Cyber Security Services
Cyber Security Services
Keeping your data and systems protected can feel like an impossible job. New threats. Shifting priorities. And no room for disruption. We help you stay on the front foot. Assured by the NCSC, BSI and CREST, our security team provides practical advice and proactive security operations for organisations worldwide. We help you understand your risks, strengthen your foundations, and build security into the way your people actually work. So your business can keep moving. Securely.
How we can help
- Cyber Strategy
-
We've sat in the CISO seat, so we know the pressure of protecting a business against threats that never stand still.
Whether you need help shaping a cyber security roadmap that fits your goals and regulatory reality, a vCISO to lean on, or hands-on guidance across architecture, infrastructure, and controls – we can help. We combine strong governance with deep technical know-how to build security that's resilient, practical, and ready for whatever's next.
- Fractional Security Roles
-
Not every organisation needs a full-time security leader. But every organisation needs the thinking of one. Our fractional security management gives you senior cyber expertise without the overhead.
From hands-on operational support to strategic leadership, we help you get a clear picture of your cyber risks, strengthen your defences, and put governance in place that actually sticks – not just at audit time, but in the way your people work.
Security manager or vCISO, we shape the support around what you actually need.
- Managed Detection and Response (SOC)
-
Cyber threats don’t work standard office hours. And neither do we.
Our managed detection and response service (MDR) gives you 24/7 monitoring and response through our CREST certified Security Operations Centre (SOC). Our team detects and triages threats in real time, backed by XDR/SIEM, threat intelligence and dark web scanning.
When we spot something, we act fast. Contain it, investigate it, and give you clear, practical steps to fix it and stop it happening again.
- CAF Audit and Assurance
-
Waterstons is an NCSC approved cyber advisor, and one of only a small number of consultancies on the NCSC Cyber Resilience Audit scheme. We’ve supported organisations in regulated sectors, so we know what good looks like, and what regulators expect.
We’ll help you get to grips with the NCSC CAF Framework, working out how ready you are for submission, where the gaps are, and what to tackle first. So you’ve got a clear, practical route to compliance.
- Essential Eight and ISO 27001
-
Certification is one of the clearest ways to prove your security credentials, but getting there shouldn't feel like a second job.
Whether you're aiming for ISO 27001 or Essential Eight, we help from start to finish across governance and technical controls. We find the gaps, help you fix them, and give you trusted, independent assurance from our certified assessors and auditors – so you can get through certification without the headaches.
- Penetration Testing
-
Our accredited testers run real-world attack simulations across your web applications, networks, systems, and even your physical environment – showing you what a real attacker could do, before they do it. Pen testing isn't about catching you out. It's about giving you a clear picture of what needs fixing.
We use industry-leading tools and threat intelligence to find weaknesses, then give you practical, prioritised steps to put things right – not just a list of problems.
We also carry out Microsoft 365 security reviews, vulnerability assessments, and Active Directory analysis, helping you reduce risk and tighten your day-to-day security.
Cybersecurity made simple for small and medium businesses
Our unique subscription service is designed for small and medium organisations that need credible, ongoing protection but don’t have time for jargon or complex tools. Cybscribe gives you practical protection, clear insight and dependable support – without the enterprise price tag.
Find out more
Partners and accreditations
Australian Cyber Security Centre
CREST SOC
Cyber Essentials
Cyber Essentials PLUS
ISO/IEC 27001
BSI ACP
North East Business Resilience Centre Trusted Partner
Scottish Business Resilience Centre Trusted Partner
Gold Standard Security for People's Postcode Lottery
"Waterstons’ partnership approach meant they worked side by side with us like one of our team to make sure our ISO 27001 project was not only a success but delivered real value right across the business."
John Young IT Security Manager People's Postcode Lottery
Read case study
Cyber Essentials: The springboard to your security journey
"Certification proves to our customers that we strive to deliver excellence both in our services and how we operate as a business – this improves confidence in our business practices and provides a world of opportunities that were previously out of reach."
Darren Carroll Head of IT Jestico + Whiles
Read case study
Investing in cyber resilience to provide safe and secure homes
“With so much personal and confidential data to protect, it was vital that we achieved Cyber Essentials Plus, and Waterstons’ help and guidance gave us all of the tools and confidence we needed to do so.”
Hassan Bahrani Head of IT Thirteen Group
Read case study
A trusted partnership in action
“Waterstons has been our trusted partner to help us not only to build an in house security function but also act as our strategic advisor in the field of cyber security. Their specialists have worked with us side by side as one virtual team to make our cyber security strategy a reality.”
Rachel Bence Chief Information officer Queen Mary University London
Read case study
Cultivating cyber resilience: Case study - People’s Postcode Lottery.
People’s Postcode Lottery
Read case study