Managed Cyber Security Partnership with ANS
Summary
Staffordshire & Shropshire Health Informatics Service (S&SHIS) partners with ANS to deliver a shared, cloud‑based Security Operations Centre (SOC) that provides continuous, 24/7 cyber security monitoring and response across NHS trusts, an Integrated Care Board and local authorities. This approach reflects the critical need to protect large volumes of sensitive health and public sector data within an increasingly complex and high‑risk cyber threat landscape.
Recognising that building an in‑house SOC would be costly and difficult due to skills shortages, S&SHIS chose an external specialist to deliver a scalable, resilient solution. The resulting platform protects a digital estate of 1,935 servers and over 39,000 users, integrating on‑premises and private cloud technologies to improve visibility, automate alerting and accelerate incident response, while maintaining patient safety and service continuity.
The SOC adopts a layered security model covering prevention, risk mitigation, threat detection, incident response and governance. It combines vulnerability management, audits, penetration testing and staff awareness activities with advanced SIEM, AI‑driven analytics and network traffic analysis, supported by professionally accredited cyber specialists and ISO 27001:2022 standards.
The solution delivers strong benefits for both healthcare and local government: improved resilience, reduced risk of service‑disrupting attacks such as ransomware, better protection of sensitive data and a cost‑effective shared model that maximises the value of public funds. As a result, S&SHIS now provides SOC services to a growing range of public sector organisations, helping ensure critical services remain secure, compliant and available to the public.
Background
We at the Staffordshire & Shropshire Health Informatics Service provide IT services to NHS trusts and local authorities, handling significant volumes of sensitive personal data across the local health economy and public sector environments.
To strengthen our security posture, we partnered with ANS to implement a cloud‑based Security Operations Centre (SOC) and monitoring solution capable of delivering continuous, round the clock oversight of our digital infrastructure. This unique, integrated system is designed to safeguard both healthcare organisations and local authorities through a single platform, engineered to meet the stringent security and operational demands of both sectors.
Challenge
The public sector is just as attractive to cyber criminals as the private sector, with attackers looking to exploit perceived gaps in the cyber security capabilities of local authorities and healthcare organisations. When a breach occurs, the consequences extend far beyond financial loss; essential public services can be disrupted and in the most serious cases lives may be put at risk.
The cyber landscape is becoming increasingly unpredictable, with threat actors adopting more sophisticated tactics. As we manage sensitive personal data across health and social care, it represents a high value target for cyber criminals, making strengthened security practices a top priority.
We recognised the importance of providing 24x7x365 SOC services to detect, monitor and respond to emerging cyber threats across our partner organisations. However, it soon became clear that establishing an in house SOC with the required expertise, experience and technology would be prohibitively expensive, especially given the fierce competition for cyber security talent and the challenges of retaining these specialists on public sector budgets.
In order to deliver robust protection for our public sector partners and strengthen their defence against cyber-attacks, we identified the need to work with an external specialist.
Solution
Advanced, adaptable cyber security technology was implemented to protect a complex digital environment comprising 1,935 servers and more than 39,000 users across three NHS trusts, an Integrated Care Board and two local authorities. Given the interdependence between healthcare and wider public sector organisations, securing this shared ecosystem was essential to protect patient services and data from increasingly sophisticated global cyber threats.
From the outset, the programme set ambitious objectives aligned to the needs of a modern public sector provider: strengthening cyber vigilance through faster and more effective incident response; improving operational efficiency through automation and proactive alerting; and safeguarding a strong track record of patient safety and high-quality care.
To address evolving threats such as ransomware, ANS delivered an integrated solution combining on‑premises technologies with private cloud capabilities. This enabled scalable, end‑to‑end visibility of the digital estate through a single, cloud-based platform, significantly improving threat detection and incident response times while minimising operational disruption for staff and patients.
Collaboration was central to success. Working closely together, the solution was tailored to the specific requirements of healthcare and local government. It provides comprehensive security testing, monitoring and alerting across the IT infrastructure via a unified dashboard, operated by professionally qualified cyber security specialists and fully accredited to ISO 27001:2022. The result is enhanced organisational resilience and a clear demonstration of how digital innovation can deliver greater value with limited resources.
The service adopts a layered approach to cyber security:

Prevention and assurance, through regular vulnerability scanning, patching effectiveness dashboards, annual domain and network security audits, reviews of privileged access, independent penetration testing, phishing awareness testing and cyber response exercises.
Risk mitigation, with clear accountability for remediation, supported by consultancy input from qualified cyber engineers.
Threat detection and monitoring, using a managed Azure Sentinel SIEM, machine learning and AI-driven analytics, near real-time log ingestion from critical systems, and network traffic analysis to identify abnormal behaviour early.
Incident management and response, via a professionally staffed SOC, structured around ITIL best practice, supported by tested incident response, business continuity and disaster recovery plans.
Governance and continuous improvement, overseen through quarterly Information Security Management Meetings involving customer representatives and informed by close links with NHS Digital and the National Cyber Security Centre.
Overall, the service delivers a robust, proactive and collaborative cyber security capability that strengthens resilience, protects patient care and supports the sustainable delivery of healthcare and public services.
We chose to engage with ANS because we have had historical relationships with them in the past. We wanted to have the relationship where it was more of a two way arrangement and the requirements that we released very much reflected that. We felt a number of other suppliers were presenting options that were very much off the shelf where the ANS model felt much more like a partnership and something that would evolve with us.
Rich McCue, Head of Technology at Staffordshire & Shropshire Health Informatics ServiceBenefits
The implementation of a shared SOC delivers substantial value across both healthcare and local government, strengthening cyber resilience while supporting efficient use of public funds. By providing continuous, 24/7 monitoring and rapid incident response, the SOC protects essential services that people rely on daily, from patient care to social support and wider community services.
Operating as a single, integrated platform, the SOC safeguards interconnected systems used across NHS trusts, Integrated Care Boards and local authorities. This shared approach enhances protection for sensitive personal data, reduces the risk of service disrupting cyber-attacks such as ransomware, and ensures potential threats are identified and contained quickly.
For public sector organisations facing increasing cyber risk and limited resources, the SOC offers a cost‑effective model. It provides access to specialist cyber security expertise, advanced threat detection technology and round the clock vigilance, without each organisation needing to build and maintain its own dedicated capability.
Ultimately, the SOC strengthens public safety, ensures continuity of critical services, and supports compliance with sector‑specific regulations and national standards. It demonstrates how shared digital infrastructure and collaborative security models can deliver improved outcomes, greater resilience and better value for the public sector.
Outcome
Working in partnership with ANS, we now deliver SOC services to a wide range of public sector organisations across both healthcare and local government. These partners benefit from a fully staffed, round the clock team that continuously monitors, identifies, triages and responds to cyber security threats. ANS SOC analysts also play an important advisory role, providing us and our partners with the latest threat intelligence and offering proactive recommendations to strengthen our overall security posture. This ensures that critical systems remain protected and operational, enabling the public to safely access the essential services we rely on.
Among the organisations using the SOC service is Staffordshire County Council, which has achieved significant improvements in its security resilience and its ability to defend against cyber threats.
Read a few of their testimonials below and watch their partnership video.
ANS evidenced both a really cost effective proposition. They demonstrated their skills and expertise not only in cyber security but also in the public sector, local government and NHS sphere and felt like a really good fit for our requirements. The skill that they have got in terms of the number of SOC engineers was really impressive.
Vic Falcus, Head of ICT at Staffordshire County CouncilIt was important to have somebody who could work with our technology stack which ANS have a deep level of experience and understanding in. One of the things that we found very useful is the knowledge of the engineers. We’ve had had a lot of logs that we have needed to get into the seam tool in order to get the most out of it, and you’ve had various engineers engaged on the project throughout who’ve been subject matter experts. It’s been really useful to lean on their knowledge and skills to get the most out of the product.
Stuart Fletcher, Head of Cyber Security at Staffordshire County CouncilThe Future
Thanks to our cyber security partnership S&SHIS and our partners benefit from a level of cyber security protection that would be difficult for individual organisations to achieve on their own. Building on this success, we are looking to expand the service to additional partners, further increasing economies of scale and strengthening cyber resilience across the wider public sector.
This has felt like a true partnership from the very beginning. ANS didn’t just deliver a product, they took the time to really understand us and the pressures we face as a 24/7 healthcare organisation. By listening to our needs, engaging with our teams, and working with us to produce a solution, together we have strengthened S&SHIS’s cyber security posture, supported our staff, and protected patient services. ANS’s proactive approach, combined with mutual respect and open communication, meant we were able to shape something together that truly works for the way we deliver care. It’s been a collaborative journey throughout.
Adam Cooper, Director of Health Informatics at Staffordshire & Shropshire Health Informatics Service
