# Culture Gem > Cybersecurity consultancy founded by Jemma Davis. We embed security into how organisations work — through culture change, behaviour science, and trusted relationships. Direct or white-label. Culture Gem partners with NHS bodies, financial services, critical infrastructure, retail, public sector, manufacturing, utilities and professional services across the UK. Specialisms include security culture and behaviour change, cyber transformation and recovery, fractional / virtual CISO leadership, incident response, awareness and training, and decision-making under pressure. ## Pages - [Home](/): Overview of Culture Gem's approach to people-first cybersecurity. - [About](/about): Background on founder Jemma Davis and the consultancy's story. - [Services](/services): Full list of cybersecurity consultancy services. - [Case Studies](/case-studies): Real-world engagements across multiple sectors. - [Partners](/partners): White-label and reseller partner programme. - [Contact](/contact): Scope a tailored cybersecurity engagement. ## Services - [Security Culture & Behaviour](/services/security-compliance): Behaviour-led security awareness, neurodiverse-adaptive content, culture assessments. - [Cyber Transformation & Recovery](/services/offensive-defensive): Post-incident recovery, NIST maturity uplift, OT/IT governance alignment. - [Security Leadership (vCISO)](/services/vciso): Fractional CISO leadership, strategy, board-level reporting. - [Tabletop & Crisis Simulations](/services/tabletop-exercises): Executive cyber crisis simulations and tabletop exercises. - [Decision-Making Under Pressure](/services/decision-making): Live, DIY and bespoke programmes to improve decisions under cyber pressure. - [Accessibility & Security](/services/accessibility-security): Inclusive security strategy and accessible controls (WCAG / EAA). - [Managed Detection & Response](/services/soc): 24/7 human-led SOC and incident response. - [Offensive Security](/services/offensive-security): Pen testing, red team and continuous assurance. - [Security Compliance](/services/security-compliance): Cyber Essentials, ISO 27001 and regulatory alignment. - [Assessments](/services/assessments): Security posture and maturity assessments. ## Case Studies - [Ardagh Group](/case-studies/ardagh-group): Post-incident cyber transformation across 16 countries. - [Holland & Barrett](/case-studies/holland-barrett): Security culture programme in retail. - [NHS Test and Trace](/case-studies/nhs-test-and-trace): Security leadership for a national programme at pace. - [Photobox](/case-studies/photobox): Security uplift for a consumer technology business. - [UKHSA](/case-studies/ukhsa): Public-sector security culture and capability. - [Utility Warehouse](/case-studies/utility-warehouse): Resilience programme in critical national infrastructure. ## Optional - [Privacy Policy](/privacy) - [Accessibility Statement](/accessibility-statement) - [Corporate Responsibility](/corporate-responsibility) - [Modern Slavery Statement](/modern-slavery) - [Terms of Sale](/terms-of-sale)