Cyber Security Services
Cyber Security Services
Keeping your data and systems protected can feel like an impossible job. New threats. Shifting priorities. And no room for disruption. We help you stay on the front foot. Assured by the NCSC, BSI and CREST, our security team provides practical advice and proactive security operations for organisations worldwide. We help you understand your risks, strengthen your foundations, and build security into the way your people actually work. So your business can keep moving. Securely.
How we can help
- Cyber Strategy
-
We've sat in the CISO seat, so we know the pressure of protecting a business against threats that never stand still.
Whether you need help shaping a cyber security roadmap that fits your goals and regulatory reality, a vCISO to lean on, or hands-on guidance across architecture, infrastructure, and controls – we can help. We combine strong governance with deep technical know-how to build security that's resilient, practical, and ready for whatever's next.
- Fractional Security Roles
-
Not every organisation needs a full-time security leader. But every organisation needs the thinking of one. Our fractional security management gives you senior cyber expertise without the overhead.
From hands-on operational support to strategic leadership, we help you get a clear picture of your cyber risks, strengthen your defences, and put governance in place that actually sticks – not just at audit time, but in the way your people work.
Security manager or vCISO, we shape the support around what you actually need.
- Managed Detection and Response (SOC)
-
Cyber threats don’t work standard office hours. And neither do we.
Our managed detection and response service (MDR) gives you 24/7 monitoring and response through our CREST certified Security Operations Centre (SOC). Our team detects and triages threats in real time, backed by XDR/SIEM, threat intelligence and dark web scanning.
When we spot something, we act fast. Contain it, investigate it, and give you clear, practical steps to fix it and stop it happening again.
- CAF Audit and Assurance
-
Waterstons is an NCSC approved cyber advisor, and one of only a small number of consultancies on the NCSC Cyber Resilience Audit scheme. We’ve supported organisations in regulated sectors, so we know what good looks like, and what regulators expect.
We’ll help you get to grips with the NCSC CAF Framework, working out how ready you are for submission, where the gaps are, and what to tackle first. So you’ve got a clear, practical route to compliance.
- Cyber Essentials and ISO 27001
-
Certification is one of the clearest ways to prove your security credentials, but getting there shouldn't feel like a second job.
Whether you're aiming for ISO 27001, Cyber Essentials, or Cyber Essentials Plus, we help from start to finish across governance and technical controls. We find the gaps, help you fix them, and give you trusted, independent assurance from our certified assessors and auditors – so you can get through certification without the headaches.
- Penetration Testing
-
Our accredited testers run real-world attack simulations across your web applications, networks, systems, and even your physical environment – showing you what a real attacker could do, before they do it. Pen testing isn't about catching you out. It's about giving you a clear picture of what needs fixing.
We use industry-leading tools and threat intelligence to find weaknesses, then give you practical, prioritised steps to put things right – not just a list of problems.
We also carry out Microsoft 365 security reviews, vulnerability assessments, and Active Directory analysis, helping you reduce risk and tighten your day-to-day security.
Rachel Bence
Chief Information Officer
"Partnering with Waterstons made our ISO 27001:2022 journey efficient, well-governed and highly effective resulting in Queen Mary University achieving certification which has added real, measurable value to the University. Their structured approach helped us embed consistent ways of working across ITS, and certification has given us greater assurance and confidence in the strength of our information security management."
Partners and accreditations
CREST SOC
CREST Penetration Testing
BSI ISO 27001 and 9001
Cyber Essentials
Cyber Essentials PLUS
BSI ACP
North East Business Resilience Centre Trusted Partner
ScotlandIS
CREST Cyber Training Provider
NCSC Cyber Resilience Audit Scheme – Assured Service Providers
NCSC Consultancy: Audit and review service provider
NCSC Consultancy: risk management service provider
Your go-to guide to the CAF
The CAF is the UK National Cyber Security Centre's (NCSC) benchmark for cyber resilience. If you're responsible for keeping your organisation secure, it matters. We've put together a practical guide that cuts through the jargon: what the CAF is, what it means for your business, and the next steps to take to make sure you're up to date with the legislation.
Find out more
ISO 27001:2022
“Our ISO 27001:2022 journey has been efficient, well-governed and highly effective resulting in Queen Mary University achieving certification which has added real, measurable value to the University. Waterstons' structured approach helped us embed consistent ways of working across ITS, and certification has given us greater assurance and confidence in the strength of our information security management.”
Rachel Bence Chief Information Officer Queen Mary University of London
Read case studyBurness Paull LLP – Incident and continuity planning
“Waterstons provided invaluable support in developing and improving our existing Business Continuity and Incident Response plans".
Burness Paull LLP
Read case studyCultivating cyber resilience: Case study - People’s Postcode Lottery.
“Working with Waterstons means having trusted, accredited advice and experts in our corner. We’re able to make informed decisions based on the information they provide. They understand us, our needs and what matters most to us.”
Mark Sandison People’s Postcode Lottery
Read case studyProtecting critical national infrastructure through cyber resilience
An organisation can only be effective in their response to an incident if they are suitably prepared with appropriate processes, people and technology capabilities in place; assisting in a deliberate and highly coordinated response.
Read case study