Venture capital · Start-ups · Boards

Technical judgement for investors, founders and boards.

OctoWorks is the advisory practice of Lawrence Munro, a serving Chief Information Security Officer with more than twenty years in cyber security. It gives investors an independent view of the technology behind a deal, helps early-stage companies with strategy, product and governance, and brings operational security experience to the boardroom.

Advisory

Three ways OctoWorks helps

Each engagement is built around a decision you need to make: whether to invest, what to build next, or how much cyber risk your organisation is carrying. The work is delivered personally by Lawrence, drawing on two decades of offensive security, security leadership and board reporting.

For venture capital

Scientific and technical advisory

Early-stage cyber security companies are difficult to assess from the outside. A pitch can describe capability that has not yet been built, and market sizing often rests on threat statistics that do not survive scrutiny. OctoWorks gives your investment team an independent, evidence-led view of the technology, the team's ability to deliver it and the risks that sit between the two.

Typical work

  • Technical and commercial due diligence on early-stage companies, from pre-seed onwards
  • Testing founder claims against working product, architecture and evidence
  • Checking the market and threat data behind an investment case against primary sources
  • Structured founder sessions, written up as a clear investment memo
  • Ongoing scientific advisory to the fund and support for portfolio companies

Track record Scientific Advisor to Osney Capital, a UK venture capital firm specialising in early-stage cyber security, since 2020. Member of the advisory board of Hetz Ventures, an Israeli venture capital firm backing seed-stage start-ups. Technical and commercial due diligence for a range of other European and US investment firms. Expert advisor and evaluator for NATO DIANA, assessing defence and security innovation against strategic and technical criteria.

For founders

Start-up advisory

Security products are bought by sceptical, technical buyers who have heard most claims before. Lawrence has sat on each side of that table. He spent many years as a penetration tester, attacking products to find where they break. As a CISO, currently at a fintech unicorn, he is the buyer your product has to convince. He has also built from the inside: as CTO of Reliance Cyber, a start-up, and as VP of Innovation at NCC Group, where he ran product and engineering teams. OctoWorks brings those views together to help you build a product and a proposition that hold up under scrutiny.

Typical work

  • Product strategy and roadmap challenge from the buyer's side of the table
  • Positioning, go-to-market and pricing for security products and services
  • Preparation for fundraising, including readiness for technical due diligence
  • Governance and advisory board support as the company grows
  • Introductions across the UK cyber security, investor and public-sector community

Track record Member of the start-up advisory board of Lupovis since 2024. Previously CTO at Reliance Cyber, VP of Innovation at NCC Group, and Global Vice President of Trustwave SpiderLabs, a 200-plus person consulting and research organisation across 16 countries.

For boards

Cyber security non-executive roles

Boards are accountable for cyber risk, and the UK Government's Cyber Governance Code of Practice, published in April 2025, sets out the actions directors are expected to take. Meeting those expectations is easier with someone at the table who manages cyber risk every day and understands how boards and their committees work. OctoWorks provides that experience in a non-executive or advisory capacity, with constructive challenge on cyber risk, resilience and technology strategy.

Typical work

  • Non-executive director and board advisor roles
  • Audit and risk committee membership with a cyber security focus
  • Independent challenge on security strategy, investment and incident readiness
  • Board briefings on the threat landscape, AI security and regulation
  • Assurance against the Cyber Governance Code of Practice

Track record Former Trustee and Director of Security B-Sides London. Former elected Executive Board member of CREST, the not-for-profit accreditation body for the technical security industry, and member of its Audit & Risk Committee. As a serving CISO, Lawrence manages enterprise risk day to day and has extensive experience of reporting to, and serving on, audit and risk committees.

Approach

How the work is done

  • Evidence over assertion

    Claims are tested against working product, primary sources and data. Where something cannot be verified, the write-up says so plainly rather than filling the gap.

  • A practitioner's view

    The advice comes from someone who has tested systems, built security teams and reported to boards, so it reflects how controls and people behave in practice.

  • Independent

    Advice is independent of vendors, and any potential conflict of interest is declared before work begins.

  • Confidential by default

    Investment, product and board discussions stay confidential, with non-disclosure agreements in place wherever you need them.

Due diligence

What a diligence engagement looks like

Timelines are agreed at the outset to fit your investment committee. A typical engagement runs in four steps.

  1. Scope

    Agree the questions that matter to the investment decision, the materials available and the deadline.

  2. Review

    Assess the product, architecture, team and roadmap, and check market and threat claims against primary sources.

  3. Founder session

    Test the assumptions directly with the founders through structured questions, and close the gaps found in review.

  4. Memo

    Receive a written assessment with a clear view of strengths, risks and the questions to carry into the next round.

Clients

Clients and references

A selection of current engagements. References appear here once each client has approved the wording.

Venture capital

Osney Capital

Scientific Advisor since 2020

A sector specialist venture capital firm investing in early-stage cyber security companies in the UK. The role brings an independent perspective on technology, risk and responsible innovation to prospective investments and the portfolio.

Awaiting approval

Reference from Osney Capital to be added once the wording is approved.

Name, role, Osney Capital

Venture capital

Coming soon

Details to follow

A new client engagement will be added here soon.

Coming soon

A reference will be added here once the wording is approved.

Name, role, organisation

Start-up

Lupovis

Start-up Advisory Board since 2024

A Glasgow-based cyber security company that turns real attacker activity into threat intelligence for security teams. The role covers strategy, product and governance, with constructive challenge on growth and risk.

Awaiting approval

Reference from Lupovis to be added once the wording is approved.

Name, role, Lupovis

About

Lawrence Munro

Chief Information Security Officer, scientific advisor and board advisor

Lawrence Munro has worked in cyber security for more than twenty years, across high-growth technology, fintech, banking and public companies. He is currently Chief Information Security Officer at Tide, accountable for cyber security strategy and security engineering across the UK, France, Germany and India, and also leads the business's IT and AI strategy.

His security career began in penetration testing and red teaming. He went on to lead KPMG's UK Cyber Defence Services and then Trustwave SpiderLabs, a 200-plus person technical consulting and research organisation across 16 countries, where revenue grew by 20 to 30 per cent a year to reach $40m. He later led the Cyber Threat Unit at Santander UK, was VP of Innovation and then Group CISO at NCC Group, and CTO at Reliance Cyber.

Alongside executive roles, he advises investors, founders and government. He has been Scientific Advisor to Osney Capital since 2020, sits on the advisory board of Hetz Ventures and the start-up advisory board of Lupovis, and is an expert advisor and evaluator for NATO DIANA. He served on the UK Government's College of Experts for DSIT and DCMS. He is a former Executive Board member of CREST and a former trustee and director of Security B-Sides London, and has presented at leading international security conferences, including Black Hat USA.

Contact

Discuss an engagement

Email a short outline of what you need, with your timeline and any fixed dates, such as an investment committee. Enquiries go directly to Lawrence.

Email

Elsewhere

This site is deliberately simple: static pages, with no cookies, analytics, forms or third-party scripts.