With many industry reports highlighting that 60%+ of the security breaches that occurred in the past year involved a vulnerability for which a patch already existed, (not a zero-day or sophisticated nation-state exploit attack) and it taking organisations over 200 days on average to identify where a security breach has occurred, now is the time for organisations to start thinking about and taking vulnerability management more seriously.

The statistics above are not unrelated, they describe a single, coherent threat that many businesses are not taking action on. Most UK organisations are carrying vulnerability risk they cannot see, prioritise or close. The root cause is almost never a lack of security tools. It is a lack of structure around how those tools are used, what they tell you, and what happens next.

In this blog article we explore why Vulnerability Management needs to be a business priority. We also cover why all organisations should be putting this capability in place if they want to stay resilient and secure against attack both today and in the future.

The difference between Scanning and Managing

Most businesses run some form of vulnerability scanning. They have a tool, sometimes built into a broader security platform, sometimes a standalone product, that periodically checks their estate and produces a list of findings. They know the tool exists. Someone on the team looks at it. Occasionally, patches are applied.

That is scanning. It is not vulnerability management.

This distinction matters because scanning answers one question – what vulnerabilities exist?

Vulnerability management answers a harder set of questions.

Which of those vulnerabilities represent the most significant risk to this particular organisation, given how its systems are configured, what data they hold, how they connect to the outside world, and what an attacker would actually need to do to exploit them? And crucially, who is responsible for fixing them, by when, and how do we know they have been fixed?

The gap between those two sets of questions is where most breaches happen. Not because organisations don’t know about vulnerabilities in their IT estates. But because they lack the structure to turn a list of findings into a governed, prioritised programme of remediation with clear accountability and measurable progress.

Why the problem is Structural, not Technical

It is tempting to treat vulnerability management as primarily a technical problem. Buy a better scanner. Add more coverage. Increase scan frequency. Each of these things has value, but none of them addresses the structural issues that cause vulnerability programmes to stall.

The first structural problem is volume without context. Modern IT estates, particularly those that have grown through cloud adoption, remote working infrastructure, or acquisitions, generate vulnerability findings at a scale that cannot be addressed manually. An uncontextualised scan of a medium-sized business might return thousands of findings across hundreds of systems. Without a clear methodology for translating that volume into a prioritised, actionable list, most organisations default to inaction. They close the highest-severity findings where they can and leave everything else in a growing backlog that nobody owns and nothing resolves.

The second structural problem is the absence of a baseline. Many organisations cannot confidently answer the question “what did our vulnerability posture look like six months ago, and has it improved”. Without a baseline, there is no way to demonstrate progress to a board, satisfy an insurer’s question about remediation, or identify whether a recent infrastructure change has materially increased exposure. Scanning without a baseline is collecting data. Vulnerability management is building a record.

The third structural problem is ownership ambiguity. In most organisations without a dedicated security operations function, vulnerability remediation falls between teams. IT operations owns patching. Development owns application code. Cloud teams own infrastructure configuration. Security owns the findings, but has no direct authority to make remediation changes. Without a clear governance model that defines who receives findings, who is accountable for remediation, and what escalation looks like when remediation stalls, vulnerability management programmes fragment into a series of disconnected conversations with no reliable closure mechanism.

The Compounding Effect of a Growing Estate

These structural problems are manageable when an organisation’s IT estate is stable and well-understood. They become significantly harder when that estate is changing, through cloud adoption, which introduces new infrastructure at a pace that outstrips manual inventory;  acquisitions, which bring inherited systems with unknown security history; rapid growth, which adds users, devices, and services faster than governance frameworks can absorb; or through the shift to hybrid and remote working, which has permanently extended the boundary of what counts as the IT estate.

The practical consequence is that many organisations are managing vulnerability risk against an incomplete picture of their own attack surface. They are scanning what they know about and making decisions about remediation priority based on a partial view that may be missing the very systems an attacker would find most attractive.

This is not a failure of security awareness. It is a structural consequence of how organisations grow, and it requires a structural response.

What Good Vulnerability Management Actually Looks Like

Understanding what good looks like is the starting point for identifying the gap between current practice and where an organisation needs to be.

Good vulnerability management begins with an accurate, maintained inventory of the assets in scope, not a theoretical list, but a continuously reconciled picture of what is actually present in the environment. This sounds basic, but it is frequently the hardest part. Shadow IT, legacy systems, cloud-native infrastructure, and contractor-managed devices all contribute to inventory drift.

From a reliable inventory, good vulnerability management applies contextual prioritisation, not just CVSS scores, but asset criticality, exploitability in the wild, network exposure, and the specific sensitivity of the data or functions hosted on affected systems. A high-severity vulnerability on an internet-facing authentication system is categorically different from the same vulnerability on an internal development server with no external connectivity, and treatment should reflect that difference.

Good vulnerability management produces governance-ready output. Executive reporting that communicates risk in business language, not technical jargon; tracking that shows remediation progress over time; and audit-ready documentation that satisfies the questions insurers, regulators, and enterprise customers are increasingly likely to ask.

Critically, good vulnerability management closes the loop. It tracks findings through to remediation, validates that patches have been applied correctly, and maintains a continuous record of the organisation’s risk posture over time, not a point-in-time snapshot that is out of date the moment it is produced.

The situations where this becomes urgent

For most organisations, vulnerability management improvement is a steady-state priority, important, but not urgent in any given week. There are situations, however, where it becomes genuinely pressing.

An upcoming cyber insurance renewal is one of the most common. Insurers are asking increasingly detailed questions about scanning frequency, remediation timelines, and the governance processes that surround vulnerability management. Organisations that cannot answer those questions credibly or that can only answer them based on informal practices rather than documented processes are finding that coverage becomes harder to obtain, premiums increase, or specific exclusions are applied to incidents that might have been prevented by better vulnerability controls.

A compliance audit or certification assessment is another area that often becomes urgent in relation to vulnerability management. ISO 27001, SOC 2, PCI DSS, Cyber Essentials Plus, and DORA all have requirements that touch vulnerability management directly or indirectly. Organisations that treat vulnerability management as a background activity often find, when they engage in a formal audit process, that their existing practices do not meet the evidentiary standard required for certification or compliance.

The third area when vulnerability management becomes a priority is when there has been a significant change to the IT estate, a cloud migration, an acquisition, a major infrastructure refresh, will routinely reveal vulnerability posture issues that were hidden by the previous environment’s stability. The act of changing creates new exposure, and the process of integrating new systems into existing governance frameworks is rarely instantaneous.

A new security leader taking stock of inherited practices will frequently find vulnerability management is an area where there is significant distance between what people believe is happening and what is actually happening in practice. Establishing a reliable baseline is often the first practical step toward building a credible programme.

And increasingly, enterprise customers and regulated sector procurement processes are requiring suppliers to demonstrate a managed approach to vulnerability risk as a condition of doing business. The question is no longer just “do you scan?” but “can you show us your remediation process and your progress over time?”

Why Existing Approaches Often Fall Short

The most common objection to investing in structured vulnerability management is “we already have tools that do this.” And often that is technically true. The gap is almost never in the tooling; it is in what surrounds the tooling.

Without a defined baseline, you cannot measure improvement. Without a prioritisation framework, high-volume scan output becomes overwhelming rather than actionable. Without tracked remediation, you cannot demonstrate to an auditor, an insurer, or a board that findings are being addressed. Without regular executive reporting, the information stays in the technical team and never reaches the people who carry the governance accountability.

At Cyberfort we have recognised where vulnerability scanning and management falls short. To help businesses our experts have created a Managed Vulnerability Health Check, which is designed to close those gaps. It is not a scanning tool, it is a structured programme that wraps around your existing environment and provides the process, the prioritisation, reporting, and the continuous tracking that turns scan output into genuine risk reduction. In the next section of this article we summarise this approach and identify what the key outcomes are for IT, security and business leaders.

The Four Steps of a Structured Approach to Vulnerability Management

Establishing or improving a vulnerability management programme is not a single project with a defined end date. It is a continuous cycle, but it has a beginning, and that beginning follows a logical sequence outlined below.

The cycle then repeats, with each iteration building on the baseline established in the previous one, so the organisation accumulates an increasingly accurate and well-evidenced picture of how its vulnerability posture changes over time.

The cycle then repeats, with each iteration building on the baseline established in the previous one, so the organisation accumulates an increasingly accurate and well-evidenced picture of how its vulnerability posture changes over time.

The gap between how fast organisations move and how often they test their security is quickly becoming one of the most significant risk factors for UK businesses.

Think about the rate of change in a typical organisation over the course of a year. New applications go live. Cloud environments are extended. Third-party integrations are added. Infrastructure is migrated. Teams expand and bring new devices and access requirements with them. Each of these changes alters the attack surface, sometimes in small ways, sometimes materially.

Now consider when penetration testing happens. For most organisations, the honest answer is ‘when it has to’ or ‘when we are required to, so we can meet a compliance standard’. Annual cycles, driven by compliance obligations or insurance requirements, have become the default rhythm. A test happens, a report is produced, remediation actions are (ideally) completed, and then the clock starts again until the same point arrives next year.

The problem with this model is not the testing itself. Penetration testing, done well, remains one of the most valuable tools available for understanding real-world exposure. The problem is the assumption that a point-in-time test, carried out once a year against an estate that changes continuously, provides meaningful ongoing assurance. It does not.

This article explores why the traditional penetration testing model has structural limitations that many organisations have not yet reckoned with, and what a more responsive approach looks like in practice.

The numbers behind the gap

Before examining the issues, it is worth understanding the value of penetration testing and why at Cyberfort we believe there needs to be a new approach taken by businesses.

According to Verizon’s 2026 Data Breach Investigations Report, vulnerability exploitation has overtaken stolen credentials as the single most common way attackers get in, now accounting for 31% of confirmed breaches, up from 20% the year before. It should also be noted that only 26% of known exploited vulnerabilities were actually remediated in 2025, down from 38% the year before. The implication is clear, the majority of successful attacks are not the result of sophisticated zero-day exploits or nation-state-level techniques. They are the result of known gaps that were either not found, prioritised, or fixed in time.

Take these findings alongside the UK government’s Cyber Security Breaches Survey 2025, which found just 12% of UK businesses carried out penetration testing in the past 12 months there is clearly a gap to close with penetration testing for businesses. Given the rate at which most organisations change their IT environments, that means the vast majority of businesses are operating with an attack surface that has not been assessed at all in the past year, let alone re-assessed against what has changed since.

Taken together, these points tell the same story. Organisations are accepting more risk than they realise, not because they are careless, but because the testing model they rely on was designed for a slower, more static environment.

Why the traditional Penetration Testing model has structural limitations

It is important to be clear, traditional, comprehensive penetration testing programmes have genuine value. For large, complex environments, particularly where regulatory requirements mandate deep, formal assessment, a structured, multi-week Pen Testing engagement conducted by a qualified team remains the right approach.

But the traditional model has characteristics that make it a poor fit for certain situations due to the following reasons:

None of these are criticisms of the traditional Pen Testing model for what it is designed to do. They are observations about the gap it leaves and the situations where a different approach is more appropriate.

The situations where testing most often falls behind and why a Rapid Pen Testing approach could be the answer

Understanding where the gap is widest helps identify where a more responsive Pen Testing approach matters most. Examples of when a Rapid Pen test approach could be the answer include:

What these situations share is a need for structured, credible security testing that can be scoped, mobilised, and delivered without the weight of a full-scale programme.

What Rapid Pen Testing actually looks like

Speed and rigour are not opposites in penetration testing. A well-designed, tightly scoped engagement can deliver genuine technical depth and actionable findings within a condensed timeframe, provided the scope is defined precisely and the methodology is structured from the outset.

The key discipline is scope definition. A rapid engagement is not a broad sweep across an entire estate. It is a focused, expert assessment of a defined target a specific application, an external perimeter, a cloud environment, a set of internal systems. Precisely because the scope is bounded, the testing can go deep within it. So, what does this look like in reality?

What you should look to achieve from a Rapid Pen Test engagement 

At the end of the engagement, the organisation should have a validated picture of its security posture within the tested scope, a prioritised remediation plan, documented evidence of testing that can be used in compliance, insurance, and customer contexts, and clear guidance on what to fix first and why.

That last point matters more than it might appear. One of the most common challenges organisations face after a pen test is knowing where to start. A long list of findings with no clear prioritisation creates paralysis rather than action. A Rapid Pen Test Sprint is designed specifically to avoid that outcome, findings are prioritised by risk, context is provided, and the remediation path is clear from the moment the report lands.

Why can’t we just undertake a vulnerability scan instead?

Automated vulnerability scanning is a useful tool. It identifies known vulnerabilities at scale and provides a baseline view of patch status and configuration. But it has a fundamental limitation, it cannot simulate what an attacker actually does.

Penetration testing is adversarial by design. A qualified tester does not just identify that a vulnerability exists, they attempt to exploit it, chain it with other weaknesses, and assess whether it can be used to gain meaningful access or impact. That context is what separates a theoretical risk from a demonstrated one.

The practical implication is that scanning and testing answer different questions. Scanning answers ‘what known vulnerabilities exist in this environment?’ Testing answers ‘what can an attacker actually do with them?’ Both questions matter, but they are not interchangeable. Organisations that rely solely on automated scanning for security assurance in between penetration tests are answering a smaller question than they may realise.

Procurement teams are quietly turning Cyber Essentials from a routine formality into a condition of doing business. If your Cyber Essentials or Cyber Essentials Plus certification isn’t in place before the next tender lands, you won’t lose on price or capability. You’ll potentially lose before you’re even in the room.

In this article Cyberfort security experts look at why more organisations are now mandating Cyber Essentials and Cyber Essentials Plus as a key requirement for their suppliers. They also cover what it means for businesses bidding for work where this certification is a critical requirement in the procurement process.

Your next lost deal won’t be logged as a lost deal in a traditional way

It will look like a procurement email. A supplier questionnaire returned with a box unticked. A tender portal that quietly closes your submission before anyone reads your pricing. No negotiation, no feedback call, no chance to explain your roadmap. You are removed from consideration on a technicality that was entirely within your control to fix and didn’t.

This is the reality facing UK businesses right now. Cyber Essentials and Cyber Essentials Plus have moved from a ‘nice-to-have’ compliance badge to a pass/fail gate embedded directly into procurement workflows, supplier onboarding portals, and prime contractor due diligence. Procurement teams are quietly turning Cyber Essentials from a routine formality into a condition of doing business.

What’s actually shaping your business priorities

Every board and leadership team we speak to is wrestling with the same set of pressures, protecting revenue in a tighter market, defending margin against rising costs, and proving to enterprise customers and public sector buyers that their supply chain is trustworthy. None of those pressures show up on a spreadsheet labelled ‘cyber security’. They show up as lost tenders, stalled renewals, and contracts that quietly go to a competitor who ticked a box you didn’t know existed.

The market reality is government frameworks have required Cyber Essentials for certain contracts for years, and that requirement is increasingly flowing down through prime contractors into their supply chains. Insurers are asking for it before they’ll quote competitively. Enterprise customers are including it into supplier onboarding as a pass/fail gate, not a nice-to-have. If your business provides products or services into government, defence, financial services, or any enterprise customer with its own compliance obligations, Cyber Essentials and Cyber Essentials Plus are no longer a security decision sitting in IT’s budget. They are a revenue decision sitting in yours.

Your customer’s customer matters here too. When your buyer signs off a contract with you, they are often answering to their own board, regulator, or insurer about the risk you represent to them. Cyber Essentials is one of the quickest, most recognisable ways for them to answer that question without a lengthy audit. If you can’t give them that answer quickly, they will find a supplier who can.

What certification actually changes for your business

This isn’t about security features. It’s about what certification does to your commercial position.
Cyber Essentials and Cyber Essentials Plus remove a qualification gap before it costs you a deal, not after, when the deal is already gone and you’re trying to work out why the phone stopped ringing.

Practically, this means your business appears on more shortlists, not fewer. Your sales team stops losing time on tenders that were disqualified before the first call. Your renewal conversations become easier, because the compliance question is already answered rather than raised as a last-minute objection by your customer’s own procurement or legal team. And your business becomes the supplier that makes a buyer’s own governance conversation easier, which is a genuine competitive advantage when two suppliers are otherwise evenly matched on price and delivery.

A single missed tender because of a compliance gap in your certification is a one-off cost. A pattern of missed tenders because certification was never prioritised is a structural gap in how much revenue your business can actually access. That’s the number your board should care about, not the cost of certification, but the addressable revenue currently closed off without it.

The businesses that treat certification as a growth enabler, not an IT task, are the ones still winning the deals everyone else quietly loses.

Why this matters beyond your own experience

At Cyberfort we’ve worked with organisations across regulated and security-conscious sectors who assumed their existing security posture was ‘good enough’ to satisfy a customer’s procurement check, only to find that assumption tested and found short at the worst possible moment – mid-tender, with a deadline measured in days rather than weeks.

The pattern is consistent, the businesses that treat Cyber Essentials certification as a proactive commercial safeguard keep their pipeline clean of avoidable losses. The businesses that treat it as a reactive box to fill in when asked, lose deals they never even knew they were being evaluated for.

So where do you actually start?

In the previous sections of this article, we have highlighted the potential impact of not having a baseline security certification like Cyber Essentials and Cyber Essentials Plus. But identifying the problem is only one part of the equation. Businesses need to fix this certification gap before it’s too late. So where should you start?

Begin with an honest audit of where certification already sits in your pipeline, not where you assume it does. Pull your live tenders and your top renewal-risk accounts and ask a blunt question of each one: does this buyer’s procurement process reference Cyber Essentials or Cyber Essentials Plus, explicitly or as a supply chain flow-down from their own customer? Don’t rely on memory or on what came up last time, procurement requirements shift quietly, often without a formal announcement, and the gap is rarely visible until a bid team hits it mid-process.

Next, separate Cyber Essentials from Cyber Essentials Plus in that audit, because they answer different questions for different buyers. Cyber Essentials is a self-assessed baseline – fast to achieve, and increasingly the minimum entry price for public sector and supply chain work. Cyber Essentials Plus adds independent, hands-on technical verification, the level that risk-conscious enterprise buyers and regulated sectors are starting to expect as standard, not as a differentiator. If you don’t know which one your pipeline actually needs, that uncertainty is itself the gap.

With that audit completed, map your certification timeline against your actual bid deadlines, not against a generic “get round to it” schedule. Certification takes real time to prepare for and complete, and that time compresses fastest in the exact quarters when tender volume peaks. If a renewal or a new tender is sitting three months out and you haven’t started, you’re not planning ahead, you’re already behind, whether or not that’s visible yet in your pipeline reporting.

From there, treat certification as a standing commercial control, not a one-off project. Build it into contract renewal reviews, into new business qualification criteria, and into the standard information your sales team gathers before a bid goes to proposal stage. The organisations that get caught out aren’t usually the ones who never considered certification, they’re the ones who treated it as a single completed task rather than a continuously maintained position. Certifications lapse. Buyer requirements change. A gap that didn’t exist in last year’s renewal cycle can exist in this year’s.

There is a pattern playing out inside businesses right now that security teams are only just beginning to grapple with. A business deploys Microsoft Copilot, ChatGPT, Claude or Gemini. The IT team follows the vendor’s setup guide, enables the licence, and rolls it out to users. Within weeks, executives are summarising emails, generating first drafts, and asking questions of their data in natural language. Productivity improves. The board is pleased.

What nobody has checked is what data these AI tools can actually reach.

Because these AI tools don’t create new access, they inherit existing permissions. If a user already had access to a shared drive containing board minutes, financial forecasts, HR records, or sensitive client data, these AI tools can now potentially surface all of it in response to a simple typed question. In many Microsoft 365 environments, permissions have accumulated over years: old shared folders never cleaned up, overly broad access granted to entire departments, files that were never meant to be widely visible sitting in locations that technically anyone with a company login can reach.

The AI tool hasn’t introduced a new vulnerability in the conventional sense. It has simply made the existing one dramatically easier to exploit.

Why This Is Happening Now

The pace of AI adoption inside organisations has outstripped the pace of governance. That isn’t a criticism, it is an observation about how enterprise technology typically evolves. When email was introduced, most organisations didn’t have an email security policy until something went wrong. When staff started using smartphones for work, mobile device management came later. When cloud storage arrived, data classification lagged behind.

AI is following a similar adoption curve, but faster and with higher stakes.

The difference this time is that AI tools don’t just store or transmit data, they actively reason over it, synthesise it, and present it in response to unstructured natural language queries. The implications of overpermissioning are therefore qualitatively different. A misconfigured shared folder in a pre-AI environment might go unnoticed indefinitely. The same misconfiguration in a Copilot-enabled environment for example, can be surfaced to anyone in the organisation within seconds.

Shadow AI adds a further dimension to this problem. While IT departments are managing official deployments, staff are independently signing up for ChatGPT, Claude, Gemini, and a growing range of AI-powered productivity tools. They are pasting customer data, internal documents, and commercially sensitive material into these tools without any visibility from the organisation’s security function. In many cases they don’t know they are doing anything wrong, the tools are freely available, the interface is intuitive, and nobody told them not to.

According to research by ISACA, only 31% of organisations have some form of formal governance in place when it comes to AI.  That means the majority of organisations are operating in a space where the rules haven’t been written, the risks haven’t been assessed, and the exposure hasn’t been mapped.

The Three Gaps at the Heart of the Problem

Understanding where the risk actually sits requires looking at three distinct but connected areas.

The data permissions gap. Before any AI tool can be safely deployed, the organisation needs to understand what its users can access and whether that access is appropriate. In most Microsoft 365 environments, this picture has never been properly mapped. Data has accumulated over years, access has been granted ad hoc, and the cumulative effect is a permissions landscape that nobody has a complete view of. AI tools surface this gap in a way that makes it impossible to ignore.

The governance gap. Most organisations don’t have policies that specifically address AI tool usage, data classification in the context of AI, or acceptable use boundaries for generative models. Without these policies, staff have no framework for deciding what is and isn’t appropriate and security teams have no baseline against which to measure behaviour or investigate incidents.

The visibility gap. Shadow AI is, by definition, invisible to the tools organisations use to monitor data flows. Conventional endpoint, network, and SIEM controls are designed to detect known threat patterns. They are not designed to identify when a member of staff pastes a client contract into a public AI tool. This isn’t a gap that can be closed with existing controls, it requires a different approach to monitoring and awareness.

The Questions Boards Are Starting to Ask

As AI governance has moved up the regulatory agenda, with the EU AI Act, FCA guidance on AI in financial services, and ICO attention on AI and personal data, boards and audit committees are beginning to ask questions that security and IT teams are struggling to answer.

What AI tools are currently operating within the business? What data can those tools access? Do we have a policy that governs AI usage? Have we assessed our exposure under relevant regulatory frameworks? How would we know if sensitive data had been processed by an unapproved AI tool?

For many organisations, the honest answer to most of these questions is currently “we don’t know.”

That isn’t a comfortable position to be in. It is, however, a fixable one, and the organisations that address it proactively will be in a fundamentally stronger position than those that wait for a regulatory inquiry or a data incident to force the issue.

When This Becomes Particularly Urgent

There are specific moments when the need for clarity around AI security becomes especially acute. Organisations that are actively rolling out Copilot or another enterprise AI tool are in the highest-risk window, the period between deployment and a proper security review is when exposure is greatest. The same is true when staff are using AI tools without explicit IT approval, when an insurance renewal or regulatory audit is approaching, when a board sign-off on AI investment is required, or when a new CIO, CISO, or CTO joins and needs to understand the existing landscape.

In each of these situations, operating without a clear view of AI security posture isn’t just a technical risk, it is a governance and accountability risk that sits at board level.

What a Structured Review Looks Like

So where should you start when looking at solving these problems with AI adoption in your business? At Cyberfort we encourage all businesses to undertake an AI Security Readiness review before any AI tool is fully deployed. From our experience understanding AI security exposure requires a methodical approach across four areas:

Step 1 — Scoping and Discovery. Establish the boundaries of the assessment: which AI tools are in scope, which parts of the estate will be reviewed, and which stakeholders need to be involved. This step also captures the organisation’s current understanding of its own AI usage, which is often the first point at which shadow AI usage becomes visible.

Step 2 — AI Usage and Exposure Review. Map the AI tools currently operating within the organisation, both sanctioned and unsanctioned. Assess data access permissions, identify overpermissioning in Microsoft 365 or other AI-adjacent environments, and establish a baseline picture of where sensitive data could be reached by AI tools.

Step 3 — Security and Governance Assessment. Evaluate the organisation’s current policies, controls, and monitoring capabilities against the specific requirements of an AI-enabled environment. Identify gaps in policy, monitoring, data classification, and incident response that are specific to AI risk.

Step 4 — Findings, Scorecard, and Roadmap. Produce a clear, executive-readable risk scorecard and a prioritised remediation roadmap. This gives the organisation both the board-level view and the technical detail needed to act.

What Good Looks Like

Organisations that have done this work properly typically come out of it with three things they didn’t have before.

First, a clear and accurate picture of what their AI tools can actually access, which is almost always different from what they assumed. Second, a governance framework that gives staff clarity on what is and isn’t acceptable, reducing the shadow AI risk significantly. Third, a documented security posture around AI that can be presented to insurers, regulators, boards, and enterprise customers when the question arises.

None of this requires stopping AI adoption. The goal isn’t to slow the business down, it is to make sure the speed of adoption doesn’t create a risk profile that leadership hasn’t had the opportunity to consider.

A certification that started life as a baseline has quietly become a commercial necessity

There was a time when Cyber Essentials was something organisations pursued because it seemed like a sensible thing to do. A government-backed certification. A signal to customers and partners that basic cyber hygiene was in order. Useful, perhaps. Reassuring, certainly. But optional.

That time has passed.

Cyber Essentials is now a requirement in a growing number of commercial and regulatory contexts. Public sector contracts, NHS supply chain agreements, central government procurement frameworks, all mandate it. An increasing number of insurers require it as a condition of cyber cover. Enterprise and large corporate buyers are writing it into supplier questionnaires as a minimum threshold. Organisations that lack it are discovering not that it would be nice to have, but that they cannot bid, renew contracts, or proceed without it.

This shift in the market has changed the nature of the question. It is no longer “should we  have Cyber Essentials?” It is “why haven’t we got it yet, and what’s stopping us?”

The answer to that second question is more instructive than most organisations expect.

What Cyber Essentials Actually Assesses

Before understanding why organisations get stuck in unlocking the business value of this security certification, it helps to understand what the scheme is actually testing. Cyber Essentials, and its more rigorous variant, Cyber Essentials Plus covers five technical control areas. These are not exotic or advanced. They represent the foundational layer of cyber hygiene that every organisation with an internet-connected environment should have in place.

The five areas are: boundary firewalls and internet gateways; secure configuration of devices and software; access control and administrative privilege management; malware protection; and patch management.

None of these are unusual. Most organisations believe they have them covered. And in many cases, they do, but not in the structured, evidenced, and consistently applied way the scheme requires.

That gap between “we have that” and “we can demonstrate that” is precisely where organisations stall.

The Three Reasons Organisations Get Stuck

From our experience at Cyberfort we see organisations attempting Cyber Essentials certification running into one of three structural problems (or all three at once) before they engage with a specialist MSSP who really understands the certification standard.

The first is the absence of a structured readiness process. Most organisations approach certification the way they might approach any compliance task: they read the requirements, make a judgement about how well they comply, and submit. What they don’t do is conduct a systematic gap analysis first. The result is that surprises emerge during the assessment itself, configurations that don’t meet the standard, devices that aren’t managed in the way assumed, or policy documents that exist in draft but have never been formally adopted. By the time these surface, the certification window is often compromised.

The second is remediation drag. Even when gaps are identified in advance, fixing them takes longer than anticipated. A device configuration change needs sign-off. A patch deployment waits for a change control window. A policy update requires review by a legal or compliance team. These are not failures of intent they are the natural friction of operating a real organisation with real governance processes. But without a structured plan that accounts for this friction, remediation spreads across weeks or months and the certification timeline slips.

The third is ownership ambiguity. In many businesses, the answer to “who is responsible for Cyber Essentials?” is genuinely unclear. It might sit with IT, a compliance function, a part-time fractional CISO, or with no one in particular. Without a clear owner who understands both the technical requirements and the business context, progress stalls at the points where decisions need to be made.

These three problems are not signs of bad security. They are signs of normal organisational complexity applied to a process that demands unusual clarity and structure.

Why the consequences of delay are increasingly material

For many years, the cost of not having Cyber Essentials was relatively abstract. You might lose out on some public sector work. You might look less credible to a prospective customer. These were real costs, but they were often speculative or hard to attribute directly.

The consequences are now considerably more material.

Research suggests that more than half of organisations seeking public sector contracts have lost or been excluded from an opportunity specifically because of the absence of Cyber Essentials certification. More than a third of UK organisations have faced questions about certification during insurance renewal processes, with some facing premium increases or coverage refusals where it was absent. And as supply chain security requirements tighten, partly driven by legislation, partly by enterprise procurement practices, the volume of organisations requiring certification from their suppliers continues to grow.

There is also a compounding effect. Cyber Essentials Plus, the independently verified variant, requires the underlying Cyber Essentials to be current and in good standing. Organisations that allow their certification to lapse, (which is common), as it must be renewed annually, find themselves having to restart from the basic level before they can progress to Cyber Essentials Plus. The longer the lapse, the more has changed in the environment, and the more work the renewal requires.

The organisations that manage this most smoothly are not the ones with the most sophisticated security environments. They are the ones with a repeatable, structured process for maintaining certification as part of their normal security operations.

What Good Looks Like: A Framework for Getting It Right

There is a clear pattern among organisations that move through Cyber Essentials certification efficiently and without disruption. It involves four logical stages, each building on the last.

The first stage is scoping and discovery. Before any gap analysis or remediation work begins, the organisation needs clarity on what is in scope. What devices, systems, and networks will the certification cover? This is not always as simple as it sounds. Cloud environments, remote working infrastructure, BYOD policies, and third-party managed services all introduce complexity. Getting scope right at the start prevents the most expensive kind of surprise: discovering mid-assessment that something was missed.

The second stage is gap analysis. With scope established, a structured review of the five control areas identifies where the current environment meets the standard and where it does not. A good gap analysis does not just flag what is missing, it produces a prioritised remediation plan that distinguishes between quick wins, items requiring planned change windows, and anything that needs a policy or governance decision before the technical fix can proceed.

The third stage is guided remediation. This is where most organisations benefit most from external support. Working through a prioritised remediation plan with a structured approach, and with advisors who have done this many times across many different environments, is materially faster than attempting it internally without that reference point. Common remediations are well understood. The sequence in which they should be addressed is known. The points of friction that typically cause delay are predictable and can be managed proactively.

The fourth stage is certification support. The final assessment and submission process has its own requirements, timelines, and common failure points. Having support through this stage, including review of self-assessment responses before submission significantly improves first-time pass rates.

Who This Matters To, and When

Cyber Essentials is relevant to virtually every UK organisation, but the urgency varies significantly depending on context. There are a number of situations where the need to act becomes pressing rather than merely prudent. The most common situations include:

  • Organisations responding to a public sector tender with a certification requirement that they cannot currently meet.

  • Businesses approaching an insurance renewal where cyber cover is under review.

  • Suppliers who have received a questionnaire from a major customer asking for certification evidence.

  • Organisations that failed a previous certification attempt and need to understand what went wrong and how to fix it.

  • Businesses that have recently changed their IT environment, through a cloud migration, an acquisition, or a change in IT provider and are no longer confident that their previous certification is still reflective of current practice.

  • Organisations that have had a team change and no longer have a clear internal owner for the process.

In each of these situations, the question is not whether to pursue certification, that has usually already been answered by an external event. The question is how to move through it as quickly and cleanly as possible.

The threat your controls were never designed to see

There is a fraud technique spreading rapidly across every sector that has nothing to do with malware, phishing links, or compromised credentials. It does not trigger your SIEM. It bypasses your email gateway. It has no payload for your endpoint agent to detect. And in 40%+ of organisations that have experienced it, it has succeeded.

The technique is AI-powered deepfake executive impersonation. Understanding how it works, why it works, and what actually stops it is one of the most important things a security, finance leader or board member can do right now.

How the attack landscape has changed

Executive impersonation is not new. Fraudsters have long posed as C-Level executives in emails, invoking urgency and authority to push through unauthorised payments. What has changed, fundamentally and recently, is the cost and complexity of doing it convincingly.

Until very recently, cloning a voice or generating a synthetic video required significant technical expertise, specialist equipment, and considerable time. It was a capability largely confined to well-resourced criminal groups and nation-state actors. That barrier has gone.

Today, generative AI tools that can clone a voice from a few minutes of audio are freely available online. The same technology that powers legitimate productivity tools including voice synthesis, video generation, and natural language models, is being repurposed by fraudsters who need no technical expertise to use them. The result is a 1,500% increase in deepfake attacks since 2023 (UK Gov 2025 Study), and an average financial impact of a successful attack being estimated to be over £210,000.

The democratisation of this capability is the critical shift. Attacks that previously required sophisticated criminal infrastructure can now be launched by individuals. The volume of attempts is increasing not because more sophisticated actors have emerged, but because the barrier to entry has effectively collapsed.

Why human judgement is the target and why that is hard to defend

To understand why this threat is so difficult to defend against, it helps to understand what it is actually attacking.

Most organisational fraud controls assume that the weakest link is the technology, that if you can secure the perimeter, filter the email, and lock down the endpoint, you have addressed the risk. Deepfake impersonation attacks do not target the technology. They target the trust that people place in the voices and faces of their colleagues and leaders.

Consider the typical high-value payment authorisation process. A finance director receives a call from someone who sounds exactly like the CEO, requesting an urgent transfer ahead of a deal closing. The voice, the tone, the vocabulary, and the sense of urgency are all consistent with the genuine article. The finance director has no reason to doubt what they are hearing, and every reason to act quickly.

The verification mechanism in that scenario is human judgement. And human judgement is precisely what AI-powered impersonation is engineered to defeat.

This is not a failure of intelligence or awareness on the part of the individual. It is a structural vulnerability in how organisations communicate and authorise actions, one that has existed for years but that has only recently become practically exploitable at scale.

The exposure organisations are not measuring

One of the most significant and underappreciated aspects of this threat is how much publicly available material already exists that could be used to construct a convincing impersonation.

For most organisations with any public profile, and for most executives who are active in their industry, the raw material needed to train an impersonation model is already out there. LinkedIn videos, Keynote recordings, Investor calls, Press interviews, Webinars, Podcast appearances. Every piece of public audio and video content featuring a senior leader is, from an attacker’s perspective, training data.

Most organisations have no idea how extensive that exposure is. They have never mapped it, or quantified it, and therefore cannot make informed decisions about how to manage it. The exposure assessment, understanding what is publicly accessible and what risk it creates, is the first and most important step in addressing this threat, because it moves the organisation from assumption to evidence.

Why existing controls have a structural blind spot

It is worth being direct about why conventional security investments do not address this risk, not as a criticism of those investments, but because understanding the gap is necessary to filling it.

Email security controls are designed to analyse digital artefacts: headers, links, attachments, sender reputation. A deepfake attack that arrives as a phone call or a WhatsApp voice note has none of these characteristics. There is nothing to scan.

SIEM and endpoint detection tools look for anomalous system behaviour, indicators of compromise, and known attack signatures. A fraudulent phone call does not generate system events. There is no log entry to correlate.

DLP tools monitor data moving across systems. A payment authorised verbally following a fraudulent instruction does not cross a data loss boundary the tool was designed to detect.

This is not a technology problem that more technology will solve, at least not primarily. The attack surface here is the communication channel and the human trust it carries, and the defence requires interventions that operate at that level.

What effective defence actually looks like

Understanding this threat clearly points toward what effective defence requires. From our experience at Cyberfort there are four interconnected components which need to be in place to defend against a deepfake attack:

Exposure mapping. Before any organisation can make informed decisions about its risk, it needs to understand what material already exists publicly and which individuals carry the greatest impersonation risk. A structured exposure review produces that picture and identifies where reduction is possible.

Risk assessment. Not all scenarios carry equal risk. The combination of who could be impersonated, which communication channels are most vulnerable, and which teams are most likely to act on impersonated instructions creates a specific risk profile that varies by organisation. Understanding that profile lets you prioritise your response.

Scenario-based testing. Awareness training that tells people deepfakes exist is not sufficient preparation. What prepares people is working through realistic simulations: hearing what a cloned voice actually sounds like, experiencing the psychology of an authority-and-urgency scenario, and practising the verification instincts needed to slow down and challenge. Organisations that have been through this consistently report it as the single most impactful element of their preparation.

Procedural controls. The most durable defence is embedding out-of-band verification into high-risk processes, making it structurally normal, rather than exceptional, to pause and confirm through a secondary channel before acting on a significant instruction. This does not slow organisations down in practice; it removes the friction that fraudsters rely on.

When this risk becomes particularly acute

While every organisation with any public profile carries some exposure, certain situations materially increase the risk or the consequences of a successful attack.

Executives who are active on LinkedIn, YouTube, or in industry media carry higher impersonation risk simply by virtue of the volume of publicly available material. Organisations going through mergers, acquisitions, or leadership changes create a period of uncertainty and unfamiliar communication patterns that fraudsters actively exploit, staff may be less sure what normal looks like, and more inclined to defer to authority. Publicly listed companies face particular scrutiny because their leadership and financial processes are more visible.

Organisations with large or frequent payment authorisation processes, particularly where those processes involve a small number of decision-makers acting on verbal instruction, carry concentrated exposure. Recent near-misses or suspected fraud attempts are a signal that the organisation may already be on a target list. And insurance renewals and regulatory audits increasingly ask direct questions about this threat, which means the question of whether you have addressed it is coming regardless.

 Five key questions organisations should be asking when it comes to deepfake and execution impersonation attacks

For any security or risk leader thinking through their organisation’s position on this threat, five questions are worth asking:

1. How much publicly available audio and video material exists featuring your senior leaders, and have you ever assessed it as an attack surface?

2. Do your finance, HR, and executive assistant teams have specific, practised protocols for verifying the identity of a caller or video sender before acting on a sensitive instruction?

3. Have your high-risk teams ever experienced a realistic impersonation simulation,  not been told it exists, but actually worked through one

4. Could you articulate to your board, in concrete terms, what your current exposure to this risk is and what controls are in place to manage it?

5. If a successful attack occurred tomorrow, would your incident response procedures cover this scenario?

If the honest answer to any of these is no, or not sure, that is the gap which needs to be addressed through training, policy updates and staff awareness of Deepfake and Executive impersonation attacks.

How quickly do you need to act and what’s involved

One of the useful things about this threat is that addressing it does not require a lengthy programme. The core work – exposure mapping, risk assessment, scenario testing, procedural control design can be completed in a focused engagement that does not consume significant internal resource or disrupt day-to-day operations. The output is a clear picture of exposure, a tested and trained team, and a set of practical controls embedded in process.

So, What does this look like?

As mentioned earlier in the article addressing this threat requires more than awareness. It requires a structured assessment of your actual exposure, a tested understanding of how your people respond under realistic conditions, and practical controls that embed durable resilience.

For example, at Cyberfort we have built a Deepfake & Executive Impersonation Defence service to help organisations prepare themselves against this type of attack effectively.

It begins with an Executive Exposure Review – a systematic mapping of the publicly available material that could be used to impersonate your key individuals. Most organisations are genuinely surprised by what this surfaces. Understanding your exposure is the essential first step.

Step 2 involves a structured Deepfake Risk Assessment that identifies your highest-risk scenarios, communication channels, and roles. Not every part of your organisation carries the same level of risk. Knowing where to focus is what makes the response proportionate and effective.

Step 3 puts your people through realistic Fraud Scenario Testing – AI-powered impersonation simulations that replicate the conditions of a real attack. This is where organisations learn the difference between theoretical awareness and genuine resilience. It is also where the specific gaps in your human controls become visible, in a controlled environment, before an attacker finds them for you.

Step 4 combines targeted AI Awareness Training with the delivery of an Executive Protection Playbook: practical verification protocols, out-of-band confirmation procedures, escalation paths, and governance processes that your teams can use immediately and sustain over time.

The outcome is not just a report. It is an organisation that has moved from unknown exposure to active, measurable resilience, with the board-level evidence of due diligence that regulators, insurers, and investors increasingly expect.

From our experience at Cyberfort, the organisations that are best placed to mitigate the risks against this type of attack are not necessarily the most technologically sophisticated. They are the ones that have looked at this honestly, understood where their exposure lies, and put the right human controls in place. That is an achievable position for any organisation, and it is a significantly better one than discovering the gap through a successful attack.

The attack that starts next door

When security teams map their risks, they tend to focus on what they can see and control: their own infrastructure, endpoints, and perimeter. That instinct is understandable. It is also increasingly misaligned with how the most significant breaches of the last two years have happened.

The pattern is consistent. An organisation with mature security controls, a hardened perimeter, and a well-resourced IT team is compromised, not through their own systems, but through a supplier. A managed service provider with access to their network, a software vendor whose update mechanism became a delivery vehicle for malicious code, a cloud platform partner whose credentials were harvested and used to move laterally into the customer’s environment.

The attacker did not knock on the front door. They walked in through a side entrance that the target organisation had never fully audited, and in many cases, did not even know existed.

This is the defining characteristic of modern supply chain cyber risk. It does not respect the perimeter you have built. It exploits the trust relationships you have extended, often necessarily, often legitimately, to the network of third parties your organisation depends on to function.

The scale of the problem is structural, not incidental

It would be reassuring to treat high-profile supply chain attacks as edge cases: sophisticated operations carried out by well-resourced nation-state actors against strategically significant targets. The data does not support that reassurance.

According to the Verizon Data Breach Investigations Report 2025, more than 30% of data breaches now involve a third-party element. Blackberry’s 2024 survey of IT decision-makers found that more than 75% of software supply chains had been exposed to a cyber attack in the preceding twelve months. And the UK Government’s Cyber Security Breaches Survey 2025 found that only 14% of organisations had undertaken a formal security review of their supply chain in the last year.

Read those three figures together and the picture becomes clear. Third-party attacks are not rare. They are not declining. And the vast majority of organisations have not formally assessed the risk they carry through their supplier relationships.

This is not primarily a technology problem. It is a governance and visibility problem. Most organisations have grown their supplier base organically over years or decades, extending access and data-sharing relationships as the business required them, without building a proportionate framework for assessing and managing the security posture of those suppliers over time.

The result is a risk landscape that is both significant and largely invisible.

Why traditional approaches fall short

The conventional response to supply chain risk tends to rely on one of two mechanisms: contractual protections, or certification-based assurance. Both have genuine value. Neither is sufficient on its own.

A supplier’s ISO 27001 certificate, or their signed GDPR data processing agreement, tells you about their intent and their documented processes at the point the certificate was issued. It does not tell you about the controls that are actually operating today, in the specific parts of their business that touch your data and your systems. Certification can be narrowly scoped, out of date, or simply not reflective of the real-world security posture of an organisation at a given moment.

Supplier questionnaires suffer from a different but related problem. They are typically completed once, reviewed once, filed, and then largely forgotten, while the risk environment continues to evolve. A supplier that passed your assessment two years ago may have undergone significant organisational change, technology change, or personnel change since then. The questionnaire response that gave you comfort at the time has not been updated to reflect any of it.

The deeper issue is one of volume and capacity. A typical mid-sized organisation has dozens, sometimes hundreds of suppliers with some form of digital access or data-sharing relationship. Applying consistent, meaningful scrutiny to every one of those relationships, at the depth required to form a genuine view of security posture, is not feasible without a structured, risk-prioritised approach that distinguishes between the suppliers that represent real exposure and those that do not.

The five gaps that create real exposure

Through our work with organisations across financial services, professional services, engineering, and critical infrastructure, five specific gaps appear with consistent regularity.

The first is the absence of a consolidated supplier inventory. Most organisations cannot produce, without significant effort, a complete list of which third parties have access to their systems, what level of access they hold, and what data they can reach. That baseline simply does not exist in a structured, maintained form.

The second is the reliance on static risk pictures in a dynamic environment. Supplier relationships change. Personnel change. Technology changes. A risk assessment that does not have a defined refresh cycle is a record of how things were, not how they are.

The third is the gap between contractual assurance and operational reality. Contracts establish obligations. They do not verify compliance. The difference between what a supplier is contractually required to do and what their security controls actually look like in practice can be significant, and that gap is rarely visible without independent assessment.

The fourth is the absence of incident response planning that accounts for supplier failure. Most organisations have internal incident response plans. Far fewer have pre-agreed response playbooks that cover the specific scenario where a supplier is compromised and the organisation needs to contain, investigate, and communicate about that compromise quickly. When a supplier incident occurs, the organisations that respond well are those that had already mapped their exposure in advance.

The fifth is the growing commercial and regulatory pressure that makes this governance gap increasingly visible. Insurers are asking harder questions about third-party risk management as a condition of coverage. Regulated sectors face specific obligations around supply chain oversight. Enterprise customers are requesting evidence of third-party assurance as part of procurement processes. The organisations that cannot answer these questions clearly are finding that the absence of a supply chain risk framework carries direct commercial consequences.

The right approach: structured, risk-prioritised, proportionate

Effective supply chain risk management does not mean applying the same level of scrutiny to every supplier relationship. It means having a clear, defensible basis for understanding which supplier relationships represent the greatest exposure and directing your assurance effort accordingly.

That starts with building and maintaining a structured view of your supplier landscape: who has access, at what level, to what data and systems. It continues with a risk-prioritised approach to assessment that distinguishes between critical suppliers, significant suppliers, and low-risk relationships, and applies proportionate scrutiny to each tier. It is sustained through embedding supply chain security assessment into procurement and vendor management processes so that new relationships are evaluated consistently before access is granted, not retrospectively.

The output of this kind of programme is not just reduced risk. It is the documented evidence of due diligence that regulators, insurers, and enterprise customers are increasingly requiring and that boards need to be able to point to when the question of third-party risk management is raised.

When does this typically become urgent?

Supply chain cyber risk tends to crystallise as a priority at specific moments. Organisations approaching an insurance renewal are often asked to demonstrate their third-party risk management practices for the first time. Those going through merger or acquisition activity find that supply chain security is a growing focus of technical due diligence. Those onboarding a new critical supplier, a managed service provider, a cloud infrastructure partner, a key software vendor, recognise that they are extending significant trust and need to verify that it is warranted.

Public sector organisations facing procurement requirements, professional services firms whose clients are asking for evidence of supply chain assurance, and businesses that have recently experienced an incident (however contained) that involved a third-party element also consistently find that this becomes a priority quickly.

In each case, the trigger is different. The underlying question is the same: do we have genuine visibility of the risk we carry through our supplier relationships, and can we demonstrate that we are managing it?

Cyber threats don’t stand still. Neither do the standards designed to stop them. If your organisation holds Cyber Essentials a Cyber Essentials Plus (CE+) certification, or has been thinking about this certification, there’s something important you need to know: the standard has been updated, and the bar has been raised.

This isn’t a minor tweak. The refreshed Cyber Essentials Plus framework reflects the reality of how businesses operate today, cloud-first environments, remote workforces, mobile devices, and an attack surface that looks nothing like it did when the original standard was written.

The good news? If you act now, you can get ahead of it. Here’s everything you need to know.

Why Cyber Essentials Plus Matters More Than Ever

Let’s start with the basics. Cyber Essentials is the UK government-backed certification scheme designed to help organisations protect themselves against the most common cyber-attacks – phishing, malware, ransomware, and unauthorised access. Cyber Essentials Plus takes that a step further: rather than a self-assessed questionnaire, it involves independent technical verification. An assessor actually tests your systems to confirm your controls work in practice, not just on paper.

For your customers, that distinction matters enormously.

In a landscape where supply chain attacks are increasingly common, your clients, partners, and procurement teams aren’t just asking whether you have a security policy, they’re asking whether you can prove it. CE+ is that proof. It tells the world that your defences have been independently tested and verified, not self-declared. For organisations bidding on government contracts, working in regulated sectors, or handling sensitive customer data, CE+ isn’t a nice-to-have. It’s increasingly a commercial prerequisite.

Beyond the contractual angle, there’s the practical one. Cyber Essentials Plus certification gives your leadership team confidence that the five core technical controls – firewalls, secure configuration, user access control, malware protection, and patch management are genuinely in place and functioning. That confidence has real value when a board is assessing risk, when an insurer is pricing a cyber policy, or when a customer is deciding whether to trust you with their data.

The updated standard makes that assurance even more meaningful, because it’s been designed for the way businesses actually work in 2026 and beyond.

What’s Changed: Old Standard vs New

The original Cyber Essentials framework was built for a world of on-premise infrastructure, desktop computers, and relatively contained network perimeters. That world has largely gone. The updated standard acknowledges this and closes the gaps that the old version left open.

Cloud services are now firmly in scope – Under the previous standard, cloud-hosted services occupied a grey area. Many organisations assumed that if a service was managed by a third-party provider, it fell outside the scope of their assessment. The updated framework makes clear that cloud services including Software as a Service (SaaS) platforms are in scope where your organisation controls the configuration. If your staff are using Microsoft 365, Google Workspace, or any other cloud platform, the way those environments are configured now counts. That’s a significant shift for organisations that have migrated heavily to the cloud and assumed their provider was handling security on their behalf.

Home and hybrid working environments are addressed directly – The old standard was written before remote working became the norm for millions of UK employees. The updated version explicitly addresses devices used outside the corporate network – including home broadband routers and personal devices used for work. If your staff are connecting from home, those endpoints and the networks they sit on are now part of the picture. For many organisations, this will require a fresh look at device management, VPN policies, and the controls applied to personally-owned devices used for work purposes.

Thin clients and virtual desktops are included – As more organisations move to virtual desktop infrastructure (VDI) and thin-client environments, the updated standard provides clearer guidance on how these are assessed. The previous version left room for ambiguity; the new one closes it.

Firmware and router security – The updated standard tightens requirements around routers and firewalls, including the firmware running on them. Default credentials, unpatched firmware, and misconfigured boundary devices have been a consistent entry point for attackers, the revised standard makes it harder to overlook these.

Stronger password and authentication requirements – The bar on credential security has been raised. The updated standard aligns more closely with current NCSC guidance on password policies, multi-factor authentication, and account management. If your organisation is still relying on password complexity rules alone, without MFA on internet-facing services, you’ll need to address that before you can certify.

Malware protection scope expanded – The updated framework takes a broader view of malware protection, including application allow-listing as an accepted control and providing clearer guidance on what’s required for different device types. Organisations that have relied on traditional antivirus alone may find they need to review their approach.

Taken together, these changes mean that organisations which previously held CE+ certification cannot assume they’ll pass under the new standard without a fresh assessment of their controls. The scope is wider, the requirements are more precise, and the technical verification is more thorough.

Why you need to ‘Act Now’ and how Cyberfort can help

At Cyberfort, we’ve been working with the Cyber Essentials framework since its inception. We’re an IASME-accredited Certification Body, which means we can take you through the full CE+ process,  from readiness assessment through to certification, with a team that understands both the technical requirements and the commercial pressures you’re working under.

Our approach to CE+ is built around three things: preparation, verification, and remediation.

Preparation – Before we put your organisation through the formal assessment, we work with you to understand your current environment, your devices, your cloud services, your remote working setup, your boundary controls. We identify the gaps against the new standard and give you a clear, prioritised action plan. No surprises on assessment day.

Verification – Our technical assessors carry out the hands-on testing that CE+ requires including scanning your external-facing systems, testing your internal controls, and verifying that what you’ve documented is what’s actually in place. This is where CE+ earns its credibility, and it’s where our experience makes a real difference. We’ve assessed organisations who have different IT estate sizes and complexity, and we know what the assessors look for.

Remediation support – If gaps are found and in our experience, they usually are, particularly under the updated standard, we don’t just flag them and walk away. Our technical team can help you close them, whether that’s configuring MFA across your cloud platforms, tightening your patch management process, or reviewing your device management policies. We see the assessment and the remediation as part of the same engagement, not two separate conversations.

The reason to act now is straightforward: the updated standard is in effect, and the window to prepare is shorter than most organisations realise. If your current certification is due for renewal, you’ll be assessed against the new requirements. If you’re pursuing CE+ for the first time, you’re starting under the new standard from day one. Either way, the organisations that begin their preparation earliest are the ones that certify fastest and the ones that avoid the costly scramble of last-minute remediation.

Why Cyberfort for CE+?

There’s no shortage of organisations offering Cyber Essentials assessments. So why does it matter who you choose?

Because certification is only part of the story. What matters is what happens before the assessment and what you’re left with afterwards.

Cyberfort brings together accredited certification, deep technical expertise, and a genuine understanding of the threat landscape. Our assessors aren’t ticking boxes; they’re experienced security professionals who understand how attackers think and where defences typically fail. That means our pre-assessment work is sharper, our gap analysis is more accurate, and our remediation guidance is practical rather than theoretical.

We also bring continuity. Many of our customers come to us for CE+ and stay with us for broader security services including penetration testing, managed detection and response, and security awareness training. That’s not a sales pitch; it’s a reflection of how security works in practice. Cyber Essentials Plus is a foundation, not a finish line, and having a partner who can support you beyond certification means you’re building on solid ground rather than starting from scratch every year.

Glen Williams, CEO of Cyberfort, recently joined Guy Clapperton on The Near Futurist Podcast to discuss how cyber security has moved far beyond basic antivirus and controls. In this two-part interview series, they explore how the threat landscape is evolving, what hasn’t changed and where businesses need to invest to be protected in the future against a changing cyber-attack landscape.

In part 2 Glen and Guy cover:

  • Why certifications are not enough to keep your business secure 
  • Communicating key cyber security messages across an organisation
  • The importance of a cyber resilience mindset and culture
  • Evaluating a cyber security services provider for your business
  • The UK Cyber Resilience Act and how it will impact businesses

Glen Williams, CEO of Cyberfort, recently joined Guy Clapperton on The Near Futurist Podcast to discuss how cyber security has moved far beyond basic antivirus and controls. In this two-part interview series, they explore how the threat landscape is evolving, what hasn’t changed and where businesses need to invest to be protected in the future against a changing cyber-attack landscape.

In part 1 they explore:

  • Why cyber security needs to be taken as seriously as physical security 
  • The ‘tooling and compliance’ misconception trap many businesses have fallen into
  • The importance of creating a cyber security culture in a business and not just relying on the IT team
  • Why deepfake attacks are on the rise and what steps organisations can take to mitigate this type of attack
  • Why certifications are important, but regular security testing holds the key to becoming resilient against attack

Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.