Lenovo ThinkPad no-POST BIOS firmware recovery in Putney SW15
Lenovo ThinkPad wouldn't POST after a failed BIOS update. At our Putney SW15 workshop we reprogrammed the SPI flash chip with verified Lenovo firmware.
Gap assessment, remediation and assisted application — we get your business ready, and an accredited certification body carries out the assessment
Last updated: August 2026
Cyber Essentials is the UK government-backed scheme that shows a business has the basic security controls genuinely in place. More and more contracts ask for it before you can even bid — public sector work in particular. Getting there means five specific control areas have to hold up under scrutiny, and small firms tend to trip on the same handful of things: personal laptops nobody manages, sign-ins without multi-factor authentication, software that stopped being patched years ago. Our job is the readiness work. We assess where you stand today, put right what would fail, help you gather the evidence, and support you through the self-assessment. The assessment itself is carried out by an accredited certification body — we make sure you walk into it prepared.
We have run our Putney workshop for over 25 years and the business is fully insured — worth knowing when someone is coming into your home or office. Security and network work is led by a CISSP-certified consultant.
Same-day turnaround is available on many jobs — ask when you book and we will confirm availability and any additional cost before we start.
We review your systems against the five Cyber Essentials controls and tell you plainly where you'd pass today and where you'd fail. No scare tactics — just a clear, prioritised list of what needs attention before you apply.
Most businesses fail on the same things: devices that aren't updating, accounts without multi-factor sign-in, admin rights handed out years ago, an old router on default settings. We put those right rather than simply writing them up in a report.
Laptops, desktops, phones and tablets brought to a consistent standard — supported operating systems, automatic updates, encryption where it's required, and user permissions that reflect who actually needs what.
The questionnaire asks you to describe what's in place, and your answers need to be accurate. We help you pull together a proper device inventory, configuration evidence and policy wording so what you declare matches reality.
We work through the self-assessment questionnaire alongside you and explain what each question is really asking, so nothing gets answered wrongly by accident. The assessment is then carried out by an accredited certification body.
Cyber Essentials is renewed each year, and standards drift in between. We keep the controls maintained through the year so the next round is a quick confirmation rather than a fresh scramble a fortnight before the deadline.
Simple steps to get your problem solved quickly and professionally.
A short conversation about your business — how many devices and accounts are involved, how people work, and whether you're aiming for Cyber Essentials or Cyber Essentials Plus. We tell you honestly what's involved before you commit.
We check your setup against the five control areas and give you a plain-English report: what would pass, what would fail, and what closing each gap actually involves. Some are ten-minute fixes; some need kit replaced.
We fix the gaps — updates, sign-in security, device configuration, firewalls and admin accounts — and record what changed, so the answers you give later are backed by evidence rather than optimism.
We help you complete the self-assessment accurately, then it goes to an accredited certification body for assessment. If anything is queried, we're on hand to sort it out rather than leaving you to interpret it alone.
Prefer the quick version? The sections above cover most needs. Expand any topic below for more detail.
It's rarely about the badge on the website. Almost every business that asks us about Cyber Essentials has one of these four reasons:
A contract asked for it
It's frequently required to bid for public-sector work, and larger private clients increasingly ask for it as part of supplier checks. No certificate, no place on the shortlist — which is why most enquiries arrive with a deadline attached.
Clients want assurance
Security questionnaires now turn up routinely in client due diligence. Being able to point to an independently assessed baseline is a far shorter answer than trying to describe your setup from scratch each time.
It forces a real baseline
The five controls aren't paperwork. Working through them tends to surface the laptop that stopped updating, the shared administrator password, and the account belonging to someone who left two years ago.
It's a sensible starting point
For a small team with no IT department, the scheme is a ready-made definition of what 'good enough' looks like — far more useful than guessing which security advice to follow.
It isn't a legal requirement for most businesses. But if you sell to the public sector or to larger companies, it's increasingly the price of entry.
Cyber Essentials covers five technical control areas. Stripped of the jargon, here's what each one asks of a small business:
There are two levels: the standard self-assessment, and Cyber Essentials Plus, which adds a hands-on technical audit of a sample of your devices. We prepare businesses for both.
None of the five controls asks you to train anyone — yet the incidents we are called out to almost always begin with a person, not a machine. The government's Cyber Security Breaches Survey puts staff awareness training at around one UK business in five, against roughly four in five of the largest organisations. It is one of the cheapest gaps a small firm can close, so we cover it alongside the technical work:
The scams that actually arrive
Not generic advice about Nigerian princes. Fake invoices with the bank details changed, a message that appears to be from a director asking for an urgent payment, a Microsoft 365 sign-in page that looks exactly right, and delivery notifications timed for when everyone is expecting a parcel.
How to check before you act
Two or three habits that stop most of it: how to see where a link really goes, why urgency in an email is itself a warning sign, and the rule that any change to payment details gets confirmed by phone on a number you already had — never one supplied in the message.
What to do in the first ten minutes
Someone will click eventually, and the damage usually depends on what happens next. Who to tell, why saying so immediately matters more than feeling embarrassed, and the sequence — change the password, sign out other sessions, check for a forwarding rule quietly copying your mail elsewhere.
Making reporting safe
Teams that get told off for clicking stop reporting, and silent incidents are the expensive ones. We help you set the tone so that flagging a mistake early is treated as the useful thing it is.
To be clear about what this is: practical guidance delivered by us as part of readiness work. It is not an accredited training platform and it does not issue training certificates — if you need certificated e-learning with completion records, that is a separate product from a training provider and we will point you at what to look for.
Worth being clear about the line, because it isn't obvious from most IT companies' websites:
Our job is simply to make sure that when the assessment happens, nothing about it comes as a surprise.
Not sure what you need? We're happy to help.
Lenovo ThinkPad wouldn't POST after a failed BIOS update. At our Putney SW15 workshop we reprogrammed the SPI flash chip with verified Lenovo firmware.
A Balham SW12 home office had a new Dell WD25 dock that charged the laptop but wouldn't drive either new monitor. We fixed the configuration on site in one visit.
What IT support really costs in the UK in 2026 — market rates per user, hourly and ad-hoc pricing, what drives the price, and our own published figures.
What Bambu Lab HMS error codes mean and how to fix the common ones — AMS feed, Z-homing, nozzle clog and heatbed errors — plus how to look up any code.
Different sectors carry different risks. Each guide below covers the systems, compliance pressures and failure points we see most in that line of work.
We provide Cyber Essentials Readiness for Small Businesses in London across South West London
Serving Wandsworth, Wimbledon, Putney, Clapham, Balham, Tooting, and surrounding areas.
View all service areasTell us what a client or tender has asked of you and we'll tell you honestly how far off you are. Gap assessment first, then a clear plan — no jargon, no pressure, and no surprises when the assessment comes round.