Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability assessment, organisations can identify and fix security gaps in internet connections, endpoints, and cloud services – ideally before attackers exploit them. This independent validation has been proven to reduce cyber risk by up to 80% (as seen with St. James’s Place), build trust with clients, support compliance requirements, and can open doors to contracts.
Introduction
Cyber Essentials Plus is a UK government-backed annual certification scheme that builds on the foundation of Cyber Essentials, to help organisations protect against common cyber threats. It references the same five key technical controls as Cyber Essentials (level one), which relate to firewalls, secure configuration, security updates, access control, and malware protection. With Cyber Essentials Plus (level two), organisations benefit from a hands-on technical audit of systems, verifying that the security controls are in place and working effectively.
Cyber Essentials Plus is suitable for organisations of all sizes and is designed for organisations that want to demonstrate a higher level of assurance – to clients, regulators, and partners. It can be chosen by organisations handling sensitive data, bidding for government contracts, or looking to demonstrate effective cyber resilience.
The certification helps reduce risk and builds trust. In this article, we look at the top 10 benefits of Cyber Essentials Plus and why it can be a valuable investment for organisations of any size.
Cyber Essentials Plus Explained
- A UK government backed cyber security scheme with annual certification
- Requirements set by the National Cyber Security Centre (NCSC)
- An independent technical audit
- Active testing:
- Remote vulnerability assessment – test whether an internet-based opportunist attacker can hack into the application system with typical low skill methods
- Check patching by authenticated vulnerability scan – identify missing vulnerability fixes, such as missing patches, updates, registry fixes, configuration changes, or scripts
- Malware protection – check devices benefit from at least one form of malware protection (anti-malware software or application allow listing)
- Multi-factor authentication (MFA) – test cloud services have been configured for MFA
- Account Separation – test accounts don’t have administrator privileges assigned
Benefits of Cyber Essentials Plus
- Independent validation – Cyber Essentials Plus testing is based on hands-on testing, carried out by an IASME certified Assessor, with proven skills and deep experience in areas such as vulnerability assessment
- Scope accuracy – one of the prerequisites for Cyber Essentials Plus testing is to align with the Certification Body on the scope of the assessment, so it’s a great opportunity for the applicant to have an independent assessor confirm an accurate scope has been applied.
- Identify and remediate internet connection vulnerabilities – testing requires specialist (vulnerability assessment) tools to be used, with deep scanning capabilities, which can identify weaknesses with internet connections that may otherwise go unnoticed. By highlighting these vulnerabilities, fixes can then be applied to reduce risk and avoid exploitation.
- Identify and remediate vulnerabilities on end points and servers – the vulnerability assessment tools can also identify weaknesses on end-points and servers. These can relate to missing patches, insecure configurations that require registry changes and obsolete software. By highlighting these vulnerabilities, organisations can better understand the risks and apply fixes.
- Confirm devices have adequate malware protection – active testing takes place to understand and measure how organisational systems and devices react to malicious software. By carrying out the tests, applicants have first-hand visibility of what those protections are and how the devices react when exposed.
- Reduced risk for cloud service authentication attacks – attacks using credential stuffing and brute force techniques can identify usernames and passwords, leading to compromised accounts and data breaches – testing cloud services for multi-factor authentication can lead to a reduction of that risk
- Validate account separation – malicious software and cyber-attacks can be more impactful when administrator level accounts are being used, so the account separation check helps ensure there would be a reduced impact via web browser and email attack vectors.
- Competitive advantage – By achieving Cyber Essentials Plus certification, organisations can publicly extend their commitment to cyber security. Further building trust with customers, suppliers and stakeholders.
- Ability to bid for contracts – Cyber Essentials Plus can be a requirement when applying for contracts, funding and grants. Increasingly organisations are requiring Cyber Essentials Plus in their supply chain and procurement processes.
- Support for UK Data Protection – Cyber Essentials Plus can further help organisations comply with the UK Data Protection Act 2018, by demonstrating personal data has protection against common internet based threats. The Cyber Security and Resilience Bill is also making its way through Parliament and is setting out requirements for organisations to strengthen their supply chain security. Based on the proven success of Cyber Essentials Plus in the supply chain, this certification may be a key leverage for organisations to help demonstrate security within their supply chain.
Relatable Case Study 1
- Organisation: St. James’s Place (Financial Service Sector)
- Challenge: faced with evolving cyber threats, St. James’s Place needed to strengthen their cyber hygiene across their network of 2,800 independent advisors
- Solution: The organisations adopted Cyber Essentials to establish a baseline of security across their partnership network
- Impact: The certification helped reduce vulnerabilities, improve client trust and support compliance with regularity expectations – with around 80% reduction in cyber security incidents
Source: https://iasme.co.uk/articles/wealth-management-firm-st-jamess-place-mandates-cyber-essentials-plus-across-network-of-partner-organisations/
Relatable Case Study 2
- Organisation: Apputee (micro sized start-up)
- Challenge: Required a solution to protect sensitive data and provide a foundation of cyber security principles
- Solution: Organisation achieved Cyber Essentials and Cyber Essential Plus
- Impact: The certification helped the organisation feel more comfortable with cyber security and to be more empowered
- Source: https://iasme.co.uk/articles/micro-start-up-prioritises-cyber-security-to-empower-amputees/
How We Help
At RB Consultancy Ltd, we support organisations by:
- Providing templates, guidance and experience to support
- Explaining what security measures are available and how they can help
- Collaborating to implement controls to support the requirements
- Assessing and issuing certifications – such as Cyber Essentials and Cyber Assurance
- Contact us for consultancy and certification support
Conclusion
Cyber Essentials Plus offers a robust framework for enhancing an organisation’s cyber security posture. By validating the effectiveness of the security measures through a technical audit, organisations can reduce the risk of cyber threats and build trust with clients, regulators, and partners. The certification demonstrates a commitment to cyber security, can provide a competitive advantage and allow for bids to be made for specific contracts. Cyber Essentials Plus is a valuable investment for organisations of any size, ensuring a higher level of assurance and protection against cyber threats.RB Consultancy Ltd helps organisations with Cyber Essentials Plus – we support the implementation of appropriate measures to help build cyber resilience. We are an IASME Certification Body and NCSC Assured Service Provider who provide services to empower and protect organisations. Holding CISSP and ISO 27001 lead implementer certification, you can Contact Us for assistance with cyber security resilience.












