Cyber Essentials is a information assurance scheme operated by the National Cyber Security Centre (NCSC) that helps organisations to protect themselves against online threats.
The Government collaborated with the Information Assurance for Small and Medium Enterprises (IASME) and the Information Security Forum (ISF) to create a set of technical controls to help organisations protect themselves against online security threats.
The complete scheme was launched on June 5, 2014. The Federation of Small Businesses (FSB), the Confederation of British Industry (CBI) and several insurance companies support it.
We started off using spreadsheets and it was a nightmare. With the ISMS.online solution, all the hard work was made easy.
The Cyber Essentials scheme is the UK Government’s answer to a safer internet space for any organisation of any size. 80% of the most common cyber security threats are covered by the Cyber Essentials controls. Developed and defined by the National Cyber Security Centre, implementation of these basic controls by your organisation should mitigate your business from the risk of cyber attacks.
Cyber Essentials certification provides a way of demonstrating to customers, investors, insurers and others that you have taken the minimum precautions to protect your organisation against cyber threats.
Cyber Essentials and its Plus variant differ in one way, Cyber Essentials Plus includes the requirement for an independent assessment to be carried out by an auditor for the purpose of certification.
Cyber Essentials Plus is the maximum level of certification (against Cyber Essentials) involving a more stringent test on an organisation’s systems by a 3rd party.
I certainly would recommend ISMS.online, it makes setting up and managing your ISMS as easy as it can get.
Irrespective of your company size, you could be a target of a cyber attack. Suppliers, vendors, and larger companies are all part of a network entwined with each other.
The damage caused by a cyber security breach will ripple down your supply chain. To ensure they are not the weakest link, organisations need to evaluate their threat profile, implement strategies and employee training in cyber security. The fines and costs associated with data breach can put small organisations out of business or cause irreparable damage.
Cyber Essentials costs start from £300 + VAT.
Costs are dependent on the size and complexity of your organisation, the cost of preparing for Cyber Essentials Plus will be different.
Cyber Essentials certification is a requirement for government contract tenders.
Suppliers will have to comply with the Cyber Essential controls if they bid on government contracts. This mandate was introduced, October 1, 2014, during the Conservative and Liberal Democrat coalition government period.
For example, the Education Skills and Funding Agency (ESFA) has introduced requirements that universities, colleges, training, contractors and employers within higher education must be Cyber Essentials compliant (2020/2021), Cyber Essentials Plus certified (2021/2022) or demonstrate compliance to an equivalent framework or standard.
Further requirements to become ISO 27001 certified and the need to demonstrate a business continuity policy are intended to be introduced at a later date.
ISO 27001 is the more comprehensive certification, but the Cyber Essentials guarantees the core elements of your business security are in line with the National Cyber Security Centre standards.
A Cyber Essentials badge can be viewed as an essential indicator of cyber security, even though ISO/IEC 27001 is seen as offering a more extensive level of assurance.
There will be some clients who will require a Cyber Essentials certificate. The two should be seen as being complementary rather than competing.
– | ISO 27001 | Cyber Essentials |
---|---|---|
What is it | The requirements of an Information Security Management System to manage information security risk are set out in an international standard. The standard is not mandatory however many contracts require it. | The NCSC backed UK assurance scheme addresses five technical security controls to help businesses address common vulnerabilities. It’s a requirement for government contracts to have cyber essentials. |
Risk | ISO 27001 uses a risk-based approach, where they set their risk acceptance criteria and risk methodology. This can be used to determine how risks are addressed. | In order to address the most common vulnerabilities in the organisation, Cyber Essentials is needed. It’s not a risk-based approach at all. |
Recognition | Around the world, ISO 27001 is recognised as an international standard. | Cyber Essentials is a UK based scheme that is not well known in other countries. |
Time to implement | Months. | Days to weeks. |
Certification process | The certification is provided by a certifying body. Stage 1 and Stage 2 audits are included in this. As long as the organisation passes the audits, certification lasts for three years. | If you want to take Cyber Essentials Plus, you need to complete a self-assessment questionnaire, undergo vulnerability scans, and be assessed by a IASME Cyber Essentials Assessor. It is a requirement that certification be repeated annually. |
Costs | Medium to high cost. | Low cost. |
Scope | The scope is defined by the organisation, but the standard is more than just focused on IT. | Cyber Essentials focuses on:
|
Applicability | Aimed at businesses of all sizes. | Aimed at all businesses, but also targets smaller businesses that may not have thought about cybersecurity. |
Cyber Essentials focuses on fundamental technical controls, but it’s not enough for GDPR.
You can display to the ICO that you are on the right path by using the technical controls of Cyber Essentials putting your organisation on the right path to GDPR compliance.
As GDPR is a extensive regulation that requires businesses protect personal data; for example:
Remember, if your organisation handles personally identifiable information of EU citizens, you must comply with GDPR. Abiding by the Cyber Essentials does not ensure compliance with GDPR.
There are five basic control areas that organisations should tackle to mitigate risk from the most common cyber attacks. These controls shows a clear commitment to improving your organisations approach to cyber security.
These five control areas should prevent up to around 80% of cyber attacks.
It helps to remember that technology is only as effective as the people using it when it comes to security, even though the five controls outlined in Cyber Essentials are fundamental technical measures. It is always advisable to conduct staff awareness training to mitigate the risk of mistakes by employees.
While Cyber Essentials is a good start, the new General Data Protection Regulation (GDPR) means you must demonstrate your commitment to protecting personal data for your staff, customers and other EU/UK citizens. Cyber Essentials compliance helps with some of the computer and network security requirements of the GDPR.
ISMS.online can help you comply with the new regulations right now, and whether or not you get Cyber Essentials today or in the future. It’s not a question of one or the other, but if you are considering the improvement of your information security, then we suggest you start with GDPR compliance and consider applying for Cyber Essentials later. You are then in a great place to start protecting all your valuable information assets by aligning to, or achieving, ISO 27001 certification.
A tailored hands-on session based on your needs and goals
ISMS.online will save you time and money
Get your quoteWe can’t think of any company whose service can hold a candle to ISMS.online.
Easily collaborate, create and show you are on top of your documentation at all times
Find out moreEffortlessly address threats & opportunities and dynamically report on performance
Find out moreMake better decisions and show you are in control with dashboards, KPIs and related reporting
Find out moreMake light work of corrective actions, improvements, audits and management reviews
Find out moreShine a light on critical relationships and elegantly link areas such as assets, risks, controls and suppliers
Find out moreSelect assets from the Asset Bank and create your Asset Inventory with ease
Find out moreOut of the box integrations with your other key business systems to simplify your compliance
Find out moreNeatly add in other areas of compliance affecting your organisation to achieve even more
Find out moreEngage staff, suppliers and others with dynamic end-to-end compliance at all times
Find out moreManage due diligence, contracts, contacts and relationships over their lifecycle
Find out moreVisually map and manage interested parties to ensure their needs are clearly addressed
Find out moreStrong privacy by design and security controls to match your needs & expectations
Find out more100% of our users Achieve ISO 27001 certification first time