The Cyber Essentials Assessment Scheme
We can help you achieve Cyber Essentials, Cyber Essentials Plus Certification and IASME Cyber Assurance.
Your Certification made easy: Pass first time and get your Cyber Essentials Certificate
What is a Cyber Essentials Certification?
Cyber Essentials and Cyber Essentials Plus is a NCSC government-backed scheme which establishes the basics of security which all businesses should follow.
As a long-established Cyber Essentials assessor, Equilibrium can help you:
- Achieve Cyber Essentials
- Strengthen your security measures
- Demonstrate to your customers that you are following best practice
Equilibrium Security are one of the few Cyber Essentials Certification bodies within the Midlands. We have been working alongside IASME conducting Cyber Essentials and Cyber Essentials Plus assessments since 2016.
Ready to achieve your security goals? We’re at your service.
Whether you are a CISO, an IT Director or a business owner, Equilibrium has the expertise to help you shape and deliver your security strategy by guiding you through your Cyber Essentials questionnaire and assessment.
Cyber Essentials 5 Key Security Controls
Firewalls and routers
A firewall must be in place to protect your internet connected devices.
Software updates
Regularly update your applications & critical systems to identify & remediate vulnerabilities.
Malware protection
Protect your organisation from virus’s, malware, and other cyber-risks.
Access controls
Reduce the likelihood of unauthorised access, by controlling who can access sensitive data.
Secure configuration
Prevent hackers gaining unauthorised access to your systems.
Cyber Essentials basic
What is the Cyber Essentials Certificate?
The Cyber Essentials scheme is a self-assessment questionnaire that is completed via an online portal. The questions are based around its five key security controls, their aim to review your current security posture and identify areas for improvement.
Our expert security consultants provide remote support to guide you through the process and help you achieve the Cyber Security Essentials certificate quickly and painlessly.
Cyber Essentials Plus
What is the Cyber Essentials Plus Certificate?
Cyber Essentials Plus is the next stage on from the basic Cyber Essentials self-assessment certification. It tests an organisations security against the information obtained in the Cyber Essentials self-assessment questionnaire. As part of the certification, we will run a series of security tests and carefully managed attacks to test the effectiveness of your security controls. Think of Cyber Essentials Plus as a in-depth practical checklist.
If there are areas that we identify that are in breach of the assessment, we will provide remediation actions that you will need to apply prior to us issuing the certification. Equilibrium Security will then issue the certification for Cyber Essentials Plus, which will be valid for 12 months.
Customer Feedback
Why Equilibrium?
- As a Cyber Essentials certification body since 2016, we are well-versed with the schemes evolving criteria.
- Our team have certified countless companies throughout the years to achieve Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance.
- We're with you every step of the way of the certification process to help you pass with flying colours!
The Cyber Essentials Process
Before we can provide a quote or proceed with the Cyber Essentials assessment we need to understand your environment so that we can fully define the technical scope of what the test will cover. Think of it as a Cyber Essentials certificate check before the questions start.
You can then move onto populating the online questionnaire. Before this is submitted, our consultants will review your answers to check they meet the scheme’s criteria. We will check the Cyber Security assessment questions and the answers you provide thoroughly. If changes are required, we provide detailed guidance on areas which need improvement. Once successful, you will be issued with a Cyber Essentials certificate for 12 months.
Our experts will remotely conduct external and internal vulnerability tests, as well as a series of other security checks from your Cyber Essentials answers to test the information obtained in your Cyber Essentials questionnaire answers.
If vulnerabilities are discovered, or other areas of non-compliance, we will provide detailed remediation guidance which needs to be applied within 30 days of the Cyber Essentials Plus assessment.
Once you have followed all remediation steps, we will conduct a retest to check your Cyber Essentials plus criteria. You will then be awarded your Cyber Essentials Plus certification for 12 months.
The Benefits of Cyber Essentials
Win new business
Cyber Essentials helps to assure new customers that you take the security of your business seriously and follow industry best practice.
Public sector contracts
Cyber Essentials and Cyber Essentials Plus permits you to work with the government and MOD.
Cyber Liability Insurance
Benefit from up to £25,000 worth of cyber insurance as part of the certification, conditions apply.
Reduce the risk of a breach
Improve cyber-resilience by implementing the baseline security requirements of the Cyber Essentials five security controls.
Want to prepare for Cyber Essentials Assessment?
We would never want you to go in blind into a self-assessment, so we have created a Cyber Essentials checklist to make sure you’re well prepared.
Here’s what to expect for a Cyber Essentials Plus Assessment:
- A qualified assessor will carry out an audit on a selection of computers to verify their alignment with the scheme’s specifications.
- The auditor will perform a vulnerability scan on these devices to ensure that patching and fundamental configurations meet the required standards.
- An external port scan of your publicly accessible IP addresses will be executed to detect any misconfigurations or vulnerabilities.
- Testing will be conducted on your default email and internet browser settings to validate their configuration and their ability to thwart the execution of potentially harmful files.
- Screenshots will be captured as evidence demonstrating the system’s compliance with Cyber Essentials.
A quick guide to the Cyber Essentials Plus Checklist
Before you complete, it’s a good idea to look over these areas and equipment as they will be assessed for your Cyber Essentials certification.
Cyber Essential Assessment plus checklist :
- Hardware and Devices: Ensure you know all the electronic equipment your organisation uses, such as computers, laptops, phones, and printers. Keep an inventory and understand ownership.
- Software and Firmware: Know your software and firmware, ensuring they're up-to-date and supported by manufacturers. Keep a list of all software used.
- Boundary Devices: Check your office firewall and router. Change default passwords and secure them against external threats.
- Firewalls and Internet Gateway: Protect your internet gateway with a firewall. Review and configure your settings, blocking unnecessary services.
- Cloud Services: List all cloud services used, enable Multi-Factor Authentication (MFA) on all accounts, and understand your shared security responsibilities.
- Secure Configurations: Disable unnecessary software and ensure default passwords are changed. Enhance security settings.
- Protection Against Malware: Keep all devices updated with automatic updates. Install and update antivirus software to protect against malware.
- User Accounts: Establish processes for creating, tracking, and managing user and admin accounts. Ensure admin accounts are used responsibly.
- Use of Passwords: Ensure that you are utilising the best protection for password guessing, establishing password quality management and user support and education within your organisation.
Looking for a top Cyber Essentials certification body?
Equilibrium is a Certification Body for The IASME Consortium, the Cyber Essentials Partner to the National Cyber Security Centre (NCSC). We can offer Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance and GDPR Readiness Assessments as a Certification Body.
If you would like to find out more about our Cyber Essentials pricing please arrange an expert call or call us on 0121 663 0055.
- Cyber Essentials
- IASME Cyber Assurance (excellent alternative to ISO 27001)
- GDPR Readiness Assessments
Frequently Asked Questions
The simple answer is no. Before you can move onto the Cyber Essentials Plus, you must first pass the Cyber Essentials basic certification, as the Plus audit assesses the information provided in your Cyber Essentials questionnaire. Once CE basic is achieved, you then meet the Cyber Essentials Plus requirements and can complete within 90 days.
Cyber Essentials basic is a self-assessed and independently verified questionnaire. The assessment has 70 questions which qualify that your current approach to securing your business is in-line with the CE framework. Cyber Essentials Plus provides a higher level of assurance, it involves us auditing your systems utilising many vulnerability tools to test the effectiveness of the security measures in place. You will not need to complete a Cyber Essentials Plus questionnaire, only for Cyber Essentials basic.
Unfortunately you will not being able to see the Cyber Essentials example questions or answers before it takes place. You will only be able to access the questions once you are set up on the portal.
Cyber Liability Insurance is provided as part of the Cyber Essentials certification package on an ‘opt-in’ basis. The cyber insurance is available for businesses with an annual turnover of under 20 million, conditions apply.
Yes, Cyber Essentials and Cyber Essentials Plus certificates are due for renewal after 12 months. If you choose not to renew, your business will be removed from the NCSC’s ‘certified organisations’ list, you will also lose your cyber insurance and ability to work with public sector companies.
If you are unsure whether or not your business is ready to undertake a Cyber Essentials or Cyber Essentials Plus assessment we can run a Gap Analysis before you move forward.
Our gap analysis carefully reviews your current Cyber Security to make sure it meets Cyber Essentials Plus requirements. It helps spot areas that don’t comply before your main assessment, giving you a chance to prepare.