ECSC Group plc
Annual Report Year Ended 31 December 2020
This page has been left deliberately blank.
Page 2
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Contents
4 Company Information
7 Chairman’s Statement
8 Chief Executive Officer’s Review
12 Chief Operating Officer’s Review
14 What We Do
17 ECSC Story
18 Typical Client Journey
19 Client Challenges
20 Client Perspective
21 Research and Development
22 Evolving Threats
23 Market Opportunities
24 Strategic Report
35 Board of Directors
37 Directors’ Report
43 Remuneration Committee Report
50 Statement of Directors Responsibilities
“I’m pleased to note that we have maintained
a stable team throughout these difficult times,
with staff retention at an improved rate of 91%.
On behalf of the board, I would like to thank
all of our clients, partners, team, advisors,
and investors for their continued support
throughout a challenging year for us all.
ECSC is well-positioned in the growing
cyber security marketplace, and we are now
resuming our organic growth strategy and
related recruitment activities. ”
David Mathewson
Non-Executive Chairman
51 Independent Auditor’s Report to the Members of ECSC Group plc
59 Consolidated Statement of Comprehensive Income
60 Consolidated Statement of Financial Position
61 Company Statement of Financial Position
62 Consolidated Statement of Changes in Equity
63 Company Statement of Changes in Equity
64 Consolidated Cash Flow Statement
65 Company Cash Flow Statement
66 Notes to the Financial Statements
Page 3
ECSC Group plcAnnual Report Year Ended 31 December 2020Nominated Advisor & Broker to the Company
Allenby Capital Limited
5 St. Helen’s Place
London
EC3A 6AB
Auditors to the Company
BDO LLP
Central Square
29 Wellington Street
Leeds
LS1 4DL
Financial Press and Investor Relations
Yellow Jersey PR
ecsc@yellowjerseypr.com
0203 004 9512
Solicitors to the Company
Freeths LLP
1 Vine Street
Mayfair
London
W1J 0AH
Registrar
Equiniti Group plc
Sutherland House
Russell Way
West Sussex
RH10 1UH
Company Information
Directors
David Mathewson (Non-Executive Chairman)
Ian Mann (Chief Executive Officer)
Lucy Sharp (Chief Operating Officer)
Gemma Basharan (Chief Financial Officer )*
Ian Castle (Chief Technical Officer)*
Elizabeth Gooch (Non-Executive Director)
*Appointed on 25 March 2020
Registered Office
28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR
Telephone Number
01274 736 223
Company Secretary
David Mathewson
Website
www.ecsc.co.uk
Page 4
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Highlights
22%
6%
Managed Detection &
Response (MDR)
recurring revenue
growth of 22%
to £2.42m
(2019: £1.98m)
MDR revenue up
6% to £2.73m
(2019: £2.59m)
£0.4m
PROFIT
£5.66m
Adjusted EBITDA*
profit £0.4m
(2019: break-even)
Revenue of £5.66m
(2019: £5.91m)
£1.12m
90
Cash at period end
£1.12m**
The Group’s bank facility
remains unutilised
(31 Dec 2019: £0.35m)
90 new Assurance
clients secured
(2019:118)
* Adjusted EBITDA excludes one-off charges and share based charges
** Including £0.42m of COVID-19 related medium-term government support relating to VAT and PAYE deferral
Page 5
Page 5
ECSC Group plcAnnual Report Year Ended 31 December 2020MDR
ASSURANCE
VENDOR
OTHER
Track Record Of Organic Growth
£6,000,000
£5,000,000
£4,000,000
£3,000,000
£2,000,000
£1,000,000
0
2014-2015
2016*
2017**
2018
2019
2020
* Adjusted for 12 months
** Restated for IFRS 15
Global Offering
General Office
Security Operations Centre
Incident Response
Page 6
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020The Group’s successful £0.5m (before costs)
fundraise in April 2020 demonstrated the continued
support from our institutional investors and reduced
our risk exposure during the uncertain months
of 2020. As a result of the growth in profitability
and cash generation, the Group did not utilise this
additional funding.
I am pleased to note that we have maintained a
stable team throughout these difficult times, with
staff retention at an improved rate of 91%.
On behalf of the board, I would like to thank all of
our clients, partners, team, advisors, and investors
for their continued support throughout a challenging
year for us all.
ECSC is well-positioned in the growing cyber
security marketplace, and we are now resuming our
organic growth strategy and related recruitment
activities.
David Mathewson
Non-Executive Chairman
23 March 2021
Chairman’s Statement
These results demonstrate solid growth in the
Group’s adjusted EBITDA profitability and cash
generation. The encouraging progress we have
seen in our Managed Detection and Response
(MDR) division has been driven by continuing
market demand and increasing awareness
of ECSC’s expertise in both the development
of technologies and in the area of Artificial
Intelligence (AI). This highlights the ongoing
requirements for all organisations to maintain their
cyber security defences, and we have emerged from
the most difficult period imaginable in a strong
position.
Despite the ongoing uncertainty caused by the
pandemic and the economic risks associated with
Brexit, the Group has continued to demonstrate
resilience and financial progress based on quality
of delivery and unrivalled client reputation and
retention. I am proud of the way the team has
adapted in order to achieve a very credible set
of results throughout a period of unprecedented
economic turmoil.
The confirmation of the multi-million-pound fines
related to the UK and European General Data
Protection Regulation (GDPR) substantiate the
new regulatory environment that all organisations
have to acknowledge; building resilience into their
cyber security protection, detection and response
capabilities. ECSC remains the trusted partner to
help organisations of all sizes achieve this.
The continued growth in 24/7/365 detection services,
delivered through the Security Operations Centres
(SOCs) in the UK and Australia, supported by the
ECSC Kepler Artificial Intelligence (AI), shows the
importance of early breach detection to contain the
incident and limit damaging consequences. For all
but the largest global organisations, the outsourcing
of this critical function continues to be the logical
choice, and ECSC has the technology, people, and
certified processes to deliver.
Page 7
ECSC Group plcAnnual Report Year Ended 31 December 2020Chief Executive Officer’s Review
The direct revenue impact of COVID-19 was most
evident in two areas:
Firstly, the Assurance division, comprising mainly
consultancy type services, was impacted with client
cancellations and delays to confirmed projects.
Having seen Assurance growth in Q1 2020 of just
over 4% compared with the 2019 average quarterly
revenue, Q2 2020 saw revenue drop by over 50%
against the same comparator.
However, Q3 2020 demonstrated a rapid recovery to
only 4% down on average 2019 quarterly revenues,
with Q4 returning to growth of over 6% against the
same comparator.
£800,000
£700,000
£600,000
£500,000
£400,000
£300,000
£200,000
£100,000
0
ASSURANCE
REVENUE
2019 AV.
Q120
Q220
Q320
Q420
Secondly, client chargeable expenses declined from
£53k in Q1 2020 to only £8k in Q2 2020, and only £21k
combined in Q3 2020 and Q4 2020 as remote working
continued.
The combined reductions in revenue for the
Assurance division in Q2 and expenses for the year
came to over £400k. This compares with the overall
Group revenue reduction of £242k for the year,
showing the reduced revenue was due to the short-
term impact of COVID-19.
The Group made solid progress during the 2020
financial year, and we are particularly pleased to
report growing adjusted EBITDA profitability and
cash generation.
The £3m of Group revenue in H2 illustrates the
recovery in the Assurance division following the
COVID-19 related impact seen in Q2. The continued
growth in recurring MDR revenue demonstrates
the resilience of this service line, and our effective
strategy of winning consulting clients and
converting them into long-term managed services
clients.
COVID-19 Impact
One year ago, at the time of publishing our annual
results, the potential impact of the pandemic was
beginning to emerge. As such, we led our Annual
Report with our strategy of managing the situation.
This included:
1. Re-engineering services traditionally delivered
on-site with clients to enable remote and home
working, ensuring the safety of our clients and
our team.
2. Ensuring the continued delivery of off-site 24/7
managed services with uninterrupted compliance
with all agreed Service Level Agreements (SLAs).
3. Making use of government support and reducing
costs to a break-even level during the short-term
period of revenue loss.
The management team, and the efforts of all
employees, ensured we met the first two objectives
and exceeded the third.
To reduce the overall risk to the Group, in April
2020 we conducted a fully subscribed £0.5m (before
costs) fundraise from existing and new institutional
investors to strengthen our cash position, and
reduce the risks of either an extended lockdown, or
potential long-term disruption without the uncertain
government support.
Page 8
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Chief Executive Officer’s Review cont.
£60,000
£50,000
£40,000
£30,000
£20,000
£10,000
0
CLIENT
EXPENSES
2019 AV.
Q120
Q220
Q320
Q420
Return to Profitability
The combination of the strong recovery in the
Assurance division in Q3, the continued recurring
revenue growth in the MDR division of 22%, and
careful control of costs, saw Group Adjusted EBITDA
profit of £0.4m (2019 break-even).
Growth Strategy
We are confident that the organic growth strategy of
ECSC remains appropriate. Despite the challenges
of 2020, we added 90 new Assurance division clients.
In addition, we expanded the Partner Programme
to over 150 partners, contributing to 4% of revenue
(2019: 2%) and 13% of the new client wins.
Key Performance Indicators
The Key Performance Indicators below were
established in 2018 to enable meaningful
measurement of the Group’s performance. See page
10.
Outlook
ECSC is well-positioned in the growing cyber
security marketplace and looks forward with
confidence to delivering improved operating results
and shareholder value.
Ian Mann
Chief Executive Officer
23 March 2021
Page 9
ECSC Group plcAnnual Report Year Ended 31 December 2020Key Performance Indicator Table
Key Performance Indicator Table
Performance
Indicator
Rationale
2020
2019
2018
Management Comment
Revenue Growth
Measurement of the
success of the organic
growth strategy
(4%)
10% 35%
Managed Detection
and Response
Recurring Revenue
Growth
Visibility of the success of
increasing the percentage
of revenue from long-term
recurring revenues
Managed Detection
and Response
Recurring Revenue
Proportion
Visibility of the success of
increasing the percentage
of revenue from long-term
recurring revenues
Managed Detection
and Response
Order Book
Combined measurement
of new client contracts
together with renewals of
existing client contracts
22% 27% 46%
43% 34% 29% In line with the strategy to
increase this proportion
£2.6m £2.6m £2.5m
Managed Detection
and Response
Gross Margin
Delivery efficiency
measurement
73% 68% 53%
Assurance Repeat
Revenue
Quasi-recurring from
longer-term consulting
clients
73% 73% 78%
Assurance Gross
Margin
Delivery efficiency
measurement
58% 54% 57%
Research and
Development
(of revenue)
Continued investment in
technology and intellectual
property development
14% 13%
8%
Page 10
The Group saw a decline
in Assurance revenue
and rechargeable
expenses due to COVID-19
pandemic. Assurance
revenues returned to
growth in Q4
Continued growth due to
new contract wins and
contract expansions,
building on the 2017
investment.
The management team’s
favoured overall measure
of progress in managed
services
Indicative of increased
leveraging of IPO
investment in capacity
Indicative of strong client
retention and continued
trust in ECSC quality
A reflection on capacity
required for growth and
management of consultant
workload
A new measure introduced
to show continued
investment in technologies
for the future
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Ian Mann, CEO, Security Operations Centre, Yorkshire
Page 11
ECSC Group plcAnnual Report Year Ended 31 December 2020Chief Operating Officer’s Overview
Our in-house recruitment strategy continues to
serve us well to ensure we attract and recruit the
best people across all teams, guaranteeing the right
mix of skills and diversity that complement and
enhance the current team. Despite the pandemic,
we have still been able to leverage our student
placement, graduate and apprenticeship schemes,
working closely with local universities, to ensure an
appropriate pipeline of talent, so we have the right
people in the right positions, for now and also with
succession planning in mind for the future.
We are very proud of the way in which everyone has
navigated through these challenging times, with
minimal detrimental impact on our ability to both
engage and retain our people, to successfully deliver
our services, to maintain quality in what we do, as
well as introduce new members across the business
in support of our growth plans.
I am pleased to be resuming recruitment activities
and have every confidence in the team to continue to
deliver the excellent service we are known for.
Lucy Sharp
Chief Operating Officer
23 March 2021
Whilst the last 12 months have been challenging for
everyone due to the COVID-19 pandemic, the Group
has not lost sight of the importance of our people
and this has been at the forefront when considering
plans to navigate through these unusual times.
As clients came to terms themselves with working
remotely and therefore halting their own security
projects, we saw a reduction in consultancy in Q2
of the year. For the Assurance division, historically
delivering consultancy services predominantly on
client sites, our teams had to adapt very quickly,
switching to delivering all our services remotely.
The team has responded remarkably well and this
is reflected in the excellent client feedback we have
received. After re-engineering our service offering
to be delivered remotely, we were able to bring
consulting delivery back up to pre-COVID numbers
through Q3 and Q4, finishing the year in a strong
position.
We are delighted to report that we have maintained
a stable team through these difficult times as seen
from our 91% staff retention rate. Our most recent
Employee Engagement Survey showed that the team
continues to feel their contribution is valued and
morale and commitment is as strong as ever. This is
testament to our continued people-focused strategy,
and in turn protects the strong, positive culture we
have built at ECSC – one of continual development,
learning and communication.
Professional development across all teams has
continued throughout the last 12 months, meaning
individuals feel equipped to be the best they can
be and are on the front foot in this ever-changing
cyber landscape. Within the Assurance division for
example, this enables individuals to contribute to
multiple service lines to increase their experience
and skills, while also increasing utilisation levels,
promoting innovation and our ability to respond to
market demand.
Page 12
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Employee Engagement Survey 2020
“I really enjoy
working at ECSC and
hope to for many
years to come”
“I have never felt so
appreciated in a role
as I do at ECSC”
“The Senior
Management Team
are awesome,
always willing to
help and support”
97%
have faith in the
Senior Management
Team to deliver on
their objectives
97%
feel proud of ECSC
98%
have a good working
relationship with
their team
97%
want to make a
difference in helping
the Company
succeed
Sample response to our latest Employee Engagement Survey
Page 13
ECSC Group plcAnnual Report Year Ended 31 December 2020What We Do
Incident response
‘emergency’ service
Remotely manage client
cyber security devices
from ECSC’s Security
Operations Centre (SOC)
Cyber security reviews
Consultancy to help
clients achieve ISO 27001
information security
certification
Technical penetration
testing of cyber security
Advise and assess clients
for certification to the
Payment Card Industry
Data Security Standard
(PCI DSS)
Develop Artificial
Intelligence (AI)
Cyber Essentials
Certifications
Page 14
Page 14
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020What We Do
For most organisations, understanding their cyber security responsibilities is often complex and
challenging, with new threats discovered daily. The priority given by organisations to cyber security
has changed significantly since we started 20 years ago, helped most recently by the introduction of the
General Data Protection Regulation (GDPR), the mandatory reporting of breaches to the Information
Commissioner’s Office (ICO) and increased fines. Given the legal responsibility now placed on
organisations to protect personal data, the sensible approach for most is to seek external help.
Despite the complexities of cyber security, a consultative approach remains at the heart of ECSC’s offering.
All communications are carried out in a format and language that is easy to be understood by all.
ECSC’s range of services can be broken down into three basic categories.
Despite regular scaremongering by certain product vendors, press releases from
organisations that have suffered a breach, and at times the media, all breaches are
preventable. We confidently make this statement based on 20 years experience in
incident response.
An organisation’s primary strategy should be breach prevention. ECSC helps in a
number of ways. The most common is to test cyber security using similar techniques
to those used by hackers. In the industry, this is referred to as penetration testing or
ethical hacking. Finding the vulnerabilities before a hacker does and remedy accordingly.
Although it may be possible to prevent all breaches, it is also sensible to have an ability
to detect breaches. Done correctly, this means that incidents can usually be contained
before expensive data-loss occurs. Additionally, under GDPR, there is a requirement to
be able to detect breaches.
ECSC’s full 24/7/365 cyber security monitoring, alerting, and analysis from the both UK
and Australian Security Operations Centres provides our managed service clients with
peace of mind.
Although it makes little sense for all but the largest organisations to build, and try
and retain, an internal incident response capability, it does makes sense to have a
relationship with external experts that can respond 24/7.
ECSC’s 20 years of incident experience mean that we can assist our clients from
the smallest and simplest event, to the most complex incident requiring extensive
investigation, an on-site team, and guidance with external stakeholder and regulator
communications.
Page 15
Page 15
ECSC Group plcAnnual Report Year Ended 31 December 2020ECSC Group plc, Security Operations Centre, Yorkshire
Page 16
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020The ECSC Story
“I’ve got to say what a great piece of
work your team have produced - really
impressed with the quality of the
document and the people. I am confident
that this will be the start of a long and
illustrious relationship with ECSC”.
The ECSC story begins in the
dotcom boom of the late 1990s.
Ian Mann was conducting
government consultancy and
running one of the first UK Cisco
training academies, teaching
the first generation of Internet
engineers. Having just completed
an MBA, Ian was looking to start
his own business. He noticed
that the security element of the
network training was the biggest
challenge for most students and
therefore concluded that this
would be a growing need for
organisations as they began to
fully utilise the Internet.
With the financial help of his credit
cards, two re-mortgages, the
backing from family and friends,
and a few work colleagues, ECSC
was born. ECSC’s second recruit
was Lucy Sharp (now COO) who
Ian employed as a school leaver.
Initially testing the security of
organisations’ new connections
to the Internet, and responding
to security incidents, very quickly
clients began to enquire whether
ECSC could manage this critical
area. In 2001, the Group’s
managed services division began;
taking internally developed
technologies originally for ECSC’s
own use, and applying them to
client environments.
As the industry began to mature,
and international standards began
to emerge, ECSC then started
supporting clients efforts to
achieve and manage a range of
certifications.
Although focusing fully on ECSC,
Ian continued to do some advisory
work for the UK’s GCHQ, and
more recently trained their new
cyber security recruits in the art of
people hacking (having authored
two books on the subject of social
engineering).
The next significant appointment
was Ian Castle, who joined in 2003
as CTO to co-ordinate the research
and development that forms
the foundation of the already
award winning ECSC proprietary
technology and managed services.
Senior Support Analyst
Major Utilities Supplier
The next current senior
management appointments came
in 2007, when Paul Lambsdown
took charge of the Group’s sales
function, with Gemma Basharan
later joining the finance team
in 2011, and Clare Macdonald
establishing the marketing team
in 2013.
Despite numerous offers to
buy the business, in 2016
ECSC decided to raise the first
institutional investment via
an initial IPO on the London
Stock Exchange AIM market.
This investment enabled the
establishment of new Security
Operations Centres in the UK and
Australia, giving true 24/7/365
‘eyes on glass’ cyber security
monitoring, without the need for
engineers to work night shifts.
Today, the senior management
team has over 80 years combined
experience within ECSC.
Page 17
ECSC Group plcAnnual Report Year Ended 31 December 2020Typical Client Journey
A client journey with ECSC tends to start from one of three starting points:
HELP, WE THINK WE’RE
IN THE MIDDLE OF A
BREACH!
THE OWNERS/DIRECTORS
NEED TO KNOW IF
THEIR ORGANISATION IS
SECURE?
WE NEED TO
DEMONSTRATE OUR
CAPABILITY THROUGH
A RECOGNISED
CERTIFICATION
Incident response call-outs can
happen at any time (although
they are more common outside of
business hours).
The priority here is to help contain
the breach, understand how to
prevent re-occurrence and then
deal with any ongoing impact.
Following this, a longer-term view
can be developed to help prevent
a repeat breach and enable the
organisation to function efficiently
with an appropriate level of
security.
The ECSC Cyber Security Reviews
are often a good place to start, as
they give non-technical managers
and owners a clear picture of
the risks and a pragmatic route
to risk reduction and ongoing
management.
Where a technical person asks
the same question, a more
‘traditional’ penetration test
may be the best solution. By
duplicating the approach of a
hacker, we help a client uncover,
and address, their vulnerabilities
before a breach occurs.
The emergence of a number of
UK and international standards,
means that clients have an
opportunity to demonstrate
competence and develop
trust with their stakeholders.
Increasingly, this is becoming
essential to doing business in
some sectors, and taking part in
sales tenders.
Although the initial objective may
be ‘get the badge’, the process of
certification usually does lead to
organisational learning, and real
enhanced security.
Although it is rare that a fully 24/7 managed solution is a starting point, it is increasingly the destination.
Clients recognise that it is almost impossible to recruit and retain this level of expertise in-house, but do
require the benefits associated with a 24/7 managed solution.
The ECSC approach has always been to understand the client’s requirements, give honest, practical advice,
and deliver effective solutions that contribute to building long-term partnerships based on trust and value.
Page 18
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Typical Client Challenges
Cyber security brings many and varied new challenges for organisations of all sizes and complexities.
They cut across vertical sectors and traditional competencies.
There are some common features in the challenges that we help our clients to solve:
DIFFICULTY IN RECRUITING
AND RETAINING SPECIALIST
SKILLS IN CYBER SECURITY
THE RATE OF
COMMUNICATION AND
INFORMATION
TECHNOLOGY CHANGE
UNDERSTANDING
THE COMMON MYTHS
PROPAGATED BY SOME
VENDORS AND/OR THE MEDIA
This may be due to the cost of
funding a specialist role, or not
having the right environment
to attract them. With a general
skills shortage, qualified and
experienced people have the
choice of roles and will tend to
be attracted by the variety and
challenge, plus the chance to
further develop their skills, not
just by the money.
However, it can also be a case that
organisations won’t need some
skills full-time, only at specific
times. For example, it makes little
sense for most organisations to
try and recruit people skilled in
emergency incident response - an
organisation may only need this
once a year.
The increasing pace of change can
nearly always be associated with
new cyber security vulnerabilities.
Despite what they say, technology
providers do not make security a
priority over their profits.
For example, in the last
12-months, people migrating
IT systems into the cloud have
accounted for 90% of the breaches
we have been called out to resolve.
These include the belief that
breaches cannot be prevented
(in 20 years of incident response,
we have never seen or heard of a
breach that was not preventable).
Another common myth is that
hackers target organisations
because they are looking for
specific targets. The reality is
that most breaches are a result
of organisations making technical
or people mistakes that are then
spotted and exploited by malicious
hackers.
Page 19
ECSC Group plcAnnual Report Year Ended 31 December 2020Client Perspective
It is fair to say that all ECSC clients want to prevent cyber security breaches. However, they also want
more than this. They usually require a range of services that have some common elements:
EASY TO UNDERSTAND DELIVERY OUTPUTS THAT
EXPLAIN CYBER SECURITY IN A LANGUAGE THEY
UNDERSTAND
Easy to understand delivery outputs that explain
cyber security in a language they understand.
This may be an ECSC Cyber Security Review that
maps and grades technical weaknesses into
a language that non-technical executives can
understand. This custom ECSC approach is now
proven to be the best way for non-technical senior
managers to understand current risks, and measure
progress towards a more defendable position.
Another example is where we summarise complex
penetration testing (ethical hacking) into a simple
Pass/Fail result that managers and business owners
can understand, with prioritised findings - each
graded by risk. This allows clients to address
findings in order of priority.
AN ONGOING PARTNERSHIP
BUILT ON TRUST
It is common for our partnership with a client to
develop over many years. Their requirements evolve
as their technology usage changes, new threats
emerge and they recognise the value that our
expertise can bring to their organisation.
In most cases, small initial engagements develop,
and in many cases these evolve into full 24/7/365
outsourced managed services.
VALUE
EMERGENCY RESPONSE
Delivering the intended outcomes efficiently and
professionally. Clients value the benefits of 20 years
experience across the range of consulting, managed
services and incident response. An unrivalled mix
for any UK provider. This means less risk for clients
than selecting new entrants.
If the worst happens, ECSC clients (and non clients)
benefit from an experienced and calm response
by an expert team. Early expert involvement in
potential breaches means that incidents can usually
be contained before expensive data-loss or system
disruption occurs.
If an incident does escalate, ECSC helps in all
aspects of response management from the
technical response and investigation to stakeholder
and regulator communications.
Page 20
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Research and Development
Our continued investment in Research and Development takes many forms, all of which are of crucial
importance to our continued success:
WHAT THE HACKERS ARE
DOING
MANAGED SYSTEMS
INTERNAL SYSTEMS
Each day, globally, there are about
40 new technical ‘vulnerabilities’
discovered and published.
Keeping track of these, and how
they relate to an organisation’s
IT system, is complex. In reality
only a small number of these are
critical but extensive experience is
needed to recognise the important
trends and developments.
Within ECSC we review new
vulnerabilities formally every 8
hours, 365 days a year and relate
them to our systems, systems
managed for clients, and wider IT
environments. We do this, so that
our clients do not need to.
Whilst technology continues to
advance, most new offerings
are designed to be pioneering
and functional with security
taking a back-seat. This means,
new IT developments, such as
cloud services, have introduced
significant new vulnerabilities,
resulting in an increased need for
our incident response services.
With managed security devices
deployed since 2001, ECSC has a
long track record of intellectual
property development, and
delivering systems that work for
our clients.
The release of our Kepler Artificial
Intelligence (AI) technology is an
example, where we can process
billions of pieces of security
information from client’s IT
systems and allow our Security
Operations Centres to operate
with efficiency and speed.
Although some people over hype
AI, we see this as enhancing the
effectiveness of real experts, but
not yet replacing the need for
skilled, experienced people.
Given the sensitivity of our client
data, ECSC does not allow any
third-parties to store or process
our information.
Therefore, continued development
of our internal systems is
important to allow us to refine
processes and enhance our
effectiveness.
Our integrated management
systems mean that we have
complete process control from the
start of our marketing activities
through to assurance delivery and
fully managed services.
Page 21
ECSC Group plcAnnual Report Year Ended 31 December 2020Evolving Threats
Cyber security has evolved, as have the risks to every organisation. There is now the recognition that
personal data has value, and with that comes a legal requirement to keep it secure.
Organisations also recognise that an increasing reliance on information technology means that a breach can
have immense impact on day-to-day operations.
Originally, before the term ‘cyber security’ was invented, most hacking was conducted by enthusiasts - often
with no malicious intent. For example, the first computer virus was actually an experiment in a university
that worked too well and spread globally.
However, as more and more organisations and individuals connected to the Internet, criminals recognised
the potential to exploit technology weaknesses, knowing the law enforcement agencies would have
difficulties catching them.
As a result, we have seen huge increases in hacking that results in criminal behaviour. The most common
being:
RANSOMWARE. Where the hacker encrypts data and demands a ransom to give you
access to your own data. For an individual this may be their photo collection, whereas for
an organisation it may be to cripple their whole IT system.
STEALING DATA. Information has value, as it can form the basis of fraud. Therefore,
credit card information and other personal data will always be a target as it can be sold
on.
More recently, nation state hackers have gained significant media coverage, and, quite rightly, attention
from the areas of government tasked with protecting critical national infrastructure. However, for most
organisations they are not a target for this activity. The reality remains that hacking is not targeted, rather
it exploits mistakes and weaknesses identified by scanning the Internet for known vulnerabilities and also
tricking IT users into causing breaches.
Therefore, organisations need help in keeping up-to-date with the continually changing threat landscape,
and understanding and controlling the potential impact of users being caught out. ECSC remains at the
leading edge of both these critical areas.
Page 22
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Market Opportunities
The EU General Data Protection Regulation (GDPR),
enacted in the UK in May 2018 by a new Data
Protection Act (DPA) represents the most significant
legal protection to personal data in more than a
decade. This new legislation impacts the cyber
security market place in three main ways:
In addition, the GDPR states that third-party
‘processors’ must apply cyber security in relation to
the risks present, not in proportion to their charges.
This means all IT outsourcing organisations have to
re-examine their approach to cyber security risk.
1. Mandatory Reporting
Organisations now have to report breaches of
personal data to the Information Commissioner’s
Office (ICO) within 72 hours of being made aware.
This means that breaches can no longer be hidden
and kept ‘in-house’. Organisations should seek
expert assistance to ensure that they have responded
appropriately to avoid substantial fines.
2. New Maximum Fines
Increased from the previous £500,000 maximum to
10m Euros or 2% of total worldwide turnover.
3. Direct ICO Liability for Third-Parties
Previously IT providers could hide behind their
agreed terms and conditions, with liability limits, if
they caused a cyber security breach. The advent of
GDPR gives them an independent liability to the ICO
with the same maximum fines.
Other factors are also driving more market
opportunities, including:
• The uptake of cloud IT services, where applying
‘traditional’ cyber controls can be difficult
or impossible, and providers often lack the
expertise to design security into their cloud
offerings.
• Ongoing skills shortages in cyber security
make more clients seek external help, either
to test their security, help implement specific
projects, or to outsource their cyber security
management.
• The pace of IT system changes and new
developments shows no sign of slowing. History
shows that the quicker technology changes,
the more cyber security vulnerabilities are
introduced and the more breaches occur.
UK cyber security market
estimated at over £8 billion
Proliferation of breaches
making cyber security a
strategic governance issue
for company boards
UK legislation (GDPR) now
in force making immediate
breach reporting
mandatory and fines up to
2% of global turnover
Page 23
ECSC Group plcAnnual Report Year Ended 31 December 2020
Cyber Security Experts
Annual Report Year Ended 31 December 2020
Page 24
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Review
Principal Activities
The principal activity of the Group during the year continued to be the provision of professional cyber security
services, including Assurance, MDR and the sale of Vendor Products.
Comparative Financial Information
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
Revenue
Assurance
MDR
Vendor Products
Other
Gross Profit
Assurance
MDR
Vendor Products
Other
Adjusted EBITDA*
Other Income
Sales & Marketing Costs
Administration Expenses
EBITDA**
Share Based Payments
Exceptional Items
Depreciation and Amortisation
Adjusted Operating Loss*
Operating Loss
2,724
2,732
125
82
5,663
1,576
1,994
25
(47)
3,548
297
(1,713)
(1,757)
375
(101)
(65)
(209)
(480)
(105)
(271)
* Adjusted Operating Loss and Adjusted EBITDA excludes one-off charges and share based charges.
* * EBITDA is defined as Earnings before Interest, Tax, Depreciation and Amortisation
(As defined in note 25 in the Financial Statement).
2,922
2,585
162
236
5,905
1,574
1,745
29
12
3,360
263
(1,958)
(1,664)
1
(105)
(6)
(110)
(594)
(593)
(704)
Page 25
ECSC Group plcAnnual Report Year Ended 31 December 2020Financial Review (continued)
Revenue & Organic Growth
controls.
Total revenue in the year ended
31 December 2020 was £5.66m,
down 4% on the comparable prior
period (revenue in the 12 months
ended 31 December 2019 was
£5.91m). Within this, Assurance
revenue fell by 7% to £2.72m
(2019: £2.92m).
EBITDA & Operating Loss
Adjusted EBITDA for the year,
which excludes one-off charges
and share based charges, was
£0.4m (2019: Break-even). EBITDA
for the year was a profit of £0.21m
(2019: loss of £0.11m).
MDR division revenue rose by
6% in the year to £2.73m (2019:
£2.59m). This includes recurring
revenue which rose to £2.42m
(2019: £1.98m) and Incident
Response revenues which fell to
£0.31m (2019: £0.60m).
Adjusted Operating Loss for
the year, which excludes one-
off charges and share based
charges, was £0.11m (2019: loss
of £0.59m). The Operating Loss in
the year was £0.27m (2019: loss of
£0.70m).
of £0.29m from HMRC in respect
of a surrender of R&D Tax Credits
from earlier periods.
Tangible Asset
Property, plant and equipment
(PPE) cost has remained at
£0.95m (2019: £0.95m). This is
offset by depreciation of £0.81m.
The Group’s capital expenditure
for the year was £0.01m. The Net
Book Value of Tangible Assets as
at 31 December 2020 was £0.15m
(2019: £0.28m).
Trade and Other Receivables
Trade and other receivables
decreased to £0.81m (2019:
£0.89m) as at 31 December 2020.
This includes £0.61m of Trade
receivables.
Trade and Other Payables
Trade and other payables
increased to £2.09m (2019:
£1.82m) as at 31 December 2020.
This includes £0.88m of deferred
income (2019: £0.87m).
Cash Flow
Cash and cash equivalents
increased by £0.77m to £1.12m
as at 31 December 2020 primarily
due to improved margins across
the Assurance and MDR divisions,
£0.29m of COVID-19 related
Government grants, and the
proceeds from the fund raise
undertaken during the year which
raised £0.5m (before costs).
Intangible Asset
Key Performance Indicators
The Key Performance Indicators
are set out on page 10.
Intangible asset costs have
increased to £1.28m (2019:
£1.09m). This is offset by
amortisation of £0.82m. The
Group’s development cost for the
year was £0.19m. The Net Book
Value of Intangible Assets as at
31 December 2020 was therefore
£0.46m (2019: £0.43m). During the
year, the Group received a refund
Vendor Products revenue in the
year fell by 23% to £0.13m (2019:
£0.16m).
Margin Generation
Gross Profit for the year was
£3.55m, yielding a 63% margin
(2019: £3.36m, yielding a 57%
margin). This was due to improved
margins across the Assurance,
MDR and Vendor divisions.
The Assurance margin rose to
58% in the year (2019: 54%). This
was due to cost controls over the
period. The Board expects the
Assurance margin to continue at a
similar level in the future.
The MDR margin rose to 73%
(2019: 68%), with the increase
being a direct result of new
contracts utilising the capacity
built in previous years and cost
Page 26
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Financial Review (continued)
These factors give the Directors
confidence in relation to going
concern.
For further information please see
pages 69.
Dividend
The Board has not declared a
dividend for the year ended 31
December 2020 (2019: £nil).
Gemma Basharan
Chief Financial Officer
23 March 2021
Balance Sheet
The Group’s Balance Sheet
as at 31 December 2020 had
Net Assets of £0.65m (2019:
£0.37m). Retained Earnings and
Distributable Reserves as at 31
December 2020 were a cumulative
loss of £5.94m (2019: cumulative
loss of £5.67m).
Going Concern
The Directors have assessed
the going concern status of the
Group by reference to a number
of factors. In particular, the
Directors have considered the
strong rate of growth in the cyber
security market; the fact that
business continues to attract new
clients and is not overly dependent
on any single client; the fact that
the business continues to retain
key staff, and that the Group has
a secured invoicing discounting
facility of £0.5m, which remains
unused. The facility was renewed
in August 2020 for a minimum 12
months period with a three month
notice period.
The Board expects to renew
the facility for a further 12
months following the annual
review expected in August 2021.
However, if it is not renewed, the
cash-flow forecast demonstrates
that the facility is for prudence
only and is not relied upon. The
Board is positive about the future
EBITDA trajectory of the Company
and continues to manage the cash
position of the Company carefully.
Page 27
ECSC Group plcAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties
ECSC Group plc (‘ECSC’ or ‘the Company’ or ‘the Group’) is exposed to a number of Macro, Business and
Financial risks. The Board is responsible for ensuring that the Group has taken a proactive approach to the
identification and mitigation of these risks in a timely manner.
Summary of Risks
The most significant risks to the Group are summarised in the table below. These risks are explained in
further detail following the summary. The table does not include all the potential risks associated with Group
activities and are not in any order of priority.
Principal Risks
Economic conditions
Rapid technological change
Competition
Cyber security breach
Reputation
Dependence on key personnel
Ability to recruit and retain skilled personnel
Reliance on key systems
Client acquisition
Client retention
Future funding requirements
Mitigating Actions/Factors
Expenditure on cyber security has become non-
discretionary in nature and is less sensitive to economic
fluctuations
Investment in proprietary intellectual property
Maintaining a broad, full-service offering
Certifications to ISO 27001, PCI DSS and Cyber
Essentials; avoidance of technologies associated with
common security breaches
Consistent focus on legal, financial, regulatory and
technological compliance
Board and Senior Management structure and
remuneration is designed to reduce the risks associated
with the loss of any single person
Ongoing development of a wide range of employee
benefits and incentives, career progression and technical
development
Disaster recovery and business continuity plans
Sales team training and development, partner
programme, and expanded marketing activities.
Expanded service delivery function and service
management layer
Flotation on the Alternative Investment Market of the
London Stock Exchange
Page 28
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)
Macro Risks
Economic Conditions and
uncertainty including Brexit and
COVID-19
demand for cyber security
services are expected to increase
in the future
Geopolitical Risks
The Group could be affected
by national and international
economic factors outside its
control, including an economic
slowdown, changes in the
monetary and fiscal policies of
the Government, exchange rate
fluctuations, commodity price
volatility, inflation, increases in
interest rates and banking sector
conditions.
The Group’s operations now or
in the future may be adversely
affected by factors outside the
control of the Group, including
election results, changes in
Government policy, terrorist
activities, labour unrest, civil
disorder and political upheaval,
war, subversive activities and
sabotage, fires, floods, natural
disasters and epidemics.
Any UK economic downturn,
either globally or locally, may have
an adverse effect on the demand
for the Group’s services. A more
prolonged economic downturn
may lead to an overall decline
in the volume of the Group’s
activities and sales, restricting the
Group’s ability to realise a profit.
However, given the proliferation of
cyber security breaches and the
damage caused, in financial and
reputational terms, expenditure
by corporates on cyber security is
increasingly of a non-discretionary
nature, such that demand has
become less sensitive to general
economic fluctuations.
The recent COVID-19 global
pandemic has brought additional
challenges to the business
environment. However during
2020 UK businesses saw an
increase in cyber attacks and
Business Risks
Technology
The markets in which the Group
operates are characterised by
rapid technological change,
changes in client requirements,
frequent product and service
introductions employing new
technologies, and the emergence
of new industry standards and
practices that could render the
Group’s existing technology and
services obsolete.
In order to compete successfully,
the Group will need to continue
to improve its services, and to
develop and market new products
that keep pace with technological
change. This may place strain
on the Group’s capital resources,
which may adversely impact the
revenues and profitability of the
Group.
The success of the Group depends
on its ability to anticipate and
respond to technological changes
and client requirements in a
timely and cost-effective manner.
There can be no assurance
that the Group will be able to
effectively anticipate and respond
to technological changes and
client needs in the future.
Intellectual Property
In order to mitigate Technology
risk and maximise its competitive
advantage, the Group seeks to
protect its intellectual property.
Much of the Group’s intellectual
property is not of a nature
that is capable of registration,
so protection of intellectual
property relies on maintaining
the confidentiality of know-how,
methodologies and processes
which, in turn, are largely
dependent on people. There is a
risk that if the confidentiality of
the Group’s intellectual property
were compromised, this could
lead to a loss of competitive
advantage. To mitigate this risk,
the Group employs strict terms
of confidentiality in its standard
terms of employment.
The Group’s software is largely
developed in-house. However,
some aspects of it are based
on open-source licences such
as the General Public License
(a widely used form of license
within the free and open-source
code software domain), which
oblige ECSC to provide access to
Page 29
ECSC Group plcAnnual Report Year Ended 31 December 2020
Principal Risks and Uncertainties (continued)
the source code of the relevant
software package if a client
requests it. There is a limited risk
that ECSC could be pursued by
way of enforcement action in this
area, which may have a material
adverse effect on the Group’s
performance.
Competition
There can be no guarantee that
the Group’s current competitors
or new entrants to the market will
not bring superior technologies,
products or services to the
market, or equivalent products
at a lower price, which may have
an adverse effect on the Group’s
business. Such companies may
also have greater financial and
marketing resources than the
Group. These competitive risks
are mitigated by maintaining a full
service offer, spanning Consulting
and Managed Services, with a
strategic focus on expanding
the recurring revenue base from
retained clients, underpinned by
a proactive account management
process.
Cyber Security Breach
As with all providers in this sector,
the potential embarrassment and
reputational impact of a major
cyber security breach for ECSC
itself is significant. However,
ECSC manages this risk in a
number of ways:
• External certification to
international security
standards, such as ISO 27001
and PCI DSS.
• Avoidance of technologies
commonly targeted for attack
– ECSC makes extensive use
of Linux-based technologies,
including all operational
desktop PCs and laptops, and
does not support Bring Your
Own Device (BYOD) policies
for any company business,
including for Associate
Consultants.
• The Company directs the
same level of security
expertise at its own security
as to that of its clients,
avoiding the common issue
with IT companies that their
own internal IT is managed
by a less capable internal
team than their client-facing
delivery team.
Reputation
The Group’s reputation, in terms
of the services it provides, the
manner in which it conducts
its business and the financial
performance it achieves, are
central to the Group’s success.
The Group’s services, and the
software on which they are based,
are complex and may contain
undetected defects when first
introduced. Such defects could
damage the Group’s reputation,
ultimately leading to an increase
in the Group’s costs or reduction
in its revenues.
Other issues that may give rise
to reputational risk include, but
are not limited to, failure to deal
appropriately with legal and
regulatory requirements in any
jurisdiction (which may result in
the issuance of a warning notice
or sanction by a regulator or an
offence being committed by a
member of the Company or any
of its employees or Directors),
money-laundering, bribery and
corruption, factually incorrect
reporting, staff disputes,
fraud (including on the part of
clients), technological delays
or malfunctions, the inability to
respond to a disaster, lack of data
privacy, and poor record-keeping.
In addition, failure to meet the
expectations of clients, suppliers,
employees, shareholders,
regulators and other business
partners may have a material
adverse effect on the Group’s
reputation.
To mitigate these varied risks, the
Group has adopted a strict and
thorough approach to compliance,
investing resources to meet
relevant legal, financial, regulatory
and technological standards and
requirements.
Dependence on Directors and
Senior Management
The Group’s performance is
substantially dependent on
the continued services and
performance of its Directors
and senior management.
Although certain Directors and
Page 30
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)
key personnel have entered into
Service Agreements or Letters of
Appointment with the Group, there
can be no assurance that the
Group will retain their services.
The loss of the services of any of
the Directors or key personnel
may have a material adverse
effect on the business, operations,
relationships and/or prospects of
the Group.
The risk of loss of a Director or
member of senior management
is mitigated by offering market
competitive remuneration for
key roles, including appropriate
levels of equity incentivisation via
the share option schemes of the
Group.
Ability to Recruit and Retain
Skilled Personnel
The Group believes that it has
the appropriate incentivisation
structures to attract and
retain the calibre of employees
necessary to ensure the growth
and development of the Group.
However, any difficulties
encountered in hiring appropriate
employees and the failure to do
so may have a detrimental effect
upon the trading performance
of the Group. The ability to
attract new employees with the
appropriate expertise and skills
cannot be guaranteed.
Reliance on Key Systems
The Group’s dependency
upon technology exposes it to
significant risk in the event that
such technology or the Group’s
systems experience any form of
damage, interruption or failure.
The Group’s systems are
vulnerable to damage or
interruption from events
including:
• power loss and infrastructure
failure;
• fire or physical destruction;
• computer hacking activities;
and
• acts of criminal damage or
terrorism.
Any malfunctioning of the Group’s
technology and systems, or those
of key third parties, even for a
short period of time, could result
in a lack of confidence in the
Group’s services, the termination
of client contracts and potential
claims for damages, with a
consequential material adverse
effect on the Group’s operations
and performance.
The Group has a well-considered,
certified and regularly rehearsed
disaster recovery and business
continuity plan to mitigate this
risk.
New Client Acquisition and
Retention of Existing Clients
The Group’s future success
depends on its ability to increase
sales of its services and products
to new clients, increase sales to
its existing clients, and maintain
existing client contractual
relationships.
The rate at which new and
existing clients purchase services
and existing clients renew their
contracts depends on a number
of factors, including the efficacy of
the Group’s services and the utility
of the Group’s new offerings, as
well as factors outside of the
Group’s control, such as clients’
perceived need for security
solutions, the introduction
of services by the Group’s
competitors that are perceived
to be superior to the Group’s
services, end clients’ IT budgets
and general economic conditions.
A failure to increase sales as a
result of any of the above could
materially adversely affect the
Group’s financial performance and
position.
Failure to Develop, Launch and
Market New Services
The Group’s long-term growth and
profitability is dependent on its
ability to develop and successfully
launch and market new services.
The Group’s revenues and market
share may suffer if it is unable
to successfully introduce new
products in a timely fashion or if
any new or enhanced products
or services are introduced by its
competitors that its customers
find more advanced and/or better
suited to their needs.
While the Group continuously
invests in research and
development to develop products
Page 31
ECSC Group plcAnnual Report Year Ended 31 December 2020Principal Risks and Uncertainties (continued)
in line with client demand and expectations, if it is not able to keep pace with product development and
technological advances, including shifts in technology in the markets in which it operates, or to meet client
demands, this could have a material adverse effect on the Group’s financial performance and position.
Financial Risks
Future Funding Requirements
Although not presently anticipated by the Directors, the Group may need in the future (more than twelve
months) to raise equity or additional debt capital to fund future acquisitions, expansion and/or business
development. There can be no guarantee that the necessary funds will be available on a timely basis, on
favourable terms, or at all, or that such funds, if raised, would be sufficient. If the Group is not able to
obtain additional capital on acceptable terms, or at all, it may be forced to curtail or abandon acquisition
opportunities, expansion and/or business development. The Board anticipates to renew the £0.5m invoice
discounting facility it currently has with Barclays in August 2021. There is no guarantee that the Group will
be able to renew the facility. However if it not renewed the cash-flow forecast demonstrates that the facility is
not reliant upon but for prudence only.
This risk is partially mitigated by the Group’s quotation on the Alternative Investment Market of the London
Stock Exchange, which provides a conduit to equity investors.
Page 32
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Statement by the Directors
Statement by the Directors in
performance of their statutory
duties in accordance with s172(1)
Companies Act 2006
•
high standards of business
conduct; and
the need to act fairly as
between shareholders of the
Company.
The Board of Directors of
ECSC Group plc consider that,
individually and together, they
have acted in the way which in
good faith would be most likely
to promote the success of the
company for the benefit of its
members as a whole (having
regard to the stakeholders and
matters set out in s172(1)(a-
f) of the Act) in the decisions
taken during the year ended 31
December 2019.
The Board looked to promote the
success of the Company, having
regard to the long term, whilst
taking into account the interests
of all stakeholders. It is designed
to secure the long-term financial
viability of the Company to the
benefit of its members and all
stakeholders, and in doing so have
regard (amongst other matters)
to:
•
•
•
•
•
the likely consequence of any
decisions in the long-term;
the interests of the company’s
employees;
the need to foster the
company’s business
relationships with suppliers,
customers and others;
the impact of the company’s
operations on the community
and environments;
the desirability of the company
maintaining a reputation for
The following paragraphs
summarises how the Directors
fulfil their duties:
Risk management
We provide business-critical
service to our clients. As we
grow, our business and our risk
environment also becomes more
complex. It is therefore vital that
we effectively identify, evaluate,
manage and mitigate the risks
we face and that we continue
to evolve our approach to risk
management.
For details on our principal risks
and uncertainties and how we
manage our risk environment,
please see page 28.
Our People
The Board recognises that our
employees are fundamental to
the delivery of our plan. We aim
to be a responsible employer
in our approach to the pay and
benefits our employees receive.
The health, safety and well-being
of our employees is of primary
concern in the way we do business
and is monitored extensively by
the Board and taken into account
in all major decision-making.
For further information please see
page 12.
Business Relationships
Our strategy prioritises organic
growth, driven by cross-selling
and up-selling services to
existing clients and bringing
new clients into the Group. To
do this we need to continue to
develop and maintain strong client
relationships.
We also aim to act responsibly
and fairly in how we engage
with our clients and suppliers,
co-operate with our regulators
and act on feedback received
from these stakeholders. All of
these considerations are taken
into account by the Board when
making strategic decisions for the
Company.
Community and environment
Our plan considered the impact of
the company’s operations on the
community, the environment and
our wider social responsibilities.
The Group wants to positively
impact the lives of the people we
work with and for, providing long-
term benefits to its employees,
customers, suppliers and
individuals in our local and wider
community. We will do this by
acting in a socially responsible
way; and encouraging our staff
and business partners to strive
for matching performance;
encouraging our staff to be
mindful of the effect of their
actions on any natural resource.
Page 33
ECSC Group plcAnnual Report Year Ended 31 December 2020Statement by the Directors
Shareholders
The Board is committed to openly engaging with its shareholders, as we recognise the importance of
effective dialogue, whether with major institutional investors, private or employee shareholders. It is
important to us that shareholders understand our strategy and objectives, so these must be explained
clearly, feedback heard and any issues or questions raised properly considered.
For further information on how we engage with our shareholders please see page 37.
As the Board of Directors, our intention is to behave responsibly with all stakeholders and to ensure
that management operates the business in a responsible manner, operating within the high standards
of business conduct and good governance expected for a business such as ours. Acting in this way will
contribute to the delivery of our plan and we intend to maintain our reputation within the industry for
responsible and compliant behaviour.
As the Board of Directors, our intention is also to make decisions which lead to the long-term success of
the company whilst behaving responsibly toward our shareholders, treating them fairly and equally, so they
benefit from the successful delivery of our strategy and plan.
Gemma Basharan
Chief Financial Officer
23 March 2021
Page 34
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Board of Directors
The Board of ECSC Group plc comprises four Executive Directors and two Non-Executive Directors. The
Board has considered its independence and effectiveness, and is satisfied to the degree of competence and
efficiency in place.
The Board is responsible for the formulation of business strategy, operational execution, financial
performance and compliance. The Executive Directors are responsible for day-to-day operational and
financial management, whilst the Non-Executive Directors are responsible for delivering effective corporate
governance.
The profile of each Director is as follows:
David Mathewson | Non-Executive Chairman
David is a Chartered Accountant who has spent most of his career in merchant banking and as a non-
executive director. He was an Executive Director of Noble Grossart Limited, Scotland’s premier merchant
bank, for many years. Previous non-executive roles include Chairman of Sportech Plc and he was also a
Director of Playtech Group plc. During his tenure at Playtech, he was appointed Chief Financial Officer
and oversaw the company move from AIM to the Main Market of the London Stock Exchange. He is
currently a Non-Executive Director of AIM traded SEC Newgate SPA, an Italian company, also traded on
AIM, and Chairman of Scram Group Ltd. The Board has reviewed David’s time commitment from his other
directorships and has concluded that they average six to seven working days per month. The Board is
therefore comfortable that David has sufficient available capacity to carry out his duties as a Non-Executive
Chairman of ECSC Group plc.
Ian Mann | Chief Executive Officer
Ian has over 19 years of experience in the cyber-security sector, having founded ECSC. He was previously
an advisor for GCHQ, and established a Cisco Networking Academy for Dixons City Technology College. Ian’s
professional certifications include CISSP, PCI QSA, and ISO Lead Auditor. Ian holds a B.Eng. in Electrical and
Electronic Engineering from the University of Nottingham, and an MBA from the Open University.
Lucy Sharp | Chief Operating Officer
Lucy has over 19 years of experience in the cyber-security sector, having joined ECSC at its inception. Lucy
worked as an ISO 27001 consultant, leading this area prior to taking the position of Operations Director
in 2012. Lucy has held a number of professional certifications, including CISSP, PCI QSA, and ISO Lead
Auditor. Whilst working at ECSC, Lucy completed a Masters in Business Management at Leeds Metropolitan
University.
Elizabeth Gooch MBE | Non-Executive Director
Elizabeth Gooch is an award-winning UK tech entrepreneur, having started her career in industry, joining
Forward Trust (a subsidiary of Midland Bank) and then Birmingham Midshires Building Society, before
establishing eg solutions in 1988. She pioneered the introduction of industrial production management
methodologies into the service sector and invented the eg operational intelligence ® software suite to
embed these techniques into businesses. eg was listed on the Alternative Investment Market and was
acquired by a major US Software Company in 2017. Elizabeth was named as one of The Telegraph’s Most
Disruptive Entrepreneurs and West Midlands Woman of the Year for her Outstanding Contribution to
Page 35
ECSC Group plcAnnual Report Year Ended 31 December 2020Board of Directors
Technology. She was made a Member of the Order of the British Empire in the Queens Jubilee Birthday
Honours 2012, in recognition of her achievements in delivering significant benefits for clients with the
products she designed. Elizabeth is now CEO of The Tech Growth Factory; a company she established to
assist the founders of small technology companies achieve their growth potential.
Ian Castle | Chief Technology Officer
Ian joined ECSC in 2003 and has been involved in the design and implementation of all technical aspects of
ECSC’s service lines and is now focused on managed services. Ian ensures the smooth and secure running
of our own systems and heads up our research and development efforts.
Gemma Basharan | Chief Financial Officer
Gemma is a Chartered Accountant who has over 14 years of financial experience both in the private and
charity sector. Gemma joined ECSC in 2011 as a management accountant before taking the position of
Financial Controller in 2016, and to Chief Financial Officer in April 2020.
BOARD OF DIRECTORS
DAVID MATHEWSON
Non-Executive Chairman
IAN MANN
CEO
LUCY SHARP
COO
IAN CASTLE
CTO
GEMMA BASHARAN
CFO
ELIZABETH GOOCH
Non-Executive Director
Page 36
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
The Directors present their report
and financial statements for the
year ended 31 December 2020.
Principal Activities and Review of
the Business
The principal activity of the Group
during the year continued to
be the provision of professional
cyber security services. Future
developments of the Group have
been reviewed as part of the
Strategic Report.
Principal Risks and Uncertainties
For information on the principal
risks and uncertainties of the
Group, please see pages 28 to 32
of the Strategic Report.
Statements).
Research and Development
Research and development
activities are grouped into three
broad areas:
• Proprietary software,
operating systems,
applications, tools and
documentation used to provide
Managed Services.
• Proprietary software, tools and
techniques used to provide
Consulting Services.
• Core internal business
systems to support revenue
generating activities.
Chairman Corporate Governance
Results and Dividends
Overview
The loss for the period, after
taxation, amounted to £269k
(2019: loss of £776k). The Board
has not declared a dividend for
the year ended 31 December 2020
(2019: £nil).
Going Concern
The Directors are satisfied that
the Group has sufficient financial
resources to continue to operate
for the foreseeable future, which
is considered to be at least the 12
months from the date of approval
of the financial statements. For
this reason, the going concern
basis is considered appropriate
for the preparation of the financial
statements (for more information
see note 4.2 to the Financial
As Chairman of the Board
of Directors of ECSC Group
plc it is my responsibility to
ensure that ECSC has both
sound corporate governance
and an effective Board. As
Chairman, my responsibilities
include leading the Board
effectively, overseeing the
Company’s corporate governance
model, communicating with
shareholders, and ensuring that
good information flows freely
between Executives and Non-
Executives in a timely manner.
ECSC Group plc has adopted the
QCA Corporate Governance Code
in line with the London Stock
Exchange’s recent changes to the
AIM Rules, requiring all AIM-listed
companies to adopt and comply
or explain non-compliance with a
recognised corporate governance
code. The Board considers that
the Group complies with the QCA
Code so far as it is practicable
having regard to the size, nature
and current stage of development
of the Company, and will disclose
any areas of non-compliance in
the text below. The Board believes
that corporate governance is
a framework which underpins
the core values for running the
business in which we all believe,
including a commitment to open
and transparent communications
with stakeholders. Further details
on Corporate Governance is on
the Group’s website at https://
investor.ecsc.co.uk/governance/
corporate-governance.html.
QCA Principles
1. Establish a strategy and
business model which
promotes long-term value for
shareholders
The Board has concluded that
the highest medium and long-
term value can be delivered to
its shareholders by a focused
strategy for the Company. Details
of Business Strategy can be found
on pages 8-9.
2.
Seek to understand and
meet shareholder needs and
expectations
The Group is strongly committed
Page 37
ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
to the maintenance of good
investor relations and seeks,
wherever possible, to build
a relationship of mutual
understanding with both
its institutional and private
client investors. The Company
communicates how it is
governed and is performing
through its Annual Report and
Accounts, full-year and half-
year announcements, regulatory
announcements and its website:
https://investor.ecsc.co.uk/. The
Group have a dedicated email
address investor@ecsc.co.uk for
shareholder enquiries.
3. Take into account wider
stakeholder and social
responsibilities and their
implications for long-term
success.
The Board recognises that the
long-term success of the Group
is reliant upon the efforts of the
employees of the Group and its
suppliers, regulators and other
stakeholders. The Group prepares
an annual strategic plan and
detailed budget which considers
a wide range of key resources and
stakeholders. Everyone within
the Group is a valued member
of the team, and our aim is to
help every individual achieve
their full potential. We offer
equal opportunities regardless
of race, gender, gender identity
or reassignment, age, disability,
religion or sexual orientation. See
employee survey, (page 12).
4. Embed effective risk
6.
management, considering
both opportunities and
threats, throughout the
organisation.
Ensure that between
them the Directors have
the necessary up-to-date
experience, skills and
capabilities.
The Board attaches considerable
importance to the Company’s
system of internal control and
risk management. An ongoing
process has been established
for identifying, evaluating, and
managing the significant risks
faced by the Group. Details of key
risks to the business can be found
on page 28.
5. Maintain the board as a well-
functioning, balanced team
led by the Chair.
ECSC is controlled by the Board
of Directors. There are two
independent Directors; David
Mathewson and Elizabeth Gooch.
Their time commitment to ECSC
are as follows:
• David Mathewson: devotes at
least two full working days
in each calendar month to
perform the duties of office;
and
• Elizabeth Gooch: reasonable
endeavours to attend all
meetings of the Board and/
or committees of the Board of
which she is a member and to
attend all general meetings of
the Company.
Details of the Board and the roles
can be found on pages 35-36.
The Directors have both a breadth
and depth of skills and experience
to fulfil their roles and deliver
the strategy of the Group for the
benefit of the shareholders over
the medium to long-term. The
Group believes that the current
balance of skills in the Board as a
whole, reflects a very broad range
of commercial and professional
skills. The Directors continue to
develop their skill set and keep up
to date with current regulations in
their prospective markets.
Details of the Directors’
experience and areas of expertise
are outlined on pages 35-36.
7. Evaluate board performance
based on clear and relevant
objectives, seeking
continuous improvement.
The Board informally review board
performance as part of the day
to day running of the business.
ECSC Group plc has yet to carry
out a formal assessment of board
effectiveness and the Board will
keep this under consideration and
put in procedures when it is felt
appropriate.
The Company has adopted a code
for Directors’ and employees’
dealings in securities which is
appropriate for a company whose
Page 38
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
securities are traded on AIM,
and is in accordance with the
requirements of the Market Abuse
Regulation which came into effect
in 2016.
8.
Promote a corporate culture
that is based on ethical values
and behaviours.
The company has clearly defined
values upon which our culture and
behaviours are based. These are
outlined in the Chief Operating
Officer’s Overview on pages 12.
9. Maintain governance
structures and processes
that are fit for purpose and
support good decision-
making by the board.
The Board is committed to,
and ultimately responsible for,
high standards of corporate
governance, and has chosen to
adopt the QCA Code. We review
our corporate governance
arrangements regularly and
expect to evolve these over
time, in line with the Group’s
growth. The Board delegates
responsibilities to Committees
and individuals as it sees fit, with
the Chairman being responsible
for the effectiveness of the Board,
and the Executive Directors being
accountable for the management
of the Company’s business and
shareholder liaison.
10. Communicate how the
Committee Responsibilities
company is governed and is
performing by maintaining a
dialogue with shareholders
and other relevant
stakeholders.
The Board is strongly committed
to the maintenance of good
investor relations and to having
constructive dialogue with its
shareholders. Executive Directors
and Chair seek to meet with
shareholders and other investors/
potential investors at regular
intervals during the year.
Committee Chairman
This report sets out information
about the remuneration of the
Directors of the Company for the
year ended 31 December 2020. As
a company admitted to AIM, ECSC
Group is not required to prepare
a Directors Remuneration report.
However, the board supports
the principle of transparency
and has prepared this report
in order to provide information
to shareholders on Directors
remuneration arrangements.
THE REMUNERATION
COMMITTEE
Committee Composition
Elizabeth Gooch MBE was
appointed chair of the Committee
on 16 April 2018. The other
member of the committee is David
Mathewson.
The Remuneration Committee’s
primary purpose is to ensure
that the remuneration packages
of the senior and most highly
rewarded team at ECSC Group
are both aligned to the company’s
purpose and values and linked
to the successful delivery of the
company’s long-term strategy.
Committee Meetings
The Remuneration Committee
met at least four times in the
period, with other board members
in attendance as appropriate. The
Committees main activities during
the year included:
• Approved proposals for
changes in the remuneration
of Directors for the
forthcoming period.
• Agreed individual share option
awards;
• Agreed targets and
performance measures for
bonus payments for the
forthcoming financial period;
and
• Administered the group’s
share schemes.
In determining the Directors
remuneration for the year, the
Committee consulted Ian Mann,
Chief Executive and Lucy Sharp,
Chief Operating Officer about its
proposals.
Page 39
ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
“As a Bradford based technology
company, we’re were very happy
to help this local school and to
support the students continued
learning during these difficult
times. After all these children
might be our apprentices in the
future!”
supplies to ensure a steady
reduction in consumption.
Directors’ Interests and
Remuneration
The Directors who held office
during the period were as follows:
Charities are given discounted
rates when engaging our services
and where practicable we seek to
support charities and/or clients
in their CSR efforts e.g. providing
prizes for raffles, raising money
for their causes and attending
charity functions.
David Mathewson
Ian Mann
Lucy Sharp
Elizabeth Gooch
Ian Castle
Gemma Basharan
Audit Committee
Environmental
ECSC Group plc recognises that
it has a responsibility to the
environment above and beyond
regulatory requirements. Action
on all parts of this policy will be
the responsibility of all staff. The
Management Team are committed
to continuous improvements in
our environmental performance.
Environmental regulations, laws
and code of practice will be
followed to ensure the continuous
awareness of environmental
issues and to maintain good
practice in our operations.
Monitoring environmental
performance will be part of our
yearly board review. We will
monitor our energy consumption
for improved environmental
performance We will monitor
our use of paper and other office
The duties of the Audit Committee
are to consider the relationship
with the Company’s auditor
(appointment, re-appointment and
terms of engagement), to review
the integrity of the Company’s
financial statements, to keep
under review the appropriateness
of the Company’s accounting
policies, and to review the
effectiveness and adequacy
of the Company’s internal
financial controls. In addition,
it will receive and review such
reports as it from time to time
requests from the Company’s
management and auditor. The
Audit Committee meets at least
twice a year and has unrestricted
access to the Company’s auditor.
The Audit Committee comprises
David Mathewson and Elizabeth
Gooch and is chaired by David
Mathewson.
Social Responsibility
ECSC Group plc’s commitment
to the continuous improvement
of our Corporate and Social
Responsibility (CSR) strategy is
an integral part of our company’s
vision and values. We want ECSC
Group plc to positively impact
the lives of the people we work
with and for, providing long-
term benefits to its employees,
customers, suppliers and
individuals in our local and
wider community. We do this by
acting in a socially responsible
way; encouraging our staff and
business partners to strive for
matching performance; and,
encouraging our staff to be
mindful of the effect of their
actions on any natural resource.
ECSC is a sponsor of the
GiveBradford 100 Club which
is a network of like minded
organisations wanting to
address the challenges facing
the district. The GiveBradford
scheme have distributed over £3.8
million in grants to date across
the Bradford District, enabling
positive change in the lives of
hundreds of thousands of people
in our communities.
During the 2020 ECSC supported
a local secondary school by
supplying wifi dongles to students
who did not have internet at home
and therefore could not continue
their studies from home during
lockdown or if they were forced
to isolate. Lucy Sharp, COO said
Page 40
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
Nomination Committee
The duties of the Nomination Committee are to consider the structure, size and composition of the Board
and make recommendations to the Board with regard to any changes. It is also responsible for identifying
and nominating candidates to fill Board vacancies as and when they arise. The Nomination Committee
also makes recommendations to the Board concerning, among other things, plans for succession for both
Executive and Non-Executive Directors. It meets at least twice a year. The Nomination Committee comprises
Elizabeth Gooch and David Mathewson and is chaired by David Mathewson.
Disclosure Committee
The Disclosure Committee is the first point of contact with the NOMAD for all routine and non-routine
matters which the NOMAD wishes to discuss with the Board and shall carry out duties to ensure the
Company’s compliance with the AIM Rules and Market Abuse Regulations. The Disclosure Committee meets
twice a year and comprises David Mathewson and Elizabeth Gooch and is chaired by David Mathewson.
Attendance at Board and Committee meetings
There were 12 Board meetings held during the year, all of which were attended by Ian Mann, Lucy Sharp,
David Mathewson and Elizabeth Gooch. Gemma Basharan attended 11 Board meetings and Ian Castle
attended 7 Board meetings during the year.
The Audit Committee had two meetings during the year at which both Elizabeth Gooch and David Mathewson
attended.
The following Directors had interests in the ordinary shares of the Company as at 31 December 2020:
David Mathewson
Ian Mann
Lucy Sharp
Elizabeth Gooch
Ian Castle
Gemma Basharan
Number of
Ordinary
Shares
35,419
2,300,948
242,635
50,000
237,441
4,214
% of Issued
Share
Capital
0.35%
22.99%
2.42%
0.50%
2.37%
0.04%
Details of the Directors remuneration are included in the Remuneration Report on pages 43-49.
Substantial Interests
At 31 December 2020, the Company had been notified, under the Disclosure guidance and Transparency
Rules, of the following major shareholdings and the percentages of voting rights represented by such
holdings, excluding the shareholdings and associated voting rights of the Directors noted above, as follows:
Page 41
ECSC Group plcAnnual Report Year Ended 31 December 2020Directors’ Report for the year ended 31 December 2020
Unicorn Asset Management
Ravinder Bahra
Hargreaves Lansdown
Artemis Investment Management
Phil McLear
Malcolm Hoare
John Leach
Annual General Meeting
Number of
Ordinary
Shares
% of Issued
Share
Capital
1,448,946
1,069,068
343,721
294,733
472,290
300,300
283,920
14.48%
10.68%
3.43%
2.95%
4.72%
3.00%
2.84%
The next Annual General Meeting will take place on 23 June 2021.
Statement of Disclosure of Information to Auditor
The Directors of the Company who held office at the date of approval of this Annual Report as set out above
each confirm that:
• so far as each Director is aware, there is no relevant audit information of which the Company’s auditors
are unaware; and
• each Director has taken all the steps that they ought to have taken as a Director in order to make
themselves aware of any relevant audit information and to establish that the Company’s auditors are
aware of that information.
Auditor
BDO LLP has indicated its willingness to continue as auditor. Accordingly a resolution proposing its
reappointment as auditor will be put to the members at the next Annual General Meeting.
On behalf of the Board
David Mathewson
Non-Executive Chairman
23 March 2021
Page 42
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report
As an AIM listed company ECSC Group plc is not required to comply with schedule 8 of the Large and
Medium-sized Companies and Groups (Accounts and Reports) Regulations 2008. Nor is it required to comply
with the principles relating to Directors remuneration in the UK Corporate Code 2018 (“the code”). The
content of this report is unaudited unless stated.
Remuneration Policy
The objectives of the remuneration policy are to ensure that the overall remuneration of Executive
Directors is aligned with the performance of the Group and preserves an appropriate balance of reward and
shareholder value.
The Company’s policy is to remunerate Directors appropriately such that they are sufficiently rewarded
and incentivised for their level of responsibility, the complexity of their role and to reflect their skills and
experience. The use of Annual Performance Bonuses and equity-based incentives, linked to Company
performance, helps to align the interests of the Directors and Shareholders.
The Remuneration Committee sets the level of basic pay and other benefits for Executive Directors and
other Senior Managers. It does this in line with its assessment of the appropriate market rate for the roles,
wishing to be able to attract and retain good candidates for these roles. In addition, the Company operates
an Executive Annual Performance Bonus Scheme covering the Executive Directors. The criteria for payment
of bonuses (which are not pensionable if paid) are set by the Remuneration Committee at the beginning of
each financial year. The award of any bonus is decided by the Remuneration Committee at the end of the
year by reference to the objectives set for the year, the corresponding performance of the Company, and by
using its discretion. The Company also operates a share based incentive scheme as outlined below.
The Company’s policy is also that a substantial proportion of the remuneration of the Executive Directors
should be performance related in order to encourage and reward improving business performance and
shareholder returns. In determining remuneration arrangements for Executive Directors, the Committee
is sensitive to pay and employment conditions elsewhere in the Cyber Security and general IT Software and
Services markets, especially when determining base salary increases.
The committee has reviewed the Remuneration Policy for the forthcoming year and has concluded that it
remains appropriate for the forthcoming three year period.
Page 43
ECSC Group plcAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)
The main components of the remuneration arrangements for Executive Directors are as follows:
Purpose & Link to Strategy
Operation
Maximum Opportunity
Performance Conditions
Base Salary
To provide fixed competitive
remuneration that will attract
and retain key employees and
reflect their experience and
position in the Group.
Reviewed annually taking into
account industry-standard
executive remuneration and
pay levels elsewhere within the
sector.
Benefits
To provide market levels of
benefits on a cost-effective
basis.
Private health cover for the
executive and their family, life
insurance cover of one-times
salary and a company car.
Pension
Providing post-retirement
benefits.
The Group contributes to
individual’s personal pension
schemes
Annual incentive
Recognises achievements
of annual objectives which
support the short to medium
term strategy of the Group
Performance targets are set by
the Remuneration Committee
at the start of the year with
input, as appropriate, from the
Executive Directors
Executive Share Options Plan
Setting value creation
through share growth as a
major objective for Executive
Directors and senior
managers. Alignment of option
holder interests with those of
shareholders through delivery
of shares.
The Group introduced a Share
Option scheme during 2020.
All the Executive Directors,
participates in the EMI
scheme. See below.
Salaries for the year ended 31
December 2020 are set out
below.
None.
Private healthcare benefits are
provided through third-party
providers and therefore the
cost to the Company may vary
from year to year.
None.
10% of base salary
None.
The bonus related Key
Performance Indicators for
this period were Revenue
and EBITDA, and they were
appropriately weighted.
The Executive Directors Annual
Performance Bonus Scheme
for 2021 was structured so
as to pay up to 25% of basic
salary for the Chief Executive
Officer and Chief Operating
Officer 20% of basic salary for
the Chief Technology Officer
and Chief Financial Officer
based on the achievement of
stretching targets in certain
key performance indicators
aligned with the Group’s
strategy.
N/A
N/A
The committee reviewed the performance of the Executive Directors against the performance for the
Annual Incentive scheme and concluded that the stretching targets agreed for the period had not been met.
However, in recognition of achievements made with establishing a successful Partner Programme and other
key objectives, the committee recommended payment of modest bonuses as detailed below.
Page 44
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)
The annual incentive paid to Executive Directors for the year ended 31 December 2020 was 7% of the basic
salary of the Chief Executive, 8% of the basic salary of the Chief Operating Officer, 7% of basic salary of the
Chief Technology Officer and 6% of basic salary of the Chief Financial Officer.
An Annual Performance Bonus Scheme for the Executive Directors is structured so as to pay up to 25% of
basic salary for both the Chief Executive and Chief Operating Officer and 20% of basic salary for both the
Chief Technology Officer and Chief Financial Officer. For the forthcoming period payment will continue to be
based on the achievement of stretching targets in weighted Key Performance Indicators linked to the Group’s
strategy.
The committee introduced a Long-Term Incentive Plan (“LTIP”) for the Executive Directors during 2020:
Vesting Period
Target Price
Ian Mann
Lucy Sharp
Ian Castle
Gemma Basharan
I Year
167 Pence
25,000
25,000
20,000
20,000
2 Years
200 Pence
25,000
25,000
20,000
20,000
3 Years
225 Pence
25,000
25,000
20,000
20,000
4 Years
250 Pence
Total Ordinary
Shares
25,000
25,000
20,000
20,000
100,000
100,000
80,000
80,000
Remuneration for Non – Executive Directors
Remuneration of the Non-Executive Directors is determined by the Board within the limits set by the
Company’s Articles of Association and is based on fees paid in similar companies, the skills required,
and the expected time commitment required of each individual. Non-Executive Directors are not entitled
to pensions, annual bonuses or employee benefits. They are entitled to participate in share option
arrangements relating to the Company’s shares and both were allocated 100,000 options on 20 April
2018. The options had an exercise price of 78 pence and are subject to a three year vesting period and the
performance condition that the Company’s closing mid-market share price must exceed 200 pence for 10
consecutive business days following the vesting date. The grant represented 2% of the current issued share
capital of the company.
Each of the Non-Executive Directors has a letter of appointment stating his/her annual fee and that his/her
appointment is initially for a term of three years, subject to re-appointment at the AGM and renewable for
further periods of three years. Their appointment may be terminated with three months written notice at any
time.
Page 45
ECSC Group plcAnnual Report Year Ended 31 December 2020
Remuneration Committee Report (continued)
Annual Bonus Payments for 2020
Following the success of the financial year ended 31 December 2020, the committee resolved to pay modest
bonuses (as set out in the table below) in recognition of the performance of the Executive Directors during
the year. The bonuses were paid after the financial year end.
Name of Director
Ian Mann
Lucy Sharp
Ian Castle
Gemma Basharan
David Mathewson
Elizabeth Gooch
Total
Salary or
Fees Paid
£’000
Benefit-in-
Kind
£’000
Pension
£’000
Annual
Bonus
£’000
Share Based
Payments
£’000
200
125
100
80
65
40
610
2
14
1
-
-
-
17
20
13
10
4
-
-
47
13
10
7
5
-
-
35
4
58
38
4
8
8
120
Year ended
31
December
2020
£’000
Year ended
31
December
2019
£’000
239
220
156
93
73
48
829
214
181
-
-
89
48
532
Notes:
• Benefits-in-Kind includes the provision of Company Cars and Private Medical insurance; and
• Share Based Payments are stated at the cost of the award recognised in the financial period.
Ian Mann, Chief Executive is the highest paid Director.
Employee Benefit Expense (including Directors) during the periods amounted to:
Wages and Salaries - Gross
Government Grants
Wages and Salaries
Social Security Costs
Pension Contributions
Share Based Payments
GROUP
Year ended
31 December
2020
£’000
GROUP
Year ended
31 December
2019
£’000
COMPANY
Year ended
31 December
2020
£’000
COMPANY
Year ended
31 December
2019
£’000
4,269
(292)
3,977
452
179
101
4,709
4,091
-
4,091
440
153
105
4,789
4,033
(203)
3,830
404
161
101
4,496
3,944
-
3,944
392
134
105
4,575
During 2020 the Group has benefited from £0.2m of Coronavirus Job Retention Scheme (CJRS) and £0.1m of
Australia grants. (see note 4.5)
Page 46
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)
Directors Interests
Details of the Directors Shareholdings are included in the Director’s Report on page 41.
Share Incentives
The Company operates an Enterprise Management Incentive (‘EMI’) Scheme. The EMI Scheme provides
the opportunity for eligible Directors and employees to buy ECSC ordinary shares at a future date in
accordance with the scheme rules. The options are subject to the option holder’s continuing employment,
are not transferable, and have a life of 10 years. All grants under the scheme are subject to approval by the
Remuneration Committee.
In August 2020 the Company cancelled over 588,040 Ordinary Share options to 20 employees, following
the cancellation the Company granted options over 588,040 new Ordinary Shares to the same Company
employees, at an exercise price of 65 pence per share. The exercise price was set by reference to the
average mid-market share price being the closing market price on 20 August 2020 in accordance with HMRC
guidelines. There was a performance condition attaching to this grant, ordinary shares trade at a mid-
market minimum price of 167 pence per share over 10 consecutive business days.
The Company also granted over 450,000 new Ordinary Shares to 32 employees, at an exercise price of
69 pence per share, subject to a 1- 4 year vesting period. The exercise price was set by reference to the
average mid-market share price being the closing market price on 27 August 2020 in accordance with HMRC
guidelines. There was a performance condition attaching to this grant, ordinary shares trade at a mid-
market minimum price of 167 pence per share over 10 consecutive business days.
Page 47
ECSC Group plcAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)
Outstanding Share Based Awards
The outstanding Share Based Awards of the Directors as at 31 December 2020 are:
Name Of Director
Type Of
Reward
Date Of
Grant
Granted In
Year
Vested In
Year
Not Vested
End Of Year
Lucy Sharp
Lucy Sharp
Lucy Sharp
Share Option
19 May 2017
Share Option
16 July 2019
69,758
50,000
Share Option
Lucy Sharp
Share Option
Lucy Sharp
Ian Mann
Ian Castle
Ian Castle
Ian Castle
Ian Castle
Ian Castle
Ian Castle
Gemma Basharan
Gemma Basharan
Gemma Basharan
Gemma Basharan
Gemma Basharan
Gemma Basharan
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
Share
Option
5 Feb
2020
21 Aug
2020
28 Sept
2020
28 Sept
2020
19 May
2017
7 Aug
2018
16 July
2019
5 Feb
2020
21 Aug
2020
28 Sept
2020
19 May
2017
7 Aug
2018
16 July
2019
5 Feb
2020
21 Aug
2020
28 Sept
2020
Cancelled/
Lapsed
In Year
69,758
50,000
25,000
25,000
144,758
100,000
100,000
-
-
-
18,602
18,602
50,000
50,000
15,000
15,000
20,000
20,000
103,602
80,000
-
-
4,651
4,651
25,000
25,000
15,000
15,000
20,000
20,000
64,651
80,000
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
Market
Price At
Grant
497.5p
78.0p
1.08p
Exercise
Price
167.0p
78.0p
108.0p
-
-
-
144,758
0.65p
0.65p
100,000
0.69p
0.69p
100,000
0.69p
0.69p
-
-
-
-
497.5p
167.0p
0.93p
93.0p
78.0p
78.0p
1.08p
108.0p
103,602
0.65p
65.0p
80,000
0.69p
69.0p
-
-
-
-
497.5p
167.0p
0.93p
93.0p
78.0p
78.0p
1.08p
108.0p
64,651
0.65p
65.0p
80,000
100,000
100,000
0.69p
79.0p
79.0p
69.0p
78.0p
78.0p
Elizabeth Gooch
Share Option
18 Apr 2018
100,000
David Mathewson
Share Option
18 Apr 2018
100,000
The closing mid-market price of the Group’s shares at 31 December 2020 was 67.5 pence. During the
financial year the share price reached a high of 145.0 pence and a low of 60.0 pence.
Page 48
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Remuneration Committee Report (continued)
Directors Service Contracts
The Service contracts and letters of appointment of Directors include the following terms:
Executive Directors
Ian Mann
Lucy Sharp
Ian Castle
Gemma Basharan
Date of Appointment
13 April 2018
02 November 2012
25 March 2020
25 March 2020
Non-Executive Directors
Date of Appointment
David Mathewson
Elizabeth Gooch
18 April 2018
16 April 2018
Statement of Voting at General Meeting
Notice Period
6 months
6 months
6 months
6 months
Notice Period
3 months
3 months
At the Annual General Meeting of the Company held (last years date 30 June 2020), all resolutions, except
resolution 7, were passed. The Board notes that resolution 7, which would have enabled the Board to issue
up to 20% of the Company’s issued share capital for cash, was not passed.
Approval
This report was approved by the Directors and signed by order of the Board.
Elizabeth Gooch MBE
Chairman of the Remuneration Committee
23 March 2021
Page 49
ECSC Group plcAnnual Report Year Ended 31 December 2020
Statement of Directors’ Responsibilities
The Directors are responsible for preparing the Annual Report and the financial statements in accordance
with applicable law and regulations.
Company Law requires the Directors to prepare financial statements for each financial year. Under that law
the Directors have elected to prepare the financial statements in accordance with International accounting
standards in conformity with the requirements of the Companies Act 2006 . Under Company Law the
Directors must not approve the financial statements unless they are satisfied that they give a true and
fair view of the state of affairs of the Company and the Group and of the profit or loss of the Group for the
reporting period. In preparing these financial statements, the Directors are required to:
• select suitable accounting policies and then apply them consistently;
• make judgments and estimates that are reasonable and prudent;
• state whether applicable accounting standards have been followed, subject to any material departures
disclosed and explained in the financial statements; and
• prepare the financial statements on the going concern basis unless it is inappropriate to presume that
the Company will continue in business.
The Directors are responsible for keeping adequate accounting records that are sufficient to show and
explain the Company’s transactions and disclose with reasonable accuracy at any time the financial position
of the Company and enable them to ensure that the financial statements comply with the Companies Act
2006. They are also responsible for safeguarding the assets of the Company and hence for taking reasonable
steps for the prevention and detection of fraud and other irregularities.
Financial information is published on the Company’s website. The maintenance and integrity of this website
is the responsibility of the Directors. The work carried out by the Company’s auditors does not involve
consideration of these matters and, accordingly, the auditors accept no responsibility for any changes that
may occur to the financial statements after they are initially presented on the website.
It should be noted that legislation in the United Kingdom governing the preparation and dissemination of
financial statements may differ from legislation in other jurisdictions.
By order of the Board
David Mathewson
Non-Executive Chairman
23 March 2021
Page 50
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Cyber Security Experts
Annual Report Year Ended 31 December 2020
Page 51
ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
Opinion on the financial statements
In our opinion:
•
•
•
•
the financial statements give a true and fair view of the state of the Group’s and of the Parent Company’s
affairs as at 31 December 2020 and of the Group’s loss for the year then ended;
the Group financial statements have been properly prepared in accordance with international accounting
standards in conformity with the requirements of the Companies Act 2006;
the Parent Company financial statements have been properly prepared in accordance with international
accounting standards in conformity with the requirements of the Companies Act 2006 and as applied in
accordance with the provisions of the Companies Act 2006; and
the financial statements have been prepared in accordance with the requirements of the Companies Act
2006.
We have audited the financial statements of ECSC Group plc (the ‘Parent Company’) and its subsidiaries
(the ‘Group’) for the year ended 31 December 2020 which comprise the Consolidated Statement of
Comprehensive Income, the Consolidated and Company Statements of Financial Position, the Consolidated
and Company Cash Flow Statements, the Consolidated and Company Statements of Changes in Equity and
notes to the financial statements, including a summary of significant accounting policies.
The financial reporting framework that has been applied in the preparation of the financial statements is
applicable law and international accounting standards in conformity with the requirements of the Companies
Act 2006 and, as regards the Parent Company financial statements, as applied in accordance with the
provisions of the Companies Act 2006.
Basis for opinion
We conducted our audit in accordance with International Standards on Auditing (UK) (ISAs
(UK)) and applicable law. Our responsibilities under those standards are further described in the
Auditor’s responsibilities for the audit of the financial statements section of our report. We believe that the
audit evidence we have obtained is sufficient and appropriate to provide a basis for our opinion.
Independence
We remain independent of the Group and the Parent Company in accordance with the ethical requirements
that are relevant to our audit of the financial statements in the UK, including the FRC’s Ethical Standard as
applied to listed entities, and we have fulfilled our other ethical responsibilities in accordance with these
requirements.
Conclusions relating to going concern
In auditing the financial statements, we have concluded that the Directors’ use of the going concern basis of
accounting in the preparation of the financial statements is appropriate.
Page 52
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
As a result of the significant assumptions and judgements made by management in assessing going
concern, which were based on their best estimates and analyses of the current market conditions, including
the potential impacts of COVID-19, going concern was considered to be a key audit matter.
Our evaluation of the Directors’ assessment of the Group and the Parent Company’s ability to continue to
adopt the going concern basis of accounting included:
• Obtaining and examining the Board’s Going concern paper, alongside supporting forecasts for the next
two years.
• Challenging management’s assumptions, such as revenue pipeline, as used in the forecast period
through review of the historic forecast accuracy, comparing forecasts to post year end results, cost
performance, current business trends and pipeline/contract analysis.
• Considering the Board’s probable scenarios of sensitivities, including COVID-19 potential impact, to
understand the robustness of the forecast trading model and the headroom available to the Group and
Parent Company.
• Review of the available cash and financing facilities within the Group, and evaluation of management’s
downside sensitivities on cash flow headroom, incorporating a review of financial covenants compliance
and headroom analysis throughout the forecast period.
• Review of the disclosures made in the financial statements and in the strategic report. We assessed
whether these adequately disclose the basis of the judgements taken and the view formed by the
Directors with respect to going concern.
Based on the work we have performed, we have not identified any material uncertainties relating to events
or conditions that, individually or collectively, may cast significant doubt on the entity’s ability to continue as
a going concern for a period of at least twelve months from when the financial statements are authorised for
issue.
Our responsibilities and the responsibilities of the Directors with respect to going concern are described in
the relevant sections of this report.
Coverage
Key audit matters
100% (2019: 100%) of Group loss before tax
100% (2019: 100%) of Group revenue
100% (2019: 100%) of Group total assets
Going concern assessment
2020
x
2019
x
Materiality
Group financial statements as a whole
£108k (2019: £97k) based on 1.85% (2019: 1.65%) of revenue - refer to ‘Our application
of materiality’ section below for details.
Page 53
ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
An overview of the scope of our audit
Our Group audit was scoped by obtaining an understanding of the Group and its environment, including
the Group’s system of internal control, and assessing the risks of material misstatement in the financial
statements. We also addressed the risk of management override of internal controls, including assessing
whether there was evidence of bias by the Directors that may have represented a risk of material
misstatement.
Financial information relating to the Parent Company and its Australian operating subsidiary were subject to
a full scope audit by the Group audit team, covering 100% of the revenue, loss before tax and total assets of
the Group for the year.
Key audit matters
Key audit matters are those matters that, in our professional judgement, were of most significance in our
audit of the financial statements of the current period and include the most significant assessed risks
of material misstatement (whether or not due to fraud) that we identified, including those which had the
greatest effect on: the overall audit strategy, the allocation of resources in the audit, and directing the
efforts of the engagement team. These matters were addressed in the context of our audit of the financial
statements as a whole, and in forming our opinion thereon, and we do not provide a separate opinion on
these matters. Besides the matter described in the Conclusions relating to going concern section, we have
not determined any other matters as key audit matters to be communicated in our report.
Our application of materiality
We apply the concept of materiality both in planning and performing our audit, and in evaluating the effect of
misstatements. We consider materiality to be the magnitude by which misstatements, including omissions,
could influence the economic decisions of reasonable users that are taken on the basis of the financial
statements.
In order to reduce to an appropriately low level the probability that any misstatements exceed materiality,
we use a lower materiality level, performance materiality, to determine the extent of testing needed.
Importantly, misstatements below these levels will not necessarily be evaluated as immaterial as we also
take account of the nature of identified misstatements, and the particular circumstances of their occurrence,
when evaluating their effect on the financial statements as a whole.
Page 54
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
Based on our professional judgement, we determined materiality for the financial statements as a whole and
performance materiality as follows:
Materiality
Group financial statements
Parent company financial statements
2020
£’000s
108
2019
£’000s
97
2020
£’000s
104
2019
£’000s
92
Basis for determining materiality
1.85% of revenues
1.65% of revenues
1.85% of revenues
1.65% of revenues
Rationale for the benchmark applied
We considered revenue to be the most appropriate measure of performance and
basis for determining materiality, given the volatility in loss before tax.
Performance materiality
81
73
78
69
Basis for determining performance materiality
75% of materiality, based upon there being a limited number of areas subject to
significant estimation uncertainty and no significant errors identified in the prior
period.
Component materiality
We set materiality for the one significant component of the Group (being the Parent company) based on
a percentage of 96% (2019: 95%) of Group materiality, which is considered aligned with the size and our
assessment of the risk of material misstatement of that component. In the audit of each component, we
further applied performance materiality levels of 75% of the component materiality to our testing to ensure
that the risk of errors exceeding component materiality was appropriately mitigated.
Reporting threshold
We agreed with the Audit Committee that we would report to them all individual audit differences in excess of
£4,320 (2019: £3,880). We also agreed to report differences below this threshold that, in our view, warranted
reporting on qualitative grounds.
Other information
The directors are responsible for the other information. The other information comprises the information
included in the Group Strategic Report, Directors Report and Consolidated Financial Statements other than
the financial statements and our auditor’s report thereon. Our opinion on the financial statements does
not cover the other information and, except to the extent otherwise explicitly stated in our report, we do not
express any form of assurance conclusion thereon. Our responsibility is to read the other information and,
in doing so, consider whether the other information is materially inconsistent with the financial statements
or our knowledge obtained in the course of the audit, or otherwise appears to be materially misstated. If we
identify such material inconsistencies or apparent material misstatements, we are required to determine
whether this gives rise to a material misstatement in the financial statements themselves. If, based on the
work we have performed, we conclude that there is a material misstatement of this other information, we
are required to report that fact.
We have nothing to report in this regard.
Page 55
ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
Other Companies Act 2006 reporting
Based on the responsibilities described below and our work performed during the course of the audit, we are
required by the Companies Act 2006 and ISAs (UK) to report on certain opinions and matters as described
below.
Strategic report and Directors’
report
Matters on which we are required
to report by exception
•
•
Responsibilities of Directors
In our opinion, based on the work undertaken in the course of the audit:
•
the information given in the Strategic report and the Directors’ report for the financial
year for which the financial statements are prepared is consistent with the financial
statements; and
the Strategic report and the Directors’ report have been prepared in accordance with
applicable legal requirements.
•
In the light of the knowledge and understanding of the Group and Parent Company
and its environment obtained in the course of the audit, we have not identified material
misstatements in the strategic report or the Directors’ report.
We have nothing to report in respect of the following matters in relation to which the
Companies Act 2006 requires us to report to you if, in our opinion:
•
adequate accounting records have not been kept by the Parent Company, or returns
adequate for our audit have not been received from branches not visited by us; or
the Parent Company financial statements are not in agreement with the accounting
records and returns; or
certain disclosures of Directors’ remuneration specified by law are not made; or we have
not received all the information and explanations we require for our audit.
As explained more fully in the statement of Directors’ responsibilities, the Directors are responsible for the
preparation of the financial statements and for being satisfied that they give a true and fair view, and for such
internal control as the Directors determine is necessary to enable the preparation of financial statements
that are free from material misstatement, whether due to fraud or error.
In preparing the financial statements, the Directors are responsible for assessing the Group’s and the Parent
Company’s ability to continue as a going concern, disclosing, as applicable, matters related to going concern
and using the going concern basis of accounting unless the Directors either intend to liquidate the Group or
the Parent Company or to cease operations, or have no realistic alternative but to do so.
Auditor’s responsibilities for the audit of the financial statements
Our objectives are to obtain reasonable assurance about whether the financial statements as a whole
are free from material misstatement, whether due to fraud or error, and to issue an auditor’s report that
includes our opinion. Reasonable assurance is a high level of assurance, but is not a guarantee that an
audit conducted in accordance with ISAs (UK) will always detect a material misstatement when it exists.
Misstatements can arise from fraud or error and are considered material if, individually or in the aggregate,
they could reasonably be expected to influence the economic decisions of users taken on the basis of these
financial statements.
Page 56
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
Extent to which the audit was capable of detecting irregularities, including fraud
Irregularities, including fraud, are instances of non-compliance with laws and regulations. We design
procedures in line with our responsibilities, outlined above, to detect material misstatements in respect of
irregularities, including fraud. The extent to which our procedures are capable of detecting irregularities,
including fraud is detailed below:
As part of the audit we gained an understanding of the legal and regulatory framework applicable to the
Group and the industries in which it operates, and considered the risk of acts by the Group that were
contrary to applicable laws and regulations, including fraud. We considered the Group’s compliance with
laws and regulations that have a significant impact on the financial statements to be UK company law, UK
tax legislation, the accounting framework and ISO security standards, and we considered the extent to which
non-compliance might have a material effect on the Group financial statements.
Based on our understanding we designed our audit procedures to identify instances of non-compliance
with such laws and regulations. Our procedures included enquiries of management and of the Directors,
reviewing the financial statement disclosures agreeing to underlying supporting documentation where
necessary, review of Board meeting minutes and review of any applicable correspondence with legal counsel
or tax authorities.
Our assessment of the susceptibility of the financial statements to fraud was through management override
of controls and revenue recognition (cut-off) which was addressed through detailed testing. We addressed
the risk of management override of internal controls, including testing journal entries processed during
and subsequent to the year, testing of significant estimates (included capitalised development costs) and
evaluating whether there was evidence of bias in the financial statements by the Directors that represented a
risk of material misstatement due to fraud.
We also communicated relevant identified laws and regulations and potential fraud risks to all engagement
team members and remained alert to any indications of fraud or non-compliance with laws and regulations
throughout the audit.
Our audit procedures were designed to respond to risks of material misstatement in the financial
statements, recognising that the risk of not detecting a material misstatement due to fraud is higher
than the risk of not detecting one resulting from error, as fraud may involve deliberate concealment by,
for example, forgery, misrepresentations or through collusion. There are inherent limitations in the audit
procedures performed and the further removed non-compliance with laws and regulations is from the
events and transactions reflected in the financial statements, the less likely we are to become aware of it.
A further description of our responsibilities is available on the Financial Reporting Council’s website at: www.
frc.org.uk/auditorsresponsibilities. This description forms part of our auditor’s report.
Use of our report
This report is made solely to the Parent Company’s members, as a body, in accordance with Chapter 3 of
Part 16 of the Companies Act 2006. Our audit work has been undertaken so that we might state to the
Page 57
ECSC Group plcAnnual Report Year Ended 31 December 2020Independent auditor’s report to the members of ECSC Group plc
Parent Company’s members those matters we are required to state to them in an auditor’s report and for no
other purpose. To the fullest extent permitted by law, we do not accept or assume responsibility to anyone
other than the Parent Company and the Parent Company’s members as a body, for our audit work, for this
report, or for the opinions we have formed.
Mark Langford (Senior Statutory Auditor)
For and on behalf of BDO LLP, Statutory Auditor
Leeds, UK
23 March 2021
BDO LLP is a limited liability partnership registered in England and Wales (with registered number
OC305127).
Page 58
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Consolidated Statement of Comprehensive Income
For the year ended 31 December 2020
Revenue
Cost of Sales
Gross Profit
Other Income
Sales & Marketing Costs
Administration Expenses
Operating Loss before Exceptional Items and Share Based Payments
Share Based Payments
Exceptional Items
Operating Loss
Finance Cost
Loss before Taxation
Taxation Credit/ (Charge)
Loss for the Year
Other Comprehensive Income
Total Comprehensive Income for the Year
Attributed to Equity Holders of the Company
Loss per Share
Basic Loss per Share
Diluted Loss per Share
Note
6
6
7
23
26
8
25
10
11
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
5,663
(2,115)
3,548
297
(1,713)
(2,403)
(105)
101
65
(271)
(48)
(319)
50
(269)
-
(269)
(269)
pence
(2.7)
(2.7)
5,905
(2,545)
3,360
263
(1,958)
(2,369)
(593)
105
6
(704)
(46)
(750)
(26)
(776)
-
(776)
(776)
pence
(8.5)
(8.5)
The financial statements were approved and authorised for issue by the Board of Directors on 23 March 2021
and were signed on its behalf by:
Gemma Basharan
Director
23 March 2021
Page 59
ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Statement of Financial Position
Note
Year ended
31 December
2020
£’000
Year ended
31 December
2019*
£’000
ASSETS
Non-current Assets
Intangible Assets
Property, Plant and Equipment
Right-of-use Assets
Deferred Tax Asset
Total Non-current Assets
Current Assets
Inventory
Trade and Other Receivables
Corporation Tax Recoverable
Cash and Cash Equivalents
Total Current Assets
TOTAL ASSETS
LIABILITIES
Current Liabilities
Trade and Other Payables
Lease Liability
Total Current Liabilities
Non-current Liabilities
Deferred Tax Liability
Lease Liability
Total Non-current Liabilities
TOTAL LIABILITIES
NET ASSETS
EQUITY
Equity attributable to Owners of the Parent:
Share Capital
Share Premium Account
Share Option Reserve
Retained Earnings
TOTAL EQUITY
12
13
18
10
14
15
7
16
17
18
10
18
20
20
20
20
455
148
746
118
1,467
9
811
216
1,122
2,158
3,625
(2,085)
(143)
(2,228)
(90)
(659)
(749)
(2,977)
648
100
6,098
392
(5,942)
648
429
283
896
77
1,685
26
890
265
351
1,532
3,217
(1,817)
(150)
(1,967)
(99)
(781)
(880)
(2,847)
370
91
5,661
291
(5,673)
370
*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of
comprehensive income for the Group or Company only financial statements.
The financial statements were approved and authorised for issue by the Board of Directors on 23 March 2021
and were signed on its behalf by:
Gemma Basharan | Director
23 March 2021
Page 60
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020
Company Statement of Financial Position
Note
Year ended
31 December
2020
£’000
Year ended
31 December
2019*
£’000
ASSETS
Non-current Assets
Intangible Assets
Property, Plant and Equipment
Right-of-use Assets
Deferred Tax Asset
Total Non-current Assets
Current Assets
Inventory
Trade and Other Receivables
Corporation Tax Recoverable
Cash and Cash Equivalents
Total Current Assets
TOTAL ASSETS
LIABILITIES
Current Liabilities
Trade and Other Payables
Lease Liability
Total Current Liabilities
Non-current Liabilities
Deferred Tax Liability
Lease Liability
Total Non-current Liabilities
TOTAL LIABILITIES
NET ASSETS
EQUITY
Equity attributable to Owners of the Parent:
Share Capital
Share Premium Account
Share Option Reserve
Retained Earnings
TOTAL EQUITY
12
13
18
10
14
15
7
16
17
18
10
18
20
20
20
20
455
147
711
118
1,431
9
887
216
1,119
2,231
3,662
(2,163)
(119)
(2,282)
(90)
(645)
(735)
(3,017)
645
100
6,098
392
(5,945)
645
429
272
839
77
1,617
26
960
265
350
1,601
3,218
(1,879)
(128)
(2,007)
(99)
(744)
(843)
(2,850)
368
91
5,661
291
(5,675)
368
*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of
comprehensive income for the Group or Company only financial statements.
For the year ended 31 December 2020, Loss after Taxation for the Company was £270k (2019: loss of £775k).
Gemma Basharan | Director
23 March 2021
Page 61
ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Statement of Changes in Equity
Balance as at 31 December 2018
Loss and Total Comprehensive Income:
Total Comprehensive Loss for the Year
Transactions with shareholders
Issue of Shares
Share Based Payments
Balance as at 31 December 2019
Loss and Total Comprehensive
Total Comprehensive Loss for the Year
Transactions with shareholders
Issue of shares
Share Based Payments
Balance as at 31 December 2020
Share
Capital
£’000
91
Share
Premium
Account
£’000
5,661
Share
Option
Reserve
£’000
Retained
Earnings
£’000
186
(4,897)
Total
£’000
1,041
-
-
-
-
-
-
91
5,661
-
9
-
100
-
437
-
6,098
-
-
105
291
-
-
101
392
(776)
(776)
-
-
(5,673)
(269)
-
-
(5,942)
-
105
370
269
446
101
648
Page 62
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company Statement of Changes in Equity
Balance as at 31 December 2018
Loss and Total Comprehensive Income:
Total Comprehensive Loss for the Year
Transactions with shareholders
Issue of Shares
Grant of Share Options
Balance as at 31 December 2019
Loss and Total Comprehensive
Total Comprehensive Loss for the Year
Transactions with shareholders
Issue of shares
Share Based Payments
Balance as at 31 December 2020
Share
Capital
£’000
91
Share
Premium
Account
£’000
5,661
Share
Option
Reserve
£’000
Retained
Earnings
£’000
186
(4,900)
Total
£’000
1,038
-
-
-
-
-
-
91
5,661
-
9
-
100
-
437
-
6,098
-
-
105
291
-
-
101
392
(775)
(775)
-
-
(5,675)
-
105
368
(270)
(270)
-
-
(5,945)
446
101
645
Page 63
ECSC Group plcAnnual Report Year Ended 31 December 2020Consolidated Cash Flow Statement
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
Note
(319)
(750)
12
18
13
23
14
15
17
4
13
12
18
16
168
175
137
(4)
48
101
306
17
(214)
268
-
377
343
720
(5)
6
(194)
(193)
(195)
(7)
500
(54)
244
771
351
1,122
177
200
217
(1)
46
105
(6)
(8)
(349)
428
(13)
52
152
204
(129)
16
(194)
(307)
(195)
(1)
-
-
(196)
(299)
650
351
Cash Flow from / (used in) Operating Activities
Loss before Taxation
Adjustment for:
Amortisation of Intangibles
Depreciation of right-of-use assets
Depreciation of Property, Plant and Equipment
Profit on Disposal of Equipment
Finance Costs
Share Based Payments
Cash used up in Operating Activities before changes in Working Capital
Change in Inventory
Change in Trade and Other Receivables
Change in Trade and Other Payables
Change on Other Non Cash Items
Cash Generated from Operating Activities
R&D Tax Credit Received
Net Cash Flow Generated from Operating Activities
Acquisition of Property, Plant and Equipment
Disposal Proceeds
Development Costs capitalised
Net Cash Flow used in Investing Activities
Principal Paid on Lease Liabilities
Interest Paid on Loans and Borrowings
Proceeds from Issue of Shares
Costs of Share Issuance
Net Cash generated from / (used in) Financing Activities
Net increase/decrease in Cash & Cash Equivalents
Cash & Cash Equivalents at beginning of period
Cash & Cash Equivalents at end of period
Page 64
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company Cash Flow Statement
Cash Flow from / (used in) Operating Activities
Loss before Taxation
Adjustment for:
Amortisation of Intangibles
Amortisation of right-of-use assets
Depreciation of Property, Plant and Equipment
Profit on Disposal of Equipment
Finance Costs
Share Based Payments
Cash used up in Operating Activities before changes in Working Capital
Change in Inventory
Change in Trade and Other Receivables
Change in Trade and Other Payables
Change on Other Non Cash Items
Cash Generated from Operating Activities
R&D Tax Credit Received
Net Cash Flow Generated from Operating Activities
Acquisition of Property, Plant and Equipment
Disposal Proceeds
Development Costs Capitalised
Net Cash Flow used in Investing Activities
Principal Paid on Lease Liabilities
Interest Paid on Loans and Borrowings
Proceeds from Issues of Shares
Costs of Share Issuance
Net Cash generated from / (used in) Financing Activities
Net increase / (decrease) in Cash & Cash Equivalents
Cash & Cash Equivalents at beginning of period
Cash & Cash Equivalents at end of period
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
Note
(320)
(749)
12
18
13
23
14
15
17
13
12
18
16
168
153
127
(4)
46
101
271
17
(220)
284
-
352
343
695
(5)
6
(194)
(193)
(172)
(7)
500
(54)
267
769
350
1,119
177
178
198
(1)
43
105
(49)
(8)
(348)
450
(13)
32
152
184
(128)
16
(194)
(306)
(173)
(1)
-
-
(174)
(296)
646
350
Page 65
ECSC Group plcAnnual Report Year Ended 31 December 2020Cyber Security Experts
Annual Report Year Ended 31 December 2020
Page 66
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements
1. Corporate Information
ECSC Group plc is incorporated
in England and Wales and
admitted to trading on the market
of the London Stock Exchange
(AIM: ECSC). Further copies of
these financial statements will
be available at the Company’s
registered office: 28 Campus
Road, Listerhills Science Park,
Bradford, West Yorkshire, BD7
1HR. These financial statements
for the year ended 31 December
2020 were approved by the Board
of Directors on 23 March 2021.
2. General Information
These financial statements may
contain certain statements about
the future outlook of ECSC Group
plc. Although the Directors believe
their expectations are based on
reasonable assumptions, any
statements about future outlook
may be influenced by factors that
could cause actual outcomes and
results to be materially different.
3. Basis of Preparation
These financial statements for
the year ended 31 December 2020
have been prepared in accordance
with International Financial
Reporting Standards, International
Accounting Standards and
Interpretations (collectively
‘IFRS’) in conformity with the
requirements of the Companies
Act 2006. The Company has taken
advantage of Section 408 of the
Companies Act 2006 and has not
included its individual statement
of comprehensive income in
these financial statements. The
Company’s overall result for the
year is given in the company
statement of financial position
and statement of changes in
shareholders’ equity.
The financial statements for
the period ended 31 December
2020 (and comparative) have
been prepared on a consolidated
basis. The consolidated financial
statements present the results of
the Company and its subsidiaries
(‘the Group’) as if they formed
a single entity. The financial
statements of the Group and
Company are both prepared in
accordance with IFRS.
Alternative performance
measures (APM)
In the reporting of financial
information, the Directors have
adopted the APM ‘Adjusted
EBITDA” (APMs were previously
termed ‘Non-GAAP measures’),
which is not defined or specified
under International Financial
Reporting Standards (IFRS).
This measure is not defined by
IFRS and therefore may not be
directly comparable with other
companies’ APMS, including those
in the Group’s industry. APMs
should be considered in addition
to, and are not intended to be a
substitute for, or superior to, IFRS
measurements.
Purpose
The Directors believe that
this APM assists in providing
additional useful information
on the underlying trends,
performance and position of the
Group. This APM is also used
to enhance the comparability of
information between reporting
periods and business units, by
adjusting for non-recurring or
uncontrollable factors which
affect IFRS measures, to aid the
user in understanding the Group’s
performance.
Consequently, APMs are used by
the Directors and management
for performance analysis,
planning, reporting and incentive
setting purposes and this remains
consistent with the prior year.
Adjusted APMs are used by the
Group in order to understand
underlying performance and
exclude items which distort
compatibility, as well as being
consistent with public broker
forecasts and measures (see note
25).
The financial statements have
been presented in thousands of
Pounds Sterling (£’000, GBP) as
this is the currency of the primary
economic environment that the
Company operates in.
Page 67
ECSC Group plcAnnual Report Year Ended 31 December 2020
Notes to the Financial Statements (continued)
4. Accounting Policies
The principal accounting policies applied in the preparation of the financial statements are set out below.
These policies have been consistently applied to all periods presented, unless otherwise stated.
4.1 Basis of Accounting
The financial statements have been prepared on the historical cost basis except as stated.
New IFRS standards, amendments to and interpretations not applied to published standards
The following new standards, amendments to standards and interpretations will be mandatory for the first
time in future financial years:
New Standards
IFRS 17 Insurance contracts
Amendments to existing standards
Amendments to References to the
Conceptual Framework in IFRS Standards
Amendments to IFRS 3 Business
Combinations – Definition of a Business
Amendments to IAS 1 and IAS 8: Definition
of Material
Amendments to IFRS 9, IAS 39 and IFRS 7:
Interest Rate Benchmark Reform
Amendments to IAS 1: Classification of
Liabilities as Current or Non-current
Amendments to: IFRS 3 Business
Combinations; IAS 16 Property, Plant and
Equipment; IAS 37 Provisions, Contingent
Liabilities and Contingent Assets
Annual Improvements to IFRSs (2018-2020
Cycle): IFRS 1, IFRS 9, Illustrative Examples
accompanying IDRS 16, IAS 41
Amendments to IFRS 16 Leases COVID
19-Related Rent Concessions
Amendments to IFRS 4 Insurance Contracts
– deferral of IFRS 9
Amendments to IFRS 9, IAS 39, IFRS 7, IFRS
4 and IFRS 16 Interest Rate Benchmark
Reform – Phase 2
Issued date
IASB mandatory effective date
(UK mandatory effective date)
UK Adoption status (EU pre 31
December 2020)
18-May-2017 and
25-June-2020
01-Jan-2023
TBC
29-May-2018
01-Jan-2020
22-Oct-2018
01-Jan-2020
31-Oct-2018
01-Jan-2020
26-Sept-2019
01-Jan-2020
23-Jan-2020
01-Jan-2022
14-May-2020
01-Jan-2022
14-May-2020
01-Jan- 2022
Endorsed
Endorsed
Endorsed
Endorsed
TBC
TBC
TBC
14-May-2020
01-Jun- 2020
Endorsed
25-Jun-2020
01-Jun-2021
Adopted by UKEB
27-Aug-2020
01-Jun-2021
Adopted by UKEB
The application of these standards and interpretations is not expected to have a material impact on the
Group’s reporting financial performance or position.
Page 68
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
4.2 Going Concern
The Directors have reviewed
whether the Group has
adequate resources to continue
in operational existence for
the foreseeable future, being
no shorter than 12 months
from the date of approving the
Annual Report. In conducting
this review, the Directors have
considered a range of factors,
including the market prospects
for cyber security services, client
relationships and dependency,
supplier relationships and
dependency, actual or potential
litigation, staff retention and
reliance, relationships with
HMRC and regulators, financing
arrangements, historic trading
and cash flow performance,
current trading and cash flow
performance, and future trading
and cash flow expectations. In
undertaking their review, the
Directors have prepared financial
projections for the years ending 31
December 2021 and 2022, a review
which assumed continued revenue
growth and cost efficiency.
The budget figures are closely
monitored against actuals on a
monthly basis. Variances that
may arise are discussed a Board
level on a monthly basis during a
review of the monthly numbers.
In the event that this revenue and
cost performance is not achieved,
the Directors have also considered
a sensitivity analysis based on
lower revenue growth and have
formulated contingency plans for
this scenario, which enable the
Group to preserve its financial
resources.
During 2020 the Group has seen
the pandemic creating additional
risks and uncertainties. These
were carefully monitored and
the Group was able to adapt
to meet the challenges arising
from COVID-19. The Group has
extensive remote and home
working options in place, fully
tested, supporting a range of
conferencing technologies, all
of which maintain cyber security
related certifications, associated
technical standards and policies.
The Group was also able to deliver
the full range of services remotely.
During 2020 the Group took
advantage of published time to pay
plans on VAT. As at 31 December
2020, £0.2m remained outstanding
in this regard. A deferred PAYE
payment plan ending 31 March
2021 was agreed with HMRC.
As at 31 December 2020, £0.2m
remained outstanding.
As at 31 December 2020, the
Group had cash and cash
equivalents of £1.1m (2019:
£0.4m) and achieved an Adjusted
EBITDA profit of £0.4m (2019:
£1k), reducing the operating loss
to £0.3m (2019: £0.7m).
On 17 April 2020, the Group
completed a fundraise of £0.45m
(net of expenses of £0.05m).
The Group continues to have an
unused invoice financing facility
with Barclays Bank PLC of £0.5m.
Based on this review, the
Directors have concluded that the
Group has adequate resources
to meet its liabilities as they fall
due and continue in operational
existence for the foreseeable
future, which is considered to
be at least the next 12 months
from the date of approval
of the financial statements.
Consequently, the Directors
have adopted the going concern
basis in preparing the financial
statements.
4.3 Revenue Recognition
The core principle is that revenue
should only be recognised as
the client receives the benefit of
the goods or services provided
under a commercial contract,
in an amount that reflects the
consideration to which the
provider expects to be entitled
for the transfer of the goods or
services.
Performance obligations and
timing of revenue recognition
Revenue comprises the sales
value of goods and services
supplied during the year, exclusive
of Value Added Tax and trade
discounts. Revenue from the
provision of Consulting services
is recognised as services are
rendered, based on the contracted
daily billing rate and the number
of days delivered during the
period.
Page 69
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Revenue from Pre-paid contracts are deferred in the balance sheet and recognised on utilisation of service
by the client. Pre-paid revenue is included within Assurance in note 6.
Revenue from MDR contracts includes:
Hardware – hardware revenue is recognised on delivery and is included within other revenue as set out in
note 6. This is when control of hardware passes to the customer.
Device build - Device build revenue is deferred and recognised on a straight line basis over the term of the
contract.
Licensing - deferred and recognised on a straight line basis over the invoice period, due to the performance
obligation not being considered distinct from management and monitoring performance obligation
Management and monitoring - deferred and recognised on a straight line basis over the invoice period.
Revenue from the sale of products (vendor) is recognised when control passes to the customer, which is
considered to occur when the software or hardware product has been delivered to the client.
Determining the transaction price
The Group’s revenue is derived from fixed price contracts and therefore the amount of revenues to be earned
from each contract is determined by reference to those fixed prices.
Costs of obtaining long-term contracts and costs of fulfilling contracts
Commissions paid to sales staff for work in obtaining Managed Service contracts are prepaid and amortised
over the terms of the contract on a straight line basis.
Commissions paid to sales staff for work in obtaining the Prepaid Consultancy contracts are recognised in
the month of invoice.
Page 70
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Contract Balances
At 1 January
Commission expensed during the period
Commissions paid in advance of contract completion
Recognised as revenue during the period
Cash received in advance of performance during
period
Contract
Assets
2020
£’000
Contract
Assets
2019
£’000
43
(62)
53
-
-
34
49
(28)
22
-
-
43
Contract
Liabilities
2020
£’000
(866)
-
-
3,390
(3,402)
(878)
Contract
Liabilities
2019*
£’000
(949)
-
-
2,429
(2,346)
(866)
* Prior year restatement
A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due as
at 31 December 2019 where the performance obligation had not commenced at that date. This restatement impacted the presentation of both the
Group or Company Statement of Financial Position page 60-61. This restatement does not impact the statement of comprehensive income for the
Group and Company only financial statements. Trade receivables and contract liabilities are stated net in respect of advance billing in line with the
requirements of IFRS 15.
Contract Assets balance of £34k (2019: £43k) is included in the Trade Receivables and Other Receivables (note 15).
Contract Liabilities balance of £878k (2019: £866k) is included in Trade Payables and Other Payables (note 17).
4.4 Finance Income
Finance income is accrued on an annual basis, by reference to the principal outstanding at the applicable
effective credit interest rate.
4.5 Government Grant Income
A government grant is recognised only when there is reasonable assurance that (a) the entity will comply
with any conditions attached to the grant and (b) the grant will be received.
The grant is recognised as income over the period necessary to match them with the related costs, for which
they are intended to compensate, on a systematic basis.
Government Grant Income is recognised in the Statement of Comprehensive Income over the period in which
the Company recognises expenses for the related costs for which the grants are intended to compensate.
Grants relating to income are deducted from the related expense.
Government tax credits available on eligible Research and Development expenditure (‘R&D Tax Credits’) and
not reclaimable through other means are recognised as Other Income (see note 7).
Coronavirus Job Retention Scheme (CJRS)
Where the Group receive Coronavirus Job Retention Scheme (CJRS) expenditure credits, it is accounted
Page 71
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
for as government grant as income and matched with the relevant staff costs in which they are intended to
compensate. The income has been recognised in the period to which the underlying furloughed staff costs
relate to in accordance with IAS20. (see note 9)
Australia Government Grants
Where the Group received the JobKeeper payment (wage subsidy which provided a $1,500 payment per
fortnight per employee from 1st April 2020 until 27 September 2020) and the Cash Flow Boost for Employers,
it is accounted for as government grant as income and matched with the relevant staff costs in which they
are intended to compensate. The income has been recognised in the period to which the underlying grant
staff costs relate to in accordance with IAS20. (see note 9)
4.6 Operating Profit
Operating Profit is stated after all expenses, including those considered to be exceptional, but before finance
income or expenses. Exceptional items are items of income or expense which, because of their nature or
size, require separate presentation to allow shareholders to better understand the financial performance of
the period and allow comparison with prior years.
4.7 Foreign Currencies
Financial assets and liabilities in foreign currencies are translated into sterling at the rates of exchange
prevailing at the balance sheet date. Transactions in foreign currencies are translated into sterling at the
rate of exchange prevailing at the date of the transaction. Exchange differences are recognised in Operating
Profit.
On consolidation, the results of overseas operations are translated into Sterling at rates approximating those
prevailing when the transactions took place. All assets and liabilities of overseas entities are translated at
the rate prevailing at the reporting date. Exchange differences arising on translating the opening net assets
at opening rate and the results of overseas operations at actual rate are recognised in Other Comprehensive
Income and accumulated in the foreign exchange reserve.
4.8 Employee Benefits
Short-Term Benefits
Wages, salaries, paid annual leave and sick leave, bonuses and non-monetary benefits are accrued in the
period in which the associated services are rendered by employees of the Company.
Defined Contribution Pension Scheme
The Company operates a defined contribution pension scheme for employees. The assets of the scheme
are held separately from those of the Company. The annual contributions are charged to the Statement of
Comprehensive Income. The Company also contributes to the personal pension plans of the Directors in
Page 72
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
accordance with their Service Contracts.
Employee Share Based Payments
Where equity settled share options are granted to employees (including Directors), the fair value of the
options at the date of grant is charged to the Consolidated Statement of Comprehensive Income, as a Share
Based Payment Charge, over the vesting period of the options, with a corresponding movement in the Share
Option Reserve.
Non-market vesting conditions are taken into account by adjusting the number of equity instruments
expected to vest at each reporting date so that, ultimately, the cumulative amount recognised over the
vesting period is based on the number of options that eventually vest. Non-vesting conditions and market
vesting conditions are factored into the fair value of the options granted. As long as all other vesting
conditions are satisfied, a charge is made irrespective of whether the market vesting conditions are satisfied.
Where the terms and conditions of options are modified before they vest, the increase in the fair value of the
options, measured immediately before and after modification, is also charged to the Consolidated Statement
of Comprehensive Income over the remaining vesting period.
Where options are cancelled and replaced, modification treatment is adopted which results in the recognition
of any incremental fair value but not any reduction in fair value. Any increase in the fair value of the options,
measured immediately at replacement, is charged to the Consolidated Statement of Comprehensive
Income. The cancelled options continue to be charged to the Consolidated Statement of Comprehensive
Income over the remaining vesting period.
4.9 Property, Plant and Equipment
All additions are initially recorded at historic cost. Depreciation is calculated so as to write-off the cost of an
asset, less its estimated residual value, over the useful economic life of that asset as follows:
• Leasehold Property
• Office Furniture and Equipment
• Computer Equipment
• Motor Vehicles
20% reducing balance
20% reducing balance
33% straight line
20% straight line
4.10 Research and Development Expenditure
Expenditure on research activities is recognised as an expense in the period in which it is incurred.
Expenditure on development activities generating an intangible asset is capitalised if all of the criteria set
out in IAS 38 are met. Capitalised assets are amortised over their useful economic life, which is considered
to be five years.
If the criteria set out in IAS 38 are not met, expenditure on development activities is recognised as an
Page 73
ECSC Group plcAnnual Report Year Ended 31 December 2020
Notes to the Financial Statements (continued)
expense in the period in which it is incurred.
4.11 Inventories
Inventories are carried at the lower of cost or net realisable value. Net realisable value is calculated based
on the expected revenue from sale in the normal course of business less any costs to sell. Due allowance is
made for obsolete and slow moving items.
4.12 Financial Instruments
Financial Assets
The Group and Company’s Financial Assets include Cash and Cash Equivalents, Trade Receivables and Other
Receivables.
•
Initial Recognition and Measurement
Financial Assets are classified as amortised cost and initially measured at fair value.
• Subsequent Measurement
Financial assets are subsequently measured at amortised cost, using the effective interest method,
less impairment. Interest is recognised by applying the effective interest method, except for short-term
receivables when the recognition of interest would be immaterial.
The Group has applied the simplified method of the expected credit loss model when calculating impairment
losses on its financial assets measured at amortised cost, such as trade receivables. This resulted in greater
judgement due to the need to factor in forward-looking information when estimating the appropriate amount
to provisions.
• De-recognition of Financial Assets
The Group and Company de-recognises a Financial Asset only when the contractual rights to the cash
flows from the asset expire, or it transfers the Financial Asset and substantially all the risks and rewards of
ownership of the asset to another entity.
•
Invoice Discounting Facility
The Group and Company will continue to retain substantially all the credit risk and therefore will continue to
recognise the receivables.
Financial Liabilities and Equity Instruments
The Group and Company’s Financial Liabilities include Trade Payables, Accruals and Other Payables .
Page 74
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Financial Liabilities are classified at amortised cost.
• Classification as Debt or Equity
Financial Liabilities and Equity Instruments issued by the Company are classified according to the substance
of the contractual arrangements entered into and the definitions of a Financial Liability and an Equity
Instrument.
•
Equity Instruments
An Equity Instrument is any contract that evidences a residual interest in the assets of the Company after
deducting all of its liabilities. Equity Instruments are recorded at the proceeds received, net of direct issue
costs.
• Trade Payables, Other Payables and Accruals
Trade Payables, Accruals and Other Payables are initially measured at fair value, net of transaction costs,
and are subsequently measured at amortised cost, where applicable, using the effective interest method,
with interest expense recognised on an effective yield basis.
•
De-recognition of Financial Liabilities
The Company de-recognises financial liabilities when the Company’s obligations are discharged, cancelled
or expire.
Offsetting of Financial Instruments
Financial Assets and Financial Liabilities are offset, and the net amount reported in the Statement of
Financial Position if there is a currently enforceable legal right to offset the recognised amounts and there is
an intention to settle on a net basis, or to realise the assets and settle the liabilities simultaneously.
4.13 Cash and Cash Equivalents
Cash and Cash Equivalents comprise cash on hand and demand deposits, and other short-term highly liquid
investments which are readily convertible to known amounts of cash and are subject to insignificant risk of
changes in value.
4.14 Impairment of Assets
Non-Financial Assets
The carrying amounts of the Group and Company’s Non-Financial Assets, other than Deferred Tax Assets,
are reviewed at each reporting date to determine whether there is any indication of impairment. If any such
indication exists, then the asset’s recoverable amount is estimated.
Page 75
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The recoverable amount of an asset or cash-generating unit is the greater of its value in use and its fair
value less costs to sell. In assessing value in use, the estimated future cash flows are discounted to their
present value using a pre-tax discount rate that reflects current market assessments of the time value of
money and risk specific to the asset. For the purpose of impairment testing, assets are grouped together into
the smallest group of assets that generates cash inflows from continuing use that are largely independent of
the cash inflows of other assets or groups of assets.
An impairment loss is recognised if the carrying amount of an asset or its cash generating unit exceeds its
estimated recoverable amount. Impairment losses are recognised in profit and loss.
Impairment losses recognised in prior periods are assessed at each reporting date for any indications that
the loss has decreased or no longer exists. An impairment loss is reversed if there has been a change in
the estimates used to determine the recoverable amount. An impairment loss is reversed only to the extent
that the asset’s carrying amount does not exceed the carrying amount that have been determined, net of
depreciation or amortisation, if no impairment loss had been recognised.
4.15 Corporation Tax
Corporation Tax expense represents the sum of the tax currently payable and Deferred Tax.
The tax currently payable is based on taxable profit for the year. Taxable profit differs from profit as reported
in the Statement of Comprehensive Income because it excludes items of income or expense that are taxable
or deductible in other years and it further excludes items that are not taxable or tax deductible.
The Company’s liability for current tax is calculated using tax rates (and tax laws) that have been enacted or
substantively enacted by the end of the financial period.
Government tax credits available on eligible Research and Development expenditure and not reclaimable
through other means are recognised as Other Income and treated as a government grant. This applies when
there are no taxable profits against which to offset the tax credit. The amount receivable by the Group and
Company is shown on the face of the balance sheet within Corporation Tax Recoverable.
4.16 Deferred Tax
Deferred Tax is recognised in respect of all timing differences that have originated but not reversed at the
balance sheet date where transactions or events have occurred at that date that will result in an obligation to
pay more, or a right to pay less or to receive more tax.
Deferred Tax Assets are recognised only to the extent that the Directors consider that it is more likely
than not that there will be suitable taxable profits from which the future reversal of the underlying timing
differences can be deducted.
Deferred Tax is measured on an undiscounted basis at the tax rates that are expected to apply in the periods
Page 76
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
in which timing differences reverse, based on tax rates and laws enacted or substantively enacted at the
balance sheet date.
4.17 Share Capital
Ordinary Share Capital is recorded at nominal value and proceeds received in excess of nominal value of
shares issued, if any, is accounted for in the Share Premium Account. Both Ordinary Share Capital and Share
Premium Account are classified as equity. Costs incurred directly to the issue of shares are accounted
for as a deduction from Share Premium Account; otherwise such costs are charged to the Statement of
Comprehensive Income.
4.18 Operating Segments
An operating segment is a component of the Group and the Company that engages in business activities
from which it may earn revenues and incur expenses, including revenues and expenses that relate to
transactions with any of the Company’s other components.
An operating segment’s operating results are reviewed regularly by the Directors of the Company to assess
performance and make decisions about resource allocation.
The Board considers that the Company’s activity constitutes three operating and three reporting segments
as defined under IFRS 8.
4.19 Related Parties
Parties are considered to be related if one party has the ability (directly or indirectly) to control the other
party or exercise significant influence over the other party in making financial and operating decisions.
Parties are also considered related if they are subject to common control or common significant influence.
Related parties may be individuals or corporate entities.
5. Critical Accounting Judgements, Estimates and Sources of Estimation Uncertainty
In applying the accounting policies, the Directors may at times be required to make critical accounting
judgements and estimates about the carrying amount of assets and liabilities. These estimates and
assumptions, when made, are based on historical experience and other factors that the Directors consider
are relevant.
The key estimates and assumptions concerning the future and other key sources of estimation uncertainty
at the end of the financial year, that have significant risk of causing a material adjustment to the carrying
amounts of assets and liabilities within the next financial year, are stated below.
Page 77
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Judgements
Going Concern
Management apply their judgement in reviewing whether the Group has adequate resources to continue
in operational existence for the foreseeable future, which is considered to be 12 months from the date
of approval of the financial statement. The Group have undertaken sensitivity analysis around a possible
uncertainties, further detail regarding the impact is detail on page 28.
Development Costs Capitalised & Amortised
Management apply their judgement in determining whether an identified intangible software asset meets
the criteria for capitalisation under IAS 38. The carrying value of Intangible Assets as at 31 December 2020
was £455k (2019: £429k).
Management estimate the percentage of development staff time used to enhance and improve the
Company’s intangible software assets in order to capitalise a proportion of salary costs each period. In the
year ended 31 December 2020, the amount of staff time capitalised into Intangible Assets was £194k (2019:
£194k).
Development Costs capitalised into Intangible Assets are amortised over management’s estimate of the
useful economic life of the asset recognised. In the year ended 31 December 2020, the useful economic life
of all Intangible Assets was estimated to be 5 years, resulting in an amortisation charge of £168k (2019:
£177k).
6. Revenue and Segment Information
The Group’s principal revenue is derived from the provision of cyber security professional services.
During this period, the Directors received information on financial performance on a divisional basis. The
Directors consider that there are three reportable operating segments: Assurance (including Remote
Support services), MDR, and Vendor Products. There were a small number of other transactions recorded
during each period which are not considered to be part of either of the three reportable operating segments.
These are presented below within the ‘Other’ caption and are not significant.
The Directors do not receive any information on the financial position of each segment, including information
on assets and liabilities. Accordingly, no such information has not been presented.
The Group is not reliant on any single client, with no single client accounting for 10% or more of revenue. All
revenue recognised is derived from external clients.
Page 78
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020
Notes to the Financial Statements (continued)
The Group has PPE located in the UK (cost of £896k; NBV of £147k) and Australia (cost of £57k; NBV of £1k).
The Group’s revenue and gross profit by operating segment for the year ended 31 December 2020 were as
follows:
Revenue
Assurance
MDR
Vendor Products
Other
Total Revenue
Gross Profit
Assurance
MDR
Vendor Products
Other
Gross Profit
Operating Loss
Finance Cost
Loss before Taxation
Revenue by country for the year ended 31 December 2020 was as follows:
United Kingdom
Europe
United States
Channel Island
Middle East
Other Countries
Total
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
2,724
2,732
125
82
5,663
1,576
1,994
25
(47)
3,548
(271)
(48)
(319)
2,922
2,585
162
236
5,905
1,574
1,745
29
12
3,360
(704)
(46)
(750)
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
5,294
278
-
89
-
2
5,708
116
9
66
2
4
5,663
5,905
Page 79
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The Group’s United Kingdom revenue by operating segment for the year ended 31 December 2020 was as
follows:
Revenue United Kingdom
Assurance
MDR
Vendor Products
Other
Total
7. Other Income
Withholding Tax
Gain on sale of Asset
R&D Tax Credits
Total
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
2,367
2,724
124
79
5,294
2,760
2,580
144
224
5,708
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
-
4
293
297
-
1
262
263
A credit has been recognised within Other Income as a result of R&D Tax Credit surrenders. For the year ended 31 December 2020, the surrender
resulted in a credit of £212k relating to R&D undertaken in 2020, included within Corporation Tax Recoverable, and an additional credit received of
£81k for additional R&D expenditure relating to 2018.
Page 80
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
8. Operating Loss
Operating Loss is stated after charging:
Depreciation of Fixed Assets
Amortisation of Intangibles - Development Costs
Amortisation of leases
R&D expenditure
Short-term and low value lease expense
Auditors Remuneration - Audit Services
Auditors Remuneration - Non-Audit Services
Taxation Compliance Services
Other Taxation and Compliance Services
Exceptional items
Inventories Expensed
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
137
168
175
786
76
45
8
12
65
8
217
177
200
785
62
42
8
13
6
44
The amount charged in respect of Auditors’ Remuneration for the Group and the Company audit was £45k. None of the subsidiaries (see note
27) of the Group were subject to audit in the year ended 31 December 2020.
9. Employee Benefit Expense
Employee Benefit Expense (including Directors) during the periods amounted to:
Wages and Salaries - Gross
Government Grants
Wages and Salaries
Social Security Costs
Pension Contributions
Share Based Payments
GROUP
Year Ended
31 December
2020
£’000
GROUP
Year Ended
31 December
2019
£’000
COMPANY
Year Ended
31 December
2020
£’000
COMPANY
Year Ended
31 December
2019
£’000
4,269
(292)
3,977
452
179
101
4,709
4,091
-
4,091
440
153
105
4,789
4,033
(203)
3,830
404
161
101
4,496
3,944
-
3,944
392
134
105
4,575
Page 81
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Directors’ remuneration for the Group and Company is as follows:
Salaries, Bonus, Benefits-in-Kind
Pension Contributions
Share Based Payments
Social Security Costs
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
662
47
120
78
907
455
30
47
57
589
Details of Directors’ remuneration can be found in the Remuneration Report on pages 43-49.
Key management personnel, being those persons having responsibility for planning, directing and
controlling the activities of the Group, are considered to be the Directors listed on pages 35-36 (Board of
Directors).
Amounts paid to the highest paid director in the period were as follows:
Year ended
31 December
2020
£’000
219
20
239
Year ended
31 December
2019
£’000
196
18
214
Year ended
31 December
2020
Year ended
31 December
2019
6
81
87
4
81
85
Salaries, Bonus, Benefits-in-Kind
Pension Contributions
Group
The average monthly number of employees during the year was:
Directors
Operational
Page 82
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Company
The average monthly number of employees during the year was:
Directors
Operational
10. Taxation
Recognised in the Statement of Comprehensive Income
Corporation Tax (Credit) / Charge
Deferred Tax (Credit) / Charge
Total Tax (Credit) / Charge
Reconciliation of Total Tax (Credit)/Charge
Loss before Tax
UK Corporation At Rate Of 19.0% (2019: 19.0%)
Expenses Not Deductible For Tax Purposes
Over/Under Provision in Prior Period - Deferred Tax
Tax Losses on Which Deferred Tax Not Recognised
Total Tax (Credit) / Charge
Deferred Tax Assets & Liabilities
Deferred Tax Assets
Deferred Tax Liabilities
Deferred Tax - Net Asset/(Liability)
Year ended
31 December
2020
£’000
6
77
83
Year ended
31 December
2020
£’000
-
(50)
(50)
Year ended
31 December
2019
£’000
4
77
81
Year ended
31 December
2019
£’000
-
26
26
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
(319)
(61)
2
(50)
59
(50)
(750)
(143)
2
26
141
26
Year ended
31 December
2020
£’000
118
(90)
28
Year ended
31 December
2019
£’000
77
(99)
(22)
Page 83
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Deferred Tax Assets of £118K is recognised in respect of unutilised trading losses, Share Based Payments
and short-term timing differences. Deferred Tax Liabilities of £90k arise on timing differences in the carrying
value of certain of the Company’s assets for financial reporting purposes and for corporation tax purposes.
These will reverse as the fair value of the related assets are depreciated over time. Deferred Tax balances
have been calculated at the rate of 19%, being the rate of Corporation Tax expected to be in force when the
timing differences reverse.
Unutilised Trading Losses
The Company continues to carry forward unutilised trading losses of £5,111k (2019: £5,696k). A Deferred Tax
Asset of £35k (2019: £22k) has been recognised as at 31 December 2020 in respect of the unutilised trading
losses. No further Deferred Tax Asset has been recognised because the Board envisages that a significant
period of time will be required to generate sufficient profits to utilise the trading losses carried forward.
11. Earnings per Share
Basic Earnings per Share is calculated by dividing the loss for the period attributable to Equity Holders of the
Company by the weighted average number of Ordinary Shares outstanding during the period (‘Basic Number
of Ordinary Shares’).
Diluted Earnings per Share is calculated by dividing the loss for the period attributable to Equity Holders of
the Company by the weighted average number of Ordinary Shares outstanding during the period plus the
weighted average number of Ordinary Shares that would be issued on conversion of all the potential dilutive
Ordinary Shares (‘Diluted Number of Ordinary Shares’), subject to the effect of anti-dilutive potential shares
being ignored in accordance with IAS 33.
Adjusted Earnings per Share is calculated by dividing Adjusted loss (after adding-back exceptional costs
incurred in the period; see note 25) by Diluted Number of Ordinary Shares.
Page 84
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The calculation of Basic, Diluted and Adjusted Earnings per Share is as follows:
Net Loss Attributable To Equity Holders Of The Company
Add Back: Exceptional Costs
Add Back: Share Based Payments
Adjusted Loss
Number Of Ordinary Shares (‘000)
Initial Weighted Average
Shares Issued in April 2020
Basic Number Of Ordinary Shares
Weighted Average Dilutive Shares In Period
Diluted Number Of Ordinary Shares
Earnings Per Share (Pence):
Basic Losses Per Share
Diluted Losses Per Share**
Adjusted Losses Per Share
Year ended
31 December
2020
£’000
Year ended
31 December
2019
£’000
(269)
65
101
(103)
9,098
909
10,007
906
10,913
(2.7)
(2.7)
(1.0)
(776)
6
105
(665)
9,098
-
9,098
661
9,759
(8.5)
(8.5)
(7.3)
** In accordance with IAS 33, the effect of anti-dilutive potential shares has been ignored.
During the year ended 31 December 2020, the following dilutive events have occurred:
• On 17 April 2020, 909,091 ordinary shares were issued for £0.45m (net of expenses of £0.05m).
• On 21 August 2020, the Company granted options over 588,037 Ordinary Shares to selected employees,
including 144,758 to Director Lucy Sharp, 103,602 to Director Ian Castle and 64,651 to Director Gemma
Basharan, of which 587,107 remain outstanding as at 31 December 2020.
• On 28 August 2020, the Company granted options over 450,000 Ordinary Shares to selected employees,
including 100,000 to Director Ian Mann, 100,000 to Director Lucy Sharp, 80,000 to Director Ian Castle and
80,000 to Director Gemma Basharan, of which 450,000 remain outstanding as at 31 December 2020.
These dilutive events were taken into account in calculating Diluted Number of Ordinary Shares.
Page 85
ECSC Group plcAnnual Report Year Ended 31 December 2020£’000
891
194
1,085
1,085
194
1,279
479
177
656
656
168
824
429
455
Notes to the Financial Statements (continued)
12. Intangible Assets
GROUP & COMPANY
Development Costs
Costs
As at 1 January 2019
Additions
As at 31 December 2019
As at 1 January 2020
Additions
As at 31 December 2020
Amortisation
As at 1 January 2019
Charges for the year
As at 31 December 2019
As at 1 January 2020
Charges for the year
As at 31 December 2020
Net Book Value
As at 31 December 2019
As at 31 December 2020
Page 86
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
13. Property, Plant and Equipment
GROUP
Leasehold
Property
£’000
Office
Equipment
£’000
Computer
Equipment
£’000
Motor
Vehicles
£’000
Total
£’000
Cost
At 1 January 2019
Reclassification due to IFRS16
Additions
Disposals
At 31 December 2019
Additions
Disposals
At 31 December 2020
Depreciation
At 1 January 2019
Reclassification due to IFRS16
Charge for Period
Disposals
At 31 December 2019
Charge for Period
Disposals
At 31 December 2020
Net Book Value
At 31 December 2019
At 31 December 2020
103
-
12
-
115
-
-
115
48
-
15
-
63
16
-
79
52
36
120
-
16
-
136
-
-
136
50
-
25
-
75
21
-
96
61
40
639
(61)
101
-
679
5
(5)
679
370
(20)
168
-
518
95
(2)
611
161
68
57
-
-
(34)
23
-
-
23
24
-
9
(19)
14
5
-
19
9
4
919
(61)
129
(34)
953
5
(5)
953
492
(20)
217
(19)
670
137
(2)
805
283
148
Page 87
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
COMPANY
Cost
At 1 January 2019
Reclassification due to IFRS16
Additions
Disposals
At 31 December 2019
Additions
Disposals
At 31 December 2020
Depreciation
At 1 January 2019
Reclassification due to IFRS16
Charge for Period
Disposals
At 31 December 2019
Charge for Period
Disposals
At 31 December 2020
Net Book Value
At 31 December 2019
At 31 December 2020
14. Inventory
Leasehold
Property
£’000
Office
Equipment
£’000
Computer
Equipment
£’000
Motor
Vehicles
£’000
Total
£’000
103
-
12
-
115
-
-
115
48
-
15
-
63
16
-
79
52
36
99
-
15
-
114
-
-
114
41
-
17
-
58
18
-
76
56
38
604
(61)
101
-
644
5
(5)
644
352
(20)
157
-
489
88
(2)
575
155
69
57
-
-
(34)
23
-
-
23
24
-
9
(19)
14
5
-
19
9
4
863
(61)
128
(34)
896
5
(5)
896
465
(20)
198
(19)
624
127
(2)
749
272
147
Inventory
9
26
9
26
GROUP
Year Ended
31 December
2020
£’000
GROUP
As At
31 December
2019
£’000
COMPANY
Year Ended
31 December
2020
£’000
COMPANY
As At
31 December
2019
£’000
Page 88
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
15. Trade Receivables and Other Receivables
Trade Receivables - Gross
Allowance for Credit Losses
Trade Receivables
Other Receivables
Intercompany Receivables
Prepayments
Accrued Income
Contract Asset
GROUP
As At
31 December
2020
£’000
GROUP
As At
31 December
2019*
£’000
COMPANY
As At
31 December
2020
£’000
COMPANY
As At
31 December
2019*
£’000
613
(5)
608
9
-
159
1
34
811
653
-
653
8
-
182
4
43
890
613
(5)
608
9
98
137
1
34
887
653
-
653
8
92
160
4
43
960
*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of
comprehensive income for the Group or Company only financial statements.
The carrying amount of Trade Receivables and Other receivables approximates to their fair value.
Intercompany Receivables represent loans provided by ECSC Group plc to ECSC Australia Pty Ltd. The loans
are repayable on demand, no expected credit loss is attributed to them.
16. Cash & Cash Equivalents
Cash & Cash Equivalents
1,122
351
1,119
350
GROUP
As At
31 December
2020
£’000
GROUP
As At
31 December
2019
£’000
COMPANY
As At
31 December
2020
£’000
COMPANY
As At
31 December
2019
£’000
Page 89
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
17. Trade Payables and Other Payables
Trade Payables
Other Taxation and Social Security
Accruals
Contract Liabilities (Restated)
Intercompany Payables
Other Payables
GROUP
As At
31 December
2020
£’000
GROUP
As At
31 December
2019*
£’000
COMPANY
As At
31 December
2020
£’000
COMPANY
As At
31 December
2019*
£’000
146
823
207
878
-
31
197
436
259
866
-
59
146
821
206
878
86
26
195
434
258
866
72
54
2,085
1,817
2,163
1,879
*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of
comprehensive income for the Group or Company only financial statements.
The carrying amount of Trade Payables and Other Payables approximates to their fair value due to their short
term nature.
18. Leases
On commencement of a contract (or part of a contract) which gives the group the right to use an asset for a
period of time in exchange for consideration, the group recognises a right-of-use asset and a lease liability
unless the lease qualifies as a ‘short-term’ lease or a ‘low-value’ lease.
All leases are accounted for by recognising a right-of-use and a lease liability except for:
• Leases of low-value assets
Leases where the underlying asset is ‘low-value’, £5k lease payments are recognised as an expense on a
straight-line basis over the lease term. The group has elected to apply the ‘low-value’ lease exemption to all
qualifying leases, but the election can be made on a lease-by-lease basis.
• Short term lease
Where the lease term is twelve months or less and the lease does not contain an option to purchase the
leased asset, lease payments are recognised as an expense on a straight-line basis over the lease term.
The group sometimes negotiates break clauses in its property leases. On a case-by-case basis, the group
will consider whether the absence of a break clause would exposes the group to excessive risk. Typically
factors considered in deciding to negotiate a break clause include:
Page 90
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
the length of the lease term;
the economic stability of the environment in which the property is located; and
•
•
• whether the location represents a new area of operations for the group.
Right-of-use Assets
A right-of-use asset is recognised at commencement of the lease and initially measured at the amount of
the lease liability, plus any incremental costs of obtaining the lease and any lease payments made at or
before the leased asset is available for use by the group.
The right-of-use asset is subsequently measured at cost less accumulated amortisation and any
accumulated impairment losses. The amortisation methods applied is on a straight-line basis over the term
of the lease.
Amortisation charge for the year included in ‘administrative expenses’ for right-of-use assets.
Group
At 1 January 2019
Additions
Amortisation
NBV at 31 December 2019
At 1 January 2020
Additions
Variable Lease Payment Adjustment
Amortisation
NBV at 31 December 2020
Office
buildings
£’000
Motor
vehicles
£’000
IT
equipment
£’000
981
-
(132)
849
849
-
4
(133)
720
56
18
(48)
26
26
22
-
(22)
26
41
-
(20)
21
21
-
(1)
(20)
-
Total
£’000
1,078
18
(200)
896
896
22
3
(175)
746
Page 91
ECSC Group plcAnnual Report Year Ended 31 December 2020
Notes to the Financial Statements (continued)
Company
At 1 January 2019
Additions
Amortisation
NBV at 31 December 2019
At 1 January 2020
Additions
Variable Lease Payment Adjustment
Amortisation
NBV at 31 December 2020
Lease Liability
Office
buildings
£’000
Motor
vehicles
£’000
IT
equipment
£’000
902
-
(110)
792
792
-
4
(111)
685
56
18
(48)
26
26
22
-
(22)
26
41
-
(20)
21
21
-
(1)
(20)
-
Total
£’000
999
18
(178)
839
839
22
3
(153)
711
The lease liability is initially measured at the present value of the lease payments during the lease term
discounted using the interest rate implicit in the lease, or the incremental borrowing rate if the interest rate
implicit in the lease cannot be readily determined.
The lease term is the non-cancellable period of the lease plus extension periods that the group is reasonably
certain to exercise and termination periods that the group is reasonably certain not to exercise.
The lease liability is subsequently increased for a constant periodic rate of interest on the remaining balance
of the lease liability and reduced for lease payments.
Interest expense for the year on lease liabilities is recognised in ‘finance costs’.
Page 92
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Group
At 1 January 2019
Additions
Interest Expense
Lease Payments
At 31 December 2019
At 1 January 2020
Additions
Variable Lease Payment Adjustment
Interest Expense
Lease Payments
At 31 December 2020
Company
At 1 January 2019
Additions
Interest Expense
Lease Payments
At 31 December 2019
At 1 January 2020
Additions
Variable Lease Payment Adjustment
Interest Expense
Lease Payments
At 31 December 2020
Group and Company
• Short-term lease expense
• Low value lease expense
£73k
£3k
Office
buildings
£’000
Motor
vehicles
£’000
IT
equipment
£’000
968
-
42
(121)
889
889
-
4
37
(150)
780
55
18
3
(53)
23
23
22
-
2
(24)
23
40
-
-
(21)
19
19
-
(1)
2
(21)
(1)
Office
buildings
£’000
Motor
vehicles
£’000
IT
equipment
£’000
890
-
39
(99)
830
830
-
4
35
(127)
742
55
18
3
(53)
23
23
22
-
2
(24)
23
40
-
-
(21)
19
19
-
(1)
2
(21)
(1)
Total
£’000
1,063
18
45
(195)
931
931
22
3
41
(195)
802
Total
£’000
985
18
42
(173)
872
872
22
3
39
(172)
764
Page 93
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
At 31 December 2020
Lease Payments
Interest Expense
Lease Liabilities
19. Secured Facilities
Up To
12 months
£’000
176
(33)
143
1-5
years
£’000
446
(84)
362
more than
5 years
£’000
317
(20)
297
The Group has been provided with payments facilities by Barclays Bank PLC, including a BACS payment
facility and a credit card facility. Barclay’s are also providing an invoice discounting facility of £500,000. The
renewal date of the facility is August 2021, where the Board is expected to renew the facility with Barclay’s.
These payment facilities are secured by a debenture in favour of Barclays that creates fixed and floating
charges over the assets of the Company.
20. Share Capital
Ordinary Share Capital
During the period ended 31 December 2020, the movement in Share Capital was:
Ordinary Shares
As at 1 January 2019
Exercise of Share Options
At at 31 December 2019
As at 1 January 2020
New Shared Issued
At at 31 December 2020
Number of
Shares Issued
and Fully Paid
Ordinary Share
Capital
£’000
9,098,497
-
9,098,497
9,098,497
909,091
10,007,588
91
-
91
91
9
100
On 17 April 2020 909,091 ordinary shares were issued for £0.45m (net of expenses of £0.05m).
Share Premium Account
The balance of the Share Premium Account represents amounts received in excess of the nominal value (1
pence per share) of Ordinary Shares. This account is non-distributable.
Share Option Reserve
The balance of the Share Option Reserve represents the accumulated amounts charged to the Statement of
Comprehensive Income in respect of Share Based Payments. This reserve is non-distributable.
Page 94
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Retained Earnings
The balance of the Retained Earnings account represents the accumulated retained profits or losses of the
Group. This account is a distributable reserve, provided that the accumulated balance is positive.
21. Financial Instruments and Financial Risk Management
The Group’s and Company’s principal financial instruments comprise:
Intercompany Receivables
• Cash and Cash Equivalents
• Trade Receivables
• Other Receivables
•
• Trade Payables
• Accruals
•
• Other Payables
Intercompany Payables
The Group’s and Company’s accounting policies, including the criteria for recognition, and the basis on
which income and expenses are recognised in respect of each class of financial asset and financial liability,
are set out in note 4.14 to the financial statements. The information about the extent and nature of these
recognised financial instruments, including significant terms and conditions that may affect the amount,
timing and certainty of future cash flows, are disclosed in the respective notes where applicable. The Group
and Company does not use financial instruments for speculative purposes.
Page 95
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The principal financial instruments used by the Group and Company, from which financial instrument risk
arises, are as follows:
Financial Assets
Trade Receivables
Other Receivables
Intercompany Receivables
Cash and Cash Equivalents
Total Financial Assets
Financial Liabilities
Trade Payables
Accruals
Intercompany Payables
Other Payables
Total Financial Liabilities
GROUP
As At
31 December
2020
£’000
GROUP
As At
31 December
2019*
£’000
COMPANY
As At
31 December
2020
£’000
COMPANY
As At
31 December
2019*
£’000
608
9
-
1,122
1,739
146
207
-
31
384
653
8
-
351
1,012
197
259
-
59
515
608
9
98
1,119
1,834
146
206
86
26
464
653
8
92
350
1,103
195
258
72
54
579
*A prior year restatement of £320k is accounted for to remove trade receivables and contract liabilities in relation to amounts invoiced but not due
as at 31 December 2019 where the performance obligation had not commenced at that date. This restatement does not impact the statement of
comprehensive income for the Group or Company only financial statements.
Fair Values
The Directors have assessed that the fair values of Cash and Cash Equivalents, Trade Receivables, Trade
Payables, Other Payables approximate to their carrying amounts largely due to the short-term maturities of
these instruments. There are no fair value adjustments to assets or liabilities charged to the Statement of
Comprehensive Income.
Market Risk
Market risk is the risk that the fair value of future cash flows of a financial instrument will fluctuate due to
changes in market prices. Market risk comprises three types of risk – commodity price risk, interest rate
risk; and foreign currency risk. The Group and Company has limited exposure to each of these risks as
discussed below.
Capital Management
The Group and Company manages its capital to ensure that it will be able to continue as a going concern
while attempting to maximise the return to stakeholders through the optimisation of the debt and equity
structure.
Page 96
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The capital structure of the Group and Company consists of issued Share Capital, Retained Earnings and
Finance Leases.
The Group and Company do not generally enter into derivative transactions (such as interest rate swaps
and forward foreign currency contracts) and has been throughout the period covered by these financial
statements, the Group’s and Company’s policy that no trading in financial derivative instruments shall be
undertaken.
Credit Risk
Credit risk is the risk that a counterparty will cause a financial loss to the Group by failing to discharge its
obligations to the Group. The Group manages its exposure to this risk by applying limits to the amount of
credit exposure to any one counterparty and employs strict minimum credit worthiness criteria as to the
choice of counterparty. The maximum exposure to credit risk for receivables and other financial assets
is represented by their carrying amount. The Group considers credit risk to be low due to its processes
and the nature of its clients, which includes a broad spread of large corporates, SMEs and public sector
organisations.
The Group uses an expected credit loss model for impairment that represents its estimate of incurred losses
in respect of the Trade Receivables as appropriate.
The Group applies the IFRS 9 simplified approach to measure expected credit losses using a lifetime
expected credit loss provision for trade receivables and contract assets. The expected loss rates are based
on the Group’s historical credit losses experienced over the two year period prior to the period end.
The historical loss rates are then adjusted for current and forward-looking information on macroeconomic
factors affecting the Group’s customer. Under the expected credit loss model impairment allowance wasn’t
material resulting in no provision being made.
Trade Receivables
Trade Receivables, net of impairment provisions, for the Group and Company as at 31 December 2020 were
£608k (2019: £653k). These Trade Receivables are not secured by any collateral or credit insurance. The
Group’s standard terms are 30 days from date of invoice but non-standard terms may be agreed with certain
customers. Invoices which remain unpaid for periods greater than agreed terms are assessed as overdue.
As at 31 December 2020, Trade Receivables past due for the Group and Company total £196k (2019: £307k) of
which nil (2019: nil) have been impaired.
Page 97
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
As at 31 December 2020, Trade Receivables of £196k (2019: £307k) were past due but not impaired, as
follows:
GROUP
As At
31 December
2020
£’000
GROUP
As At
31 December
2019*
£’000
COMPANY
As At
31 December
2020
£’000
COMPANY
As At
31 December
2019*
£’000
196
-
-
196
305
2
-
307
196
-
-
196
305
2
-
307
Up to 3 months
3 months to 6 months
6 months to 12 months
Cash Holdings
The Group only holds cash at mainstream banking institutions to mitigate the credit risk on cash deposits.
The credit rating of the principal banking institution is A (Standard & Poor’s).
Interest Rate Risk
The Company’s exposure to changes in interest rates relates to Cash Holdings and Finance Leases.
Cash is held either on current or short term deposits at a floating rate of interest determined by the relevant
bank’s prevailing base rate.
Interest Rate Sensitivity
When reviewing sensitivity to movement in interest rates, it is noted that interest rates are at historically low
levels and that Cash balances significantly outweigh debt balances.
The Directors consider that any downward movement in interest rates would be immaterial to the Group. The
Directors consider that an upward movement in interest rates would benefit the Group, although the impact
of a 1% rise in interest rates would be immaterial.
Foreign Currency Exchange Risks
Foreign currency risk is the risk that the fair value or future cash flows of an exposure will fluctuate because
of the changes in foreign exchange rates. The Group’s exposure to the risk of changes in foreign exchange
rates relates primarily to the Group’s operating activities when revenue or expenses are denominated in a
foreign currency.
The Group does not hedge its foreign currencies. Transactions with customers are mainly denominated in
GBP.
Page 98
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
The Group has suppliers that invoice in US dollars and Australian dollars. The balances exposed to credit
risk at year end were as follows:
US Dollars
Australian Dollars
Liquidity Risks
As At
31 December
2020
000
As At
31 December
2019
000
-
3
3
-
1
1
Liquidity risk arises from the Group’s management of working capital. It is the risk that the Group will
encounter difficulty in meeting its financial obligations as they fall due. The Group’s policy is to ensure
that it will always have sufficient cash to allow it to meet its liabilities when they become due. Budgets
and forecasts are agreed and set by the Board in advance to ensure the Group’s cash requirement to be
anticipated.
The maturity profile of the Group’s financial liabilities at the reporting dates, based on contractual
undiscounted payments including lease payments, are summarised below:
Due within 3 months
Trade Payables, Other Taxation ans Social Security, Accruals, Other Payables
22. Related Party Transactions
ECSC Australia Pty Ltd
As At
31 December
2020
£’000
As At
31 December
2019
£’000
1,207
1,207
951
951
During the year ended 31 December 2020, ECSC Group plc incurred management fees to ECSC Australia
Pty Ltd of £204k (2019: £312k). As at 31 December 2020, the balance payable by ECSC Group plc to ECSC
Australia Pty Ltd in respect of outstanding management fees was £86k (2019: £72k).
As at 31 December 2020, the loan balance payable by ECSC Australia Pty Ltd to ECSC Group plc was £98k
(2019: £92k). The loan is repayable on demand and attracts interest at the rate of 3% over base rate.
Athene VCS Ltd
During the year ended 31 December 2019, Athene VCS a company owned by Elizabeth Gooch (Non-Executive
Page 99
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Director), invoiced ECSC Group plc £5k for a strategic review service. This transaction was entered into on an
arm’s length basis. The balance payable as at 31 December 2020 was £nil (2019: nil)
Expandly
During the year ended 31 December 2020, ECSC Group plc invoiced Expandly £5k a company that Elizabeth
Gooch (Non-Executive Director) is a Director of, for consultancy work. This transaction was entered into on
an arm’s length basis. The balance payable as at 31 December 2020 was £nil (2019: nil)
23. Share Based Payments
Share Based Payment Schemes
The Company operates a number of equity-settled Share Based Payment schemes, as follows:
• Enterprise Management Incentive (‘EMI’) Scheme
• Save As You Earn (‘SAYE’) Share Option Scheme
• Non-Executive Director Remuneration Scheme (‘NED Scheme’)
• Non-Executive Directors Share Options (‘NED1 Scheme’)
EMI Scheme
On 04 February 2020 the Company granted over 65,000 Ordinary Shares at an exercise price of 108 pence per
share, subject to a three year vesting period to the following Directors:
Lucy Sharp
Ian Castle
Gemma Basharan
Ordinary Shares
25,000
20,000
20,000
In order for the options to vest, Ordinary Shares must trade at a minimum mid-market price 200 pence per
share over 30 consecutive trading days during the vesting period.
During the year ended 31 December 2020, option over 65,000 Ordinary Shares were cancelled.
Page 100
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
On 21 August 2020 the Company cancelled options over 588,040 Ordinary Shares in the Company as set out
below.
EMI Grant Date
May-17
Dec-17
Aug-18
Jul-19
Feb-20
TOTAL
Exercise
Price
(pence)
Cancelled
Ordinary
Shares
167
140
93
78
108
152,540
25,000
170,000
175,500
65,000
588,040
Following the above cancellation of Ordinary Shares options, on 21 August 2020, the Company granted
options over 588,040 new Ordinary Shares to the same Company employees, at an exercise price of 65 pence
per share. In order for the new Options to vest and become exercisable at any time over a ten-year period
from the date of grant subject to the Company’s closing mid-market price exceeding 167 pence per Ordinary
Share for 10 consecutive business days.
Within the grant the following Directors of the Company were granted the following Ordinary Shares:
Lucy Sharp
Ian Castle
Gemma Basharan
Ordinary Shares
144,758
103,602
64,651
During the year ended 31 December 2020, options over 933 Ordinary Shares have lapsed, such that options
over 587,107 Ordinary Shares remain exercisable in the future.
On 28 August 2020 the Company granted over 450,000 new Ordinary Shares in the Company at an exercise
price of 69 pence per share. Over 95,000 Ordinary Share options were granted to Employees and become
exercisable one year from the date of grant, subject to the Company’s closing mid-market share price
exceeding 167 pence for 10 consecutive business days. All Options expire on the tenth anniversary of the date
of grant.
Page 101
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Within the grant the following Directors of the Company were granted the following Ordinary Shares:
Ian Mann
Lucy Sharp
Ian Castle
Gemma Basharan
Ordinary Shares
100,000
100,000
80,000
80,000
The Director Options are exercisable from the relevant vesting date, subject to the Company’s closing mid-
market share price exceeding certain targets for 10 consecutive business days, being 167 pence for the first
vesting period, 200p for the second vesting period, 225 pence for the third vesting period and 250 pence for
the final vesting period.
None have lapsed by the year 31 December 2020, such that options over 450,000 Ordinary Shares remain
exercisable in the future.
Page 102
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Exercised during the year
Expired during the year
Outstanding at 31 December 2020
Option Pricing Assumptions:
Pricing Model
Weighted Average share price at
grant date (pence)
Weighted average exercise price
(pence)
Notes to the Financial Statements (continued)
Scheme
Number of Options:
EMI
(May-17)
EMI
(Dec’17)
EMI
(Aug’18)
EMI
(Jul’19)
EMI
(Feb 20)
EMI
(Aug 20)
EMI
(Sep 20)
SAYE
NED
NED 1
(Apr’18)
Total
Outstanding at 01 January 2019
174,490
25,000
180,000
-
Granted during the year
Forfeited during the year
Exercised during the year
Expired during the year
-
(21,950)
-
-
-
-
-
-
-
175,500
(10,000)
-
-
-
-
-
Outstanding at 31 December 2019
152,540
25,000
170,000
175,500
Exercisable at 31 December 2019
-
-
-
-
Outstanding at 01 January 2020
152,540
25,000
170,000
175,500
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
Granted during the year
-
-
-
-
65,000
588,040
450,000
Forfeited during the year
(152,540)
(25,000)
(170,000)
(175,000)
(65,000)
(933)
26,784
6,411
200,000
612,685
-
(7,200)
-
-
-
-
-
-
-
-
-
-
175,500
(39,150)
-
-
19,584
6,411
200,000
749,035
-
19,584
6,411
6,411
-
6,411
200,000
749,035
-
-
-
(19,584)
-
-
-
-
-
-
-
-
1,103,040
(588,973)
-
(19,584)
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
587,107
450,000
-
6,411
200,000
1,243,518
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
Black
Scholes
312
167
135
140
93
93
78
78
108
108
65
65
69
69
131
125
125
-
79
78
Weighted Average contract life
3 years
3 years
3 years
3 years
3 years
10 years
10 years
3 years
0 years
3 years
Weighted Average risk free rate
Volatility
Option Valuation:
Option Valuation at grant date
(£’000)
Share Based Payments Charge
in 2020:
Share Based Payment Charge
(£’000)
Weighted Average Exercise Price:
At grant date, forfeit date and end
of period (pence)
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
1%
40%
-
30
-
-
3
-
-
-
15
13
-
-
-
6
-
190
155
-
-
65
24
69
(5)
-
8
-
-
45
398
15
101
78
Page 103
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
Share Based Payment Charge
In accordance with the requirements of IFRS 2, the Company calculated the fair value of the share options
at the date of grant using a Black Scholes option pricing model for the EMI and SAYE Schemes. For the NED
scheme, the fair value of the services rendered was assessed.
A Share Based Payment charge is recognised by spreading the fair value of the option over the maturity
period, with allowance made for options that have lapsed in the period.
The movement in the number of options during the year, the option pricing assumptions, the option valuation
at the grant date and the Share Based Payment Charge in the year, for each scheme described above, is as
follows:
The volatility assumption, calculated at the standard deviation of expected share price returns, is based on
analysis of the share prices of comparable companies over the last 3-5 years.
Modification treatment
In accordance with the requirements of IFRS 2, the Company adopted the modification treatment with
regards to the cancellation and replacement of options. This resulted in no incremental fair value being
recognised as the fair value at the grant date of the replacement options was lower than the fair value
of the cancelled options. The cancelled options continue to be charged to the Consolidated Statement of
Comprehensive Income over the remaining vesting period.
24. Controlling Party
ECSC Group plc does not have an ultimate controlling party.
Page 104
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
25. Adjusted Loss before Taxation and Adjusted EBITDA
Adjusted Loss before Taxation
Loss Before Taxation
Share Based Payments
Exceptional Items
Adjusted Loss Before Taxation
Adjusted EBITDA:
Operating Loss
Depreciation and Amortisation
EBITDA**
Share Based Payments
Exceptional Items
Adjusted EBITDA*
Operating Loss
Share Based Payments
Exceptional Items
Adjusted Operating Loss*
* Adjusted Operating Loss and EBITDA excludes one-off charges and share based charges.
* * EBITDA is defined as Earnings before Interest, Tax, Depreciation and Amortisation.
Year Ended
31 December
2020
£’000
Year Ended
31 December
2019
£’000
(319)
101
65
(153)
(750)
105
6
(639)
Year Ended
31 December
2020
£’000
Year Ended
31 December
2019
£’000
(271)
480
209
101
65
375
(704)
594
(110)
105
6
1
Year Ended
31 December
2020
£’000
Year Ended
31 December
2019
£’000
(271)
101
65
(105)
(704)
105
6
(593)
Page 105
ECSC Group plcAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
26. Exceptional Costs
During the year ended 31 December 2020, the Company undertook a restructure exercise to reduce its
operating costs due to the effect of COVID-19 on consultancy revenues. In achieving these recurring
cost savings, a number of one-off, exceptional costs were incurred, including payments in lieu of notice
and redundancy payments. These Exceptional Costs totalled £65k and were charged to the Statement of
Comprehensive Income in the year ended 31 December 2020.
Exceptional Costs are analysed as follows:
Payments in Lieu of Notice
Redundancy Payments
Employee Benefit Expense
Taxation & Social Security Costs
Staff Related Costs
Legal Costs
Exceptional Costs
As At
31 December
2020
£’000
As At
31 December
2019
£’000
46
7
53
8
61
4
65
-
-
-
-
-
6
6
Page 106
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020Notes to the Financial Statements (continued)
27. Subsidiary Undertakings
ECSC Group plc currently has the following wholly-owned subsidiaries, which are incorporated and
registered in England and Wales:
Name of Subsidiary
Registered Office
Date of Incorporation
Principal Activity
ECSC Services Limited
ECSC Labs Limited
ECSC Australia Limited
28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR
28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR
28 Campus Road
Listerhills Science Park
Bradford
BD7 1HR
18 April 2017
Dormant
18 April 2017
Dormant
29 September 2016
Intermediary holding company
ECSC Australia Limited currently has the following wholly-owned subsidiary, which is incorporated and
registered in Australia:
Name of Subsidiary
Registered Office
Date of Incorporation
Principal Activity
ECSC Australia Pty Limited
Governor Phillip Tower
Level 36
1 Farrer Place
Sydney
NSW 2000
The share capital of each Group entity is as follows:
20 March 2017
Provision of professional cyber
security services
Entity
Ordinary Shares In Issue
Nominal Value
Investment At Cost
ECSC Services Limited
ECSC Labs Limited
ECSC Australia Limited
ECSC Australia Pty Limited
Total
*AUD = Australian Dollars
1 share
1 share
1 share
100 shares
£1
£1
£1
AUD 1
£1
£1
£1
AUD 100
£60
Page 107
ECSC Group plcAnnual Report Year Ended 31 December 2020Who would have believed we would ever get to this point! I know it is silly, but I am sat here
with a huge smile on my face for once!
[ECSC Employee] has just left for his train - and I am the only person in the office to know the
news!
Thanks very much - we’ve a few to go yet, but the support we have had on this long slog has
been first class!
Compliance Manager, Major Train Operator
[ECSC Employee] was extremely helpful and helped us through the certification procedures
and what would be required and expected. However, [ECSC Employee] went over and above at
each opportunity, offering up suggestions on up-skilling our in house teams and gave tips on
things to look out for and improve upon.
[ECSC Employee] ensured he was on hand at all times throughout the process, offering up
several communication methods, and helped us work through issues working with a third
party to ensure we completed the requirement in time to help us achieve certification.
ECSCs professional services have gone over and above expectations. [ECSC Employee] is a
true asset to the company, and I would be more than happy to work with him again on our next
project.
Security and Infrastructure Analyst, Online Retailer
I’ve got to say what a great piece of work your team have produced - really impressed with the
quality of the document and the people.
I am confident that this will be the start of a long and illustrious relationship with [ECSC
Client].
Senior Support Analyst, Major Utilities Supplier
Page 108
Cyber Security ExpertsAnnual Report Year Ended 31 December 2020