If you were looking for help to improve your business’s cyber security, a good place to start would be the UK’s National Cyber Security Centre, part of GCHQ, whose role is to keep the country secure against cyber attacks. So when they provide free advice, you’d expect most businesses to be rushing to implement it. However, you’d be wrong. The NCSC has developed a security tool to help organisations protect themselves against the most common cyber threats, but although it’s been available for almost five years, less than ten per cent of UK businesses have implemented it.
This is the Cyber Essentials scheme, which will help to protect your business against the most common cyber threats. Having been certified ourselves to the advanced level, Cyber Essentials Plus, we believe the scheme gives every organisation a solid security baseline which will mitigate the majority of cyber attacks and minimise the damage if something does go wrong e.g. someone accidentally opens a malicious attachment or clicks on a link. It also covers mobile device protection and basic security policies.
The scheme covers five areas of control:
There are two levels of accreditation. Cyber Essentials is an independently verified self-assessment against the five controls, with a qualified assessor verifying the information provided. Cyber Essentials Plus is a higher level of assurance in which a qualified and independent assessor examines the five controls and tests that they work by simulating basic hacking and phishing attacks.
These five controls may seem like obvious security measures. However, get them right and you will protect your organisation against the most common cyber attacks. Don’t just take our word for it – listen to the experts at the NCSC.