cyber.law
Supreme OS · Vertical #22

cyber.law

AI-native UK cyber compliance. Cyber Essentials self-assessment, IASME certification routing, breach response, and recertification — at £29/month.

~30k
Cyber Essentials certifications/yr
PPN 09/14
CE required for HMG contracts
5.5m
UK businesses in scope
85%
Stack reuse
£5,800
4-week build
78×
Y1 return multiple
Documents
📊
Strategy
Market thesis · CE mandate landscape · GTM · revenue model · exit comparables
🔧
Tech Reuse Blueprint
85% reuse audit · net-new build spec · 4-week plan
📐
Product Spec
User journeys · feature spec · DB schema · API surface
📅
Build Plan
4-week sprint · £5,800 budget · resource plan · risk register
🌐
Landing Page
Customer-facing site · free CE readiness check · 3 pricing tiers
🤖
Claude Project Setup
Project instructions + 7 India team prompts for daily ops
Runtime Dashboard
Operational view · deployment surface · module health
📦
Developer Pack
Snap modules · n8n · templates · SQL · railway · manifest
Vertical Status
Status
Pre-Launch
Target: Q2 2027
Build Cost
£5,800
4 weeks · 85% reuse
Y1 Revenue Target
£452k
Mixed subs + cert pass-through
Return Multiple
78×
Y1 revenue ÷ build cost
Exit Zone
£40–80m
Y5–7 · 8–15× ARR
Primary Channel
Zero-CAC
gdpr.law + form.law cross-sell
Snap-Tool Architecture (85% reuse)
gdpr.law
Article 32 Engine
85%
Cyber + GDPR overlap is structural · ICO enforcement context shared
form.law
New-Co Trigger
95%
Month-6 cyber audit prompt · first enterprise tender moment
employ.law
Staff Awareness
70%
Phishing simulation · awareness training records · User Access Control evidence
pension.law
Recert Cron
65%
Annual CE recertification cycle · same pattern, 12-month window
apex saas
Document Factory
80%
Cyber policy pack · BYOD · acceptable use · incident response
supreme capital
Cyber Insurance
100%
Cyber insurance referral · CE-certified attracts materially better premiums
Session Rules
  1. Self-assessment first. Every customer journey opens with the guided IASME 54-question Cyber Essentials self-assessment. Trust precedes premium.
  2. IASME is the assessor — we are not. Never imply cyber.law issues certifications. We prepare, route, and stamp — IASME's approved assessors certify.
  3. Article 32 framing wherever possible. UK GDPR Article 32 is the regulatory hook for every cyber control.
  4. Vulnerability scanning is orchestrated, not built. Route through NCSC-approved partners; don't roll our own.
  5. Breach response is regulated-adjacent. ICO 72-hour notification + insurance disclosure must be paired with Supreme Capital and gdpr.law. trained QA reviewer mandatory.
  6. trained QA reviewer on every CE submission. IASME acceptance rate is the KPI.
  7. gdpr.law cross-sell at every breach signal. Cyber events almost always trigger GDPR consequences.
  8. form.law month-6 trigger. First enterprise tender = highest-intent moment. Wire to that, not to schedule.