Introduction
Many organisations achieve Cyber Essentials certification and then wonder whether Cyber Essentials Plus is worth the additional effort.
Cyber Essentials Plus builds upon the standard certification by independently validating that security controls are functioning correctly.
What Will Be Tested?
The assessment typically includes:
Vulnerability Scanning
Devices are scanned for common weaknesses and missing updates.
External Testing
Internet-facing systems are reviewed to identify exposed services and vulnerabilities.
Malware Protection Validation
Security controls are checked to ensure malicious software would be detected and prevented.
User Device Testing
Sample devices are examined to verify compliance with Cyber Essentials requirements.
Preparing for Success
Before assessment, organisations should ensure:
- Devices are patched
- MFA is enabled
- Unsupported software is removed
- Administrative privileges are reviewed
Preparation significantly increases the likelihood of a successful outcome.
Conclusion
Cyber Essentials Plus provides independent assurance that your security controls are operating effectively and demonstrates a higher level of commitment to cyber security.