Cyber Essentials certification and the policies behind it
Certification achieved, backed by governance the business could actually maintain afterwards.
The challenge
The business needed to demonstrate baseline security to clients and insurers, but an initial review showed gaps that would not have passed assessment. Patching was inconsistent, device configuration varied, and administrative accounts had grown beyond what was needed. There was also very little written governance sitting behind any of it.
What I did
I took the business through Cyber Essentials certification end to end, working through each control requirement in turn rather than treating it as a form-filling exercise. Device builds were standardised, patching brought under control, and administrative accounts tightened. Alongside the technical work I wrote the governance underneath it: GDPR, acceptable use, BYOD, asset management and AI data usage policies.
The outcome
Certification achieved, with policies written to be usable rather than to sit unread. The internal team were left able to maintain the standard at renewal without external help.
At a glance
- Cyber Essentials certification achieved
- Device builds standardised across the estate
- Patching brought under consistent control
- Administrative accounts reduced to genuine need
- GDPR, acceptable use, BYOD and AI policies written
- Internal team equipped to maintain it at renewal
Related service
This work falls under Security, compliance & zero-trust. If you are facing something similar, that page explains how I approach it.
Response times: within 2 hours during working hours, and never more than 24 hours.
Other case studies
Three phone systems merged into one cloud platform
Read case study →Zero-trust rebuild after a suspected data theft
Read case study →Replacing Salesforce with an in-house CRM module
Read case study →Facing something similar?
Tell me what you are dealing with and I will give you a straight view on how I would approach it.