Cyber Essentials Support for Kent Businesses

Get ready for Cyber Essentials without the jargon. We help Kent SMEs understand the requirements, fix the gaps and submit with confidence, guided by an IRCA ISO 27001 lead auditor.

What is Cyber Essentials?

Cyber Essentials is the UK Government-backed scheme that shows your business has the basic protections in place against the most common cyber attacks. It's run by the National Cyber Security Centre (NCSC) and its delivery partner IASME.

More and more SMEs are being asked for it. It's required for many central government contracts, it's increasingly requested by local councils, the NHS, housing associations and main contractors, and many insurers look more favourably on businesses that hold it.

The five controls you need to meet

Cyber Essentials checks five areas of your IT:

  • Firewalls. Your internet connection and devices are protected by properly configured firewalls.
  • Secure configuration. Default passwords are changed and unnecessary software and accounts are removed.
  • User access control. Staff only have the access they need, admin accounts aren't used for everyday work, and multi-factor authentication is switched on for cloud services.
  • Malware protection. Antivirus or equivalent protection is active and kept up to date.
  • Security update management. All software is still supported by the manufacturer, and critical updates are applied within 14 days.

How we help

Most businesses don't fail Cyber Essentials because their IT is bad. They fail because they misunderstand a question, leave something out of scope, or miss one unsupported laptop. We make sure that doesn't happen.

  1. Free consultation. We explain what's involved and whether Cyber Essentials or Cyber Essentials Plus is right for you.
  2. Scoping. We work out exactly which devices, users, offices and cloud services need to be included.
  3. Gap check. We go through the requirements with you and identify anything that would fail.
  4. Clear fix list. You get a plain-English list of what needs changing. Your IT person or provider makes the changes, and we're on hand to answer their questions.
  5. Final review. We check your answers and evidence before you submit, so you're ready to pass.

Your assessment is then marked by an independent, IASME-licensed Certification Body. The certification fee is paid to them separately, and we'll tell you the exact cost up front.

Independent advice, not a sales pitch

Many businesses go straight to a Certification Body. That works, but many Certification Bodies also sell IT services, software or fixed-price remediation packages, so the company telling you what needs fixing is often the same one selling you the fix.

ISOHS is an independent advisor. We don't sell hardware, software or IT contracts, and we don't earn commission from anyone. That means:

  • Options, not one answer. Where something needs fixing, we explain the alternatives, from free built-in settings to paid products, so you choose what suits your budget.
  • Use who you already have. Your existing IT provider, or your own staff, can make the changes. You're not tied to a particular supplier.
  • Compare quotes with confidence. If you do need outside help, we'll help you understand what you're being quoted for and whether you actually need it.
  • Free choice of Certification Body. When you're ready, you pick the Certification Body you want for the assessment. We'll help you compare.

Cyber Essentials Plus

Cyber Essentials Plus uses the same five controls but adds a hands-on technical audit of your systems by a licensed assessor. We help you prepare so your devices and settings are ready before the assessor arrives, reducing the risk of failures and retests.

Why ISOHS

  • ISO 27001 lead auditor (IRCA). Information security is part of what we audit, so we know how assessors think.
  • Plain English. We explain the requirements in business terms, not IT jargon.
  • Independent. We're not a Certification Body or an IT reseller, so we give you options and alternative quotes rather than a single package to buy.
  • One consultant for everything. Many clients combine Cyber Essentials with ISO 9001, ISO 27001 or SSIP accreditation, as the same tenders often ask for all of them.

Cyber Essentials, ISO 27001 and SSIP

Cyber Essentials and ISO 27001. Cyber Essentials covers basic technical controls. ISO 27001 is a full information security management system. Cyber Essentials is a quick, affordable first step, and the work you do counts towards ISO 27001 later.

Cyber Essentials and SSIP. Contractors applying for CHAS, SMAS or SafeContractor are often asked about cyber security in the same tender. We can handle both together.

Cyber Essentials: common questions

How long does it take?

For most small businesses, two to four weeks from first conversation to submission, depending on how much needs fixing. Certification is valid for 12 months.

How much does it cost?

There are two parts: our support fee, which we quote as a fixed price after the free consultation, and the certification fee paid to the Certification Body, which is set by IASME and depends on the size of your business.

Do we need an IT company to do the work?

Not always. Many small businesses can make the changes themselves with our guidance. If you have an IT provider, we work alongside them.

Why not just go straight to a Certification Body?

You can, and some businesses do. The difference is that we're independent: we don't sell IT products or services, so we show you the different ways to fix each gap and let you choose, rather than offering one fixed package. You stay free to use your own IT provider and pick any Certification Body you like.

What usually causes a fail?

The most common problems are unsupported software, such as old versions of Windows, missing multi-factor authentication on Microsoft 365 or Google Workspace, and staff using admin accounts day to day. We check for all of these before you submit.

Do you cover the whole of Kent?

Yes. We support businesses across Kent and the South East, with on-site visits where helpful and remote support for everything else.

Get Cyber Essentials sorted

Book a free consultation and we'll tell you how close you already are, and what it will take to pass.