Cyber Essentials

Certified, without the panic

Most businesses come to us because a customer or an insurer has asked for Cyber Essentials and the deadline is closer than they'd like. We check where you actually stand, fix the gaps, and sit with you while the questionnaire gets filled in.

The five controls

What you'll be assessed on

None of it is exotic. It's the basics, applied to every machine and every account — which is where most businesses come unstuck.

Firewalls and internet gateways

Business-grade firewalls with remote access restricted and default passwords removed.

Secure configuration

Devices set up to a known standard instead of however they came out of the box, with unused accounts and services removed.

User access control

Everyone with their own account, admin rights only where needed, multi-factor authentication on cloud services, leavers actually removed.

Malware protection

Managed endpoint protection on every device, with alerts monitored centrally.

Security update management

Operating systems and applications patched within the required window, and nothing left running that the vendor no longer supports.

The questionnaire itself

We go through it with you question by question, in plain English, so the answers are accurate and you can evidence them if asked.

How we run it

From first look to certificate

You'll know what needs doing, what it costs and how long it will take before any work starts.

  • Gap assessment across devices, accounts and cloud services
  • A plain-English list of what passes and what doesn't
  • Remediation work quoted up front, done in agreed stages
  • The questionnaire completed with you, not for you
  • Support if the assessor comes back with queries
  • A reminder and a re-check before your annual renewal

FAQ

Questions we get asked

Been asked for Cyber Essentials?

Tell us the deadline and roughly how many people and devices you have. We'll tell you whether it's realistic and what standing in your way.