ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

Achieving Cyber Essentials certification

Terry Lewis at RoboShadow asks whether organisations are ready for the updated Cyber Essentials framework

Linked InXFacebook

Cyber Essentials has long been the UK government’s baseline for cyber-security, and for good reason. It’s practical, accessible, and when applied properly, it works. The success of Cyber Essentials has never really come from requiring organisations to deploy cutting-edge security technologies; rather, it’s always been focused on making sure fundamental security controls are in place.

 

That said, for too long many organisations have treated it like a tick-box exercise. The threat landscape hasn’t stood still, so it’s only natural that the framework has had to adapt. The increased emphasis on demonstrating continuous visibility and ongoing security assurance, rather than relying on a one-off assessment, is undoubtedly going to cause some discomfort for organisations. But if businesses aren’t already thinking this way, the reality is they’re probably already behind the curve.

 

In many respects, this update is both necessary and long overdue. We’re now in an era of advancing AI threats, where security through obscurity is no longer a viable option. Cyber Essentials remains the foundation that every organisation should be building on, because getting the basics right is still the most effective way to start. Organisations that embrace this mindset will be in a much stronger position to remain resilient, stay competitive, and meet their compliance obligations along the way.

 

 

The end of wiggle room

Previous versions of Cyber Essentials left far too much room for interpretation. Businesses could squeeze through certification while quietly ignoring the real purpose of the controls. Scope was narrowly defined, exclusions were applied liberally, and devices were left out of assessments because they were “legacy” or “not business critical. Those days are over.

 

The updated framework shuts down the loopholes. Scope is broader, definitions are tighter, and expectations around MFA, software patching and firewall configuration are tougher, and cloud services and personal devices are firmly in play. The government is sending a very clear message: Cyber Essentials should reflect how organisations actually operate and not how they wish they operated.

 

And that’s a good thing. A watered-down certification is worse than no certification at all because it gives businesses a false sense of security. The updated framework forces organisations to confront their real attack surface, and that’s exactly where the conversation needs to be.

 

 

Certification takes longer than you think

A common mistake that organisations make is underestimating how long it takes to identify and fix gaps in the lead-up to Cyber Essentials renewal. Organisations might assume that because they obtained certification last time, they must be in good shape.  The reality is that what worked before is no longer enough.

 

The environment has changed. The framework has changed. Attackers have changed. This isn’t Cyber Essentials “levelling up”, this is Cyber Essentials catching up with reality. When the framework first launched, organisations weren’t dealing with AI-enabled attackers, sprawling cloud estates, or employees accessing corporate data from every corner of the planet – and now we are.

 

With 83% of breaches involving AI according to a recent research report from Gigamon, attackers have more automation, more reach, and more capability than ever before. On top of heightened threats, global research suggests that organisations can only see around 60% of their attack surface at any given time. When cloud services, remote working infrastructure, and employee-owned devices are brought into scope under the new framework, businesses will discover assets they didn’t know existed.

 

Patching - a basic Cyber Essentials requirement - is also becoming more difficult. Just 32% of organisations have policies in place to apply critical updates within 14 days, which is a basic security standard and a core Cyber Essentials requirement. Closing that gap is not simply a matter of running an update. It will involve testing, scheduling, managing legacy systems that cannot easily be patched, and dealing with the operational disruption that comes with it. Businesses must build in far more time for remediation than they typically allow.

 

 

The UK skills gap is real, but not an excuse

The UK’s skills shortage is well-documented, but its impact on an organisation’s ability to be Cyber Essentials compliant is often not discussed.  According to analysis conducted by the UK government, around 49% of UK companies have a basic cyber-security skills gap, meaning they lack the in-house capability to carry out even the foundational security tasks that Cyber Essentials require.

 

Meeting the controls outlined in the updated framework is not actually technically complex. Configuring firewalls correctly, managing user access, and patching software are all basic cyber-security skills. In fact, many of the foundational requirements within Cyber Essentials can be achieved using existing platform features and freely available security tools. MFA, vulnerability scanning, endpoint protection and asset visibility aren’t reserved for large enterprises anymore.

 

However, where most organisations fall short is understanding what ‘good’ looks like, assessing the current state, and having the bandwidth to fix any issues while consistently applying the basics across the entire environment.

 

For the majority of organisations, the answer isn’t to hire its way out of the problem as the talent doesn’t exist at the scale needed. The answer is tooling and automation – platforms that continuously monitor the IT environment, flag non-compliance and provide teams with clear, actionable steps mapped directly to Cyber Essentials.

 

Technology can bridge gaps that headcount can’t, but only if organisations choose tools that simplify problems and don’t add unnecessary complexity or noise.

 

 

What must businesses do now?

All organisations must have comprehensive visibility of their internal and external attack surface. An asset inventory must include everything – corporate devices, cloud services, remote endpoints and personal devices accessing business data. If it touches an organisation’s data or systems, it is likely in scope.

 

Following this, organisations need to assess their current position against the five controls within Cyber Essentials: firewalls, secure configuration, user access control, malware protection, and patch management. Relying on last year’s assessment will be a mistake, as both an organisation’s controls and environment are likely to have changed, in addition to the threat landscape.

 

Multi-factor authentication (MFA) requirements are significantly stricter under the new framework, particularly for cloud services and remote access. This is a major change for organisations; however, getting it right creates a foundation that carries forward into wider regulatory standards, cyber-insurance expectations, and demonstrating appropriate technical measures under GDPR.

 

Ultimately, organisations must stop treating Cyber Essentials compliance as an annual chore and tick-box exercise. Security is continuous, and if they only think about Cyber Essentials once a year, they’re already out of date.

 


 

Terry Lewis is Founder and CEO at RoboShadow

 

Main image courtesy of iStockPhoto.com and Bongkod Worakandecha

Linked InXFacebook
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543