Skip to main content

Cyber Essentials Readiness for Small Businesses in London

Gap assessment, remediation and assisted application — we get your business ready, and an accredited certification body carries out the assessment

4.8-star Google rating 25+ years experience Local & independent Insured, 25+ years

Last updated: August 2026

Overview

Ready for Cyber Essentials, without the guesswork

Cyber Essentials is the UK government-backed scheme that shows a business has the basic security controls genuinely in place. More and more contracts ask for it before you can even bid — public sector work in particular. Getting there means five specific control areas have to hold up under scrutiny, and small firms tend to trip on the same handful of things: personal laptops nobody manages, sign-ins without multi-factor authentication, software that stopped being patched years ago. Our job is the readiness work. We assess where you stand today, put right what would fail, help you gather the evidence, and support you through the self-assessment. The assessment itself is carried out by an accredited certification body — we make sure you walk into it prepared.

An honest gap assessment against the five Cyber Essentials controls
Remediation of what's failing — devices, accounts, patching, firewalls
Help gathering evidence and completing the self-assessment questionnaire
Annual renewal preparation, so you're not starting from scratch each year
Gap assessment first Readiness, not certification Plain-English guidance
What you get

What every cyber essentials readiness job includes

Established and insured

We have run our Putney workshop for over 25 years and the business is fully insured — worth knowing when someone is coming into your home or office. Security and network work is led by a CISSP-certified consultant.

Same-day turnaround is available on many jobs — ask when you book and we will confirm availability and any additional cost before we start.

Features

What Cyber Essentials Readiness Covers

Gap Assessment

We review your systems against the five Cyber Essentials controls and tell you plainly where you'd pass today and where you'd fail. No scare tactics — just a clear, prioritised list of what needs attention before you apply.

Fixing the Failing Controls

Most businesses fail on the same things: devices that aren't updating, accounts without multi-factor sign-in, admin rights handed out years ago, an old router on default settings. We put those right rather than simply writing them up in a report.

Device & Account Hardening

Laptops, desktops, phones and tablets brought to a consistent standard — supported operating systems, automatic updates, encryption where it's required, and user permissions that reflect who actually needs what.

Evidence Gathering

The questionnaire asks you to describe what's in place, and your answers need to be accurate. We help you pull together a proper device inventory, configuration evidence and policy wording so what you declare matches reality.

Assisted Application

We work through the self-assessment questionnaire alongside you and explain what each question is really asking, so nothing gets answered wrongly by accident. The assessment is then carried out by an accredited certification body.

Annual Renewal Preparation

Cyber Essentials is renewed each year, and standards drift in between. We keep the controls maintained through the year so the next round is a quick confirmation rather than a fresh scramble a fortnight before the deadline.

Process

How We Get You Ready

Simple steps to get your problem solved quickly and professionally.

1

Scope

A short conversation about your business — how many devices and accounts are involved, how people work, and whether you're aiming for Cyber Essentials or Cyber Essentials Plus. We tell you honestly what's involved before you commit.

2

Assess

We check your setup against the five control areas and give you a plain-English report: what would pass, what would fail, and what closing each gap actually involves. Some are ten-minute fixes; some need kit replaced.

3

Remediate

We fix the gaps — updates, sign-in security, device configuration, firewalls and admin accounts — and record what changed, so the answers you give later are backed by evidence rather than optimism.

4

Apply

We help you complete the self-assessment accurately, then it goes to an accredited certification body for assessment. If anything is queried, we're on hand to sort it out rather than leaving you to interpret it alone.

In Depth

What to Expect

Prefer the quick version? The sections above cover most needs. Expand any topic below for more detail.

Why small businesses bother with Cyber Essentials

It's rarely about the badge on the website. Almost every business that asks us about Cyber Essentials has one of these four reasons:

A contract asked for it

It's frequently required to bid for public-sector work, and larger private clients increasingly ask for it as part of supplier checks. No certificate, no place on the shortlist — which is why most enquiries arrive with a deadline attached.

Clients want assurance

Security questionnaires now turn up routinely in client due diligence. Being able to point to an independently assessed baseline is a far shorter answer than trying to describe your setup from scratch each time.

It forces a real baseline

The five controls aren't paperwork. Working through them tends to surface the laptop that stopped updating, the shared administrator password, and the account belonging to someone who left two years ago.

It's a sensible starting point

For a small team with no IT department, the scheme is a ready-made definition of what 'good enough' looks like — far more useful than guessing which security advice to follow.

It isn't a legal requirement for most businesses. But if you sell to the public sector or to larger companies, it's increasingly the price of entry.

The five controls, in plain English

Cyber Essentials covers five technical control areas. Stripped of the jargon, here's what each one asks of a small business:

  • Firewalls — your internet connection and your devices are protected by properly configured firewalls, not left on the settings they arrived with
  • Secure configuration — kit is set up deliberately: default passwords changed, unnecessary accounts and software removed, nothing left switched on 'just in case'
  • User access control — everyone has their own account, administrator rights are limited to those who genuinely need them, and leavers are removed promptly
  • Malware protection — every device in scope has working, up-to-date protection against malicious software
  • Security update management — operating systems and applications are still supported by their vendor and are patched, with high-risk updates applied within the timescales the scheme sets

There are two levels: the standard self-assessment, and Cyber Essentials Plus, which adds a hands-on technical audit of a sample of your devices. We prepare businesses for both.

Staff awareness and phishing — the control the scheme doesn't cover

None of the five controls asks you to train anyone — yet the incidents we are called out to almost always begin with a person, not a machine. The government's Cyber Security Breaches Survey puts staff awareness training at around one UK business in five, against roughly four in five of the largest organisations. It is one of the cheapest gaps a small firm can close, so we cover it alongside the technical work:

The scams that actually arrive

Not generic advice about Nigerian princes. Fake invoices with the bank details changed, a message that appears to be from a director asking for an urgent payment, a Microsoft 365 sign-in page that looks exactly right, and delivery notifications timed for when everyone is expecting a parcel.

How to check before you act

Two or three habits that stop most of it: how to see where a link really goes, why urgency in an email is itself a warning sign, and the rule that any change to payment details gets confirmed by phone on a number you already had — never one supplied in the message.

What to do in the first ten minutes

Someone will click eventually, and the damage usually depends on what happens next. Who to tell, why saying so immediately matters more than feeling embarrassed, and the sequence — change the password, sign out other sessions, check for a forwarding rule quietly copying your mail elsewhere.

Making reporting safe

Teams that get told off for clicking stop reporting, and silent incidents are the expensive ones. We help you set the tone so that flagging a mistake early is treated as the useful thing it is.

To be clear about what this is: practical guidance delivered by us as part of readiness work. It is not an accredited training platform and it does not issue training certificates — if you need certificated e-learning with completion records, that is a separate product from a training provider and we will point you at what to look for.

What we do — and what we don't

Worth being clear about the line, because it isn't obvious from most IT companies' websites:

  • We assess your setup against the scheme's requirements and tell you where you stand
  • We fix the controls that would fail, and configure what's missing
  • We help you gather evidence and complete the self-assessment accurately
  • We prepare you for the Cyber Essentials Plus technical audit if you're going for that level
  • We prepare you for the annual renewal, so standards don't quietly slip between assessments
  • We do not assess or award certification — that is done by an accredited certification body, independently of us

Our job is simply to make sure that when the assessment happens, nothing about it comes as a surprise.

Not sure what you need? We're happy to help.

FAQ

Frequently Asked Questions

Do you issue Cyber Essentials certification?
No. Under the scheme, certification can only be issued by an accredited certification body, and we are not one. What we provide is the readiness work: assessing your setup against the five controls, putting right anything that would fail, helping you gather the evidence, and supporting you through the self-assessment. The assessment and the certificate come from an accredited certification body, independently of us. That separation is how the scheme is designed to work, and we’re happy to point you to the official listing of certification bodies so you can choose one.
What's the difference between Cyber Essentials and Cyber Essentials Plus?
The standard level is a self-assessment: you declare that the five controls are in place, and your answers are reviewed by an accredited certification body. Cyber Essentials Plus adds an independent technical audit, where an assessor tests a sample of your actual devices to confirm the controls genuinely work. Plus is much harder to pass on paperwork alone, which is precisely why some clients ask for it. We prepare businesses for both — see how we got a charity’s laptop fleet ready for Cyber Essentials Plus.
Is Cyber Essentials a legal requirement?
For most businesses, no — it’s voluntary. In practice it becomes compulsory the moment a contract asks for it, and that happens often: it’s a common condition for central government work, and larger private buyers increasingly ask suppliers for it during due diligence. Even if nobody has asked you yet, the controls behind it are worth having. Our guide, Cyber Essentials explained for small businesses, walks through what the scheme actually covers.
What does it cost, and how long does it take?
There are two separate costs. The scheme’s own assessment fee is paid to the certification body and is set independently of us. Our side — the readiness work — depends entirely on the state of your setup: a well-managed business may need very little, while one with unsupported machines and no central control may need hardware sorted first. Timescales follow the same logic, from a couple of weeks to considerably longer if kit needs replacing. We quote after the gap assessment so the figure is real rather than a guess. Businesses on our managed IT support tend to have most of the controls maintained already, which makes renewal far simpler. Call 020 7610 0500 or use our contact form.
Do you provide staff security awareness or phishing training?
We provide practical staff guidance and phishing awareness as part of readiness work — a session with your team covering the scams that actually reach small businesses, how to check a suspicious message before acting on it, and what to do in the first ten minutes if someone has already clicked. What we do not offer is an accredited training platform or a training certificate, and we would rather say so plainly than dress it up. If you specifically need certificated e-learning with completion tracking for an audit or an insurer, that is a product to buy from a training provider, and we will happily tell you what to look for. Our part is making sure the advice your team receives is relevant to how your business is actually attacked.
Is staff training part of the Cyber Essentials requirements?
Not directly — the five controls are technical, and none of them requires you to train anybody. But the questionnaire asks you to describe practices that only hold up if people follow them, and the attacks that get through a technically compliant business are overwhelmingly aimed at people rather than machines. The government’s own Cyber Security Breaches Survey puts staff awareness training at around one UK business in five, against roughly four in five of the largest organisations — which is a sizeable gap for a small firm to close cheaply. We fold it into readiness work because it is the highest-value hour we can spend with a team, not because a certificate depends on it.
We already use Microsoft 365 and antivirus — isn't that enough?
It’s usually a good start, but the scheme asks for specifics that default setups often miss: multi-factor sign-in on every account, administrator access properly separated from day-to-day accounts, unsupported devices removed from the boundary, and updates applied within the timescales the scheme sets. Our cybersecurity and Microsoft 365 setup work covers most of that ground, and it’s usually where the gap assessment concentrates. Sound backups sit alongside it — not part of the five controls, but the thing you’ll want when something does go wrong.

See all frequently asked questions

Explore more

Related Case Studies

View all
Explore more

Helpful Guides

View all

How Much Does IT Support Cost in the UK?

What IT support really costs in the UK in 2026 — market rates per user, hourly and ad-hoc pricing, what drives the price, and our own published figures.

Coverage

Service Areas

We provide Cyber Essentials Readiness for Small Businesses in London across South West London

Serving Wandsworth, Wimbledon, Putney, Clapham, Balham, Tooting, and surrounding areas.

View all service areas

Been Asked for Cyber Essentials?

Tell us what a client or tender has asked of you and we'll tell you honestly how far off you are. Gap assessment first, then a clear plan — no jargon, no pressure, and no surprises when the assessment comes round.

Same day service available
Fast Response
Expert Technicians