Skip to main content
Bearded man working with laptop

Keeping your data and systems protected can feel like an impossible job. New threats. Shifting priorities. And no room for disruption. We help you stay on the front foot. Assured by the NCSC, BSI and CREST, our security team provides practical advice and proactive security operations for organisations worldwide. We help you understand your risks, strengthen your foundations, and build security into the way your people actually work. So your business can keep moving. Securely.

How we can help

Cyber Strategy

We've sat in the CISO seat, so we know the pressure of protecting a business against threats that never stand still.

Whether you need help shaping a cyber security roadmap that fits your goals and regulatory reality, a vCISO to lean on, or hands-on guidance across architecture, infrastructure, and controls – we can help. We combine strong governance with deep technical know-how to build security that's resilient, practical, and ready for whatever's next.

Fractional Security Roles

Not every organisation needs a full-time security leader. But every organisation needs the thinking of one. Our fractional security management gives you senior cyber expertise without the overhead.

From hands-on operational support to strategic leadership, we help you get a clear picture of your cyber risks, strengthen your defences, and put governance in place that actually sticks – not just at audit time, but in the way your people work.

Security manager or vCISO, we shape the support around what you actually need.

Managed Detection and Response (SOC)

Cyber threats don’t work standard office hours. And neither do we.

Our managed detection and response service (MDR) gives you 24/7 monitoring and response through our CREST certified Security Operations Centre (SOC). Our team detects and triages threats in real time, backed by XDR/SIEM, threat intelligence and dark web scanning.

When we spot something, we act fast. Contain it, investigate it, and give you clear, practical steps to fix it and stop it happening again.

CAF Audit and Assurance

Waterstons is an NCSC approved cyber advisor, and one of only a small number of consultancies on the NCSC Cyber Resilience Audit scheme. We’ve supported organisations in regulated sectors, so we know what good looks like, and what regulators expect.

We’ll help you get to grips with the NCSC CAF Framework, working out how ready you are for submission, where the gaps are, and what to tackle first. So you’ve got a clear, practical route to compliance.

Cyber Essentials and ISO 27001 

Certification is one of the clearest ways to prove your security credentials, but getting there shouldn't feel like a second job.

Whether you're aiming for ISO 27001, Cyber Essentials, or Cyber Essentials Plus, we help from start to finish across governance and technical controls. We find the gaps, help you fix them, and give you trusted, independent assurance from our certified assessors and auditors – so you can get through certification without the headaches.

Penetration Testing

Our accredited testers run real-world attack simulations across your web applications, networks, systems, and even your physical environment – showing you what a real attacker could do, before they do it. Pen testing isn't about catching you out. It's about giving you a clear picture of what needs fixing.

We use industry-leading tools and threat intelligence to find weaknesses, then give you practical, prioritised steps to put things right – not just a list of problems.

We also carry out Microsoft 365 security reviews, vulnerability assessments, and Active Directory analysis, helping you reduce risk and tighten your day-to-day security.

 

Rachel Bence

Chief Information Officer

"Partnering with Waterstons made our ISO 27001:2022 journey efficient, well-governed and highly effective resulting in Queen Mary University achieving certification which has added real, measurable value to the University. Their structured approach helped us embed consistent ways of working across ITS, and certification has given us greater assurance and confidence in the strength of our information security management."

Partners and accreditations

CREST SOC

CREST SOC

CREST PEN testing

CREST Penetration Testing

logo

BSI ISO 27001 and 9001

Cyber Essentials Logo

Cyber Essentials

Cyber Essentials Pus

Cyber Essentials PLUS

BSI ACP

BSI ACP

NEBRC Trusted Partner 2021-22 Logo

North East Business Resilience Centre Trusted Partner

ScotlandIS Gold members

ScotlandIS

crest training provider logo

CREST Cyber Training Provider

logo

NCSC Cyber Resilience Audit Scheme – Assured Service Providers

logo

NCSC Consultancy: Audit and review service provider

logo

NCSC Consultancy: risk management service provider

Your go-to guide to the CAF

The CAF is the UK National Cyber Security Centre's (NCSC) benchmark for cyber resilience. If you're responsible for keeping your organisation secure, it matters. We've put together a practical guide that cuts through the jargon: what the CAF is, what it means for your business, and the next steps to take to make sure you're up to date with the legislation.

Find out more
Front cover of the CAF guide

Get in touch

Name

We will only use the information you provide in this form to contact you in regards to your enquiry to us. For more information, please read our privacy policy.

Learning and thinking