15 Aug 2024

What is Cyber Essentials and why does it matter?

Many organisations ignore cybersecurity and its benefits for people, culture, and finances. They think they won’t be targeted by cyber-crime. But cyber attackers know that data is valuable both internally and externally. Indeed, blocking companies from their own data can be as harmful as leaking it.

Half of businesses and a third of charities have faced cyber-attacks in the past year. This number is higher for medium (70%) and large (74%) businesses, and high-income charities (66%) Gov.uk, 2024.

Cyber Essentials is a government-backed scheme to help organisations protect against common cyber-attacks. It demonstrates to customers, suppliers and other stakeholders that the organisation is proactive about data protection.

Who does Cyber Essentials apply to?

Cyber Essentials is recommended for all organisations. Since October 2014, many government contracts require Cyber Essentials certification before going to tender. Suppliers to the following government departments must be certified if you are handling sensitive data:

  • Non-ministerial departments
  • Executive agencies
  • Non-departmental public bodies including the Ministry of Defence

Supplier requirements:

Suppliers must certify to Cyber Essentials if they handle, store or process any of the following, for a government department:

  • Personal information of citizens (e.g. home addresses, bank details)
  • Personal information of government employees (e.g. payroll, travel bookings)
  • ICT systems that store or process data at the OFFICIAL level of the Government Protective Marking scheme

What if I don’t work with government contracts?

Cyber Essentials is useful for all organisations. It shows good internal controls and helps protect against common cyber-attacks. Cyber criminals target businesses of all sizes. Cyber Essentials is achievable for all, no matter how complex or simple your IT infrastructure is.

How to get Cyber Essentials certified

Start with a Cyber Essentials self-assessment, which can be supported by an accredited certification body. After the self-assessment, a Cyber Essentials auditor will review your organisation and give feedback for improvements and how to further align to the standard. You will then be issued with a certificate that is valid for 12 months. The standard is updated annually to protect against new threats.

How can we help?

PKF Francis Clark is an accredited certification body of the IASME Consortium. We can support you throughout the certification process. For more information, contact our cyber security Director, Phil Osgathorpe, for a free initial conversation.

Get in touch

Latest news

Reduce your debtor’s days and improve cashflow with Xero’s payment services

28 August 2024

Read
A man is analysing some cyber data on a large screen

Secure by design principles: foundations for building resilient digital services – step two

5 August 2024

Read

Future trends in cloud accounting

24 July 2024

Read
A laptop is placed on a table while a woman checks her phone for an email.

Making tax digital – all you need to know

11 June 2024

Read
A man is looking at his accounts on a computer screen.

Making tax digital for ITSA – all you need to know

11 June 2024

Read
A lady is looking at a laptop with numbers and a padlock on the screen.

The importance of cyber security in your business

15 April 2024

Read
A female farmer stands amongst her crop as she checks her computer tablet.

Cyber & Agriculture

7 November 2023

Read
An office worker sits in front of a computer whilst looking at a notepad with his mobile phone held to his ear.

Everything you need to know about: Receipt Capture Apps

11 October 2023

Read
Padlock resting on a computer coding sheet

Cybersecurity – latest trends, challenges and actions

14 July 2023

Read
A lady is looking at a laptop with numbers and a padlock on the screen.

Information security benchmark ISO 27001 – what has changed?

6 March 2023

Read
A group of primary school children work on computer tablets in the classroom.

Cyber security in schools

22 February 2023

Read
A business woman talks on her mobile phone whilst working at her computer at home.

Digitalisation of Bookkeeping: how it is positively impacting UK businesses

17 February 2023

Read