top of page
pexels-pixabay-161863.jpg

Cyber security and data protection in Scotland

Cyber & Privacy does not need to be complex

ICA Consultancy has consultants based in Scotland, supporting organisations across Edinburgh, Glasgow and beyond. We work with legal and professional services firms, a listed recruitment group, a national gaming operator and financial services organisations that need senior security and data protection leadership without building a full in-house team. Every consultant is an ex-industry practitioner.

Who we work with in Scotland

Legal services: a legal services group headquartered in Edinburgh

Recruitment: a listed international staffing group with a major base in Glasgow

Gambling and leisure: a national bingo and gaming operator with clubs across Scotland

How we help them

01.

Maturity assessments. An independent view of where you stand, for boards, investors, auditors and regulators.

02.

ISO 27001 and Cyber Essentials Plus. From gap analysis, implementation, to certification

03.

CISO and DPO as a Service. Senior, named security and data protection leadership without a full-time hire.

04.

DORA & Operational Resilience. Scenario testing and DORA for firms with EU entities, clients or providers.

05.

Culture360º. Measurable security culture across offices and hybrid teams, reported to the board.

Why a Scotland-based team matters

Our Scottish consultants can be on site in Edinburgh and Glasgow for workshops, audits and incident exercises, without the cost of flying a team up from London. Legal, asset management, insurance and banking are central to the Scottish economy, and they are the sectors where we do most of our work across the UK.

What Scottish firms are being asked to prove

Client and panel security requirements

Cyber Essentials Plus, ISO 27001 and panel questionnaire responses backed by a named CISO

Law firms and professional services firms on bank, insurer and corporate panels

FCA and PRA operational resilience

Mapping important business services, setting impact tolerances, scenario testing

Edinburgh and Glasgow asset managers, insurers and banks

DORA

Gap analysis, ICT risk framework, third-party register, testing

Scottish firms with EU entities, clients or ICT providers

UK GDPR and ICO expectations

DPO as a Service, records of processing, DPIAs, breach response

Every organisation handling personal data, especially client-confidential data

Cyber insurance renewals

A named security lead, evidenced controls and a tested incident plan

Every organisation buying cover

See the results

FRACTIONAL CISO

No in-house security leadership. A board with a need.

No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.

15

risks scored across three phases of the programme

SECURITY & PRIVACY ROADMAP

Two disciplines, one baseline, one roadmap

A listed international recruitment group had security and data protection assessed in the same quarter, with one improvement plan built from both. Both capabilities were then held fractionally rather than hired.

3.24

overall security maturity by 2023, from a baseline of 1.95

MANAGED SECURITY CULTURE

Nine hundred thank-yous

Every phishing report gets an automatic thank-you in Teams. Phishing data and learning data joined into one score, proportionate remediation that escalates with the mistake, and a chase list of the people failing on both.

900+

phishing reports acknowledged automatically

Do you only work with large firms?

No. Most Scottish clients have between 50 and a few thousand staff. We scale the service to the firm.

Which areas do you cover?

Edinburgh, Glasgow and the Central Belt, with on-site support elsewhere in Scotland as needed.

Is UK GDPR different in Scotland?

No. UK GDPR and the Data Protection Act 2018 apply across the UK, so your obligations are the same.

Frequently Asked Questions

Based in Scotland and need a security or data protection lead?

bottom of page