Firewalls
Boundary firewalls and internet gateways configured deliberately rather than left as the router arrived from the provider.
Cyber Essentials Readiness
Which is the whole difficulty. The five controls are not complicated and the certification is not expensive — the work is getting your business into a state where the honest answers are the passing ones. That is what we do.
What it is, plainly
Three things about the scheme that are worth understanding before you spend anything on it.
Certification is issued by bodies accredited by IASME, the scheme's delivery partner. We are not one of them and will not pretend to be. What we do is get the controls genuinely in place and the self-assessment answerable honestly, then point you at a certifying body to issue it.
Cyber Essentials covers five basic technical controls. Meeting them makes you meaningfully harder to attack opportunistically, which is how most small businesses are actually attacked. It does not make you secure, and anybody selling it as though it does is overselling.
This is usually the real reason a small business looks at it. Public sector contracts and a growing number of private supply chains require it, so it stops being a security decision and becomes a commercial one — you cannot bid without it.
The five controls
Boundary firewalls and internet gateways configured deliberately rather than left as the router arrived from the provider.
Devices and software set up to reduce what is exposed — default passwords gone, unnecessary accounts and services removed, nothing left switched on because nobody looked.
Accounts that match who actually works for you now, administrative rights held only by people who need them, and a way to know that is still true in six months.
Protection against malicious software on the devices your people actually use, including the ones they own and work on.
Everything patched and in support. This is the control that fails most often, and it fails quietly — it takes one unattended plugin or one operating system past its end of life.
Scope. The certificate covers what you declare it covers, and a self-assessment that quietly excludes the awkward half of the business is worth very little. Deciding scope honestly is most of the work.
How it runs
An inventory of the devices, accounts, software and services your business really runs on — including the ones nobody has thought about since they were set up. Most small businesses have never had one.
We go through the self-assessment with you and write down the true answers, including the failing ones. That document is the actual work plan, and it is uncomfortable reading the first time.
Closing the gaps, in the order that reduces real risk fastest rather than the order the form lists them in.
You submit to a certifying body. Then the harder part: it lapses annually, and a business drifts out of compliance quietly. We can keep watching it if you want that.
No, and be wary of anyone who says they can while also doing your remediation. Certification is issued by bodies accredited by IASME. We get you into a state where you can answer the assessment honestly and pass it, and then you certify with a body that does that for a living.
It depends almost entirely on what state things are in when we start. A business with modern equipment, everything in support and a clear idea of who has access can be ready in a couple of weeks. One with unsupported systems and accounts belonging to people who left in 2021 takes longer, and finding that out is itself worth having.
The basic scheme is a self-assessment that you complete and an accredited body reviews. Plus adds hands-on technical verification by an assessor — they check rather than take your word for it. Some contracts specify which one they require, so check the requirement before choosing.
It is the commonest reason and it is a perfectly good one. The useful thing is that the work still has to be real: you cannot bid on a certificate you obtained by answering untruthfully, because the declaration is signed by a company officer and it is that officer's problem if it is wrong.
No, and we say so early. We are not a helpdesk and do not want to be one — we secure and maintain what we build and host. If you need somebody to fix a laptop on a Tuesday morning you need a different kind of firm, and we would rather tell you that than take the work.
What we actually do about security day to day — access, updates, tested backups, monitoring and private internal networks.
Read moreIf you are not sure where you are exposed, the two-day audit establishes it for a fixed price and tells you what to fix first.
See what's includedWhere sensitive work needs building properly rather than assembled from whatever was to hand.
See what we buildIt is free to look at, and the first honest run through it tells you more about your business than most paid assessments will. We will do it with you and tell you what the gaps would cost to close.