Equality, Diversity and Inclusion

How we select the people we work with, how we recruit, how we keep our own service usable, and what we expect of clients and suppliers.

Solusec Ltd · Company No. 13352754 · Approved: 26 September 2026 · Next review: 30 September 2027

Plain English summary: Solusec is a small consultancy and this statement is written to match. Rather than quote workforce percentages that at our scale would tell you very little, it commits to process: how we choose the people we work with, how we recruit, how we make our own service usable, and what we expect of clients and suppliers. Those are the things you can hold us to.

1  Our approach

Solusec Ltd is a small cyber security consultancy. Work is carried out by the founder, Daly Whyte, and by a small number of senior consultants engaged directly, with Daly overseeing every engagement.

That shapes what this statement usefully contains. At our scale, a percentage describing the make-up of the team is arithmetic on single figures: it would identify individuals, it would swing wildly on a single change, and it would tell an evaluator very little about how we actually behave. So this statement is about behaviour, which is specific, checkable, and the same whether we are five people or fifty.

Everything below is something you can hold us to.

2  Legal framework

We comply with the Equality Act 2010. We do not discriminate on the basis of age, disability, gender reassignment, marriage or civil partnership, pregnancy or maternity, race, religion or belief, sex, or sexual orientation, whether in engaging consultants, in recruitment, in who we accept as a client, or in how we deliver work.

Where we work on a public sector contract, we support the contracting authority in meeting its obligations under the Public Sector Equality Duty, and we will complete whatever equality information a procurement process reasonably requires.

3  Choosing the people we work with

Consultants are selected on demonstrable capability: technical skill, relevant accreditation, and evidence of work they have actually done. Nothing else is relevant and nothing else is considered.

In practice the strongest evidence in this field is public and verifiable, such as published CVEs, a bug bounty record, responsible disclosure credits and professional accreditation. That matters here because it is evidence that does not depend on which university somebody attended, who they know, or whether they interview smoothly. We prefer it for that reason as well as for what it proves.

We engage consultants on written terms at professional rates, and we do not ask anyone to work unpaid as a trial.

4  Recruitment and selection

These commitments govern how we bring people in, and they are set down in advance, because it is easier to be honest about a hiring principle before there is a particular hiring decision to rationalise.

  • Roles advertised openly with the salary range published, not "competitive" and not negotiated from whatever the candidate last earned.
  • Selection against a written specification of what the role needs, agreed before applications are read.
  • No requirement for a degree where the work does not need one. This industry is full of excellent people who came in sideways, and several of the best practitioners we know did.
  • Reasonable adjustments offered as a matter of course at every stage, not on request only.
  • Flexible and remote working available by default, because our work supports it and rigidity on this excludes carers and disabled people for no operational reason.
  • Feedback given to candidates who ask for it.

5  Accessibility of what we deliver

Inclusion in a consultancy is partly about whether the people you serve can actually use what you give them.

  • Reports are written in plain English, with technical detail kept where it belongs rather than used to impress. A finding nobody understands does not get fixed.
  • We provide reports in an alternative format on request, and we will talk a client through findings verbally where reading a long document is a barrier.
  • Meetings run remotely by default, which removes a travel barrier for a good many people, and we caption or provide notes on request.
  • Our website is built to be usable with a keyboard and a screen reader. If you hit something on it that does not work for you, tell us and we will fix it.

6  Clients and suppliers

We expect the people we work with to treat our consultants with the same respect we expect from ourselves. Harassment or discrimination directed at anyone working on our behalf is grounds for us to withdraw from an engagement, and we would rather lose the work than leave somebody in it.

We do not impose diversity requirements on our suppliers, because at our purchasing scale that would be a gesture rather than leverage. We will answer any question a client's procurement process puts to us about our own practices.

7  Widening the route in

The barrier to entry in security is not usually ability, it is access: unpaid labs, expensive certifications, and knowing somebody. Where we can do something about that within the means of a business this size, we do. We answer questions from people trying to get into the field, we publish what we know rather than gating it, and we support the local and educational programmes we are part of, including the BESA LaunchPad programme and work with the local chamber of commerce.

These are modest things. We would rather list what we actually do than describe a programme we do not run.

8  Reporting duties and what we publish

For the avoidance of doubt in a tender response, here is what we do and do not publish, and why.

  • Gender pay gap. The reporting duty under the Equality Act 2010 regulations applies to organisations with 250 or more employees. It does not apply to a business of our size, and we do not publish one.
  • Workforce demographics. We do not publish these. At our scale any breakdown would identify individuals, which is a data protection problem rather than a transparency win, and a single change would move every figure. We will publish them at the point they say something meaningful.
  • Diversity training. We do not run a formal programme. Everyone working with us is briefed on the standards of conduct set out in this statement as part of engagement onboarding.

If your procurement process needs one of these and our answer is a problem, tell us at the questionnaire stage rather than at award, and we will tell you plainly whether it is something we can address.

9  Raising a concern

Anyone who believes they have experienced or witnessed discrimination, harassment or unfair treatment in connection with our business can raise it by emailing info@solusec.co.uk, marked for the attention of the Director. Concerns are taken seriously, handled confidentially, and raising one will not disadvantage anybody.

10  Approval and review

This statement was approved by Daly Whyte, Director, on 26 September 2026. It is reviewed annually, and next by 30 September 2027, and sooner if the size or structure of the business changes materially.

If you are assessing us as a supplier and need this in a particular format, or need a signed copy on letterhead, email info@solusec.co.uk and we will send one the same day.