Corstorphine & Wright Case Study | Bistech

A blueprint for success.

Ranked 13th in the AJ100, Corstorphine & Wright is an award-winning architectural practice known for their creative approach and cross-sector experience. They focus on delivering real commercial, civic, and social value in every project, whether they’re refurbishing a century-old Grade I-listed building in Liverpool or designing an ultra-modern leisure destination in central London.

The challenge

Like many industries, architecture is facing a growing number of cyber threats. 59% of construction and engineering firms have experienced an attack in the past two years, including top American firm CannonDesign, which had more than 5.7 TB of sensitive client and corporate data stolen in a ransomware attack in 2023.

Corstorphine & Wright’s IT team saw the rising risks and knew their security needed to be stronger, especially when it came to having visibility into potential vulnerabilities. But without the right resources in-house, tackling this challenge on their own wasn’t realistic.

We’re a small team, and while we’re great at what we do, we needed specialists to fill the gaps we couldn’t cover ourselves,” explained Jonathan Carthy, Head of IT.

They ultimately chose to partner with Bistech, who could help them safeguard their intellectual property, keep operations running smoothly, and reduce the risk of reputational damage from data breaches or downtime.

The solution

Bistech began by evaluating Corstorphine & Wright’s security setup to pinpoint any gaps and get a clearer picture of their needs. This review made it clear that they needed a more proactive approach to threat management, better visibility, and scalable solutions that aligned with their compliance goals.

To address these needs, Bistech introduced one of their cyber security partners to design and implement a solution that fit Corstorphine & Wright’s technical needs, budget, and long-term plans. They also made sure to consider the unique challenges of the architectural industry, ensuring the business would be fully covered on all fronts.

The services included:

  • Managed Detection and Response (MDR), a 24/7 service that actively hunts down and responds to threats before they even trigger alerts.
  • Security Operations Centre (SOC), a service providing real-time monitoring, rapid incident response, and forensic analysis when needed.

Corstorphine & Wright were impressed by the ease of the rollout, describing the phased implementation as “smooth and without challenges.”

The benefits

According to Jonathan, the new approach has benefitted Corstorphine & Wright in numerous ways:

  • By detecting and responding to threats in minutes, not hours, the MDR and SOC services have greatly reduced the risk of data breaches and disruptions. He noted, “Constant monitoring has given us confidence and peace of mind. It means we’re no longer tied up with firefighting issues, and we can focus on what really matters – moving the business forward.
  • The services have also eased the load on the IT team, letting them focus on more important priorities. “It’s allowed us to innovate and spend more time driving business forward, rather than dealing with day-to-day issues.
  • The stronger security posture has reassured senior stakeholders and external investors alike. “Our board knows we’re covered 24/7. It’s given them – and me – real confidence in our security strategy.”
  • Finally, the services played a key role in helping Corstorphine & Wright earn “Secure by Design” accreditation, which has strengthened the company’s credibility and built trust with clients.

At a glance…

24/7 protection

Round-the-clock monitoring safeguards the business from cyber threats at all times.

More time for what matters

Now with a dedicated MDR service, the IT team is free to focus on more strategic goals.

Stronger customer trust

Clients know their data is safe, building more trust in the business.