Skip to Content

Published 27/05/2016 – est. 3 minutes to read.

Welcome to our first Blog!  We are regularly asked by our Clients: “Should I implement ISO 27001, Cyber Essentials, or both?”  The answer depends on the Organisation, its Business goals, compliance requirements, resources, and, of course, budget!

So let’s recap – what is Cyber Essentials?  Cyber Essentials is a government-backed, industry-supported scheme to help organisations protect themselves against common cyber-attacks.  Cyber Essentials helps organisations of all sizes guard against common cyber threats. It shows their commitment to cybersecurity to customers, partners, suppliers, and regulators. It’s not new; it’s been around since June 2014, and since October 2014, the UK government has required all suppliers bidding for certain sensitive and personal information-handling contracts to be certified under the Cyber Essentials scheme.

So what’s covered?  The Cyber Essentials certification covers the following 5 areas:

  • Network Security
  • Secure Device Configuration
  • User Access Control
  • Malware Protection
  • Patch Management

What is ISO27001?  ISO 27001 is the international standard that describes best practices for implementing an information security management system (ISMS).  An ISO27001 ISMS is a system of processes, documents, technology, and people that helps manage, monitor, audit, and improve your organisation’s information security. It helps you manage all your security practices in one place, consistently and cost-effectively.  Cyber Essentials focuses solely on the technical controls and approaches that an Organisation should adopt to improve its cyber defences.  They complement each other perfectly.

Cyber Essentials certification is achieved by performing a Gap Analysis of your company’s Cyber Security posture against the Cyber Essentials Audit questionnaire.  Where gaps are identified, action must be taken to make the required changes to comply with the Audit controls.  Once completed, the questionnaire is submitted to a Certification Body and reviewed.  Many of our customers are terrified of Cyber Essentials, but with a little hand-holding and guidance, they can become certified in a relatively short period of time.  Cyber Essentials Plus provides a higher level of assurance, in which an independent assessor examines the same five controls and tests whether they work in practice by simulating real-world hacking attacks.

Cyber Essentials and Cyber Essentials Plus is a well worth investment for Organisations of all shapes and sizes, and in some cases it is only when schemes like these are embraced and implemented, Organisations actually realise that their level of Cyber Security defence is weak – whether this be default administrator passwords on internet facing gateways or a number of File and Application Servers that haven’t been patched for over 12 months!

Another question we often get is: isn’t Cyber Essentials for small Organisations?  The answer is No!  Cyber Essentials/Cyber Essentials Plus is designed for organisations of any size – even the largest banks, such as Barclays, are Cyber Essentials- and Cyber Essentials Plus-certified!

If you would like to hear more about how Cyber Security Specialists can help your Organisation achieve Cyber Essentials, Cyber Essentials Plus or ISO27001, please email info@cybersecurityspecialists.co.uk or call 0161 706 0244 to speak to a member of the team.

Contact us

Related Pages

Cyber Essentials Icon.

Cyber Essentials

 

Learn more about Cyber Essentials

Cyber Essentials Plus Icon.

Cyber Essentials Plus

 

Learn more about Cyber Essentials Plus

CS360 ai icon.

CS360.ai Exposure Management Platform

 

Learn more about CS360.ai