For boards, CISOs and C-suites under growing scrutiny

About Loopli

Straight-talking security, compliance and resilience – designed around how your business actually runs.
One operating model for cyber, compliance and resilience.
CEO

Who we are

Loopli is an information and cyber security advisory firm that helps organisations turn messy controls and obligations into a calm, predictable operating model. Loopli is built on over 20 years' frontline experience from its founder, Owen Jones, designing, running and proving security across healthcare, financial services, critical infrastructure,
public sector and fast-growth technology – now multiplied by a wider team with deep domain expertise.
Loopli exists because we've seen too many organisations spend heavily on tools while boards still lack a clear, defendable story about how security and resilience are being run.

Our OSbD (Organisational Security by Design) methodology combines:

A single view of your obligations and risks,

A practical control and evidence framework,

and a realistic plan to operate and improve it over time.

"Security should be calmer, not louder."

– Owen Jones

Leadership

Owen Jones

Founder & CEO

Owen is a senior technology and security leader with over two decades’ experience building and running security, risk and resilience capabilities in complex environments – from national-scale healthcare systems to global IoT providers.

Career highlights

  • Led security and resilience programmes across organisations with multi-billion-pound revenues and national-scale critical systems.
  • Built and managed large matrix teams of security, infrastructure and operations specialists.
  • Worked directly with boards, government bodies and regulators on cyber, resilience and assurance.

Loopli is the vehicle for taking that experience – and the OSbD model he’s refined over many years – to organisations that need pragmatic, high-standards security without the big-4 overhead.

Social Media

Our team

OSbD , strategy & client leadership

Behind OSbD is a team that’s spent decades actually running security, risk, resilience and large-scale change in complex organisations – not just advising from the sidelines. We’ve built Loopli so you get board-grade thinking, hands-on delivery experience and reliable programme execution in the same room. You won’t meet everyone on day one, but they’re the bench we draw on as your operating model takes shape and matures.

OSbD, strategy & client leadership

Owen Jones

Owen Jones

Founder & CEO

20+ years operating ... 20+ years operating at IT Director/CISO level, leading security, risk and resilience across national healthcare, IoT and regulated services. Owen is the principal architect of Loopli’s OSbD™ (Organisational Security by Design) operating model and leads executive and board engagement, acting as a board-facing cyber and internal controls advisor for leadership teams preparing for Provision 29-style declarations. He also owns SecureROI™, working with CEOs and CFOs to align security, resilience and cloud spend with clear outcomes, risk reduction and measurable value, and he regularly leads supplier and third-party risk operating-model work – aligning SaaS and supply-chain controls with OSbD™ and the assurance and evidence patterns internal audit and external reviewers expect.

John-Paul France

John-Paul France

Principal Consultant – Business Transformation & Go-to-Market

Enterprise transform... Enterprise transformation and go-to-market consultant with delivery leadership across strategy, execution and stabilisation. John-Paul focuses on making sure OSbD™ and SecureROI™ changes land cleanly in the business – aligning stakeholders, operating models, culture and commercial priorities so security, risk and resilience support growth instead of getting in the way.

Andy Rodger

Andy Rodger

Principal Consultant, Cloud & Security Platforms

Cloud and security p... Cloud and security platforms specialist with extensive experience helping organisations get meaningful value from SIEM, XDR and managed detection and response, while keeping architectures practical and cost-aware. Andy focuses on turning complex, multi-vendor cloud and security estates into a coherent, monitorable and auditable platform layer that plugs cleanly into your OSbD™ operating model – across Microsoft and other strategic platforms – always from a vendor-agnostic, operating-model perspective rather than a product quota.

Justin Leal

Justin Leal

Chief Growth Officer – Middle East & North Africa

Leads Loopli’s regio... Leads Loopli’s regional presence across MENA, focusing on partnerships, client success and market expansion where regulatory and resilience expectations are rapidly evolving.

Programme delivery, transformation & resilience

Mark Jones

Mark Jones

Lead Technical Consultant – Infrastructure & Service Delivery

30+ years as a senio... 30+ years as a senior IT manager and professional services lead; specialises in turning roadmap decisions into practical, well-run technical workstreams across infrastructure, platforms and services.

Gary Quigley

Gary Quigley

Senior Delivery Manager – Security & Resilience Programmes

Coordinates multi-te... Coordinates multi-team technology initiatives with strong planning, risk management and stakeholder alignment – keeping OSbD™ and SecureROI™ programmes predictable rather than heroic.

Operations, PMO & consistency

Maria Truman

Maria Truman

Head of PMO

10+ years delivering... 10+ years delivering bespoke and transformation infotech projects; shapes Loopli’s PMO practices so programmes run to agreed scope, cadence and quality.

Andrea Matyszczyk

Andrea Matyszczyk

Head of Operations & Service Quality

25+ years in senior ... 25+ years in senior business and operations management; ensures we have the right people, processes and tooling behind the scenes so delivery feels calm, reliable and consistent on your side.

Governance, risk & assurance

Danette Copestake

Danette Copestake

Head of Digital Governance & Assurance

Fractional CIO and d... Fractional CIO and digital transformation adviser with deep experience in cloud, automation, data and GenAI across large enterprises and financial services. Danette owns Loopli’s GRC and assurance thinking at enterprise operating-model level – spanning enterprise risk and internal control frameworks, data protection, privacy-by-design, Provision 29-style effectiveness declarations, AI governance and ethical risk, and designing the assurance and evidence patterns internal audit and external reviewers expect. She works alongside client DPOs and legal/privacy counsel to make sure OSbD decisions and AI initiatives align with your formal data protection obligations. She focuses on making sure your OSbD controls, audits, standards, supplier and third-party arrangements, and AI initiatives form a joined-up governance story that stands up to executive, regulator and insurer scrutiny.

Revenue & client engagement

Peter Russell

Peter Russell

Sales & Go-to-Market Consultant

Sales and go-to-mark... Sales and go-to-market practitioner who supports revenue growth, partnerships and sales operations – helping us have the right conversations with the right people in your organisation, and ensuring engagements start with clear expectations on both sides.

How This Shows Up in Your Engagement

On any given engagement, you'll work with a small, senior core team – typically combining OSbD and SecureROI strategy (Owen and/or John-Paul), digital governance and assurance (Danette), cloud and security platforms (Andy), and delivery/PMO leadership (for example Gary and Maria) – with additional specialists drawn in as needed for infrastructure, data, partnerships, or specific regions.

We turn this into a small set of OSbD metrics and board-ready dashboards so your leadership can actually see how controls are operating over time.

For you, that means:

Board-level credibility when it matters – from people who have sat in or alongside equivalent seats.

Hands-on experience of ISO 27001, BC/DR, GRC, data protection, AI governance and large-scale technology programmes, not just theoretical mappings.

Fluent in risk, audit and assurance language – so internal audit, risk and external reviewers see a coherent, evidence-backed control story, not a parallel universe run by IT.

Consistent delivery discipline so OSbD and SecureROI work feels structured, predictable and sustainable – not like another big-bang project.

How We Work With You

We don't do black-box assessments or throw hundred-page PDFs over the fence.

Listen first

We start with your strategy, constraints, outages, near misses and stakeholder pressures.

Co-design the operating model

We agree a control and evidence framework that's appropriate for your size, sector and risk profile.

Prioritise what truly moves risk

We focus on the changes that genuinely reduce risk and friction, not just those that look good in a tool.

Embed ownership and routines

We help you integrate responsibilities and rhythms so security and compliance become part of how you operate, not a parallel universe.

Operate, measure, improve

We help you integrate responsibilities and rhythms so security and compliance become part of how you operate, not a parallel universe.

What we stand for

Our goal isn’t to scrape through an audit. Compliance is necessary but not sufficient. We aim for resilient operations that can withstand real-world attacks and scrutiny – and then we make sure you can demonstrate that.

About Us

What makes Loopli different

Not another SOC or tool

We don’t sell a SIEM, SOC or MDR platform. We sit above your tools and suppliers as the governance and evidence engine that makes them worth the money.

More than a vCISO

This isn’t a single advisor on a retainer. OSbD gives you an operating model – roles, controls, evidence and rhythms – that outlives any one individual.

UK & EU governance-first

We’re built around the Cyber Governance Code, Provision 29, Cyber Essentials/+, NIS2, DORA and CAF. We know what boards, regulators and insurers are starting to expect – and we design with that in mind.

Economics built-in

SecureROI connects risk and controls to spend. We help you keep and tune what works, and retire or right-size what doesn’t.

Tool- and vendor-agnostic

We’re happy to work alongside your existing MSPs, MDR/SOC providers and technology stack. Our only agenda is a coherent, effective operating model.

In practice, this means:

We'll challenge and coordinate your existing vendors rather than pushing you to rip-and-replace.

We'll join key risk and audit conversations when it matters, but we won't drown you in decks.

We'll help you simplify control sets before we suggest adding anything new.

Typical SOC/MDR/compliance factory

  • Tickets and dashboards
  • Siloed reports
  • Tool-led approach
  • Limited board-level visibility
  • Operating model
  • Governance framework
  • Evidence-based approach
  • Board-ready reporting
What you get from the Baseline:
1
board ready summary
board- and exec-ready summary of your cyber and resilience posture.
2
control and evidence
material control and evidence register you can build on for Provision 29 and audits.
3
90-day action plan
A pragmatic 90-day action plan, with owners and priorities.
4
recommended mix of:
  • Loopli programmes (your 7 core services),
  • internal work, and
  • supplier changes.
Board Ready Summary
Board & C-suite Clarity, accountability and a defendable position.
CIO/CISO & IT leadership Fewer scatter-gun projects, more joined-up control.
Risk, audit & compliance leaders An operating model that lines up with your frameworks.

Let's talk about where you are today

If you're not sure whether you need a full operating model reset, a focused programme, or just better visibility, a short conversation usually makes it clear.

Most new engagements start with an OSbD Baseline so we can give you a defendable, board-grade view of your current position.

Book an introductory call