented a risk of material 
misstatement.

Financial information relating to the Parent Company and its Australian operating subsidiary were subject to 
a full scope audit by the Group audit team, covering 100% of the revenue, loss before tax and total assets of 
the Group for the year.

Key audit matters

Key audit matters are those matters that, in our professional judgement, were of most significance in our 
audit of the financial statements of the current period and include the most significant assessed risks 
of material misstatement (whether or not due to fraud) that we identified, including those which had the 
greatest effect on: the overall audit strategy, the allocation of resources in the audit, and directing the 
efforts of the engagement team. These matters were addressed in the context of our audit of the financial 
statements as a whole, and in forming our opinion thereon, and we do not provide a separate opinion on 
these matters. Besides the matter described in the Conclusions relating to going concern section, we have 
not determined any other matters as key audit matters to be communicated in our report.

Our application of materiality

We apply the concept of materiality both in planning and performing our audit, and in evaluating the effect of 
misstatements.  We consider materiality to be the magnitude by which misstatements, including omissions, 
could influence the economic decisions of reasonable users that are taken on the basis of the financial 
statements. 

In order to reduce to an appropriately low level the probability that any misstatements exceed materiality, 
we use a lower materiality level, performance materiality, to determine the extent of testing needed. 
Importantly, misstatements below these levels will not necessarily be evaluated as immaterial as we also 
take account of the nature of identified misstatements, and the particular circumstances of their occurrence, 
when evaluating their effect on the financial statements as a whole. 

Page 54

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

Based on our professional judgement, we determined materiality for the financial statements as a whole and 
performance materiality as follows:

Materiality

Group financial statements

Parent company financial statements

2020
£’000s

108

2019
£’000s

97

2020
£’000s

104

2019
£’000s

92

Basis for determining materiality

1.85% of revenues

1.65% of revenues

1.85% of revenues

1.65% of revenues

Rationale for the benchmark applied

We considered revenue to be the most appropriate measure of performance and 
basis for determining materiality, given the volatility in loss before tax.

Performance materiality

81

73

78

69

Basis for determining performance materiality

75% of materiality, based upon there being a limited number of areas subject to 
significant estimation uncertainty and no significant errors identified in the prior 
period.

Component materiality

We set materiality for the one significant component of the Group (being the Parent company) based on 
a percentage of 96% (2019: 95%) of Group materiality, which is considered aligned with the size and our 
assessment of the risk of material misstatement of that component. In the audit of each component, we 
further applied performance materiality levels of 75% of the component materiality to our testing to ensure 
that the risk of errors exceeding component materiality was appropriately mitigated.

Reporting threshold  

We agreed with the Audit Committee that we would report to them all individual audit differences in excess of 
£4,320 (2019: £3,880).  We also agreed to report differences below this threshold that, in our view, warranted 
reporting on qualitative grounds.

Other information

The directors are responsible for the other information. The other information comprises the information 
included in the Group Strategic Report, Directors Report and Consolidated Financial Statements other than 
the financial statements and our auditor’s report thereon. Our opinion on the financial statements does 
not cover the other information and, except to the extent otherwise explicitly stated in our report, we do not 
express any form of assurance conclusion thereon. Our responsibility is to read the other information and, 
in doing so, consider whether the other information is materially inconsistent with the financial statements 
or our knowledge obtained in the course of the audit, or otherwise appears to be materially misstated. If we 
identify such material inconsistencies or apparent material misstatements, we are required to determine 
whether this gives rise to a material misstatement in the financial statements themselves. If, based on the 
work we have performed, we conclude that there is a material misstatement of this other information, we 
are required to report that fact.

We have nothing to report in this regard.

Page 55

ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

Other Companies Act 2006 reporting

Based on the responsibilities described below and our work performed during the course of the audit, we are 
required by the Companies Act 2006 and ISAs (UK) to report on certain opinions and matters as described 
below.  

Strategic report and Directors’ 
report

Matters on which we are required 
to report by exception

• 

• 

Responsibilities of Directors

In our opinion, based on the work undertaken in the course of the audit:
• 

the information given in the Strategic report and the Directors’ report for the financial 
year for which the financial statements are prepared is consistent with the financial 
statements; and
the Strategic report and the Directors’ report have been prepared in accordance with 
applicable legal requirements.

• 

In the light of the knowledge and understanding of the Group and Parent Company 
and its environment obtained in the course of the audit, we have not identified material 
misstatements in the strategic report or the Directors’ report.

We have nothing to report in respect of the following matters in relation to which the 
Companies Act 2006 requires us to report to you if, in our opinion:
• 

adequate accounting records have not been kept by the Parent Company, or returns 
adequate for our audit have not been received from branches not visited by us; or
the Parent Company financial statements are not in agreement with the accounting 
records and returns; or
certain disclosures of Directors’ remuneration specified by law are not made; or we have 
not received all the information and explanations we require for our audit.

As explained more fully in the statement of Directors’ responsibilities, the Directors are responsible for the 
preparation of the financial statements and for being satisfied that they give a true and fair view, and for such 
internal control as the Directors determine is necessary to enable the preparation of financial statements 
that are free from material misstatement, whether due to fraud or error.

In preparing the financial statements, the Directors are responsible for assessing the Group’s and the Parent 
Company’s ability to continue as a going concern, disclosing, as applicable, matters related to going concern 
and using the going concern basis of accounting unless the Directors either intend to liquidate the Group or 
the Parent Company or to cease operations, or have no realistic alternative but to do so.

Auditor’s responsibilities for the audit of the financial statements

Our objectives are to obtain reasonable assurance about whether the financial statements as a whole 
are free from material misstatement, whether due to fraud or error, and to issue an auditor’s report that 
includes our opinion. Reasonable assurance is a high level of assurance, but is not a guarantee that an 
audit conducted in accordance with ISAs (UK) will always detect a material misstatement when it exists. 
Misstatements can arise from fraud or error and are considered material if, individually or in the aggregate, 
they could reasonably be expected to influence the economic decisions of users taken on the basis of these 
financial statements.

Page 56

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

Extent to which the audit was capable of detecting irregularities, including fraud

Irregularities, including fraud, are instances of non-compliance with laws and regulations. We design 
procedures in line with our responsibilities, outlined above, to detect material misstatements in respect of 
irregularities, including fraud. The extent to which our procedures are capable of detecting irregularities, 
including fraud is detailed below:

As part of the audit we gained an understanding of the legal and regulatory framework applicable to the 
Group and the industries in which it operates, and considered the risk of acts by the Group that were 
contrary to applicable laws and regulations, including fraud. We considered the Group’s compliance with 
laws and regulations that have a significant impact on the financial statements to be UK company law, UK 
tax legislation, the accounting framework and ISO security standards, and we considered the extent to which 
non-compliance might have a material effect on the Group financial statements.

Based on our understanding we designed our audit procedures to identify instances of non-compliance 
with such laws and regulations. Our procedures included enquiries of management and of the Directors, 
reviewing the financial statement disclosures agreeing to underlying supporting documentation where 
necessary, review of Board meeting minutes and review of any applicable correspondence with legal counsel 
or tax authorities. 

Our assessment of the susceptibility of the financial statements to fraud was through management override 
of controls and revenue recognition (cut-off) which was addressed through detailed testing. We addressed 
the risk of management override of internal controls, including testing journal entries processed during 
and subsequent to the year, testing of significant estimates (included capitalised development costs) and 
evaluating whether there was evidence of bias in the financial statements by the Directors that represented a 
risk of material misstatement due to fraud. 

We also communicated relevant identified laws and regulations and potential fraud risks to all engagement 
team members and remained alert to any indications of fraud or non-compliance with laws and regulations 
throughout the audit.

Our audit procedures were designed to respond to risks of material misstatement in the financial 
statements, recognising that the risk of not detecting a material misstatement due to fraud is higher 
than the risk of not detecting one resulting from error, as fraud may involve deliberate concealment by, 
for example, forgery, misrepresentations or through collusion. There are inherent limitations in the audit 
procedures performed and the further removed non-compliance with laws and regulations is from the 
events and transactions reflected in the financial statements, the less likely we are to become aware of it.

A further description of our responsibilities is available on the Financial Reporting Council’s website at: www.
frc.org.uk/auditorsresponsibilities.  This description forms part of our auditor’s report.
Use of our report

This report is made solely to the Parent Company’s members, as a body, in accordance with Chapter 3 of 
Part 16 of the Companies Act 2006.  Our audit work has been undertaken so that we might state to the 

Page 57

ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc

Parent Company’s members those matters we are required to state to them in an auditor’s report and for no 
other purpose.  To the fullest extent permitted by law, we do not accept or assume responsibility to anyone 
other than the Parent Company and the Parent Company’s members as a body, for our audit work, for this 
report, or for the opinions we have formed.

Mark Langford (Senior Statutory Auditor)
For and on behalf of BDO LLP, Statutory Auditor
Leeds, UK
23 March 2021

BDO LLP is a limited liability partnership registered in England and Wales (with registered number 
OC305127).

Page 58

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Consolidated Statement of Comprehensive Income

For the year ended 31 December 2020

Revenue

Cost of Sales

Gross Profit

Other Income

Sales & Marketing Costs

Administration Expenses

Operating Loss before Exceptional Items and Share Based Payments

Share Based Payments

Exceptional Items

Operating Loss

Finance Cost

Loss before Taxation

Taxation Credit/ (Charge)

Loss for the Year

Other Comprehensive Income

Total Comprehensive Income for the Year

Attributed to Equity Holders of the Company

Loss per Share

Basic Loss per Share

Diluted Loss per Share

Note

6

6

7

23

26

8

25

10

11

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

5,663

(2,115)

3,548

297

(1,713)

(2,403)

(105)

101

65

(271)

(48)

(319)

50

(269)

-

(269)

(269)

pence

(2.7)

(2.7)

5,905

(2,545)

3,360

263

(1,958)

(2,369)

(593)

105

6

(704)

(46)

(750)

(26)

(776)

-

(776)

(776)

pence

(8.5)

(8.5)

The financial statements were approved and authorised for issue by the Board of Directors on 23 March 2021 
and were signed on its behalf by:

Gemma Basharan
Director
23 March 2021

Page 59

ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Statement of Financial Position

Note

Year ended
31 December
2020
£’000

Year ended
31 December
2019*
£’000

ASSETS

Non-current Assets

Intangible Assets

Property, Plant and Equipment

Right-of-use Assets

Deferred Tax Asset

Total Non-current Assets

Current Assets

Inventory

Trade and Other Receivables

Corporation Tax Recoverable

Cash and Cash Equivalents

Total Current Assets

TOTAL ASSETS

LIABILITIES

Current Liabilities

Trade and Other Payables

Lease Liability

Total Current Liabilities

Non-current Liabilities

Deferred Tax Liability

Lease Liability

Total Non-current Liabilities

TOTAL LIABILITIES

NET ASSETS

EQUITY

Equity attributable to Owners of the Parent:

Share Capital

Share Premium Account

Share Option Reserve

Retained Earnings

TOTAL EQUITY

12

13

18

10

14

15

7

16

17

18

10

18

20

20

20

20

455

148

746

118

1,467

9

811

216

1,122

2,158

3,625

(2,085)

(143)

(2,228)

(90)

(659)

(749)

(2,977)

648

100

6,098

392

(5,942)

648

429

283

896

77

1,685

26

890

265

351

1,532

3,217

(1,817)

(150)

(1,967)

(99)

(781)

(880)

(2,847)

370

91 

5,661 

291

(5,673)

370

*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due 
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of 

comprehensive income for the Group or Company only financial statements.

The financial statements were approved and authorised for issue by the Board of Directors on 23 March 2021 
and were signed on its behalf by:

Gemma Basharan | Director   
23 March 2021 

Page 60

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020 
 
 
 
 
 
 
 
     
Company Statement of Financial Position

Note

Year ended
31 December
2020
£’000

Year ended
31 December
2019*
£’000

ASSETS

Non-current Assets

Intangible Assets

Property, Plant and Equipment

Right-of-use Assets

Deferred Tax Asset

Total Non-current Assets

Current Assets

Inventory

Trade and Other Receivables

Corporation Tax Recoverable

Cash and Cash Equivalents

Total Current Assets

TOTAL ASSETS

LIABILITIES

Current Liabilities

Trade and Other Payables

Lease Liability

Total Current Liabilities

Non-current Liabilities

Deferred Tax Liability

Lease Liability

Total Non-current Liabilities

TOTAL LIABILITIES

NET ASSETS

EQUITY

Equity attributable to Owners of the Parent:

Share Capital

Share Premium Account

Share Option Reserve

Retained Earnings

TOTAL EQUITY

12

13

18

10

14

15

7

16

17

18

10

18

20

20

20

20

455

147

711

118

1,431

9

887

216

1,119

2,231

3,662

(2,163)

(119)

(2,282)

(90)

(645)

(735)

(3,017)

645

100

6,098

392

(5,945)

645

429

272

839

77

1,617

26

960

265

350

1,601

3,218

(1,879)

(128)

(2,007)

(99)

(744)

(843)

(2,850)

368

91 

5,661 

291

(5,675)

368

*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due 
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of 

comprehensive income for the Group or Company only financial statements.

For the year ended 31 December 2020, Loss after Taxation for the Company was £270k (2019: loss of £775k).

Gemma Basharan | Director    
23 March 2021

Page 61

ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Statement of Changes in Equity

Balance as at 31 December 2018

Loss and Total Comprehensive Income:

Total Comprehensive Loss for the Year

Transactions with shareholders

Issue of Shares

Share Based Payments

Balance as at 31 December 2019

Loss and Total Comprehensive

Total Comprehensive Loss for the Year

Transactions with shareholders

Issue of shares

Share Based Payments

Balance as at 31 December 2020

Share
Capital
£’000

91

Share
Premium
Account
£’000

5,661

Share
Option
Reserve
£’000

Retained
 Earnings
£’000

186

(4,897)

Total
£’000

1,041

-

-

-

-

-

-

91 

5,661 

-

9

-

100

-

437

-

6,098

-

-

105

291

-

-

101

392

(776)

(776)

-

-

(5,673)

(269)

-

-

(5,942)

-

105

370

269

446

101

648

Page 62

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company Statement of Changes in Equity

Balance as at 31 December 2018

Loss and Total Comprehensive Income:

Total Comprehensive Loss for the Year

Transactions with shareholders

Issue of Shares

Grant of Share Options

Balance as at 31 December 2019

Loss and Total Comprehensive

Total Comprehensive Loss for the Year

Transactions with shareholders

Issue of shares

Share Based Payments

Balance as at 31 December 2020

Share
Capital
£’000

91

Share
Premium
Account
£’000

5,661

Share
Option
Reserve
£’000

Retained
 Earnings
£’000

186

(4,900)

Total
£’000

1,038

-

-

-

-

-

-

91

5,661 

-

9

-

100

-

437

-

6,098

-

-

105

291

-

-

101

392

(775)

(775)

-

-

(5,675)

-

105

368

(270)

(270)

-

-

(5,945)

446

101

645

Page 63

ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Cash Flow Statement

Year ended
31 December 
2020
£’000

Year ended
31 December 
2019
£’000

Note

(319)

(750)

12

18

13

23

14

15

17

4

13

12

18

16

168

175

137

(4)

48

101

306

17

(214)

268

-

377

343

720

(5)

6

(194)

(193)

(195)

(7)

500

(54)

244

771

351

1,122

177

200

217 

(1)

46

105

(6)

(8)

(349)

428

(13)

52

152

204

(129)

16

(194)

(307)

(195)

(1)

-

-

(196)

(299)

650

351

Cash Flow from / (used in) Operating Activities

Loss before Taxation

Adjustment for:

Amortisation of Intangibles

Depreciation of right-of-use assets

Depreciation of Property, Plant and Equipment

Profit on Disposal of Equipment

Finance Costs

Share Based Payments

Cash used up in Operating Activities before changes in Working Capital

Change in Inventory

Change in Trade and Other Receivables

Change in Trade and Other Payables

Change on Other Non Cash Items

Cash Generated from Operating Activities

R&D Tax Credit Received 

Net Cash Flow Generated from Operating Activities

Acquisition of Property, Plant and Equipment

Disposal Proceeds

Development Costs capitalised

Net Cash Flow used in Investing Activities

Principal Paid on Lease Liabilities

Interest Paid on Loans and Borrowings

Proceeds from Issue of Shares

Costs of Share Issuance

Net Cash generated from / (used in) Financing Activities

Net increase/decrease in Cash & Cash Equivalents

Cash & Cash Equivalents at beginning of period

Cash & Cash Equivalents at end of period

Page 64

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company Cash Flow Statement

Cash Flow from / (used in) Operating Activities

Loss before Taxation

Adjustment for:

Amortisation of Intangibles

Amortisation of right-of-use assets

Depreciation of Property, Plant and Equipment

Profit on Disposal of Equipment

Finance Costs

Share Based Payments

Cash used up in Operating Activities before changes in Working Capital

Change in Inventory

Change in Trade and Other Receivables

Change in Trade and Other Payables

Change on Other Non Cash Items

Cash Generated from Operating Activities

R&D Tax Credit Received

Net Cash Flow Generated from Operating Activities

Acquisition of Property, Plant and Equipment

Disposal Proceeds

Development Costs Capitalised

Net Cash Flow used in Investing Activities

Principal Paid on Lease Liabilities 

Interest Paid on Loans and Borrowings

Proceeds from Issues of Shares

Costs of Share Issuance

Net Cash generated from / (used in) Financing Activities

Net increase / (decrease) in Cash & Cash Equivalents

Cash & Cash Equivalents at beginning of period

Cash & Cash Equivalents at end of period

Year ended
31 December 
2020
£’000

Year ended
31 December 
2019
£’000

Note

(320)

(749)

12

18

13

23

14

15

17

13

12

18

16

168

153

127

(4)

46

101

271

17

(220)

284

-

352

343

695

(5)

6

(194)

(193)

(172)

(7)

500

(54)

267

769

350

1,119

177

178

198

(1)

43

105

(49)

(8)

(348)

450

(13)

32

152

184

(128)

16

(194)

(306)

(173)

(1)

-

-

(174)

(296)

646

350

Page 65

ECSC Group plcAnnual Report Year Ended 31 December 2020Cyber Security Experts
Annual Report Year Ended 31 December 2020

Page 66

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements

1.  Corporate Information

ECSC Group plc is incorporated 
in England and Wales and 
admitted to trading on the market 
of the London Stock Exchange 
(AIM: ECSC). Further copies of 
these financial statements will 
be available at the Company’s 
registered office: 28 Campus 
Road, Listerhills Science Park, 
Bradford, West Yorkshire, BD7 
1HR. These financial statements 
for the year ended 31 December 
2020 were approved by the Board 
of Directors on 23 March 2021.

2.  General Information

These financial statements may 
contain certain statements about 
the future outlook of ECSC Group 
plc. Although the Directors believe 
their expectations are based on 
reasonable assumptions, any 
statements about future outlook 
may be influenced by factors that 
could cause actual outcomes and 
results to be materially different.

3.  Basis of Preparation

These financial statements for 
the year ended 31 December 2020 
have been prepared in accordance 
with International Financial 
Reporting Standards, International 
Accounting Standards and 
Interpretations (collectively 
‘IFRS’) in conformity with the 
requirements of the Companies 
Act 2006. The Company has taken 
advantage of Section 408 of the 
Companies Act 2006 and has not 

included its individual statement 
of comprehensive income in 
these financial statements. The 
Company’s overall result for the 
year is given in the company 
statement of financial position 
and statement of changes in 
shareholders’ equity.

The financial statements for 
the period ended 31 December 
2020 (and comparative) have 
been prepared on a consolidated 
basis. The consolidated financial 
statements present the results of 
the Company and its subsidiaries 
(‘the Group’) as if they formed 
a single entity. The financial 
statements of the Group and 
Company are both prepared in 
accordance with IFRS. 

Alternative performance 
measures (APM)

In the reporting of financial 
information, the Directors have 
adopted the APM ‘Adjusted 
EBITDA” (APMs were previously 
termed ‘Non-GAAP measures’), 
which is not defined or specified 
under International Financial 
Reporting Standards (IFRS). 

This measure is not defined by 
IFRS and therefore may not be 
directly comparable with other 
companies’ APMS, including those 
in the Group’s industry. APMs 
should be considered in addition 
to, and are not intended to be a 
substitute for, or superior to, IFRS 
measurements.

Purpose 

The Directors believe that 
this APM assists in providing 
additional useful information 
on the underlying trends, 
performance and position of the 
Group. This APM is also used 
to enhance the comparability of 
information between reporting 
periods and business units, by 
adjusting for non-recurring or 
uncontrollable factors which 
affect IFRS measures, to aid the 
user in understanding the Group’s 
performance. 

Consequently, APMs are used by 
the Directors and management 
for performance analysis, 
planning, reporting and incentive 
setting purposes and this remains 
consistent with the prior year.  
Adjusted APMs are used by the 
Group in order to understand 
underlying performance and 
exclude items which distort 
compatibility, as well as being 
consistent with public broker 
forecasts and measures (see note 
25). 

The financial statements have 
been presented in thousands of 
Pounds Sterling (£’000, GBP) as 
this is the currency of the primary 
economic environment that the 
Company operates in.

Page 67

ECSC Group plcAnnual Report Year Ended 31 December 2020 
Notes to the Financial Statements (continued)

4.  Accounting Policies

The principal accounting policies applied in the preparation of the financial statements are set out below. 
These policies have been consistently applied to all periods presented, unless otherwise stated. 

4.1  Basis of Accounting

The financial statements have been prepared on the historical cost basis except as stated.

New IFRS standards, amendments to and interpretations not applied to published standards 

The following new standards, amendments to standards and interpretations will be mandatory for the first 
time in future financial years:

New Standards

IFRS 17 Insurance contracts

Amendments to existing standards

Amendments to References to the 
Conceptual Framework in IFRS Standards

Amendments to IFRS 3 Business 
Combinations – Definition of a Business

Amendments to IAS 1 and IAS 8: Definition 
of Material

Amendments to IFRS 9, IAS 39 and IFRS 7: 
Interest Rate Benchmark Reform

Amendments to IAS 1: Classification of 
Liabilities as Current or Non-current

Amendments to: IFRS 3 Business 
Combinations; IAS 16 Property, Plant and 
Equipment; IAS 37 Provisions, Contingent 
Liabilities and Contingent Assets

Annual Improvements to IFRSs (2018-2020 
Cycle): IFRS 1, IFRS 9, Illustrative Examples 
accompanying IDRS 16, IAS 41

Amendments to IFRS 16 Leases COVID 
19-Related Rent Concessions

Amendments to IFRS 4 Insurance Contracts 
– deferral of IFRS 9

Amendments to IFRS 9, IAS 39, IFRS 7, IFRS 
4 and IFRS 16 Interest Rate Benchmark 
Reform – Phase 2

Issued date

IASB mandatory effective date 
(UK mandatory effective date)

UK Adoption status (EU pre 31 
December 2020)

18-May-2017 and 
25-June-2020

01-Jan-2023

TBC

29-May-2018

01-Jan-2020

22-Oct-2018

01-Jan-2020

31-Oct-2018

01-Jan-2020

26-Sept-2019

01-Jan-2020

23-Jan-2020

01-Jan-2022

14-May-2020

01-Jan-2022

14-May-2020

01-Jan- 2022

Endorsed

Endorsed

Endorsed

Endorsed

TBC

TBC

TBC

14-May-2020

01-Jun- 2020

Endorsed

25-Jun-2020

01-Jun-2021

Adopted by UKEB

27-Aug-2020

01-Jun-2021

Adopted by UKEB

The application of these standards and interpretations is not expected to have a material impact on the 
Group’s reporting financial performance or position. 

Page 68

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

4.2  Going Concern

The Directors have reviewed 
whether the Group has 
adequate resources to continue 
in operational existence for 
the foreseeable future, being 
no shorter than 12 months 
from the date of approving the 
Annual Report. In conducting 
this review, the Directors have 
considered a range of factors, 
including the market prospects 
for cyber security services, client 
relationships and dependency, 
supplier relationships and 
dependency, actual or potential 
litigation, staff retention and 
reliance, relationships with 
HMRC and regulators, financing 
arrangements, historic trading 
and cash flow performance, 
current trading and cash flow 
performance, and future trading 
and cash flow expectations. In 
undertaking their review, the 
Directors have prepared financial 
projections for the years ending 31 
December 2021 and 2022, a review 
which assumed continued revenue 
growth and cost efficiency. 

The budget figures are closely 
monitored against actuals on a 
monthly basis. Variances that 
may arise are discussed a Board 
level on a monthly basis during a 
review of the monthly numbers. 
In the event that this revenue and 
cost performance is not achieved, 
the Directors have also considered 
a sensitivity analysis based on 
lower revenue growth and have 
formulated contingency plans for 

this scenario, which enable the 
Group to preserve its financial 
resources.

During 2020 the Group has seen 
the pandemic creating additional 
risks and uncertainties. These 
were carefully monitored and 
the Group was able to adapt 
to meet the challenges arising 
from COVID-19. The Group has 
extensive remote and home 
working options in place, fully 
tested, supporting a range of 
conferencing technologies, all 
of which maintain cyber security 
related certifications, associated 
technical standards and policies. 
The Group was also able to deliver 
the full range of services remotely.

During 2020 the Group took 
advantage of published time to pay 
plans on VAT. As at 31 December 
2020, £0.2m remained outstanding 
in this regard.  A deferred PAYE 
payment plan ending 31 March 
2021 was agreed with HMRC. 
As at 31 December 2020, £0.2m 
remained outstanding.  

As at 31 December 2020, the 
Group had cash and cash 
equivalents of £1.1m (2019: 
£0.4m) and achieved an Adjusted 
EBITDA profit of £0.4m (2019: 
£1k), reducing the operating loss 
to £0.3m (2019: £0.7m).

On 17 April 2020, the Group 
completed a fundraise of £0.45m 
(net of expenses of £0.05m). 
The Group continues to have an 
unused invoice financing facility 

with Barclays Bank PLC of £0.5m.

Based on this review, the 
Directors have concluded that the 
Group has adequate resources 
to meet its liabilities as they fall 
due and continue in operational 
existence for the foreseeable 
future, which is considered to 
be at least the next 12 months 
from the date of approval 
of the financial statements. 
Consequently, the Directors 
have adopted the going concern 
basis in preparing the financial 
statements. 

4.3  Revenue Recognition

The core principle is that revenue 
should only be recognised as 
the client receives the benefit of 
the goods or services provided 
under a commercial contract, 
in an amount that reflects the 
consideration to which the 
provider expects to be entitled 
for the transfer of the goods or 
services.

Performance obligations and 
timing of revenue recognition

Revenue comprises the sales 
value of goods and services 
supplied during the year, exclusive 
of Value Added Tax and trade 
discounts. Revenue from the 
provision of Consulting services 
is recognised as services are 
rendered, based on the contracted 
daily billing rate and the number 
of days delivered during the 
period. 

Page 69

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Revenue from Pre-paid contracts are deferred in the balance sheet and recognised on utilisation of service 
by the client. Pre-paid revenue is included within Assurance in note 6. 

Revenue from MDR contracts includes:

Hardware – hardware revenue is recognised on delivery and is included within other revenue as set out in 
note 6. This is when control of hardware passes to the customer. 

Device build - Device build revenue is deferred and recognised on a straight line basis over the term of the 
contract. 

Licensing - deferred and recognised on a straight line basis over the invoice period, due to the performance 
obligation not being considered distinct from management and monitoring performance obligation

Management and monitoring - deferred and recognised on a straight line basis over the invoice period.  
Revenue from the sale of products (vendor) is recognised when control passes to the customer, which is 
considered to occur when the software or hardware product has been delivered to the client.

Determining the transaction price

The Group’s revenue is derived from fixed price contracts and therefore the amount of revenues to be earned 
from each contract is determined by reference to those fixed prices.

Costs of obtaining long-term contracts and costs of fulfilling contracts

Commissions paid to sales staff for work in obtaining Managed Service contracts are prepaid and amortised 
over the terms of the contract on a straight line basis.

Commissions paid to sales staff for work in obtaining the Prepaid Consultancy contracts are recognised in 
the month of invoice.

Page 70

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Contract Balances

At 1 January

Commission expensed during the period

Commissions paid in advance of contract completion

Recognised as revenue during the period

Cash received in advance of performance during 
period

Contract 
Assets 
2020
£’000

Contract 
Assets 
2019 
£’000

43

(62)

53

-

-

34

49

(28)

22

-

-

43

Contract 
Liabilities 
2020
£’000

(866)

-

-

3,390

(3,402)

(878)

Contract 
Liabilities 
2019* 
£’000

(949)

-

-

2,429

(2,346)

(866)

* Prior year restatement
A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due as 
at 31 December 2019 where the performance obligation had not commenced at that date. This restatement impacted the presentation of both the 
Group or Company Statement of Financial Position page 60-61. This restatement does not impact the statement of comprehensive income for the 
Group and Company only financial statements. Trade receivables and contract liabilities are stated net in respect of advance billing in line with the 
requirements of IFRS 15. 

Contract Assets balance of £34k (2019: £43k) is included in the Trade Receivables and Other Receivables (note 15). 

Contract Liabilities balance of £878k (2019: £866k) is included in Trade Payables and Other Payables (note 17).

4.4  Finance Income

Finance income is accrued on an annual basis, by reference to the principal outstanding at the applicable 
effective credit interest rate.

4.5  Government Grant Income

A government grant is recognised only when there is reasonable assurance that (a) the entity will comply 
with any conditions attached to the grant and (b) the grant will be received. 

The grant is recognised as income over the period necessary to match them with the related costs, for which 
they are intended to compensate, on a systematic basis. 

Government Grant Income is recognised in the Statement of Comprehensive Income over the period in which 
the Company recognises expenses for the related costs for which the grants are intended to compensate. 
Grants relating to income are deducted from the related expense.

Government tax credits available on eligible Research and Development expenditure (‘R&D Tax Credits’) and 
not reclaimable through other means are recognised as Other Income (see note 7).

Coronavirus Job Retention Scheme (CJRS)

Where the Group receive Coronavirus Job Retention Scheme (CJRS) expenditure credits, it is accounted 

Page 71

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

for as government grant as income and matched with the relevant staff costs in which they are intended to 
compensate. The income has been recognised in the period to which the underlying furloughed staff costs 
relate to in accordance with IAS20. (see note 9)

Australia Government Grants

Where the Group received the JobKeeper payment (wage subsidy which provided a $1,500 payment per 
fortnight per employee from 1st April 2020 until 27 September 2020) and the Cash Flow Boost for Employers, 
it is accounted for as government grant as income and matched with the relevant staff costs in which they 
are intended to compensate. The income has been recognised in the period to which the underlying grant 
staff costs relate to in accordance with IAS20. (see note 9)

4.6  Operating Profit 

Operating Profit is stated after all expenses, including those considered to be exceptional, but before finance 
income or expenses. Exceptional items are items of income or expense which, because of their nature or 
size, require separate presentation to allow shareholders to better understand the financial performance of 
the period and allow comparison with prior years. 

4.7  Foreign Currencies

Financial assets and liabilities in foreign currencies are translated into sterling at the rates of exchange 
prevailing at the balance sheet date. Transactions in foreign currencies are translated into sterling at the 
rate of exchange prevailing at the date of the transaction. Exchange differences are recognised in Operating 
Profit.

On consolidation, the results of overseas operations are translated into Sterling at rates approximating those 
prevailing when the transactions took place. All assets and liabilities of overseas entities are translated at 
the rate prevailing at the reporting date. Exchange differences arising on translating the opening net assets 
at opening rate and the results of overseas operations at actual rate are recognised in Other Comprehensive 
Income and accumulated in the foreign exchange reserve.

4.8  Employee Benefits

Short-Term Benefits

Wages, salaries, paid annual leave and sick leave, bonuses and non-monetary benefits are accrued in the 
period in which the associated services are rendered by employees of the Company. 

Defined Contribution Pension Scheme

The Company operates a defined contribution pension scheme for employees. The assets of the scheme 
are held separately from those of the Company. The annual contributions are charged to the Statement of 
Comprehensive Income. The Company also contributes to the personal pension plans of the Directors in 

Page 72

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

accordance with their Service Contracts.

Employee Share Based Payments

Where equity settled share options are granted to employees (including Directors), the fair value of the 
options at the date of grant is charged to the Consolidated Statement of Comprehensive Income, as a Share 
Based Payment Charge, over the vesting period of the options, with a corresponding movement in the Share 
Option Reserve.

Non-market vesting conditions are taken into account by adjusting the number of equity instruments 
expected to vest at each reporting date so that, ultimately, the cumulative amount recognised over the 
vesting period is based on the number of options that eventually vest. Non-vesting conditions and market 
vesting conditions are factored into the fair value of the options granted. As long as all other vesting 
conditions are satisfied, a charge is made irrespective of whether the market vesting conditions are satisfied.

Where the terms and conditions of options are modified before they vest, the increase in the fair value of the 
options, measured immediately before and after modification, is also charged to the Consolidated Statement 
of Comprehensive Income over the remaining vesting period.

Where options are cancelled and replaced, modification treatment is adopted which results in the recognition 
of any incremental fair value but not any reduction in fair value. Any increase in the fair value of the options, 
measured immediately at replacement, is  charged to the Consolidated Statement of Comprehensive 
Income. The cancelled options continue to be charged to the Consolidated Statement of Comprehensive 
Income over the remaining vesting period.

4.9  Property, Plant and Equipment

All additions are initially recorded at historic cost. Depreciation is calculated so as to write-off the cost of an 
asset, less its estimated residual value, over the useful economic life of that asset as follows:

•  Leasehold Property 
•  Office Furniture and Equipment    
•  Computer Equipment 
•  Motor Vehicles 

20% reducing balance
20% reducing balance
33% straight line
20% straight line

4.10  Research and Development Expenditure 

Expenditure on research activities is recognised as an expense in the period in which it is incurred. 

Expenditure on development activities generating an intangible asset is capitalised if all of the criteria set 
out in IAS 38 are met.  Capitalised assets are amortised over their useful economic life, which is considered 
to be five years.

If the criteria set out in IAS 38 are not met, expenditure on development activities is recognised as an 

Page 73

ECSC Group plcAnnual Report Year Ended 31 December 2020 
 
 
 
 
 
 
Notes to the Financial Statements (continued)

expense in the period in which it is incurred.

4.11  Inventories 

Inventories are carried at the lower of cost or net realisable value. Net realisable value is calculated based 
on the expected revenue from sale in the normal course of business less any costs to sell. Due allowance is 
made for obsolete and slow moving items. 

4.12  Financial Instruments

Financial Assets

The Group and Company’s Financial Assets include Cash and Cash Equivalents, Trade Receivables and Other 
Receivables.

• 

Initial Recognition and Measurement

Financial Assets are classified as amortised cost and initially measured at fair value.

•  Subsequent Measurement

Financial assets are subsequently measured at amortised cost, using the effective interest method, 
less impairment. Interest is recognised by applying the effective interest method, except for short-term 
receivables when the recognition of interest would be immaterial.

The Group has applied the simplified method of the expected credit loss model when calculating impairment 
losses on its financial assets measured at amortised cost, such as trade receivables. This resulted in greater 
judgement due to the need to factor in forward-looking information when estimating the appropriate amount 
to provisions. 

•  De-recognition of Financial Assets

The Group and Company de-recognises a Financial Asset only when the contractual rights to the cash 
flows from the asset expire, or it transfers the Financial Asset and substantially all the risks and rewards of 
ownership of the asset to another entity. 

• 

 Invoice Discounting Facility

The Group and Company will continue to retain substantially all the credit risk and therefore will continue to 
recognise the receivables.

Financial Liabilities and Equity Instruments

The Group and Company’s Financial Liabilities include Trade Payables, Accruals and Other Payables . 

Page 74

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Financial Liabilities are classified at amortised cost.

•  Classification as Debt or Equity

Financial Liabilities and Equity Instruments issued by the Company are classified according to the substance 
of the contractual arrangements entered into and the definitions of a Financial Liability and an Equity 
Instrument.

• 

 Equity Instruments

An Equity Instrument is any contract that evidences a residual interest in the assets of the Company after 
deducting all of its liabilities. Equity Instruments are recorded at the proceeds received, net of direct issue 
costs.

•  Trade Payables, Other Payables and Accruals

Trade Payables, Accruals and Other Payables are initially measured at fair value, net of transaction costs, 
and are subsequently measured at amortised cost, where applicable, using the effective interest method, 
with interest expense recognised on an effective yield basis.

• 

 De-recognition of Financial Liabilities

The Company de-recognises financial liabilities when the Company’s obligations are discharged, cancelled 
or expire.

Offsetting of Financial Instruments

Financial Assets and Financial Liabilities are offset, and the net amount reported in the Statement of 
Financial Position if there is a currently enforceable legal right to offset the recognised amounts and there is 
an intention to settle on a net basis, or to realise the assets and settle the liabilities simultaneously.

4.13  Cash and Cash Equivalents

Cash and Cash Equivalents comprise cash on hand and demand deposits, and other short-term highly liquid 
investments which are readily convertible to known amounts of cash and are subject to insignificant risk of 
changes in value.

4.14  Impairment of Assets

Non-Financial Assets

The carrying amounts of the Group and Company’s Non-Financial Assets, other than Deferred Tax Assets, 
are reviewed at each reporting date to determine whether there is any indication of impairment. If any such 
indication exists, then the asset’s recoverable amount is estimated.

Page 75

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The recoverable amount of an asset or cash-generating unit is the greater of its value in use and its fair 
value less costs to sell. In assessing value in use, the estimated future cash flows are discounted to their 
present value using a pre-tax discount rate that reflects current market assessments of the time value of 
money and risk specific to the asset. For the purpose of impairment testing, assets are grouped together into 
the smallest group of assets that generates cash inflows from continuing use that are largely independent of 
the cash inflows of other assets or groups of assets. 

An impairment loss is recognised if the carrying amount of an asset or its cash generating unit exceeds its 
estimated recoverable amount. Impairment losses are recognised in profit and loss. 

Impairment losses recognised in prior periods are assessed at each reporting date for any indications that 
the loss has decreased or no longer exists. An impairment loss is reversed if there has been a change in 
the estimates used to determine the recoverable amount. An impairment loss is reversed only to the extent 
that the asset’s carrying amount does not exceed the carrying amount that have been determined, net of 
depreciation or amortisation, if no impairment loss had been recognised.

4.15  Corporation Tax

Corporation Tax expense represents the sum of the tax currently payable and Deferred Tax. 

The tax currently payable is based on taxable profit for the year. Taxable profit differs from profit as reported 
in the Statement of Comprehensive Income because it excludes items of income or expense that are taxable 
or deductible in other years and it further excludes items that are not taxable or tax deductible. 

The Company’s liability for current tax is calculated using tax rates (and tax laws) that have been enacted or 
substantively enacted by the end of the financial period.

Government tax credits available on eligible Research and Development expenditure and not reclaimable 
through other means are recognised as Other Income and treated as a government grant. This applies when 
there are no taxable profits against which to offset the tax credit. The amount receivable by the Group and 
Company is shown on the face of the balance sheet within Corporation Tax Recoverable.

4.16  Deferred Tax

Deferred Tax is recognised in respect of all timing differences that have originated but not reversed at the 
balance sheet date where transactions or events have occurred at that date that will result in an obligation to 
pay more, or a right to pay less or to receive more tax.

Deferred Tax Assets are recognised only to the extent that the Directors consider that it is more likely 
than not that there will be suitable taxable profits from which the future reversal of the underlying timing 
differences can be deducted.

Deferred Tax is measured on an undiscounted basis at the tax rates that are expected to apply in the periods 

Page 76

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

in which timing differences reverse, based on tax rates and laws enacted or substantively enacted at the 
balance sheet date.

4.17  Share Capital

Ordinary Share Capital is recorded at nominal value and proceeds received in excess of nominal value of 
shares issued, if any, is accounted for in the Share Premium Account. Both Ordinary Share Capital and Share 
Premium Account are classified as equity.  Costs incurred directly to the issue of shares are accounted 
for as a deduction from Share Premium Account; otherwise such costs are charged to the Statement of 
Comprehensive Income.

4.18  Operating Segments

An operating segment is a component of the Group and the Company that engages in business activities 
from which it may earn revenues and incur expenses, including revenues and expenses that relate to 
transactions with any of the Company’s other components. 

An operating segment’s operating results are reviewed regularly by the Directors of the Company to assess 
performance and make decisions about resource allocation.

The Board considers that the Company’s activity constitutes three operating and three reporting segments 
as defined under IFRS 8. 

4.19  Related Parties 

Parties are considered to be related if one party has the ability (directly or indirectly) to control the other 
party or exercise significant influence over the other party in making financial and operating decisions.  
Parties are also considered related if they are subject to common control or common significant influence.  
Related parties may be individuals or corporate entities.

5.  Critical Accounting Judgements, Estimates and Sources of Estimation Uncertainty

In applying the accounting policies, the Directors may at times be required to make critical accounting 
judgements and estimates about the carrying amount of assets and liabilities. These estimates and 
assumptions, when made, are based on historical experience and other factors that the Directors consider 
are relevant.

The key estimates and assumptions concerning the future and other key sources of estimation uncertainty 
at the end of the financial year, that have significant risk of causing a material adjustment to the carrying 
amounts of assets and liabilities within the next financial year, are stated below.

Page 77

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Judgements

Going Concern

Management apply their judgement in reviewing whether the Group has adequate resources to continue 
in operational existence for the foreseeable future, which is considered to be 12 months from the date 
of approval of the financial statement. The Group have undertaken sensitivity analysis around a possible 
uncertainties, further detail regarding the impact is detail on page 28. 

Development Costs Capitalised & Amortised

Management apply their judgement in determining whether an identified intangible software asset meets 
the criteria for capitalisation under IAS 38. The carrying value of Intangible Assets as at 31 December 2020 
was £455k (2019: £429k).

Management estimate the percentage of development staff time used to enhance and improve the 
Company’s intangible software assets in order to capitalise a proportion of salary costs each period. In the 
year ended 31 December 2020, the amount of staff time capitalised into Intangible Assets was £194k (2019: 
£194k).

Development Costs capitalised into Intangible Assets are amortised over management’s estimate of the 
useful economic life of the asset recognised. In the year ended 31 December 2020, the useful economic life 
of all Intangible Assets was estimated to be 5 years, resulting in an amortisation charge of £168k (2019: 
£177k). 

6.  Revenue and Segment Information

The Group’s principal revenue is derived from the provision of cyber security professional services. 

During this period, the Directors received information on financial performance on a divisional basis. The 
Directors consider that there are three reportable operating segments: Assurance (including Remote 
Support services), MDR, and Vendor Products. There were a small number of other transactions recorded 
during each period which are not considered to be part of either of the three reportable operating segments. 
These are presented below within the ‘Other’ caption and are not significant. 

The Directors do not receive any information on the financial position of each segment, including information 
on assets and liabilities. Accordingly, no such information has not been presented.

The Group is not reliant on any single client, with no single client accounting for 10% or more of revenue. All 
revenue recognised is derived from external clients. 

Page 78

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020 
Notes to the Financial Statements (continued)

The Group has PPE located in the UK (cost of £896k; NBV of £147k) and Australia (cost of £57k; NBV of £1k). 
The Group’s revenue and gross profit by operating segment for the year ended 31 December 2020 were as 
follows:

Revenue

Assurance

MDR

Vendor Products

Other

Total Revenue

Gross Profit

Assurance

MDR

Vendor Products

Other

Gross Profit

Operating Loss

Finance Cost

Loss before Taxation

Revenue by country for the year ended 31 December 2020 was as follows:

United Kingdom

Europe

United States

Channel Island

Middle East

Other Countries

Total

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

2,724

2,732

125

82

5,663

1,576

1,994

25

(47)

3,548

(271)

(48)

(319)

2,922

2,585

162

236

5,905

1,574

1,745

29

12

3,360

(704)

(46)

(750)

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

5,294

278

-

89

-

2

5,708

116

9

66

2

4

5,663

5,905

Page 79

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The Group’s United Kingdom revenue by operating segment for the year ended 31 December 2020 was as 
follows:

Revenue United Kingdom

Assurance

MDR

Vendor Products

Other

Total

7.  Other Income

Withholding Tax

Gain on sale of Asset

R&D Tax Credits

Total

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

2,367

2,724

124

79

5,294

2,760

2,580

144

224

5,708

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

-

4

293

297

-

1

262

263

A credit has been recognised within Other Income as a result of R&D Tax Credit surrenders. For the year ended 31 December 2020, the surrender 
resulted in a credit of £212k relating to R&D undertaken in 2020, included within Corporation Tax Recoverable, and an additional credit received of 

£81k for additional R&D expenditure relating to 2018. 

Page 80

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

8.  Operating Loss

Operating Loss is stated after charging:

Depreciation of Fixed Assets

Amortisation of Intangibles - Development Costs

Amortisation of leases

R&D expenditure

Short-term and low value lease expense

Auditors Remuneration - Audit Services

Auditors Remuneration - Non-Audit Services

                    Taxation Compliance Services

                    Other Taxation and  Compliance Services

Exceptional items

Inventories Expensed

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

137

168

175

786

76

45

8

12

65

8

217

177

200

785

62

42

8

13

6

44

The amount charged in respect of Auditors’ Remuneration for the Group and the Company audit was £45k.  None of the subsidiaries (see note 
27) of the Group were subject to audit in the year ended 31 December 2020.

9.  Employee Benefit Expense 

Employee Benefit Expense (including Directors) during the periods amounted to:

Wages and Salaries - Gross

Government Grants

Wages and Salaries

Social Security Costs

Pension Contributions

Share Based Payments

GROUP
Year Ended
31 December
2020
£’000

GROUP
Year Ended
31 December
2019
£’000

COMPANY
Year Ended
31 December
2020
£’000

COMPANY
Year Ended
31 December
2019
£’000

4,269

(292)

3,977

452

179

101

4,709

4,091

-

4,091

440

153

105

4,789

4,033

(203)

3,830

404

161

101

4,496

3,944

-

3,944

392

134

105

4,575

Page 81

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Directors’ remuneration for the Group and Company is as follows:

Salaries, Bonus, Benefits-in-Kind

Pension Contributions

Share Based Payments

Social Security Costs

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

662

47

120

78

907

455

30

47

57

589

Details of Directors’ remuneration can be found in the Remuneration Report on pages 43-49. 

Key management personnel, being those persons having responsibility for planning, directing and 
controlling the activities of the Group, are considered to be the Directors listed on pages 35-36 (Board of 
Directors).

Amounts paid to the highest paid director in the period were as follows:

Year ended
31 December
2020
£’000

219

20

239

Year ended
31 December
2019
£’000

196

18

214

Year ended
31 December
2020

Year ended
31 December
2019

6

81

87

4

81

85

Salaries, Bonus, Benefits-in-Kind

Pension Contributions

Group

The average monthly number of employees during the year was:

Directors

Operational

Page 82

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company
The average monthly number of employees during the year was:

Directors

Operational

10. Taxation

Recognised in the Statement of Comprehensive Income

Corporation Tax (Credit) / Charge

Deferred Tax (Credit) / Charge

Total Tax (Credit) / Charge

Reconciliation of Total Tax (Credit)/Charge

Loss before Tax

UK Corporation At Rate Of 19.0% (2019: 19.0%)

Expenses Not Deductible For Tax Purposes  

Over/Under Provision in Prior Period - Deferred Tax

Tax Losses on Which Deferred Tax Not Recognised

Total Tax (Credit)  / Charge

Deferred Tax Assets & Liabilities

Deferred Tax Assets

Deferred Tax Liabilities

Deferred Tax - Net Asset/(Liability)

Year ended
31 December
2020
£’000

6

77

83

Year ended
31 December
2020
£’000

-

(50)

(50)

Year ended
31 December
2019
£’000

4

77

81

Year ended
31 December
2019
£’000

-

26

26

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

(319)

(61)

2

(50)

59

(50)

(750)

(143)

2

26

141

26

Year ended
31 December
2020
£’000

118

(90)

28

Year ended
31 December
2019
£’000

77

(99)

(22)

Page 83

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Deferred Tax Assets of £118K is recognised in respect of unutilised trading losses, Share Based Payments 
and short-term timing differences. Deferred Tax Liabilities of £90k arise on timing differences in the carrying 
value of certain of the Company’s assets for financial reporting purposes and for corporation tax purposes. 
These will reverse as the fair value of the related assets are depreciated over time. Deferred Tax balances 
have been calculated at the rate of 19%, being the rate of Corporation Tax expected to be in force when the 
timing differences reverse.

Unutilised Trading Losses

The Company continues to carry forward unutilised trading losses of £5,111k (2019: £5,696k). A Deferred Tax 
Asset of £35k (2019: £22k) has been recognised as at 31 December 2020 in respect of the unutilised trading 
losses. No further Deferred Tax Asset has been recognised because the Board envisages that a significant 
period of time will be required to generate sufficient profits to utilise the trading losses carried forward.

11. Earnings per Share

Basic Earnings per Share is calculated by dividing the loss for the period attributable to Equity Holders of the 
Company by the weighted average number of Ordinary Shares outstanding during the period (‘Basic Number 
of Ordinary Shares’).

Diluted Earnings per Share is calculated by dividing the loss for the period attributable to Equity Holders of 
the Company by the weighted average number of Ordinary Shares outstanding during the period plus the 
weighted average number of Ordinary Shares that would be issued on conversion of all the potential dilutive 
Ordinary Shares (‘Diluted Number of Ordinary Shares’), subject to the effect of anti-dilutive potential shares 
being ignored in accordance with IAS 33.

Adjusted Earnings per Share is calculated by dividing Adjusted loss (after adding-back exceptional costs 
incurred in the period; see note 25) by Diluted Number of Ordinary Shares.

Page 84

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The calculation of Basic, Diluted and Adjusted Earnings per Share is as follows:

Net Loss Attributable To Equity Holders Of The Company

Add Back: Exceptional Costs

Add Back: Share Based Payments

Adjusted Loss

Number Of Ordinary Shares (‘000)

Initial Weighted Average

Shares Issued in April 2020

Basic Number Of Ordinary Shares

Weighted Average Dilutive Shares In Period

Diluted Number Of Ordinary Shares 

Earnings Per Share (Pence):

Basic Losses Per Share

Diluted Losses Per Share**

Adjusted Losses Per Share

Year ended
31 December
2020
£’000

Year ended
31 December
2019
£’000

(269)

65

101

(103)

9,098

909

10,007

906

10,913

(2.7)

(2.7)

(1.0)

(776)

6

105

(665)

9,098

-

9,098 

661

9,759

(8.5)

(8.5)

(7.3)

** In accordance with IAS 33, the effect of anti-dilutive potential shares has been ignored.

During the year ended 31 December 2020, the following dilutive events have occurred:

•  On 17 April 2020, 909,091 ordinary shares were issued for £0.45m (net of expenses of £0.05m). 
•  On 21 August 2020, the Company granted options over 588,037 Ordinary Shares to selected employees, 
including 144,758 to Director Lucy Sharp, 103,602 to Director Ian Castle and 64,651 to Director Gemma 
Basharan, of which 587,107 remain outstanding as at 31 December 2020.

•  On 28 August 2020, the Company granted options over 450,000 Ordinary Shares to selected employees, 

including 100,000 to Director Ian Mann, 100,000 to Director Lucy Sharp, 80,000 to Director Ian Castle and 
80,000 to Director Gemma Basharan, of which 450,000 remain outstanding as at 31 December 2020.

These dilutive events were taken into account in calculating Diluted Number of Ordinary Shares.  

Page 85

ECSC Group plcAnnual Report Year Ended 31 December 2020£’000

891

194

1,085

1,085

194 

1,279

479

177

656

656

168 

824

429

455

Notes to the Financial Statements (continued)

12. Intangible Assets

GROUP & COMPANY

Development Costs

Costs

As at 1 January 2019

Additions

As at 31 December 2019

As at 1 January 2020

Additions

As at 31 December 2020

Amortisation

As at 1 January 2019

Charges for the year

As at 31 December 2019

As at 1 January 2020

Charges for the year

As at 31 December 2020

Net Book Value

As at 31 December 2019

As at 31 December 2020

Page 86

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

13. Property, Plant and Equipment

GROUP

Leasehold
Property
£’000

Office 
Equipment
£’000

Computer
Equipment
£’000

Motor
Vehicles
£’000

Total
£’000

Cost

At 1 January 2019

Reclassification due to IFRS16

Additions

Disposals

At 31 December 2019

Additions

Disposals

At 31 December 2020

Depreciation

At 1 January 2019

Reclassification due to IFRS16

Charge for Period

Disposals

At 31 December 2019

Charge for Period

Disposals

At 31 December 2020

Net Book Value

At 31 December 2019

At 31 December 2020

103

-

12

-

115

-

-

115 

48

-

15

-

63

16

-

79

52

36

120

-

16

-

136

-

-

136 

50

-

25

-

75

21

-

96

61

40

639

(61)

101

-

679

5

(5)

679 

370

(20)

168

-

518

95

(2)

611

161

68

57

-

-

(34)

23

-

-

23 

24

-

9

(19)

14

5

-

19

9

4

919

(61)

129

(34)

953

5

(5)

953 

492

(20)

217

(19)

670

137

(2)

805

283

148

Page 87

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

COMPANY

Cost

At 1 January 2019

Reclassification due to IFRS16

Additions

Disposals

At 31 December 2019

Additions

Disposals

At 31 December 2020

Depreciation

At 1 January 2019

Reclassification due to IFRS16

Charge for Period

Disposals

At 31 December 2019

Charge for Period

Disposals

At 31 December 2020

Net Book Value

At 31 December 2019

At 31 December 2020

14. Inventory

Leasehold
Property
£’000

Office 
Equipment
£’000

Computer
Equipment
£’000

Motor
Vehicles
£’000

Total
£’000

103

-

12

-

115

-

-

115 

48

-

15

-

63

16

-

79

52

36

99

-

15

-

114

-

-

114

41

-

17

-

58

18

-

76

56

38

604

(61)

101

-

644

5

(5)

644

352

(20)

157

-

489

88

(2)

575

155

69

57

-

-

(34)

23

-

-

23

24

-

9

(19)

14

5

-

19

9

4

863

(61)

128

(34)

896

5

(5)

896

465

(20)

198

(19)

624

127

(2)

749

272

147

Inventory

9

26

9

26

GROUP
Year Ended
31 December
2020
£’000

GROUP
As At
31 December
2019
£’000

COMPANY
Year Ended
31 December
2020
£’000

COMPANY
As At
31 December
2019
£’000

Page 88

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

15. Trade Receivables and Other Receivables

Trade Receivables - Gross

Allowance for Credit Losses

Trade Receivables

Other Receivables

Intercompany Receivables 

Prepayments

Accrued Income

Contract Asset

GROUP
As At
31 December
2020
£’000

GROUP
As At
31 December
2019*
£’000

COMPANY
As At
31 December
2020
£’000

COMPANY
As At
31 December
2019*
£’000

613

(5)

608

9

-

159

1

34

811

653

-

653

8

-

182

4

43

890

613

(5)

608

9

98

137

1

34

887

653

-

653

8

92

160

4

43

960

*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due 
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of 

comprehensive income for the Group or Company only financial statements.

The carrying amount of Trade Receivables and Other receivables approximates to their fair value.

Intercompany Receivables represent loans provided by ECSC Group plc to ECSC Australia Pty Ltd. The loans 
are repayable on demand, no expected credit loss is attributed to them.

16. Cash & Cash Equivalents

Cash & Cash Equivalents

1,122

351

1,119

350

GROUP
As At
31 December
2020
£’000

GROUP
As At
31 December
2019
£’000

COMPANY
As At
31 December
2020
£’000

COMPANY
As At
31 December
2019
£’000

Page 89

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

17. Trade Payables and Other Payables

Trade Payables

Other Taxation and Social Security

Accruals

Contract Liabilities (Restated)

Intercompany Payables

Other Payables

GROUP
As At
31 December
2020
£’000

GROUP
As At
31 December
2019*
£’000

COMPANY
As At
31 December
2020
£’000

COMPANY
As At
31 December
2019*
£’000

146

823

207

878

-

31

197

436

259

866

-

59

146

821

206

878

86

26

195

434

258

866

72

54

2,085

1,817

2,163

1,879

*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due 
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of 

comprehensive income for the Group or Company only financial statements.

The carrying amount of Trade Payables and Other Payables approximates to their fair value due to their short 
term nature.

18. Leases

On commencement of a contract (or part of a contract) which gives the group the right to use an asset for a 
period of time in exchange for consideration, the group recognises a right-of-use asset and a lease liability 
unless the lease qualifies as a ‘short-term’ lease or a ‘low-value’ lease.

All leases are accounted for by recognising a right-of-use and a lease liability except for:

•  Leases of low-value assets

Leases where the underlying asset is ‘low-value’, £5k lease payments are recognised as an expense on a 
straight-line basis over the lease term. The group has elected to apply the ‘low-value’ lease exemption to all 
qualifying leases, but the election can be made on a lease-by-lease basis.

•  Short term lease

Where the lease term is twelve months or less and the lease does not contain an option to purchase the 
leased asset, lease payments are recognised as an expense on a straight-line basis over the lease term.

The group sometimes negotiates break clauses in its property leases. On a case-by-case basis, the group 
will consider whether the absence of a break clause would exposes the group to excessive risk. Typically 
factors considered in deciding to negotiate a break clause include: 

Page 90

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

the length of the lease term; 
the economic stability of the environment in which the property is located; and 

• 
• 
•  whether the location represents a new area of operations for the group.

Right-of-use Assets

A right-of-use asset is recognised at commencement of the lease and initially measured at the amount of 
the lease liability, plus any incremental costs of obtaining the lease and any lease payments made at or 
before the leased asset is available for use by the group.

The right-of-use asset is subsequently measured at cost less accumulated amortisation and any 
accumulated impairment losses. The amortisation methods applied is on a straight-line basis over the term 
of the lease.

Amortisation charge for the year included in ‘administrative expenses’ for right-of-use assets.

Group 

At 1 January 2019

Additions

Amortisation

NBV at 31 December 2019

At 1 January 2020

Additions

Variable Lease Payment Adjustment

Amortisation

NBV at 31 December 2020

Office
buildings
£’000

Motor
vehicles
£’000

IT
equipment
£’000

981

-

(132)

849

849

-

4

(133)

720

56

18

(48)

26

26

22

-

(22)

26

41 

-

(20)

21

21

-

(1)

(20)

-

Total
£’000

1,078

18

(200)

896

896

22

3

(175)

746

Page 91

ECSC Group plcAnnual Report Year Ended 31 December 2020 
 
Notes to the Financial Statements (continued)

Company

At 1 January 2019

Additions

Amortisation

NBV at 31 December 2019

At 1 January 2020

Additions

Variable Lease Payment Adjustment

Amortisation

NBV at 31 December 2020

Lease Liability

Office
buildings
£’000

Motor
vehicles
£’000

IT
equipment
£’000

902

-

(110)

792

792

-

4

(111)

685

56

18

(48)

26

26

22

-

(22)

26

41 

-

(20)

21

21

-

(1)

(20)

-

Total
£’000

999

18

(178)

839

839

22

3

(153)

711

The lease liability is initially measured at the present value of the lease payments during the lease term 
discounted using the interest rate implicit in the lease, or the incremental borrowing rate if the interest rate 
implicit in the lease cannot be readily determined.

The lease term is the non-cancellable period of the lease plus extension periods that the group is reasonably 
certain to exercise and termination periods that the group is reasonably certain not to exercise.

The lease liability is subsequently increased for a constant periodic rate of interest on the remaining balance 
of the lease liability and reduced for lease payments.

Interest expense for the year on lease liabilities is recognised in ‘finance costs’.

Page 92

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Group

At 1 January 2019

Additions

Interest Expense

Lease Payments

At 31 December 2019

At 1 January 2020

Additions

Variable Lease Payment Adjustment

Interest Expense

Lease Payments

At 31 December 2020

Company

At 1 January 2019

Additions

Interest Expense

Lease Payments

At 31 December 2019

At 1 January 2020

Additions

Variable Lease Payment Adjustment

Interest Expense

Lease Payments

At 31 December 2020

Group and Company

•  Short-term lease expense  
•  Low value lease expense   

£73k
£3k

Office
buildings
£’000

Motor
vehicles
£’000

IT
equipment
£’000

968

-

42

(121)

889

889

-

4

37

(150)

780

55

18

3

(53)

23

23

22

-

2

(24)

23

40

-

-

(21)

19

19

-

(1)

2

(21)

(1)

Office
buildings
£’000

Motor
vehicles
£’000

IT
equipment
£’000

890

-

39

(99)

830

830

-

4

35

(127)

742

55

18

3

(53)

23

23

22

-

2

(24)

23

40

-

-

(21)

19

19

-

(1)

2

(21)

(1)

Total
£’000

1,063

18

45

(195)

931

931

22

3

41

(195)

802

Total
£’000

985

18

42

(173)

872

872

22

3

39

(172)

764

Page 93

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

At 31 December 2020

Lease Payments

Interest Expense

Lease Liabilities

19. Secured Facilities

Up To 
12 months
£’000

176

(33)

143

1-5
years
£’000

446

(84)

362

more than
5 years
£’000

317

(20)

297

The Group has been provided with payments facilities by Barclays Bank PLC, including a BACS payment 
facility and a credit card facility. Barclay’s are also providing an invoice discounting facility of £500,000. The 
renewal date of the facility is August 2021, where the Board is expected to renew the facility with Barclay’s.

These payment facilities are secured by a debenture in favour of Barclays that creates fixed and floating 
charges over the assets of the Company.

20. Share Capital 

Ordinary Share Capital

During the period ended 31 December 2020, the movement in Share Capital was:

Ordinary Shares

As at 1 January 2019

Exercise of Share Options

At at 31 December 2019

As at 1 January 2020

New Shared Issued

At at 31 December 2020

Number of 
Shares Issued 
and Fully Paid

Ordinary Share 
Capital 
£’000

9,098,497

-

9,098,497

9,098,497

909,091

10,007,588

91

-

91

91

9

100

On 17 April 2020 909,091 ordinary shares were issued for £0.45m (net of expenses of £0.05m). 

Share Premium Account

The balance of the Share Premium Account represents amounts received in excess of the nominal value (1 
pence per share) of Ordinary Shares. This account is non-distributable.

Share Option Reserve

The balance of the Share Option Reserve represents the accumulated amounts charged to the Statement of 
Comprehensive Income in respect of Share Based Payments. This reserve is non-distributable.

Page 94

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Retained Earnings

The balance of the Retained Earnings account represents the accumulated retained profits or losses of the 
Group. This account is a distributable reserve, provided that the accumulated balance is positive.  

21.  Financial Instruments and Financial Risk Management 

The Group’s and Company’s principal financial instruments comprise:

Intercompany Receivables

•  Cash and Cash Equivalents
•  Trade Receivables
•  Other Receivables
• 
•  Trade Payables
•  Accruals
• 
•  Other Payables

Intercompany Payables

The Group’s and Company’s accounting policies, including the criteria for recognition, and the basis on 
which income and expenses are recognised in respect of each class of financial asset and financial liability, 
are set out in note 4.14 to the financial statements. The information about the extent and nature of these 
recognised financial instruments, including significant terms and conditions that may affect the amount, 
timing and certainty of future cash flows, are disclosed in the respective notes where applicable. The Group 
and Company does not use financial instruments for speculative purposes.

Page 95

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The principal financial instruments used by the Group and Company, from which financial instrument risk 
arises, are as follows:

Financial Assets

Trade Receivables

Other Receivables

Intercompany Receivables

Cash and Cash Equivalents

Total Financial Assets

Financial Liabilities

Trade Payables

Accruals

Intercompany Payables

Other Payables

Total Financial Liabilities

GROUP
As At
31 December
2020
£’000

GROUP
As At
31 December
2019*
£’000

COMPANY
As At
31 December
2020
£’000

COMPANY
As At
31 December
2019*
£’000

608

9

-

1,122

1,739

146

207

-

31

384

653

8 

-

351 

1,012

197 

259

-

59 

515

608

9

98

1,119

1,834

146

206

86

26

464

653

8 

92 

350 

1,103

195 

258

72 

54 

579

*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due 
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of 

comprehensive income for the Group or Company only financial statements.

Fair Values

The Directors have assessed that the fair values of Cash and Cash Equivalents, Trade Receivables, Trade 
Payables, Other Payables approximate to their carrying amounts largely due to the short-term maturities of 
these instruments. There are no fair value adjustments to assets or liabilities charged to the Statement of 
Comprehensive Income.

Market Risk

Market risk is the risk that the fair value of future cash flows of a financial instrument will fluctuate due to 
changes in market prices. Market risk comprises three types of risk – commodity price risk, interest rate 
risk; and foreign currency risk. The Group and Company has limited exposure to each of these risks as 
discussed below.

Capital Management

The Group and Company manages its capital to ensure that it will be able to continue as a going concern 
while attempting to maximise the return to stakeholders through the optimisation of the debt and equity 
structure. 

Page 96

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The capital structure of the Group and Company consists of issued Share Capital, Retained Earnings and 
Finance Leases.

The Group and Company do not generally enter into derivative transactions (such as interest rate swaps 
and forward foreign currency contracts) and has been throughout the period covered by these financial 
statements, the Group’s and Company’s policy that no trading in financial derivative instruments shall be 
undertaken.

Credit Risk

Credit risk is the risk that a counterparty will cause a financial loss to the Group by failing to discharge its 
obligations to the Group. The Group manages its exposure to this risk by applying limits to the amount of 
credit exposure to any one counterparty and employs strict minimum credit worthiness criteria as to the 
choice of counterparty. The maximum exposure to credit risk for receivables and other financial assets 
is represented by their carrying amount. The Group considers credit risk to be low due to its processes 
and the nature of its clients, which includes a broad spread of large corporates, SMEs and public sector 
organisations.

The Group uses an expected credit loss model for impairment that represents its estimate of incurred losses 
in respect of the Trade Receivables as appropriate.  

The Group applies the IFRS 9 simplified approach to measure expected credit losses using a lifetime 
expected credit loss provision for trade receivables and contract assets. The expected loss rates are based 
on the Group’s historical credit losses experienced over the two year period prior to the period end. 

The historical loss rates are then adjusted for current and forward-looking information on macroeconomic 
factors affecting the Group’s customer. Under the expected credit loss model impairment allowance wasn’t 
material resulting in no provision being made.

Trade Receivables

Trade Receivables, net of impairment provisions, for the Group and Company as at 31 December 2020 were 
£608k (2019: £653k). These Trade Receivables are not secured by any collateral or credit insurance. The 
Group’s standard terms are 30 days from date of invoice but non-standard terms may be agreed with certain 
customers. Invoices which remain unpaid for periods greater than agreed terms are assessed as overdue. 

As at 31 December 2020, Trade Receivables past due for the Group and Company total £196k (2019: £307k) of 
which nil (2019: nil) have been impaired.

Page 97

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

As at 31 December 2020, Trade Receivables of £196k (2019: £307k) were past due but not impaired, as 
follows:

GROUP
As At
31 December
2020
£’000

GROUP
As At
31 December
2019*
£’000

COMPANY
As At 
31 December
2020
£’000

COMPANY
As At 
31 December
2019*
£’000

196

-

-

196

305

2 

-

307

196

-

-

196

305

2 

-

307

Up to 3 months

3 months to 6 months

6 months to 12 months

Cash Holdings

The Group only holds cash at mainstream banking institutions to mitigate the credit risk on cash deposits. 
The credit rating of the principal banking institution is A (Standard & Poor’s).

Interest Rate Risk

The Company’s exposure to changes in interest rates relates to Cash Holdings and Finance Leases. 

Cash is held either on current or short term deposits at a floating rate of interest determined by the relevant 
bank’s prevailing base rate. 

Interest Rate Sensitivity 

When reviewing sensitivity to movement in interest rates, it is noted that interest rates are at historically low 
levels and that Cash balances significantly outweigh debt balances.

The Directors consider that any downward movement in interest rates would be immaterial to the Group. The 
Directors consider that an upward movement in interest rates would benefit the Group, although the impact 
of a 1% rise in interest rates would be immaterial.

Foreign Currency Exchange Risks

Foreign currency risk is the risk that the fair value or future cash flows of an exposure will fluctuate because 
of the changes in foreign exchange rates. The Group’s exposure to the risk of changes in foreign exchange 
rates relates primarily to the Group’s operating activities when revenue or expenses are denominated in a 
foreign currency.

The Group does not hedge its foreign currencies. Transactions with customers are mainly denominated in 
GBP. 

Page 98

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

The Group has suppliers that invoice in US dollars and Australian dollars. The balances exposed to credit 
risk at year end were as follows:

US Dollars

Australian Dollars

Liquidity Risks

As At
31 December
2020
000

As At
31 December 
2019
000

-

3

3

-

1

1

Liquidity risk arises from the Group’s management of working capital. It is the risk that the Group will 
encounter difficulty in meeting its financial obligations as they fall due. The Group’s policy is to ensure 
that it will always have sufficient cash to allow it to meet its liabilities when they become due. Budgets 
and forecasts are agreed and set by the Board in advance to ensure the Group’s cash requirement to be 
anticipated.

The maturity profile of the Group’s financial liabilities at the reporting dates, based on contractual 
undiscounted payments including lease payments, are summarised below:

Due within 3 months

Trade Payables, Other Taxation ans Social Security, Accruals, Other Payables

22. Related Party Transactions

ECSC Australia Pty Ltd

As At
31 December
2020
£’000

As At
31 December 
2019
£’000

1,207

1,207

951

951

During the year ended 31 December 2020, ECSC Group plc incurred management fees to ECSC Australia 
Pty Ltd of £204k (2019: £312k). As at 31 December 2020, the balance payable by ECSC Group plc to ECSC 
Australia Pty Ltd in respect of outstanding management fees was £86k (2019: £72k).

As at 31 December 2020, the loan balance payable by ECSC Australia Pty Ltd to ECSC Group plc was £98k 
(2019: £92k). The loan is repayable on demand and attracts interest at the rate of 3% over base rate.

Athene VCS Ltd

During the year ended 31 December 2019, Athene VCS a company owned by Elizabeth Gooch (Non-Executive 

Page 99

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Director), invoiced ECSC Group plc £5k for a strategic review service. This transaction was entered into on an 
arm’s length basis. The balance payable as at 31 December 2020 was £nil (2019: nil)

Expandly

During the year ended 31 December 2020, ECSC Group plc invoiced Expandly £5k a company that Elizabeth 
Gooch (Non-Executive Director) is a Director of, for consultancy work. This transaction was entered into on 
an arm’s length basis. The balance payable as at 31 December 2020 was £nil (2019: nil)

23. Share Based Payments

Share Based Payment Schemes

The Company operates a number of equity-settled Share Based Payment schemes, as follows:

•  Enterprise Management Incentive (‘EMI’) Scheme
•  Save As You Earn (‘SAYE’) Share Option Scheme
•  Non-Executive Director Remuneration Scheme (‘NED Scheme’)
•  Non-Executive Directors Share Options (‘NED1 Scheme’)

EMI Scheme

On 04 February 2020 the Company granted over 65,000 Ordinary Shares at an exercise price of 108 pence per 
share, subject to a three year vesting period to the following Directors:

Lucy Sharp

Ian Castle

Gemma Basharan

Ordinary Shares

25,000

20,000

20,000

In order for the options to vest, Ordinary Shares must trade at a minimum mid-market price 200 pence per 
share over 30 consecutive trading days during the vesting period.

During the year ended 31 December 2020, option over 65,000 Ordinary Shares were cancelled. 

Page 100

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

On 21 August 2020 the Company cancelled options over 588,040 Ordinary Shares in the Company as set out 
below.

EMI Grant Date

May-17

Dec-17

Aug-18

Jul-19

Feb-20

TOTAL

Exercise 
Price 
(pence)

Cancelled
Ordinary
Shares

167

140

93

78

108

152,540

25,000

170,000

175,500

65,000

588,040

Following the above cancellation of Ordinary Shares options, on 21 August 2020, the Company granted 
options over 588,040 new Ordinary Shares to the same Company employees, at an exercise price of 65 pence 
per share. In order for the new Options to vest and become exercisable at any time over a ten-year period 
from the date of grant subject to the Company’s closing mid-market price exceeding 167 pence per Ordinary 
Share for 10 consecutive business days. 

Within the grant the following Directors of the Company were granted the following Ordinary Shares:

Lucy Sharp

Ian Castle

Gemma Basharan

Ordinary Shares

144,758

103,602

64,651

During the year ended 31 December 2020, options over 933 Ordinary Shares have lapsed, such that options 
over 587,107 Ordinary Shares remain exercisable in the future.

On 28 August 2020 the Company granted over 450,000 new Ordinary Shares in the Company at an exercise 
price of 69 pence per share. Over 95,000 Ordinary Share options were granted to Employees and become 
exercisable one year from the date of grant, subject to the Company’s closing mid-market share price 
exceeding 167 pence for 10 consecutive business days. All Options expire on the tenth anniversary of the date 
of grant. 

Page 101

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Within the grant the following Directors of the Company were granted the following Ordinary Shares:

Ian Mann

Lucy Sharp

Ian Castle

Gemma Basharan

Ordinary Shares

100,000

100,000

80,000

80,000

The Director Options are exercisable from the relevant vesting date, subject to the Company’s closing mid-
market share price exceeding certain targets for 10 consecutive business days, being 167 pence for the first 
vesting period, 200p for the second vesting period, 225 pence for the third vesting period and 250 pence for 
the final vesting period.

None have lapsed by the year 31 December 2020, such that options over 450,000 Ordinary Shares remain 
exercisable in the future.

Page 102

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Exercised during the year

Expired during the year

Outstanding at 31 December 2020

Option Pricing Assumptions:

Pricing Model

Weighted Average share price at 
grant date (pence)

Weighted average exercise price 
(pence)

Notes to the Financial Statements (continued)

Scheme

Number of Options:

EMI
(May-17)

EMI
(Dec’17)

EMI
(Aug’18)

EMI
(Jul’19)

EMI
(Feb 20)

EMI
(Aug 20)

EMI
(Sep 20)

SAYE

NED

NED 1
(Apr’18)

Total

Outstanding at 01 January 2019

174,490

25,000

180,000

-

Granted during the year

Forfeited during the year

Exercised during the year

Expired during the year

-

(21,950)

-

-

-

-

-

-

-

175,500

(10,000)

-

-

-

-

-

Outstanding at 31 December 2019

152,540

25,000

170,000

175,500

Exercisable at 31 December 2019

-

-

-

-

Outstanding at 01 January 2020

152,540

25,000

170,000

175,500

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

Granted during the year

-

-

-

-

65,000

588,040

450,000

Forfeited during the year

(152,540)

(25,000)

(170,000)

(175,000)

(65,000)

(933)

26,784

6,411

200,000

612,685

-

(7,200)

-

-

-

-

-

-

-

-

-

-

175,500

(39,150)

-

-

19,584

6,411

200,000

749,035

-

19,584

6,411

6,411

-

6,411

200,000

749,035

-

-

-

(19,584)

-

-

-

-

-

-

-

-

1,103,040

(588,973)

-

(19,584)

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

587,107

450,000

-

6,411

200,000

1,243,518

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

Black 
Scholes

312

167

135

140

93

93

78

78

108

108

65

65

69

69

131

125

125

-

79

78

Weighted Average contract life 

3 years

3 years

3 years

3 years

3 years

10 years

10 years

3 years

0 years

3 years

Weighted Average risk free rate

Volatility

Option Valuation:

Option Valuation at grant date 
(£’000)

Share Based Payments Charge 
in 2020:

Share Based Payment Charge 
(£’000)

Weighted Average Exercise Price:

At grant date, forfeit date and end 
of period (pence)

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

1%

40%

-

30

-

-

3

-

-

-

15

13

-

-

-

6

-

190

155

-

-

65

24

69

(5)

-

8

-

-

45

398

15

101

78

Page 103

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

Share Based Payment Charge

In accordance with the requirements of IFRS 2, the Company calculated the fair value of the share options 
at the date of grant using a Black Scholes option pricing model for the EMI and SAYE Schemes. For the NED 
scheme, the fair value of the services rendered was assessed.

A Share Based Payment charge is recognised by spreading the fair value of the option over the maturity 
period, with allowance made for options that have lapsed in the period.

The movement in the number of options during the year, the option pricing assumptions, the option valuation 
at the grant date and the Share Based Payment Charge in the year, for each scheme described above, is as 
follows:

The volatility assumption, calculated at the standard deviation of expected share price returns, is based on 
analysis of the share prices of comparable companies over the last 3-5 years.

Modification treatment

In accordance with the requirements of IFRS 2, the Company adopted the modification treatment with 
regards to the cancellation and replacement of options. This resulted in no incremental fair value being 
recognised as the fair value at the grant date of the replacement options was lower than the fair value 
of the cancelled options. The cancelled options continue to be charged to the Consolidated Statement of 
Comprehensive Income over the remaining vesting period.

24. Controlling Party

ECSC Group plc does not have an ultimate controlling party.

Page 104

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

25. Adjusted Loss before Taxation and Adjusted EBITDA

Adjusted Loss before Taxation

Loss Before Taxation

Share Based Payments

Exceptional Items

Adjusted Loss Before Taxation

Adjusted EBITDA:

Operating Loss

Depreciation and Amortisation

EBITDA**

Share Based Payments

Exceptional Items

Adjusted EBITDA*

Operating Loss

Share Based Payments

Exceptional Items

Adjusted Operating Loss*

* Adjusted Operating Loss and EBITDA excludes one-off charges and share based charges. 

* *  EBITDA is defined as Earnings before Interest, Tax, Depreciation and Amortisation.

Year Ended
31 December
2020
£’000

Year Ended
31 December
2019
£’000

(319)

101

65

(153)

(750)

105

6

(639)

Year Ended
31 December
2020
£’000

Year Ended
31 December
2019
£’000

(271)

480

209

101

65

375

(704)

594

(110)

105

6

1

Year Ended
31 December
2020
£’000

Year Ended
31 December
2019
£’000

(271)

101

65

(105)

(704)

105

6

(593)

Page 105

ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

26. Exceptional Costs

During the year ended 31 December 2020, the Company undertook a restructure exercise to reduce its 
operating costs due to the effect of COVID-19 on consultancy revenues. In achieving these recurring 
cost savings, a number of one-off, exceptional costs were incurred, including payments in lieu of notice 
and redundancy payments. These Exceptional Costs totalled £65k and were charged to the Statement of 
Comprehensive Income in the year ended 31 December 2020.

Exceptional Costs are analysed as follows:

Payments in Lieu of Notice

Redundancy Payments

Employee Benefit Expense

Taxation & Social Security Costs

Staff Related Costs

Legal Costs

Exceptional Costs

As At
31 December
2020
£’000

As At
31 December
2019
£’000

46

7

53

8

61

4

65

-

-

-

-

-

6

6

Page 106

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)

27. Subsidiary Undertakings

ECSC Group plc currently has the following wholly-owned subsidiaries, which are incorporated and 
registered in England and Wales:

Name of Subsidiary

Registered Office

Date of Incorporation

Principal Activity

ECSC Services Limited

ECSC Labs Limited

ECSC Australia Limited

28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR

28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR

28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR

18 April 2017

Dormant

18 April 2017

Dormant

29 September 2016

Intermediary holding company

ECSC Australia Limited currently has the following wholly-owned subsidiary, which is incorporated and 
registered in Australia:

Name of Subsidiary

Registered Office

Date of Incorporation

Principal Activity

ECSC Australia Pty Limited

Governor Phillip Tower 
Level 36
1 Farrer Place
Sydney
NSW 2000

The share capital of each Group entity is as follows:

20 March 2017

Provision of professional cyber 
security services

Entity

Ordinary Shares In Issue

Nominal Value

Investment At Cost

ECSC Services Limited

ECSC Labs Limited

ECSC Australia Limited

ECSC Australia Pty Limited

Total

*AUD = Australian Dollars

1 share

1 share

1 share

100 shares

£1

£1

£1

AUD 1

£1

£1

£1

AUD 100

£60

Page 107

ECSC Group plcAnnual Report Year Ended 31 December 2020Who would have believed we would ever get to this point!  I know it is silly, but I am sat here 
with a huge smile on my face for once! 

[ECSC Employee] has just left for his train - and I am the only person in the office to know the 
news! 

Thanks very much - we’ve a few to go yet, but the support we have had on this long slog has 
been first class!

Compliance Manager, Major Train Operator

[ECSC Employee] was extremely helpful and helped us through the certification procedures 
and what would be required and expected. However, [ECSC Employee] went over and above at 
each opportunity, offering up suggestions on up-skilling our in house teams and gave tips on 
things to look out for and improve upon. 

[ECSC Employee] ensured he was on hand at all times throughout the process, offering up 
several communication methods, and helped us work through issues working with a third 
party to ensure we completed the requirement in time to help us achieve certification. 

ECSCs professional services have gone over and above expectations. [ECSC Employee] is a 
true asset to the company, and I would be more than happy to work with him again on our next 
project.

Security and Infrastructure Analyst, Online Retailer

I’ve got to say what a great piece of work your team have produced - really impressed with the 
quality of the document and the people. 

I am confident that this will be the start of a long and illustrious relationship with [ECSC 
Client].

Senior Support Analyst, Major Utilities Supplier 

Page 108

Cyber Security ExpertsAnnual Report Year Ended 31 December 2020