What is Cyber Essentials>
In a nutshell, Cyber Essentials is a certification that verifies your company meets the most basic requirements of security as defined by the NCSC (National Cyber Security Centre) which ultimately overseas the standard. If you don’t meet these requirements you are more vulnerable. The scheme is delivered by IASME via an army of IT Professionals who act as assessors of the standard.
Cyber Essentials comes in two tiers.
- Self Assessment
- Assessed
The self-assessment is a question set that you fill in yourself, and the answers assessed for compliance with the standard. Nevertheless it is fairly rigorous and covers some technical areas, such as what versions of operating systems, browsers, and security software are in use, as well as policies such as how you mange admin rights. As such, you will likely need some help and guidance from your IT department or external support.
The assessed version comes later, if you want it, and involves the assessor taking your answers from the self-assessment and checking them directly. This includes a random sampling of your machines for update status and vulnerabilities, a basic external scan of your firewalls, checking that security software is working as expected, and verifying that MFA is enabled on all your Cloud services.
Not Just Technical, But Educational
While the Cyber Essentials baseline does check that technical controls are in place, that’s not it’s only purpose. It’s other significant benefit is to raise awareness within the organisation about what controls are in place, and what procedures there are for managing changes such as new software or staff access and admin rights.
Some 98% of cyber attacks in 2023 came in some form of social engineering – i.e. phishing, CEO fraud, and similar. Training and Awareness is therefore a vital component of any security solution in any company. The more staff are aware of the need for security and what the threats actually look like, the more savvy they will be in spotting them early.
Whose Fault Is It Anyway?
There is an old saying in the Cyber Security world that ‘you cannot outsource responsibility’. You may have an IT Support provider in place, but that doesn’t mean you are secure.
As IASME says:
“If your organisation outsources its IT, a third-party provider will manage your network for you, however, the responsibility for your network security is still yours… some IT providers may have good technical knowledge, but they do not always have good understanding about cyber security.”
In short, you cannot assume that your IT Support is taking care of your security. And even if they are, the responsibility is still yours, not theirs, regardless of whatever contractual requirements you may have in place for service delivery. If a staff member gives away their password, while technical controls may be in place, the breach is human error, not the fault of IT Support.
Let’s say IT implements MFA on all your Microsoft 365 accounts. They’re not responsible for any other cloud services you may use, so you cannot rely on them to do the same there, and some services have no centralised way of enforcing it on all accounts, leaving it up to individual staff to apply it themselves. Or, what if you decide you don’t want MFA on M365 and they disable it, because after all, you are the client and that’s what you want?
How do you know that your IT Support is protecting their own accounts? Do you know how they access your systems? It may surprise you. Do they have MFA themselves on those accounts? Does anyone share access to admin accounts?
What To Ask Your IT Support About Cyber Essentials
IASME have put together a list of questions, which mirrors the Cyber Essentials question set and your IT support should be able to answer them, or provide their own certificate for CE. If they can’t, you really need to question whether they are suitable for supporting you for IT, let alone whether you can rely on them for your security.
See here for the IASME guidance and the questions you should be asking: Cyber Essentials guide to working with a third party IT Provider
Macnamara’s Certifications
Macnamara holds both Cyber Essentials and Cyber Essentials Plus and are a certification body for the standard, as well as holding a suite of other certifications around security and information management (up to and including, as of October 2024, ISO27001). This is not just because we take security seriously, but as assessors ourselves we are required to meet if not exceed the standards that we are assessing against.
Our Certifications – Macnamara ICT

Ready to Talk?
If you’re looking for certification on Cyber Essentials and your IT Support doesn’t have it themselves or cannot assess you or help you through it, then get in touch and we can help you out.


