Compliance

cyber essentials plus vs iso 27001 comparison a three shields stepped plinth

Cyber Essentials Plus vs ISO 27001: Smart, Proven Choice

Cyber Essentials, Cyber Essentials Plus and ISO 27001 are treated as three rungs on one ladder, and that is the first mistake. Two of them certify a fixed set of five technical controls; the third certifies the management system that decides which controls you need at all. This guide sets the three side by side on assessment method, cost, elapsed time, scope, renewal and buyer recognition. It walks through the five Cyber Essentials controls under version 3.3 of the Requirements for IT Infrastructure, the five test cases behind a Cyber Essentials Plus audit, and the mandatory clauses and 93 Annex A controls that ISO 27001 adds on top. It closes with a decision path based on who is actually asking, the evidence overlap if you end up holding both, and the sequencing that keeps the combined bill down.

Read more
cyber essentials failure reasons how to avoid a shield five panels plinth

Cyber Essentials Failure Reasons: Proven Fixes to Avoid

Cyber Essentials failure is rarely caused by a sophisticated security gap. It is caused by an end-of-life laptop nobody logged, a cloud service quietly left outside the scope statement, or a director who has been reading email from an administrator account for four years. This guide works through the reasons organisations actually fail against version 3.3 of the Requirements for IT Infrastructure: scope boundaries that exclude what they cannot, unsupported software as an automatic fail, the 14-day patching deadline and its CVSS trigger, administrator account separation, mandatory MFA on cloud services, home working and BYOD traps, undocumented firewall rules, and the five Cyber Essentials Plus test cases where paper answers meet a live scan. It closes with a 60-day readiness plan and what to do inside the two-working-day correction window if a result has already come back non-compliant.

Read more
cyber essentials for suppliers contract clauses a shield with keyhole plinth

Cyber Essentials for Suppliers: Proven Safe Contract Terms

Most organisations ask for Cyber Essentials during the tender and never mention it again, which leaves the requirement sitting in a questionnaire with no expiry date, no evidence obligation and no consequence attached. This guide shows how to write it into the contract instead: which suppliers belong in scope and at what level, model clause wording for the certification obligation, how to define scope so a certificate for somewhere else cannot satisfy it, what evidence to demand and how to verify it against the register, how the obligation flows down to subcontractors, what happens when certification lapses mid-term, and a proportionate remedy ladder that runs from a rectification plan to termination without ending a workable relationship.

Read more
microsoft 365 offboarding checklist departing employees a closed door slab on plinth

Microsoft 365 Offboarding Checklist: Essential Risk Guide

Disabling an account is not offboarding. This guide walks the full sequence for a departing employee — revoking live sessions rather than just resetting the password, converting the mailbox to a licence-free shared mailbox, rescuing OneDrive before the deletion clock runs, reassigning ownerless Teams, reclaiming licences and add-ons, retiring devices in Intune, and keeping the compliance evidence that proves it all happened.

Read more
microsoft 365 data retention vs backup a sealed cube beside open cube with arrow

Microsoft 365 Data Retention vs Backup: Simple Risk Guide

Retention preserves; backup restores — and confusing the two is where most avoidable data loss in UK businesses begins. This guide draws the line precisely: what Microsoft 365 data retention actually does through Purview policies, labels and the Preservation Hold Library, which native windows expire and when, the five structural gaps where preservation stops and restoration starts, the failure scenarios retention cannot cover, what retention is genuinely better at, how each side is licensed and priced, and a 30-day plan to close the gap.

Read more
microsoft 365 security audit tenant checklist a shield with magnifying glass

Microsoft 365 Security Audit: Proven Tenant Risk Checklist

A working tenant audit checklist for UK businesses on Business Premium, E3 or E5 — how to scope the review, enumerate privileged roles and MFA exemptions, read Conditional Access exclusions properly, harden email and DMARC, find anonymous sharing links and guest sprawl, audit OAuth consent and service principals, confirm logging and alerting would actually detect an incident, and turn the findings into a ranked list somebody will fix.

Read more
iso 42001 implementation cost controls certification a glowing seal above layered cube core

ISO 42001 Implementation: Essential Cost and Risk Guide

A realistic ISO 42001 implementation lands between roughly £15,000 and £90,000 in the first year, and almost none of that sits on a single invoice. This guide splits the number into certification body audit fees, external support, tooling and internal staff time, maps all 38 Annex A controls you will have to evidence, explains how the AI impact assessment differs from a risk assessment, sets out a realistic six to fifteen month timeline from gap analysis to certificate, and lists nine levers that genuinely reduce spend without weakening the certificate.

Read more
iso 27001 certification cost uk smes a certificate seal on stacked coin discs

ISO 27001 Certification Cost: The Smart, Essential UK SME Guide

The realistic ISO 27001 certification cost for a UK SME lands between roughly £6,000 and £48,000 in the first year, and almost none of that sits on a single invoice. This guide splits the number into certification body audit fees, external support, tooling and internal staff time, benchmarks each by headcount, explains how audit days are calculated, sets out a realistic six to twelve month timeline from gap analysis to certificate, and lists nine levers that genuinely reduce spend without putting the audit outcome at risk.

Read more
cyber security and resilience bill a glossy shield ringed by network nodes

Cyber Security and Resilience Bill: Essential Risk Guide

The Cyber Security and Resilience Bill brings managed service providers, data centres and designated critical suppliers into cyber regulation for the first time. Even businesses that are never regulated directly will feel it, because their IT supplier acquires a regulator, a 24-hour incident reporting clock and turnover-based fines. This guide covers where the Bill has reached in Parliament, the four-part managed service provider test, the customer notification duty most buyers miss, the two penalty bands, and the five questions worth putting to your provider before your next renewal.

Read more
CHAT