Firewalls
Firewalls configured properly. At the boundary, and on the device itself where that matters.
- Boundary firewalls
- Host-based firewalls
- Documented rule sets
The UK government-backed baseline. More contracts and insurers ask for it every year.
Cyber Essentials is a UK government-backed certification scheme. The National Cyber Security Centre created it, and IASME delivers it. Five technical controls, that is all it is. Between them they stop most of the automated attacks that sweep the internet looking for anything left open. Certification is valid for twelve months.
It matters commercially as much as technically. Central government contracts involving certain personal or sensitive information require suppliers to hold it, a growing number of private-sector buyers ask for it during procurement, and some cyber insurance policies price it in. For a small business it is often the cheapest way to get an obstacle out of a sales process, which is usually why people ring us about it in the first place rather than for the security itself.
Firewalls configured properly. At the boundary, and on the device itself where that matters.
Default accounts and passwords gone. Unnecessary services switched off. Everything built to a known-good baseline.
People have the access their role needs and nothing more, with administrator rights tightly controlled and reviewed.
Anti-malware protection deployed and kept current on every in-scope device.
Supported software only, with critical and high-severity patches applied within 14 days of release.
Cyber Essentials is a self-assessment questionnaire verified by a certification body. The questionnaire is not difficult to read. The hard part is answering every question truthfully. Most organisations that fail do so because a handful of devices are unpatched, running unsupported software, or nobody can say with confidence who has administrator rights.
So we work in that order. We audit what you have against the five controls, produce a gap list, fix the gaps, then complete the assessment. Because the certification lapses after twelve months, we keep the underlying controls in place year-round rather than scrambling each renewal.
Gap assessment, remediation, assessment submission and year-round maintenance of the five controls.
If your customer or contract specifically requires the audited version, see Cyber Essentials Plus. We also wrote a plain-English walkthrough of the scheme for Essex businesses: the Cyber Essentials guide.
How we work
Most security quotes begin with a conversation and end with a list of products you're asked to trust. Ours begins with a scan.
We built our own audit software, ShadowAudit, because the tools we could buy either cost more than our clients' entire IT budget or produced hundred-page reports nobody reads. It checks fifteen configuration controls on every Windows machine, finds the devices on your network that nobody remembers plugging in, and looks at your business from outside to see what the internet can reach.
Every finding carries the evidence that produced it. Not "your password policy is
weak" but net accounts: minimum length 0, and the setting that fixes it.
You can check our work, and so can anyone you hire after us.
First we look from outside. Before we visit, we scan what your business publishes to the internet from our own systems. Open ports, certificate problems, forgotten subdomains, mail records that let anyone send email as you. This is the half most firms have never had checked, and it's the half an attacker starts with.
Then we look from inside. On site, we check each Windows machine against the same fifteen controls: patching, encryption, firewall, antivirus, account policy, legacy protocols. We sweep the network and list every device on it. That list alone tends to produce a surprise or two.
Then you get a report you can act on. Findings ordered by what an attacker would use first, each with the fix, the effort involved, and what breaks if it's applied carelessly. Written for whoever signs things off, not for an engineer.
We do not touch a system without written authority. The free perimeter check takes one signed form. A paid audit takes three: the engagement letter, a scope schedule naming every machine we may look at and everything we may not, and a data processing agreement covering the personal data an audit inevitably sees.
All four are published on our downloads page, blank and in full. Read exactly what you would be agreeing to, and what we are promising not to do, before you speak to anyone here.
Read the case study: 1,241 password attempts in a day on our own server
| What | Price | What you get |
|---|---|---|
| Perimeter check | Free | What the internet can reach on your domain and public address. Remote, no visit, no obligation. You get the findings whether or not you hire us. |
| Full audit | £450 to £650 | Everything above, plus every Windows machine checked on site, a device inventory, and the written report. |
| Cyber Essentials readiness | £650 to £950 | The full audit mapped to the five controls, with a pass or fail against each and the work needed to close the gaps. |
| Managed Cyber Essentials | £99 per client, per month | Gap assessment, the remediation work, the submission itself, and keeping the controls in place between renewals. |
Prices exclude VAT. The IASME certification fee is set by the scheme and paid separately, from £300 + VAT depending on your size. We're not a certification body, so that fee never comes to us.
Worth being straight about, because plenty of firms aren't.
It isn't a penetration test. Nothing we run exploits anything, guesses a password or tries to break in. It's a configuration and exposure audit. If you need someone to actively attack your systems, that's a different engagement with a signed scope, and we'll tell you so rather than dress this up as one.
The Cyber Essentials mapping is readiness, not certification. We tell you whether you'd pass. The certificate is issued by an IASME-accredited body once the questionnaire goes in, and we handle that submission for you.
It won't find everything. Nothing does. It checks Windows machines properly and treats printers, phones and network kit as devices with open ports rather than auditing them internally. We say that in every report rather than letting a clean page imply more than it should.
If your systems are already in reasonable shape, a few weeks. The variable is remediation, not paperwork. What usually costs the time is an unsupported operating system, or software that has to be replaced before you can answer the questionnaire honestly.
We manage it for £99 per client per month, covering the gap assessment, remediation work, the submission itself and keeping the controls in place between renewals. The IASME certification fee is set by the scheme and depends on your organisation's size.
Twelve months. It is a point-in-time certification, so it has to be renewed annually. That is why we treat the five controls as continuous work rather than an annual scramble.
You need it for central government contracts that involve handling certain personal or sensitive information, and it is increasingly requested in private-sector procurement. If a specific tender is driving this, send us the requirement and we will tell you whether Cyber Essentials or Cyber Essentials Plus is the one being asked for.
You get feedback on what did not meet the standard and can resubmit. In practice we would rather find those gaps during our own audit, before submission, which is the point of doing the gap assessment first.
Yes. Home workers and the devices they use for work are in scope, which surprises people. Company-managed laptops used at home need the same five controls as anything in the office.
Tell us about your setup and we'll come back within one business day with a free, no-obligation IT health check.