Cyber Essentials Plus
Cyber Essentials is a simple but effective, Government backed scheme that will help you to protect your organisation, whatever its size, against a whole range of the most common cyber-attacks.
Cyber-attacks come in many shapes and sizes, but the vast majority are very basic in nature, carried out by relatively unskilled individuals. They’re the digital equivalent of a thief trying your front door to see if it’s unlocked. Our advice is designed to prevent these attacks
Following a layered approach, the Cyber Essentials Plus assessment additionally includes an onsite technical review of the build and maintenance of the organisation’s workstations and mobile devices, including checks on:
Patch levels of the Operating Systems
Patch levels of additional applications installed (Office, Adobe, Java, Firefox, Chrome etc)
Up to date mobile Operating Systems
Up to date mobile applications
Lock screens enabled on mobile devices
Other configuration and account handling weaknesses associated with the build of the devices.
Additionally, how the organisation manages the handling of known (but non-malicious in our test cases) malware originating from Internet downloads and emails is assessed.
Cyber Essentials Plus is a pre-requisite certifications for supplying to some elements of UK Government, Defence and Healthcare.
Providers we use
When selecting a SOC package for your business, several considerations should be made. Is it compatible with your existing IT infrastructure? Does the SOC platform align with your needs and safeguard your digital assets?
At Cybaverse, we offer packages with both Crowdstrike and Microsoft Sentinel meaning you're not limited to working with one provider that doesn't suit your businesses needs.
Benefits of this service
Benefits of Microsoft Sentinel
Benefits of Crowdstrike
How we work
Work with our clients and prospects to share knowledge and confirm cyber security direction and goals.
Enhance the service offering, looking to develop build on security processes each month.
Deliver training to staff to ensure a cyber security culture and enhance protection further.
Monitor and maintain standards ensuring that procedures are in place to review security protocols.
How we do it
SOC Services with Microsoft Sentinel
SOC Services with CrowdStrike
Cybaverse will engage with the client to determine their requirements and ensure that the engagement is correctly scoped to deliver on those requirements and make sure all of the correct legal requirements are satisfied.
At the start at of all compliance engagements we carryout a gap analysis to gain an understanding of the current posture mapped to the required standard
Our experienced industry experts will advise and consult on best practises, not only to reach the standard required but beyond with a wider security strategy in mind.
Cybaverse offers audit and certification services for Cyber Essentials, Cyber Essentials Plus and IAMSE Governance and can support the ISO27001 audit process
On completion we provide a comprehensive report, however we do not stop there, we offer a continued partner relationship to support your business at all times
Frequently asked questions
The Cyber Essentials Plus is the same as the Cyber Essentials self-assessment, but with an additional audit from an approved Cyber Security company to confirm that the tools declared in the self-assessment are implemented in the business.
Cyber Essentials Plus minimised human error on the self-assessment and provides a second level of protection for organisations. An auditor will confirm the tools declared in cyber essentials are up to date and configured appropriately. Cyber Essentials Plus is mandatory for any organisation looking to provide services to the government.
Cyber Essentials plus involves an online self-assessment questionnaire. You will get access to a portal where you can submit your questions over a period of time. Once you are happy with your answers you can submit them for marking. Once the questions have been marked, you will then book in an audit for an approved cyber essentials provider to sample check your network, and confirm that your answers are correct. Once the audit has taken place, you will be issued with the Cyber Essentials Plus certification which lasts 12 months.
As Cyber Essentials Plus involves a self-assessment, the timeframe is heavily controlled by you. You will need to work with a provider that can mark and audit your assessment in your desired timeframe. Cybaverse offers a 24 hour marking package to ensure that you meet even the smallest of deadlines.
Cyber Essentials Plus is not mandatory for business, however it is advised. It is mandatory for all businesses with or tendering for, a government contract.
Cyber Essentials Plus helps protect against cyber attacks by requiring organisations to implement a set of basic cybersecurity controls that can help to reduce the risk of common cyber threats. These controls include: · Boundary firewalls and internet gateways · Secure configuration · User access control · Malware protection · Patch management By implementing these controls, organisations can reduce their exposure to common cyber threats such as malware, phishing, and hacking. Cyber Essentials Plus also requires that these controls be independently verified through an external audit.
The Cyber Essentials Plus certification needs to be renewed every 12 months.
Yes, companies can achieve Cyber Essentials Plus certification even if they use cloud services. The Cyber Essentials Plus scheme recognises that many organisations now use cloud services for some or all of their IT infrastructure, and as such, has specific requirements for the use of cloud services. To achieve Cyber Essentials Plus certification, companies must demonstrate that they have implemented appropriate security measures to their cloud services. This includes ensuring that cloud services are configured securely, that access to cloud services is controlled through appropriate user accounts, and that any data stored in the cloud is adequately protected and encrypted.
Any type of business, regardless of size or industry, can benefit from obtaining Cyber Essentials Plus certification. However, some businesses that may be particularly well-suited for this certification include: · Small and medium-sized businesses (SMBs): SMBs are often targeted by cyber criminals due to their limited resources and the perception that they may have weaker security defences. · Businesses that handle sensitive information: Any business that handles sensitive information, such as personal or financial data, should consider obtaining Cyber Essentials Plus certification to ensure that this information is adequately protected against cyber threats. · Government contractors: Many government agencies require their contractors to obtain Cyber Essentials Plus certification as a condition of doing business. This is particularly true for companies that handle sensitive information on behalf of the government. · Businesses that want to improve their cybersecurity posture: Even businesses that have not experienced a cyber attack can benefit from obtaining Cyber Essentials Plus certification, as it demonstrates a commitment to cybersecurity and provides a roadmap for improving cybersecurity defences. Overall, any business that wants to protect against common cyber threats and demonstrate a commitment to cybersecurity should consider obtaining Cyber Essentials Plus certification.
The cost of Cyber Essentials Plus depends on the numbers of employees in your organisation. It can range from £750 to £2,500.
Our Happy Clients
In comparison to other penetration test offers that we had received we felt that Cybaverse’s was the most honest. A lot of other testers had originally said they would be able to test all our infrastructure in 3-4 days, which was later proven to be impossible.
If you are looking for a company to really deliver on the service they are offering, I would look no further. Very quick and easy process. They completed the report within a tight timeframe and offered plenty of helpful advice!
It’s really refreshing to work with experts who act as an extension of our team. Cybaverse don’t stop at identifying issues, they are happy to work with us to solve them too.
Their knowledge in the subject matter was excellent and I found them easy to engage, personable and approachable.
From a business perspective, Cybaverse provide an efficient, thorough, and cost-effective security service which has benefitted thinkmoney considerably over the course of the last year.
If you are not just looking for a certificate and really want to understand and explore your issues, then choose Cybaverse.
We have increased our internal security knowledge across the organisation and especially in IT and Engineering. This has allowed us to bring some services in-house and substitute those with more advanced external services.
We were impressed by Cybaverse’s technical knowledge and expertise. We also found their professional and collaborative approach made the engagement a pleasure, giving us confidence in their ability and the ongoing relationship.
I would highly recommend Cybaverse to any business serious about securing their digital infrastructure. Their expertise, professionalism, and tailored approach make them a valuable partner in navigating the complex landscape of cyber security. They not only identify issues but also work closely with you to implement effective solutions.
We work with
Let's talk
We’re here to help! Submit your information or call the office on +44 (0)1243 670 854 and a member of our team would be happy to help.
Cybaverse are a team of highly skilled, motivated and qualified professionals businesses can depend on. Offering routine to bespoke services whilst striving to exceed customers expectations. We guide our clients to be a step ahead of the adversaries in the ever-evolving cyber security landscape.
We work with our clients to identify the best, most practical, cost effective, requirements for their business. During engagements, we strive to identify real-world issues, confirm vulnerabilities, and provide guidance to secure your computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
Cybaverse has a clear ethos which drives the company internally and externally, this excels our client experience and reputation.
Beyond Excellence - Going above and beyond to achieve the highest standards.
Consistently Dependable - Dedicated to supporting one another and our clients.
Paving New Paths - Constantly looking for ways to innovate and improve.
Charismatic Engagement - Have fun and be ourselves.