ISO 27001SOC 2 Type IIISO 9001

About NexaCore

Eighteen years inside regulated enterprise technology

NexaCore was founded in 2007 to do one thing properly: deliver technology programmes for organisations where failure carries regulatory, financial and human consequences. That focus has never widened, and it defines how the firm is structured, staffed and governed today.

Corporate headquarters tower viewed from below against a clear sky

Our Story

Founded on a simple, unfashionable premise

In 2007 our founders were programme directors inside two European banks. Both had watched large transformation budgets consumed by partners who staffed engagements with whoever was available, treated compliance as a downstream activity, and disappeared before the benefits were measured. NexaCore was built as the opposite of that experience.

The commitments made in the first client contract remain in the standard master services agreement today: the team you interview is the team that delivers; the compliance evidence is produced as work proceeds, not reconstructed for the auditor; and the business case is re-measured after go-live by the client's own finance function, with the result published in a joint benefits review.

Eighteen years later NexaCore employs more than 3,400 practitioners across four delivery regions and holds active contracts with over 250 enterprise clients. Roughly 84% of revenue comes from organisations that were already clients three years earlier — which we regard as the only client satisfaction metric that cannot be gamed.

Senior leaders in discussion around a boardroom table

Milestones

How the firm grew

Deliberate, sector-led expansion — each new region opened only once an anchor client required local delivery presence.

  • 2007

    Founded in London

    Established by four former banking programme directors with an initial focus on core-banking integration and regulatory reporting.

  • 2011

    ISO 27001 certification

    First certification achieved across all delivery operations, four years before it became a common procurement requirement in the sector.

  • 2014

    Bengaluru delivery centre

    Opened to support follow-the-sun operations for two multinational manufacturing clients. Now our largest engineering hub.

  • 2017

    Healthcare practice established

    A dedicated practice for HIPAA and GxP-regulated environments, formed around a 14-hospital clinical data programme.

  • 2019

    North American headquarters

    New York office opened alongside SOC 2 Type II attestation, enabling direct contracting with US financial institutions.

  • 2021

    Security operations centres

    Three regional SOCs commissioned, bringing managed detection and response in-house rather than through subcontract.

  • 2023

    Frankfurt & sovereign cloud

    EU delivery centre opened with data-residency-controlled landing zones for public sector and DORA-scoped financial clients.

  • 2025

    3,400 practitioners

    Singapore operations centre completes the four-region follow-the-sun model; 250th active enterprise contract signed.

Operating Principles

Four commitments in every contract

These are not aspirations on a wall. Each one is a clause our clients can enforce.

Team continuity

The core team is named in the statement of work. Replacements require your written approval and a documented handover period.

Evidence as you go

Control evidence, change records and architecture decisions are produced during delivery and handed over continuously.

Measured benefits

Business cases are re-measured after go-live by your finance function, and the result is published in a joint review.

Exit without penalty

Every managed service contract includes a defined, priced exit plan with knowledge transfer. Lock-in is not our commercial model.

NexaCore in numbers

3,400+
Practitioners across four delivery regions
84%
Revenue from clients of three years or more
6.4 yrs
Average consultant tenure at NexaCore
14
Countries with active client operations

Leadership

The executive team

Practitioners first. Every member of the executive committee still holds direct accountability for a client portfolio or a delivery region.

Portrait of Daniel Whitfield, Chief Executive Officer

Daniel Whitfield

Chief Executive Officer

Co-founder. Previously programme director for core banking replacement at a European retail bank. Chairs the client governance board and personally sponsors the firm's ten largest accounts.

Portrait of Priya Nair, Chief Technology Officer

Priya Nair

Chief Technology Officer

Leads architecture and the design authority. Twenty-two years in distributed systems and cloud platform engineering, including seven years as chief architect for a global payments processor.

Portrait of Marcus Feldman, Chief Information Security Officer

Marcus Feldman

Chief Information Security Officer

Accountable for the security practice and the three regional SOCs. Former head of security operations at a systemically important financial market infrastructure provider. CISSP, CISM.

Portrait of Sophie Lindqvist, Chief Delivery Officer

Sophie Lindqvist

Chief Delivery Officer

Owns global delivery assurance and the quality management system. Previously ran ERP transformation portfolios across Nordic manufacturing. Chairs the firm's programme escalation committee.

Portrait of Adeyemi Okonkwo, Managing Director, Americas

Adeyemi Okonkwo

Managing Director, Americas

Leads the New York practice and North American client portfolio. Eighteen years advising US financial institutions on regulatory technology and operational resilience programmes.

Portrait of Clara Bennett, Chief Financial Officer

Clara Bennett

Chief Financial Officer

Responsible for commercial governance, benefits assurance and the firm's independent benefits-review methodology. Chartered accountant with prior audit-practice experience.

Certifications & Compliance

Independently audited, annually re-certified

Certificates and audit reports are available to clients and prospective clients under NDA. Scope statements cover all delivery regions unless otherwise noted.

ISO/IEC 27001:2022

Information security management. Certified since 2011, all regions in scope.

ISO 9001:2015

Quality management system covering delivery, assurance and service operations.

SOC 2 Type II

Annual attestation across security, availability and confidentiality trust criteria.

Cyber Essentials Plus

UK NCSC-backed scheme, independently tested annually across corporate infrastructure.

ISO 22301:2019

Business continuity management, exercised twice yearly with documented outcomes.

GDPR & UK DPA 2018

Appointed DPO, standard contractual clauses and documented transfer impact assessments.

PCI DSS v4.0

Qualified assessors on staff; NexaCore-operated cardholder environments assessed annually.

HIPAA & HITRUST

Business associate agreements in place; HITRUST CSF alignment for healthcare workloads.

Global Presence

Four delivery regions, one operating model

Engagement leadership sits in your jurisdiction. Delivery follows the sun. Data residency is enforced at the platform layer, not by policy alone.

United States

New York

Americas headquarters. Financial services practice, regulatory technology advisory and the Americas security operations centre.

United Kingdom

London

Registered head office. Group functions, EMEA financial services and the design authority for global architecture standards.

Germany

Frankfurt

EU delivery centre with sovereign and data-residency-controlled landing zones for DORA and NIS2-scoped clients.

India

Bengaluru

Largest engineering hub. Application development, data engineering and the follow-the-sun managed service capability.

Singapore

Singapore

APAC operations centre covering managed services, MAS-aligned advisory and regional client delivery.

Poland

Kraków

Nearshore delivery centre for EMEA clients — ERP integration, quality engineering and platform operations.

United States

Austin

Cloud and data engineering hub, and the North American hypercare centre for post-go-live support.

United Arab Emirates

Dubai

Middle East client office supporting banking, energy and public sector programmes across the GCC.

Governance working session with the team mapping commitments on a wall

Responsibility

Governance beyond the engagement

NexaCore reports annually against environmental, social and governance commitments that are audited alongside our quality management system. Clients in regulated sectors increasingly require this reporting as part of third-party risk assessment, so we produce it to the same standard as our security evidence.

  • Carbon-neutral corporate operations since 2023, with a 2030 net-zero target covering delivery travel and data centre consumption
  • Supplier code of conduct applied to all subcontractors, with annual attestation and audit rights
  • Modern slavery statement published annually under the UK Modern Slavery Act 2015
  • Independent whistleblowing channel operated by a third party and reported to the audit committee
  • Pay-gap reporting published in all jurisdictions where we employ more than 250 people
  • Apprenticeship and returner programmes accounting for 12% of annual technical hiring
Request our ESG and assurance pack

Next Step

Meet the team that would run your programme

We will introduce the specific practice leads and delivery managers who would be accountable for your engagement — before any commercial discussion.