Compliance & cyber security
Customers and supply chains are increasingly asking SMEs to prove they have proper cyber security controls in place. Kinetic helps you understand what is required, close gaps and put practical controls in place.
Certified cyber security support
Kinetic helps engineering and manufacturing SMEs prepare for Cyber Essentials, close the technical gaps behind the answers, and move towards Cyber Essentials Plus when customers, tenders or supply chains require a higher level of assurance.
Why this is coming up now
For many engineering and manufacturing SMEs, Cyber Essentials Plus is no longer optional. It can become a requirement for keeping contracts, winning tenders or satisfying customer security checks - particularly in aerospace, defence, secure facilities and public sector supply chains.
Tier 1 suppliers and cyber security insurers are increasingly asking businesses further down the supply chain to prove the same standard, often with a short deadline attached. Leaving it until a customer asks rarely leaves enough time to close the gaps properly, so businesses that prepare early are in a far stronger position when the request lands.
"Our customers are telling us we need Cyber Essentials Plus."
"A Tier 1 supplier is asking for more compliance."
"We need to prove our IT and cyber security controls are good enough."
"We have had a cyber security insurance questionnaire and do not know how to answer it properly."
How the process works
The current Cyber Essentials standard requires you to understand what is in scope and confirm that the required controls are working across users, devices, software, networks and cloud services. We guide the process from readiness review through to submission and renewal.
Identify the networks, users, devices, cloud services, software and accounts included in the assessment.
Check the current setup against the Cyber Essentials controls and agree the work needed before submission.
Implement practical changes such as MFA, patching, device hardening, access control and malware protection.
Support the self-assessment, prepare for Plus where required, and review the controls each year.
Readiness review
A readiness review gives you a clear view of what is already in good shape and what needs to be fixed before certification. The final work required depends on your actual systems, so we avoid generic pricing on this page and confirm requirements after reviewing your environment.
Number of users and devices, administrator accounts, leaver process, third-party access, mobile devices and BYOD.
Microsoft 365, line-of-business applications, operating systems, cloud storage, hosted services and unsupported software.
Firewalls, remote access, update management, malware protection, backup position and evidence of controls.
What we help with
Certification depends on your systems meeting the required standard. We help you get there by working through the controls that actually matter:
The five controls
We translate the standard into practical IT work, so the answers on the assessment reflect controls that are actually in place.
Review internet-facing services, firewall rules, remote access, default passwords and software firewalls for remote users.
Remove unnecessary accounts, software and services, harden devices, and check password, PIN or biometric controls.
Confirm operating systems, applications, browsers, security tools and firmware are supported and updated quickly enough.
Review MFA, administrator rights, standard user permissions, leaver processes and third-party support accounts.
Check that devices have active, updated protection against malware, malicious code and malicious websites.
Cyber Essentials Plus adds independent testing to verify that the required controls work in practice.
Typical preparation work
Cyber Essentials Plus
It is often the level requested by customers, tenders, suppliers, insurers and higher-compliance supply chains. We help you prepare by making sure the underlying controls are implemented, evidenced and maintained rather than rushed at the point of assessment.
You confirm the five controls are in place through a verified self-assessment questionnaire.
A certification body independently tests that the same controls are actually working in practice, not just declared.