Information & Cyber Security Services

In health and care, a security failure is not only an IT problem, it is a patient safety and compliance problem. ETHOS provides information and cyber security built for that reality, from ISO 27001 and the Data Security and Protection Toolkit to Cyber Essentials and retained Virtual CISO and DPO support. The same team that helps you meet clinical safety and regulatory standards secures the systems behind them, so your security, safety and compliance are handled as one.

ISO 27001 Services

  • Implementation and Certification Support: From initial gap analysis to full certification, we guide you through every step of achieving ISO 27001 compliance.
  • Second-Party Audits: We perform thorough second-party audits to evaluate your compliance with ISO 27001 standards.
  • DSPT Submission Audits: We make sure your Data Security and Protection Toolkit (DSPT) submissions meet all necessary requirements.

Virtual CISO and DPO Services

  • Virtual CISO: Retained access to a senior Chief Information Security Officer, without the cost of a permanent hire. Ongoing security governance, board reporting and strategic oversight, scaled to your organisation.
  • Virtual DPO: Retained Data Protection Officer support to meet your UK GDPR obligations, from day-to-day advice to formal accountability.

Risk Management and Training

  • Risk Management: Comprehensive risk assessments and management strategies to identify, prioritise and mitigate security threats.
  • Security Awareness Training: Tailored training to educate your staff on best practice and emerging threats.

Certification Assistance

  • Cyber Essentials and Cyber Essentials Plus: Support for achieving both certifications, demonstrating your commitment to cyber security to clients, partners and regulators.

Data Protection and Privacy

  • Data Protection Advice: Expert guidance on UK GDPR compliance and wider data protection obligations.
  • Data Protection Impact Assessments: Assess the impact of data processing activities on privacy, to ensure compliance and reduce risk.

Incident Management

  • Incident Response and Investigations: Rapid response to security incidents, including investigation and recovery planning to minimise impact and restore operations.

Why choose ETHOS?

Most cyber providers do not understand health and care. We do. ETHOS combines information security expertise with a working knowledge of clinical safety, medical device regulation and NHS data governance, so you get protection and compliance from a team that understands the sector you operate in.

The ETHOS team is driven by improving information & Cyber Security in the sector and is passionate about their work

The ETHOS team is driven by improving information & Cyber Security in the sector and is passionate about their work. We offer a free initial diagnostic conversation or health check. If you would like to discuss your information security challenges with a member of the team, then please contact us.