Key takeaways from the MSP cybersecurity survey 2024

MSP cybersecurity survey

How prepared are managed service providers (MSPs) to deal with cyber threats? 

This might seem like an obvious question, but there’s surprisingly little research on the subject. So, we set out to change this. Alongside our friends at OnePoll, we surveyed 250 UK business leaders from every major industry to understand the challenges and opportunities facing MSPs.

Here are the key takeaways from the CyberSmart MSP survey 2024.

The MSP cybersecurity survey 2024: 5 things you need to know

MSPs are among the most attractive targets for cybercriminals. 87% of respondents said they’d experienced at least one breach in the last year – with many suffering multiple attacks.

So, why are they such a popular target?

Many businesses rely on MSPs for everything from IT support to network monitoring. They provide essential services, but need privileged access to their customers’ critical systems and data to deliver them.

As such, breaching an MSP gives cybercriminals access to data from multiple targets. This allows them to reach more victims with minimal effort, maximising the amount they can earn from a single attack.

Want to know more? Read our MSP report in full here.

2. Malware and ransomware are the biggest threats to MSPs

Cyber threats take various forms. Some, like phishing, are more common than others. But for MSPs, the biggest threats come from malware and ransomware.

57% of respondents ranked malware and ransomware as their biggest concerns, ahead of unpatched vulnerability exploits (41%) and insider threats (37%). These results are particularly interesting given that many businesses don’t have ransomware recovery plans or policies to deal with them.

3. MSPs overlook key cybersecurity risks

Despite growing awareness among MSPs of the biggest cybersecurity risks, our survey revealed some notable exceptions. 

The cybersecurity skills gap is a prime example. Only 35% of respondents identified it as a key concern – in sharp contrast to recent World Economic Forum research suggesting it remains a serious threat.

Alarmingly, only 26% recognised supply chain attacks as a threat, while few explicitly mentioned phishing. This is particularly surprising, given that 84% of businesses that reported breaches last year experienced some form of phishing attack. 

4. Customers expect more from MSPs

IT services are the bread and butter for many MSPs, providing guidance and support for businesses that don’t have the resources to manage their infrastructure in-house. But customer expectations are changing.

65% of respondents said customers expect MSPs to implement or manage their cybersecurity. Meanwhile, 73% feel their security capabilities are under greater scrutiny, especially during request for proposal (RFP) and new business meetings.

In response, we’ve seen many MSPs adapt their services to meet this demand. 70% of respondents have expanded their capabilities over the last year, adding cybersecurity support services and products to their portfolios.

5. Cybersecurity confidence is high among MSPs

Nearly all respondents said they were confident in their business’s cybersecurity. We defined this as having or engaging in at least one of the following:

  • Continuous threat monitoring
  • Proactive risk management
  • Risk reporting
  • Incident response and recovery
  • Cybersecurity training
  • Cybersecurity policies
  • Demonstrable cyber credentials (e.g., Cyber Essentials)

When we dig a little deeper, this confidence appears misplaced. Only 55% and 54% of SMEs have clear policies for accessing and sharing sensitive data, respectively. This suggests a disconnect between perception and reality.

A golden opportunity for MSPs

Our survey reveals some interesting truths about MSP cybersecurity.

MSPs remain the most popular target for cybercriminals, with malware and ransomware attacks the biggest threats. Service providers are increasingly aware of the dangers of the digital frontier and are confident in their defences, but overlook some key risks nonetheless.

Arguably, the most interesting point is the changing perception among customers. Many now expect service providers to offer cybersecurity products and services as standard. While this might seem like another hurdle to overcome at first glance, it presents a golden opportunity to MSPs willing to adapt to meet this demand.

Introducing: The new look CyberSmart Active Protect for Mobile

Active Protect for Mobile

Today marks the launch of our new and improved CyberSmart Active Protect for Mobile application. Along with a dramatic facelift, the new app includes a range of new mobile-specific security features. Here’s everything you need to know. 

What is CyberSmart Active Protect for Mobile?

Active Protect for Mobile safeguards your devices and company data from mobile security threats while empowering employees to manage their own cyber risk.

Downloadable from your device's app store, Active Protect takes just minutes to set up. The app scans for security misconfigurations, unsafe apps, malicious content and more. And, all while ensuring the privacy of personal messages, locations, and browsing history.

Why have we relaunched Active Protect for Mobile? 

The way cybercriminals target businesses is changing. And mobile threats are at the forefront of this.

For example, 80% of phishing sites specifically target mobile devices or are designed to function on desktop and mobile. What’s more, it’s estimated that the average employee is six to 10 times more likely to fall for SMS phishing attacks than email-based attacks.

However, at the same time, there’s a lack of mobile-specific solutions designed for small businesses. So, we’ve decided to step up by overhauling our previous mobile version of CyberSmart Active Protect to ensure customers are secure no matter what device they’re using.

What’s new?

As we mentioned earlier, Active Protect for Mobile really has undergone a radical overhaul. This isn’t the place for a complete spec sheet (but please get in touch if you would like one), but here are a few of the key benefits.

Updated security controls 

Active Protect for Mobile includes a glut of new security controls. For a full run-down of the new checks, we recommend reading our guide (available on request). However, some of the top security checks include:

- Unsafe apps

- Malicious content checker

- Wi-Fi checker

- Device rooting/not jailbroken

- Security patches 

- Operating system up to date

- Timeline of device changes

- Unlock authentication

Intuitive new design

Designed with the latest UX principles in mind, our mobile app is easy to use and quick to protect your employees and customers from cyber threats.

Privacy-first 

Although Active Protect for mobile protects employees’ personal information from cyber threats just as effectively as companies’ data, it only gathers security settings. This makes it perfect for bring-your-own-device (BYOD) environments.

Brandable app

You can now add your company logo to the app and make it your own. This is ideal for managed service providers and value-added resellers looking to add our mobile app to your existing offer to customers. 

MDM compatible 

Active Protect for Mobile is compatible with all major mobile device management (MDM) software, making it simple to administer devices at scale. 

Push notifications

Push notifications keep users informed about critical security issues, in real time. So, if something changes in a device’s security, you’ll know about it immediately.

EU and UK data centres

All data is stored in UK and EU data centres and is encrypted in transit and at rest. This means company and customer security data is protected at all times.

Smart policies enabled

With our smart policies enabled for our mobile app, you’ll be able to distribute and gather company policy agreements from all employees, wherever they are, in minutes.

Connects to CyberSmart dashboard

All Security Controls are reported back to the CyberSmart web dashboard, so you can manage mobile, tablet and desktop devices from one place.

How can I get the app? 

If you’re an existing customer, CyberSmart Active Protect for Mobile can be downloaded from the Android or iOS app stores. Although, we recommend reading our knowledge base article on how to install it.

If you’re a new customer, get in touch! We’d love to talk you through Active Protect for Mobile and how CyberSmart can help you and your customers.

5 MSP cybersecurity threats (and how to stop them)

msp cybersecurity threats

Few targets are as enticing to cybercriminals as managed service providers (MSPs). And for good reason.

From IT support to finance management, MSPs provide essential services to large customer bases. But to deliver them, they need privileged access to internal systems and sensitive data. As such, successfully breaching an MSP can give cybercriminals access to huge amounts of information from multiple businesses.

To help you stay one step ahead, we’ve listed five of the most common MSP cybersecurity threats – along with some simple tips to defend against them. 

The 5 most common MSP cybersecurity threats

1. Phishing

Phishing is a form of social engineering attack that tricks people into handing over sensitive information or downloading malicious software. Typically, by impersonating a trusted individual or organisation, or by creating panic.

Cybercriminals often use email to initiate phishing attacks. How many times have you seen messages like this appear in your inbox?

“Hi Jane, this is Bob. We need to send an urgent payment to a new supplier, but I’m in a meeting for the rest of the day. Can you organise it on my behalf, please? It needs to go out immediately. Please see the details attached.”

Generative AI has made phishing attacks harder to spot and more dangerous. For example, advanced AI can clone the voice of trusted contacts.

Quick tips to defend against phishing

  • Check the sender’s name and address: does it look legitimate?
  • Read emails carefully: are there any obvious typos or grammatical mistakes? Does the tone sound strange?
  • Report suspicious emails: not sure if an email’s legitimate? Forward it to the National Cyber Security Centre.
  • Install antivirus software: some programs can spot malicious links or and potential phishing sites. 
  • Train staff: run regular training sessions to help employees spot the tell-tale signs of a phishing attack, and teach them what to do in the event of a breach.
Want to know more about the threats facing MSPs? Check out our MSP Survey 2024.

2. Malware and Ransomware

A combination of “malicious software”, cybercriminals use malware to attack business-critical systems, disrupt operations, and steal sensitive data. It comes in various forms, the most common being:

  • Ransomware
  • Spyware
  • Adware
  • Trojan horses
  • Worms

Cybercriminals have even begun to lease malicious software. Known as malware-as-a-service, this model allows people with minimal coding skills to launch full-blown cyber-attacks.

Small and medium-sized businesses (SMBs) are particularly vulnerable to malware. Few have the knowledge or skills to handle a targeted attack, which explains why 57% of industry leaders see it as the biggest MSP cybersecurity threat.

Quick tips to defend against malware and ransomware

  • Only use secure networks: avoid public or unsecured networks when using work devices.
  • Backup data regularly: create separate copies of important files so you can quickly restore lost data in the event of a breach.
  • Install anti-malware: this monitors your systems to identify and sometimes remove malicious software.
  • Invest in a ransomware recovery toolkit: these contain business continuity and disaster recovery plans, helping you respond constructively to breaches.

3. IT vulnerability exploits

Unlike the other MSP cybersecurity threats on this list, IT vulnerability exploits describe a tactic or method – rather than a specific type of threat.

IT vulnerability exploits don’t rely on victims to click on malicious links or download compromised software. Instead, they deliberately target weaknesses in your software, systems, or processes, often using exploit kits.

Common vulnerabilities include:

  • Misconfigured programs
  • Unpatched software
  • Weak passwords
  • Bugs

Quick tips to defend against IT vulnerability exploits

  • Patch your software: install updates as soon as they become available to nip vulnerabilities in the bud.
  • Install vulnerability scanning software: scan your systems periodically to identify and address potential issues.
  • Run penetration tests: simulate cyber-attacks to pinpoint weaknesses and see how your systems stand up to threats.
  • Follow cybersecurity best practices: create clear processes and policies to minimise vulnerabilities that stem from human error, such as duplicated passwords.

4. Insider threats

As the name suggests, insider threats originate from within your business. They fall into two broad categories: accidental and malicious.

  1. Accidental: caused by someone unintentionally exposing your systems to cyber threats. For example, by clicking on a malicious link, visiting a compromised website, or leaving an unprotected device in a public place.
  2. Malicious: caused by someone deliberately abusing their access rights to steal data or damage your systems. Malicious insider threats often stem from disgruntled employees, contractors, or partners.

This MSP cybersecurity threat has become more common in recent years. 38% of UK SMEs attribute this to the cost-of-living crisis, and it stands to reason. Financial pressures force many businesses to reduce headcount, while some employees may need to find other revenue streams to make ends meet.

Quick tips to defend against insider threats

  • Set strict access controls: only give administrative rights and account access when employees need it to do their jobs.
  • Embrace multi-factor authentication (MFA): enforce MFA on business-critical systems and accounts to provide extra protection.
  • Look out for suspicious activity: monitor systems for common insider threat indicators, such as unusual login behaviour or privilege escalation.
  • Enforce strong security policies: ensure a consistent approach to cybersecurity across your business, with clear guidelines governing things like password etiquette and access privileges.

5. Supply chain attacks

Supply chain attacks are an indirect MSP cybersecurity threat. They work by exploiting weaknesses in third-party software, hardware, or services to bypass your defences and give cybercriminals access to your systems.

Because they originate through legitimate suppliers, supply chain attacks are difficult to spot. For example, it took months for cybersecurity professionals to discover the root cause of 2019’s infamous SolarWinds attack.

Alarmingly, only 26% of MSPs see supply chain attacks as a threat – suggesting a lack of awareness among industry leaders.

Quick tips to defend against supply chain attacks

  • Enforce strong cybersecurity measures: before worrying about your suppliers, ensure your cybersecurity is up to scratch.
  • Speak to your suppliers: start an open dialogue with channel partners to discuss cybersecurity challenges and best practices.
  • Conduct cybersecurity risk assessments: evaluate current and new suppliers to ensure their cybersecurity meets minimum requirements. 
  • Follow NCSC supply chain security guidance: this lists the five basic steps to secure your supply chain. 

No threat is insurmountable

MSP cybersecurity threats come in many forms. The good news is that most are relatively unsophisticated. Adopting simple and affordable security measures can go a long way in securing your business. Not sure where to start? Consider a cybersecurity certification, like the government-backed Cyber Essentials scheme. Built around five security controls, it provides impartial guidance to help you improve your cyber hygiene.

Although MSPs are increasingly under threat, the current landscape also offers new opportunities. Read our latest report to find out more.

Key takeaways from the Cyber Essentials Impact Evaluation Report

Cyber Essentials Impact Evaluation Report

As anyone in the cybersecurity industry knows, October marks an important anniversary for the sector. The government-backed Cyber Essentials scheme turns 10 this year. And, alongside a bunting-draped celebration at the House of Lords, the Department for Science Technology and Innovation (DSIT) has commissioned the Cyber Essentials Impact Evaluation Report.

Undertaken by Pye Tait Consulting, the study examines the scheme’s effectiveness, organisations’ motivations for certification, and the ease of adopting its technical controls. However, the report is also 110 pages long. So, to save you several hours, here are our key takeaways from the report. 

Cyber Essentials technical controls boost cyber confidence

The study reveals that Cyber Essentials’ five technical controls are remarkably effective. Citing research on the protections, it concludes they mitigate 99% of ‘internet-originating’ vulnerabilities when implemented. 

This isn’t really news. Researchers at Lancaster University concluded the same as far back as 2015. However, what’s far more interesting is how Cyber Essentials makes business leaders feel. A significant majority (82%) of users express confidence that these controls protect against common cyber threats, with 80% believing they help mitigate organisational risks.

In other words, Cyber Essentials is a key step towards building complete cyber confidence.

Cyber Essentials has been effective in building cyber awareness

Cyber Essentials was always intended to do more than help businesses put technical controls in place. The plan was that by completing the assessment process, organisations would also become more aware of the threats and better equipped to counter them.

Cyber Essentials has also been a success by this measure. The report reveals that Cyber Essentials users have a heightened ability to identify unsophisticated cyberattacks, with 64% agreeing that certification aids in this identification. And that’s not all. Certified organisations also demonstrate greater concern about cyberattacks and better appreciate the potential impact than non-certified organisations.

The same is true for the understanding of cybersecurity. Most users (85%) reported an improved understanding of cyber risks and how to reduce them (88%). Perhaps most importantly, this positive trend was most notable among senior management, with 86% saying Cyber Essentials has improved their understanding. 

Cyber Essentials stimulates wider security practices

Another of the original aims of Cyber Essentials was that it would act as a catalyst for bigger things. Think of it as a strong foundation that businesses could build the rest of their security architecture on top of. 

Again, the study finds that the scheme has been largely successful at doing just that. 76% of certified organisations have taken additional steps beyond the technical controls to enhance their cybersecurity. Alongside this, almost three-quarters (71%) of respondents agreed that the scheme has strengthened how seriously they take cybersecurity. And, hearteningly, this has helped foster a culture of shared responsibility for cybersecurity within their organisations, encouraging regular discussions and proactive measures.

Cyber Essentials as a supply chain assurance tool 

There’s also some evidence that Cyber Essentials has grown some extra functions over its ten-year lifespan. For example, Cyber Essentials is increasingly used as a supply chain assurance tool.

Those surveyed revealed that a third (33%) of all contracts they’ve entered into in the last year required them to be Cyber Essentials certified. What’s more, a growing number of businesses are setting these obligations for their own suppliers. Some 15% of Cyber Essentials users have made it mandatory for their suppliers to be certified and plan to continue doing so, while a further third (33%) are actively considering mandating Cyber Essentials in the future. 

However, there is definitely room for improvement on this count. Just under half of Cyber Essentials users (45%) take Cyber Essentials into account when assessing the cyber risk a supplier poses, meaning we’ve some way to go before Cyber Essentials can be considered a universal stamp of assurance for suppliers. 

The scheme has created value beyond security for businesses

One of the biggest historical barriers to Cyber Essentials adoption, particularly among small businesses, has been value for money. It’s not uncommon for those new to the scheme to ask ‘Do I really need this?’

Nevertheless, those who’ve taken up Cyber Essentials certification have been overwhelmingly positive about the commercial benefits. 69% of surveyees noticed increased competitiveness post-certification. Meanwhile, 80% agreed that being certified can reduce the financial cost to their organisation of a common, unsophisticated cyberattack.

There’s also some evidence that Cyber Essentials has a positive impact on businesses' cyber insurance costs. Firstly, through the, often free, bundled insurance offered alongside Cyber Essentials by many certification providers. And, secondly by dramatically decreasing the likelihood of a claim.

The report cites the NCSC’s 2023 Annual Review which suggests that 80% fewer cyber insurance claims are made when Cyber Essentials is in place, compared with organisations that have the same insurance policy and don’t have Cyber Essentials certification. Although, according to the government's latest figures, this is now even higher at 92%.

There is still room for improvement 

Despite the positive findings of the report, it does have a blind spot. Although general cyber awareness among Cyber Essentials users is excellent, it’s debatable whether the same is true across society.

The NCSC's 2024 Cyber Security Breaches Survey revealed that awareness of Cyber Essentials has actually declined in recent years. Just 12% of businesses and 11% of charities are aware of the Cyber Essentials scheme. This is consistent with 2023 figures but represents a decrease over the past 2-3 years.

Plus, while 141,712 certificates have been issued and thousands of businesses have adopted the scheme, this only represents a small fraction of the UK’s estimated 5.6 million businesses. 

In short, we have an awareness problem. 

The report does list wider-reaching marketing campaigns among its recommendations, so it’s great to see that DSIT recognises the problem. But for the cybersecurity community, our mission is clear. Given the huge benefits felt by those who’ve already adopted Cyber Essentials, we need to reach more businesses and generate greater awareness of the scheme and security measures beyond it.

Achieve that and we’ll have helped build a far safer online environment for UK businesses by the time Cyber Essentials hits 20.

Have you read our 2024 MSP survey yet? It's full of insight on MSPs' cybersecurity and the future of the industry. Get your copy here.

Cybersecurity budgets for SMEs: Are we doing enough to make the case?

Cybersecurity budgets for SMEs

Cybersecurity is a growing concern for businesses of all sizes, but the situation is particularly challenging for small and medium-sized enterprises (SMEs). Limited resources often mean smaller budgets for cybersecurity, leaving these organisations vulnerable to increasingly sophisticated cyberattacks. As a cybersecurity professional, whether you’re an MSP or consultant, you've likely faced the frustrating reality of tight budgets, even when the risks are clear.

A recent report by ISACA reveals a troubling statistic. 52% of cybersecurity professionals in Europe believe their organisation’s budget is insufficient. Yet, 58% of organisations expect to face an attack within the next 12 months. This disconnect suggests that many budget holders are still unconvinced of the need for stronger security measures.

In this blog, we’ll explore why cyber security budgets in SMEs tend to be lower, the misconceptions that drive this, and how you can better educate businesses as a cyber security professional. You’ll also discover practical ways to work within limited budgets while delivering effective protection.

Planning a cybersecurity budget

When it comes to cybersecurity, many SMEs operate under the belief that paying for basic protection is enough to keep them safe. “I pay for cybersecurity, so I’m secure,” is a common but misguided sentiment. In reality, most SMEs are just as much at risk as larger enterprises, yet their budgets are often disproportionately lower.

The reasons behind this are understandable. SMEs typically have fewer resources and often prioritise immediate business needs over long-term risks. However, as cyber threats grow more frequent and sophisticated, underfunding cybersecurity is a dangerous gamble. 

For cybersecurity professionals, the key challenge is not just to provide solutions but to effectively communicate the real-world impacts of insufficient protection. Businesses need to understand that the risk isn’t hypothetical. Recent data shows that 41% of businesses experienced more cyberattacks in the last year alone. 

This is where education becomes essential. By using statistics and real-life examples, you can help budget holders grasp the true risks and long-term costs of an attack, which often far outweigh the cost of prevention.

During the planning phase, we should consider risk assessments to help businesses understand their unique vulnerabilities. You can then use this information to tailor security solutions that align cybersecurity measures with a customer’s specific budget and needs. 

However,  education is the most important thing. Taking the time to explain how even a small increase in budget can significantly reduce risk.

Allocating a budget and prioritising

When budgets are tight, it’s crucial to help SMEs prioritise the areas where investment will have the greatest impact. To start, businesses must understand the cost of an attack. 

Downtime, reputational damage, and the cost of recovery can devastate a small business. For instance, ransomware attacks can result in 22 days of downtime on average, a crippling scenario for any SME. By outlining these potential outcomes, you can paint a clearer picture of the necessity of increased investment in cybersecurity.

When working within a limited budget, focus on the fundamentals. Schemes such as Cyber Essentials provide this, which is why the controls within this scheme are often described as the foundations of cybersecurity for any business.

Controls such as multi-factor authentication (MFA) can protect against the most common entry points for attackers. Applying the latest updates will ensure that your network has the latest patches and will not fall victim to an attacker exploiting a hole in third-party software.

One of the most cost-effective ways to reduce risk is to educate employees about cyber threats in particular how to recognise and respond to phishing attempts.

In short, the key is to ensure that budget holders understand the return on investment of cybersecurity. Investing in protection now will likely save them from much larger costs in the future.

Common mistakes and misconceptions

The mindset of small businesses thinking they are too small to be attacked puts organisations at risk and makes it harder for cybersecurity professionals to justify larger budgets.

Another frequent error is assuming that simply paying for a cybersecurity service guarantees complete protection. In reality, cybersecurity is not a one-and-done solution, it requires continuous monitoring, updating, and adjusting. Security professionals must guide businesses away from these misconceptions and towards a more realistic understanding of their vulnerabilities.

For example, a small business might believe that because they’ve installed antivirus software or a firewall they’re fully protected. However, the continuously evolving threat landscape means that yesterday’s security measures are often inadequate for today’s attacks. 

Part of a security professional's job is to clarify that cybersecurity is an ongoing process. Regular assessments, updates, and education are crucial to keeping an SME safe from the constantly changing tactics of cybercriminals.

Optimising cybersecurity investments

Even with a limited budget, there are ways to maximise the effectiveness of a business's cyber security investments. Cybersecurity professionals have the opportunity to help businesses make the most of what they have while still ensuring adequate protection.

The use of cost-effective security tools that offer solid protection. This ensures businesses are getting the best value for their investment. Tools such as CyberSmart Active Protect provide vulnerability management, security awareness training and policy management.

Often, the biggest vulnerabilities in an organisation aren’t its systems, but its people. Utilising the free resources CyberSmart offers such as white papers, blogs and webinars provides additional regular training to employees on concurrent threats and how to protect against them, as well as respond to them. This can greatly reduce the risk of an attack.

By helping businesses invest wisely, we can ensure they get the best possible protection within their financial constraints. It’s about balancing short-term costs with the long-term need for security and showing businesses that even a modest increase in their cyber security budget can significantly reduce their risk of a costly attack.

As cyber threats continue to grow, SMEs can no longer afford to view cyber security as an optional or secondary concern. The consequences of a successful attack can be devastating, and yet many businesses are still under-investing in their security measures. 

How to help your customers

For cybersecurity professionals, the task is twofold: educating businesses on the real risks they face and helping them allocate their budgets effectively. By focusing on clear communication, prioritising essential security measures, and optimising available resources, you can ensure that even the smallest budgets deliver real protection.

In the end, the key message to convey to businesses is simple: cybersecurity is an investment, not just a cost. And with the right approach, even a limited budget can provide meaningful protection against today’s ever-evolving cyber threats.

Want to know more about how to keep your customers safe on a smaller budget? Check out our guide to cybersecurity on a budget.

Cost of living CTA 2
















Cyber Essentials password policy best practices

cyber essentials password policy

One of the key aspects of securing your workforce is implementing strong passwords that comply with Cyber Essentials password policy best practices.

Cyber Essentials is a UK government-backed scheme that teaches businesses how to protect themselves from common online threats.

Why adopt Cyber Essentials password policy recommendations?

A weak password can be the difference between a secure system and a damaging data breach.

Cyber Essentials provides guidelines that help businesses protect themselves against cyber threats. Following them can reduce the risk of unauthorised access by ensuring your systems are as secure as possible.

Cyber Essentials password requirements

To get certified, your business must implement a password policy that meets the following requirements: 

1. Password complexity 

The NCSC recommends using its three random words approach to password creation. However, you can also use a randomly generated password created by a password manager. The key is that your passwords are complex and near-impossible to guess. 

2. Unique credentials

Reusing passwords across multiple personal and company accounts presents a major risk. If a hacker gets hold of them, they could gain access to sensitive data.

Cyber Essentials requires all employees to use unique passwords for every account. Password managers can help employees maintain unique passwords without the burden of remembering them all. 

3. Account lock-up mechanisms

Cyber Essentials recommends implementing account lock-up mechanisms to protect against brute-force attacks, where hackers attempt to guess passwords by trying different combinations. This temporarily locks accounts after a certain number of unsuccessful login attempts, requiring additional verification to regain access.

4. Multi-factor authentication

Multi-factor authentication (MFA) adds an essential layer of security that requires users to verify their identity using two or more methods. This might include a password, a pin, or even a fingerprint. 

Cyber Essentials strongly recommends implementing MFA for accessing all critical systems. This ensures that even if a hacker obtains a password, they can’t access sensitive data without the second verification step.

Implementing a CE password policy

Creating a Cyber Essentials-compliant password policy is the first step to securing your business. But ensuring your team adheres to it requires careful planning and execution. 

1. Employee training and awareness

Even the strongest password policy can fail if employees don’t know how to use it or where to find it. Every team needs regular training and reminders about the importance of strong passwords and the specific policy requirements.

Consider running interactive training sessions, webinars, and regular cybersecurity newsletters to keep employees informed and engaged. Highlight real-world examples of password-related breaches to emphasise the importance of compliance.

2. Password management tools

Managing multiple, complex passwords can be daunting. Password management tools offer a secure way to store and retrieve passwords, reducing the temptation to reuse or simplify them. 

These tools generate strong, random passwords for each account and store them securely. This makes it easier for employees to adhere to Cyber Essentials password policy best practices without sacrificing convenience. 

3. Monitoring and support

Implement monitoring tools that allow your IT team to oversee compliance and respond quickly to potential issues.

These tools can also help identify unusual patterns, such as multiple failed login attempts that may indicate a security breach. By monitoring these activities, you can prevent minor issues from escalating into major security incidents. 

4. Secure access solutions

Beyond passwords, implementing secure access solutions is crucial. Use secure channels such as VPNs to encrypt data and prevent hackers from intercepting it.

Executing a Cyber Essentials password policy

Securing your businesses' digital infrastructure is more important than ever as attacks become more frequent. A well-crafted password policy that complies with Cyber Essentials will protect your business from cybercriminals. 

To learn more about Cyber Essentials and how it can benefit your business, check out our guide to UK certifications.

Cybersecurity certifications

Press release: CyberSmart partners with e92plus

e92Plus

LONDON, UK - 1st October 2024 - CyberSmart, a leading provider of cyber risk management for small businesses has today launched its partnership with e92plus, the UK’s top independent cybersecurity Value Added Distributor (VAD). 

e92plus has long been dedicated to protecting its partners and helping them accelerate business growth through its suite of channel-first security and cloud solutions. Indeed, e92plus has helped over 1,200 VARs, MSPs, SIs, CSPs and consultancies across the UK and Ireland.

CyberSmart offers an all-in-one cybersecurity monitoring, optimisation, training and insurance solution, proven to defend against the unexpected. Like e92plus, CyberSmart focuses on delivering its cybersecurity platform through the channel, making this an auspicious partnership.

The partnership will focus on delivering CyberSmart’s cyber risk management platform, including Cyber Essentials certification, products CyberSmart Active Protect and CyberSmart Vulnerability Manager, and cyber insurance to e92plus’ partners throughout the UK and Ireland. 

While the partnership is launching primarily in the UK and Ireland, e92plus plans to launch alongside CyberSmart in the Netherlands and other EU markets in the coming years.

The joining of forces between CyberSmart and e92plus is timely. A recent survey from CyberSmart reveals that 65% of MSP customers now expect their provider to manage their cybersecurity infrastructure or their cybersecurity and IT infrastructure. This partnership will help deliver the tools MSPs and VARs need to meet customer demand. 

“We’re excited to be working with Cybersmart to bring their platform to our partner community” explains Mukesh Gupta, CEO at e92plus. “We’re seeing strong demand in the SMB and mid-market sectors for more assistance around cybersecurity strategy, processes and compliance standards, and this addresses that growing marketing need. The requirements are so complex and diverse, and many businesses struggle to have the internal staff and expertise to manage their cybersecurity tools, let alone manage frameworks, address staff training and ensure an organisation has the right risk management and reporting in place. For our VARs and MSPs, this is a perfect way to build their services and consultancy offering without significant investment”.

“We’re delighted to be working with e92plus,” said Jamie Akhtar, CEO at CyberSmart. “Our businesses share a vision of what cybersecurity for SMBs should look like. The demand for solutions that can help smaller businesses get on top of their cybersecurity, compliance and risk management is only growing. And, this partnership addresses the demand, while giving MSPs and VARs a fast and simple route to building up their cybersecurity capabilities. We see this as another important step towards our mission of providing complete cyber confidence to every small business.”

Cyber Essentials vs. Cyber Essentials Plus: which is best for your business

cyber essentials vs cyber essentials plus

If you've been considering a cybersecurity certification for your business, you've probably been weighing up Cyber Essentials vs Cyber Essentials Plus.

By choosing the right certification, you ensure that your cybersecurity measures align with your business’s specific needs and help you stay ahead of potential risks. Whether you need basic protection or a more thorough assessment, this guide will help you decide which certification is the best fit for you.

What are Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a government-backed certification scheme designed to help businesses protect themselves from the most common cyber threats. This framework equips businesses with the essential steps needed to strengthen their defences and minimise security risks.

Cyber Essentials Plus follows the same fundamental framework but includes an additional independent audit, offering a higher level of security and assurance.

How are they similar?

Both Cyber Essentials and Cyber Essentials Plus follow the same five security controls:

  • Boundary firewalls and internet gateways: ensuring a secure internet connection
  • Secure configuration: guaranteeing devices are set up securely
  • User access control: restricting access to data and services
  • Malware protection: implementing defensive measures against viruses 
  • Patch management: keeping software and devices up to date

These controls are the backbone of the Cyber Essentials scheme, helping organisations mitigate risks and protect against common cyber threats.

How are they different?

The key distinction between Cyber Essentials and Cyber Essentials Plus lies in the assessment process.

Cyber Essentials

This certification ends with a self-assessment. You complete a questionnaire to confirm you’ve implemented the necessary security controls in your business. A certification body then reviews the assessment and decides whether you've met the qualification requirements.

Cyber Essentials Plus

Cyber Essentials Plus includes an independent audit. An auditor will thoroughly evaluate your security controls, ensuring you've implemented them correctly.

Advantages of Cyber Essentials and Cyber Essentials Plus

Cyber Essentials

Cyber Essentials is a cost-effective way to simplify and demonstrate your commitment to cybersecurity. It’s essential for companies bidding for government contracts. Not only does it provide a solid foundation for further security measures, but it also provides businesses with a competitive edge as it builds trust and allows you to bid for government contracts. 

Cyber Essentials Plus

The Plus certification offers enhanced credibility through third-party verification, increasing trust with customers and partners. This is especially for those in industries with strict data security regulations such as healthcare or the financial sector. It also helps you to stand out when securing contracts and increases protection against advanced threats. 

Cyber Essentials vs. Cyber Essentials Plus: the verdict

It might sound like a bit of a non-conclusion, but choosing between Cyber Essentials and Cyber Essentials Plus depends on your business's needs.

Cyber Essentials is a great starting point for businesses looking to demonstrate basic cybersecurity measures. However, if your industry demands higher assurance levels or if you handle sensitive data, Cyber Essentials Plus offers added credibility and support through independent verification.

Cybersecurity certifications



Is Cyber Essentials certification worth the investment?

Is Cyber Essentials worth the investment?

If you’re considering Cyber Essentials certification, you’ve probably got some questions about the process. Most importantly, what does it cost and is Cyber Essentials certification worth the investment? If so, we’ve got you covered. Read on for everything you need to know. 

How much does Cyber Essentials cost?

From 2014-2022, you paid a flat fee of £300 plus VAT to get a Cyber Essentials certification. However, in 2022, the National Cyber Security Centre (NCSC) adopted a tiered pricing structure. 

Under the new tiered system, Cyber Essentials costs range from £300 to £600 plus VAT. Tiers are decided by factors such as business size, number of locations, and the current level of cybersecurity measures in place.

This fee covers the assessment and certification process. However, the total cost can vary due to factors like the support required to meet the five assessment controls:

  • Firewalls
  • Secure configuration
  • Use access control
  • Malware protection
  • Patch management

Costs can also differ from certification body to certification body, with some charging for extra support, resubmissions and additional services. 

Ready to get started with Cyber Essentials Certification? CyberSmart offers the fastest and simplest route to certification on the market.

Why have Cyber Essentials costs changed?

With the rise of cloud services, remote work, and digital transformation, businesses face new challenges in securing their data and systems.

To address these changes, the NCSC and IASME Consortium updated the Cyber Essentials requirements, which now include:

  • Cloud services: ensuring secure configuration of cloud platforms
  • Multi-factor authentication (MFA): adding an extra layer of security for user logins
  • Password management: implementing stronger password policies
  • Security updates: regular software updates to protect against vulnerabilities
  • Remote working: securing remote access to company systems and data

These updates have led to more rigorous assessments, particularly for larger companies, and you’ll see this reflected in the new pricing.

The benefits of Cyber Essentials certification

Now for the most important question, is Cyber Essentials certification worth the investment? 

In short, yes. Cyber Essentials certification offers benefits to every organisation. Let’s take a look at some of the key reasons to invest in certification.

You’ll be more secure 

Cyber Essentials helps you put a strong security foundation in place. When its security controls are properly implemented, your organisation will be far better prepared to identify, prevent and respond to attacks. In fact, Cyber Essentials can reduce your cyber risk by up to 98.5%.

Reduced risk 

Cyber Essentials focuses on critical elements of your security like regularly patching applications and implementing multi-factor authentication (MFA). These and other controls dramatically reduce the risk of a breach.

Cost-effectiveness 

Although getting Cyber Essentials certified requires some investment, the upfront cost is negligible compared to the cost of a breach. The Department of Science Innovation and Technology (DSIT) estimates that the single most disruptive breach from the last 12 months cost businesses £1,205 on average.

It’s also worth noting that while that figure looks low, it’s for a single breach. Many organisations suffer multiple breaches per year, so the real cost is likely to be higher. Adopting robust security controls can help prevent a breach in the first place, saving your organisation money in the long run.

Assure customers and partners 

Gone are the days when cybersecurity and data protection were secondary concerns for customers. Research shows that 60% of men and women are more concerned about their personal data than a year ago. And this influences decision-making in the workplace. 

As a result, businesses are increasingly reluctant to work with organisations that can’t demonstrate a commitment to security. 

Completing Cyber Essentials allows you to demonstrate you take cybersecurity and data protection seriously. You’ll even get a digital badge to display on your website, ultimately,  helping you show your credentials and win business. 

Better response to incidents 

Every business hopes to avoid being breached. However, cybercriminals are resourceful and excellent at finding unknown vulnerabilities. Cyber Essentials can help you put in place the processes you need to recover quickly, even if the worst-case scenario does happen.

Ability to bid for government contracts 

Cyber Essentials will likely be mandated if your organisation is a government body. But, you may not know it also applies to government suppliers. Getting Cyber Essentials certified can give you the ability to bid for lucrative government contracts, opening up an additional revenue stream. Or, if you’re already a government supplier, help you keep that contract. 

Meet your compliance requirements 

While this doesn’t apply to every industry, there are many sectors where Cyber Essentials certification is mandatory or at the very least, strongly recommended for compliance. These include sectors like education, healthcare, financial services and law. 

What should you look for in a Cyber Essentials certification body? 

We’ve established why Cyber Essentials is worth the investment. However, not all certification providers are created equal. So, what should you look for when picking a certification body?

Unlimited support 

Cyber Essentials certification is usually a fairly straightforward process. Nevertheless, if it’s your first time or you have more complex needs (such as multiple offices or hybrid working) you’ll need support. Look for providers who offer unlimited support and provide ready access to auditors. 

Free resubmissions 

It’s not always possible to complete the certification process first-time. In many cases, you’ll need to remediate aspects of your IT estate. And, when this happens, some providers will charge you for resubmissions, so keep an eye out for those who don’t. 

In-assessment guidance and automation

Some certification bodies use assessment platforms that guide as you go or automate parts of the process. Although this can (but not always) mean a greater up-front cost, it’s well worth it for the time it’ll save you.

Ongoing protection

Cyber Essentials is a great first step, but year-round protection goes further than certification day. Look for providers that will help your business stay protected year-round through vulnerability scanning, threat detection and cyber insurance. 

Want to know more about cybersecurity certifications? Check out our guide to UK certifications for everything you need to know.

What to expect from Cyber Essentials audits

cyber essentials audit

If you’re looking to strengthen your cybersecurity and data protection processes, a Cyber Essentials or Cyber Essentials Plus certification could be right for you.

Cyber Essentials is a framework that provides guidance to help businesses protect themselves against cyber threats. The final step in the process is a self-assessment to ensure you’ve implemented the necessary tools and measures to protect your business. 

Cyber Essentials Plus adheres to the same security controls, but it offers hands-on technical verification and an independent, third-party audit for added peace of mind.

Why consider Cyber Essentials or Cyber Essentials Plus accreditation?

You might decide to go for Cyber Essentials or Cyber Essentials Plus accreditation because of:

  • Client assurance: demonstrate to clients that data protection is a top priority
  • Industry standards: you work in an industry with higher-than-standard cybersecurity requirements
  • Bid for government contracts: having Cyber Essentials is mandatory when bidding for government contracts and creates a clear distinction from other businesses
  • Improved security processes provide a framework to improve your internal processes, saving time, money, and stress when implementing your cybersecurity

What’s the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is an independently verified self-assessment certification that ensures an organisation adheres to the most robust cybersecurity controls.

Cyber Essentials Plus requires the exact same technical expectations as Cyber Essentials but also includes an independent technical audit of your IT systems. It adds an extra level of assurance, but the pass bar is slightly higher than Cyber Essentials' self-assessment.

To achieve Cyber Essentials Plus, you first need to be Cyber Essentials certified. Here's a breakdown of the steps involved:

Cyber Essentials 

Cyber Essentials has five security controls you must meet to achieve certification. 

  • Firewalls
  • Secure configuration
  • User access control
  • Malware protection
  • Security update management

Obtaining the Cyber Essentials certification includes completing a self-assessment questionnaire, which the certification body reviews. Business owners must approve the self-assessment answers before sending them. 

Is there a Cyber Essentials audit?

There is no Cyber Essentials audit. The self-assessment will provide a range of questions that relate to the five control areas of Cyber Essentials, and the certification will expire after 12 months.

Cyber Essentials Plus 

Cyber Essentials Plus includes an additional technical audit of your IT systems to verify you have the right controls in place. An external auditor assesses your devices, systems, and processes for additional validation and added protection. 

Want to protect your business from 98.5% of cyber threats? Get Cyber Essentials certified today.

Benefits of a Cyber Essentials Plus audit

  • Credibility: an independent audit is more credible than a self-assessment
  • Independent assessment: provides an additional layer of validation beyond the self-assessment required for Cyber Essentials
  • Compliance assurance: an objective, professional opinion ensures compliance, providing peace of mind
  • Client trust: provides external proof that you take cybersecurity and data management seriously, enhancing trust with clients

What to expect from the Cyber Essentials Plus auditor

During the Cyber Essentials Plus audit, the auditor will:

  • Confirm which devices need auditing
  • Scan devices to identify vulnerabilities using Nessus Professional scanning software
  • Observe email processing with test attachments
  • Check downloads of file attachments from test websites
  • Verify that you've installed and configured your antivirus software correctly
  • Test multi-factor authentication (MFA) on applicable cloud services
  • Assess how well default browsers block malicious activity
  • Confirm account separation between admin and user accounts
  • Capture screenshots for evidence

Prepare for your Cyber Essentials Plus audit:

Information to give the auditor

  • Administrator-level domain access or create a new admin account
  • A list of all in-scope devices and operating systems
  • User email addresses for email/web tests
  • A signed consent form

Check and update software:

  • Ensure all devices, including servers, are up to date
  • Download and install the 7-day trial of Nessus Professional for a credentialed patch scan or use an alternative PCI-approved scanning tool
  • Remove unused software from all devices

If you run Windows:

  • Enable file and print sharing. You can find this option in advanced sharing settings

If you run Windows 10:

  • Set the Windows service “RemoteRegistry” start-up type to “manual.” Access this by typing “services” in the home screen search bar
  • Create a new registry value:
  • Type “regedit” in the home screen search bar
  • Hive and key path: HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem
  • On System, right-click and select New –> DWORD (32-bit) Value / REG_DWORD
  • Value name: LocalAccountTokenFilterPolicy
  • Value data: 1 (decimal)

If you run macOS:

  • Enable file sharing and remote login. You’ll find these options in System Preferences –> Sharing
  • Update AV engines and signature files. If you use an enterprise management dashboard to do this, even better
  • Activate and update AV plugins for every browser

Need more support?

If you’re not ready for a Cyber Essentials self-assessment or Cyber Essentials Plus audit, don’t rush into it. Make sure you’re prepared and consider your industry, goals, size, and the benefits of gaining a certification. 

Proving your cybersecurity credentials is important, and you can take it slow by starting with Cyber Essentials before graduating to Cyber Essentials Plus. By following these steps, you’ll be well-prepared for your Cyber Essentials self-assessment or Cyber Essentials Plus audit. 

For more guidance, download our comprehensive guide to cybersecurity certifications in the UK.

Cybersecurity certifications