ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Cyber Essentials: the case for compliance

cyber security standards compliance
cyber security standards compliance

Phil Robinson at Prism Infosec asks why more organisations aren’t embracing Cyber Essentials and ISO 2700

 

Cyber-security standards enable businesses to readily implement best practice but their adoption remains low. Only 6 per cent of businesses have the Cyber Essentials certification and a paltry one per cent have Cyber Essentials Plus. Just 8 per cent adhere to ISO 27001 according to the Cyber Security Breaches Survey 2022 published by the DCMS.

 

If we look specifically at medium to large businesses, the UK government’s Cyber Security Longitudinal Survey (CSLS) found 32 per cent comply with all three standards but 41 per cent have none of them.

 

Standards undoubtedly raise the bar and make businesses more secure. So why aren’t more businesses keen to comply?

 

According to the DCMS, the chief reason is that most are oblivious to the existence of Cyber Essentials, with only 16 per cent claiming to be aware of the standard. Others expressed concerns over the lack of flexibility, saying the requirements could not be tailored to the needs of their business. A further reason was of course cost, with many seeking to justify the time and investment needed to attain accreditation.

 

Cyber Essentials, however, is widely regarded as a low-cost exercise. It’s a self-certified standard and is relatively quick to complete, with accreditation lasting a year.

 

For those businesses worth less than £20m, cyber insurance can be optionally included at no further cost. Yet even with this sweetener, the longitudinal survey found only 19 per cent of businesses had adopted Cyber Essentials, only 15 per cent were ISO 27001 compliant and a mere eight per cent had passed the audit necessary to achieve Cyber Essentials Plus.

 

Compliance comparisons

Cyber Essentials seeks to protect data by securing IT infrastructure, networks and devices. It’s a pre-requisite to tender for any UK Government contract so it is sometimes perceived as public sector-oriented when in fact it is equally applicable to suppliers, third parties and customers in a commercial context.

 

It seeks to establish a reasonable baseline of cyber-security hygiene that will deter the most common threats through the application of technical controls. These are applied across five areas: boundary firewalls and Internet gateways, secure configurations, user access controls, malware protection and patch management.

 

In contrast, ISO 27001 is focused not just on the protection of electronic assets, but all information, even paper-based documents. Internationally recognised, it’s more extensive than Cyber Essentials, with 114 controls in 14 groups and 35 control categories.

 

Unlike Cyber Essentials, it can take 6 to 12 months to complete (if done properly, using an accredited certification body) with accreditation by an external auditor. Because of this, it tends to be regarded as expensive. On the plus side, it does last three years, albeit with a requirement to conduct audits during that time.

 

What’s interesting about ISO 27001 is that it doesn’t supersede Cyber Essentials. ISO 27001 is risk management-based. Outside mandatory requirements, the business can choose which security controls to implement. As a result, many organisations request that, even if a supplier is ISO 27001 accredited, they must also have Cyber Essentials because the latter prescribes specific controls that must be observed.

 

But Cyber Essentials is by no means an easy win. Very few businesses manage to satisfy all five requirements, with only 16 per cent of medium, 18 per cent of large and 25 per cent of very large organisations making the grade.

 

Talk to any Cyber Essentials auditor and they’ll tell you that ISO 27001 accredited businesses often struggle to achieve Cyber Essentials Plus, particularly in the areas of patch management and maintaining supported applications, Operating Systems and hardware assets.

 

Selecting a standard

So, does this mean that businesses should choose between them? Various factors come into play here, from the size of the business and the amount of data it processes to its target markets.

 

The CSLS study revealed clear patterns of adoption, with IT and communications businesses the most likely to comply with all three standards. In these industries, 47 per cent have ISO 27001, 42 per cent Cyber Essentials and 27 per cent Cyber Essentials Plus.

 

Those in the Financial sector companies tended to opt for Cyber Essentials (32 per cent) and Cyber Essentials Plus (17 per cent), as did those in the Scientific sector. Conversely, administration and real estate businesses opted for ISO 27001, with 21 per cent accredited to the standard.

 

Rather worryingly, 22 per cent embraced compliance with Cyber Essentials and nine per cent Cyber Essentials Plus as a reaction to a cyber incident in the last 12 months. (This is compared with 15 per cent and 6 per cent for those organisations that had not had an incident).

 

This reveals that compliance can and does improve security posture, but it also emphasises the need for businesses to be proactive. It makes much more sense to get accredited to minimise the impact of an attack.

 

There are also plenty of sectors where organisations largely have either elected not to adopt any of the three standards or remain unaware of them. These include the hospitality sector, retail, social care, production and utilities. Companies in all these sectors would benefit from achieving or at the very least validating their maturity against a baseline cyber-security standard.

 

First steps towards cyber compliance

For those looking to take that first step, the advice should be to look at which standard to start with. But that’s not the end of the journey. Cyber Essentials can provide a good introduction to certification and won’t monopolise resource but it’s worth considering upgrading this to Cyber Essentials Plus.

 

This step should be taken within three months of being awarded Cyber Essentials certification. It involves an independent auditor assessing a sample of user endpoints (laptops, workstations, mobile devices etc), cloud services (Office 365, Google Apps et al) and Internet IP addresses for compliance with applicable areas of the standard.

 

Many choose to then move on to ISO 27001 because it is so much more extensive in scope, covers information in different formats, and is so well known, engendering confidence.

 

Starting with ISO 27001 can lead to the implementation within the business of a more comprehensive framework that incorporates governance, compliance, risk management and business continuity planning, for instance.

 

It is then possible to certify with Cyber Essentials / Plus to assess the effectiveness of technical security controls in practice, as the two are complementary in approach. It’s even possible to seek accreditation of all three standards simultaneously and this can save considerable time and expense.

 

What’s imperative is that all industries realise these standards are relevant to them and can help them to dramatically improve their understanding and observance of cyber-security best practice. These standards are the result of the best minds in the business and years of tried and tested security techniques - who wouldn’t want to benefit from that?

 


 

Phil Robinson is Principal Security Consultant and Founder of Prism Infosec

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543