Compliance & cyber security

Cyber Essentials Plus and supply chain cyber security support

Customers and supply chains are increasingly asking SMEs to prove they have proper cyber security controls in place. Kinetic helps you understand what is required, close gaps and put practical controls in place.

Check if your IT is ready for Cyber Essentials Plus Call 01623 707 888

Certified cyber security support

Guidance from a Cyber Essentials Plus certified provider

Kinetic helps engineering and manufacturing SMEs prepare for Cyber Essentials, close the technical gaps behind the answers, and move towards Cyber Essentials Plus when customers, tenders or supply chains require a higher level of assurance.

Cyber Essentials certification logo Cyber Essentials Plus certification logo

Why this is coming up now

Cyber Essentials Plus is becoming a condition of doing business

For many engineering and manufacturing SMEs, Cyber Essentials Plus is no longer optional. It can become a requirement for keeping contracts, winning tenders or satisfying customer security checks - particularly in aerospace, defence, secure facilities and public sector supply chains.

Tier 1 suppliers and cyber security insurers are increasingly asking businesses further down the supply chain to prove the same standard, often with a short deadline attached. Leaving it until a customer asks rarely leaves enough time to close the gaps properly, so businesses that prepare early are in a far stronger position when the request lands.

"Our customers are telling us we need Cyber Essentials Plus."

"A Tier 1 supplier is asking for more compliance."

"We need to prove our IT and cyber security controls are good enough."

"We have had a cyber security insurance questionnaire and do not know how to answer it properly."

How the process works

Cyber Essentials is a readiness and implementation process, not just a form

The current Cyber Essentials standard requires you to understand what is in scope and confirm that the required controls are working across users, devices, software, networks and cloud services. We guide the process from readiness review through to submission and renewal.

1

Confirm scope

Identify the networks, users, devices, cloud services, software and accounts included in the assessment.

2

Review readiness

Check the current setup against the Cyber Essentials controls and agree the work needed before submission.

3

Close gaps

Implement practical changes such as MFA, patching, device hardening, access control and malware protection.

4

Submit and maintain

Support the self-assessment, prepare for Plus where required, and review the controls each year.

Readiness review

What we check before certification

A readiness review gives you a clear view of what is already in good shape and what needs to be fixed before certification. The final work required depends on your actual systems, so we avoid generic pricing on this page and confirm requirements after reviewing your environment.

Users, devices and accounts

Number of users and devices, administrator accounts, leaver process, third-party access, mobile devices and BYOD.

Software and cloud services

Microsoft 365, line-of-business applications, operating systems, cloud storage, hosted services and unsupported software.

Networks and protection

Firewalls, remote access, update management, malware protection, backup position and evidence of controls.

What we help with

Cyber Essentials, Cyber Essentials Plus and the controls behind them

Certification depends on your systems meeting the required standard. We help you get there by working through the controls that actually matter:

  • Cyber Essentials and Cyber Essentials Plus readiness
  • Cyber security insurance and supplier security questionnaires
  • Multi-factor authentication (MFA) and access control
  • Patching, endpoint protection and device management
  • Backup controls and evidence of controls
  • User awareness training and phishing simulations

The five controls

The practical areas Cyber Essentials expects you to manage

We translate the standard into practical IT work, so the answers on the assessment reflect controls that are actually in place.

1

Firewalls

Review internet-facing services, firewall rules, remote access, default passwords and software firewalls for remote users.

2

Secure configuration

Remove unnecessary accounts, software and services, harden devices, and check password, PIN or biometric controls.

3

Security updates

Confirm operating systems, applications, browsers, security tools and firmware are supported and updated quickly enough.

4

User access control

Review MFA, administrator rights, standard user permissions, leaver processes and third-party support accounts.

5

Malware protection

Check that devices have active, updated protection against malware, malicious code and malicious websites.

Plus

Technical verification

Cyber Essentials Plus adds independent testing to verify that the required controls work in practice.

Typical preparation work

Common changes before a business is ready

Cyber Essentials Plus

When customers need more than self-assessment

It is often the level requested by customers, tenders, suppliers, insurers and higher-compliance supply chains. We help you prepare by making sure the underlying controls are implemented, evidenced and maintained rather than rushed at the point of assessment.

Cyber Essentials

Self-assessment

You confirm the five controls are in place through a verified self-assessment questionnaire.

Cyber Essentials Plus

Independent testing

A certification body independently tests that the same controls are actually working in practice, not just declared.

Need Cyber Essentials Plus because a customer or supplier asked for it?

Speak to Kinetic and we will help you understand exactly what is being asked of you.