Preparation for Cyber Resilience
The Department of Science and Information Technology (DSIT) has recently released a code of practice for organisations who wish to be Cyber Resilient. Cyber Essentials Plus, whilst very welcome, focuses on technical controls, and is not sufficient on its own.
Whilst DSIT cannot recommend particular commercial product, they have done mapping exercises for the code of practice against both IASME Cyber Assurance (ICA). They have found that both do fulfill their requirements for cyber resilience (both require relevant management and user controls, as well as technical controls).
ISO27001 is designed for larger organisations, and Regola would always recommend that an organisation with sufficient resources should aim for this "gold standard".
However, for smaller organisations, ICA (particular at L2) would be sufficient for smaller organisations seeking cyber resilience.
Regola's experienced staff provide consultancy for organisations wishing to be Cyber Resilient.
Other Products and Services from Regola Digital Consulting
Cyber Essentials Preparation
Some IT people find the Cyber Essentials guidance intuitive; many business people find the language and concepts more demanding. We are here to support businesses! over 250000 certificates have now be awarded, but some businesses do fail. Prepare well, and that won't be you.
It is normal for a business to take the Cyber Essentials assessment and be told by the assessor that they have a small number of corrections to make, and they are given a small window of time. Few get it completely right first time. What a business would not want, however, to do is take Cyber Essentials and then comprehensively fail it.
To prepare businesses for assessment, we offer microbusinesses a service of 30 minutes free discussion, with a follow-up and a clearly written set of "do's and don'ts". Extra time and consultancy beyond this is available, but will be charged at the normal consultancy rate. After the 30 minutes, we point businesses at the self-help facilities available on the IASME website.
We are a Certification Body (the only one in South Devon) and do plenty of assessing ourselves. If you sign up for assessment through us, rather than through IASME, you'll get our friendly and comprehensive service right through to certification, and on to cyber essentials plus (within 90 days) if you so wish.
Cyber Assurance Level 1 Consultancy & Certification
Cyber Assurance is a comprehensive, flexible and affordable cyber security standard. This provides assurance that an organisation has put in place a range of important cyber security, privacy and data protection measures. It aligns directly with the UK Government’s 10 steps to Cyber Security with additional Data Privacy controls and offers smaller companies within a supply chain a ‘right sized’ approach to show their level of information security for a realistic cost.
Important cyber security measures are included such as assessing and managing risk, training people and setting practical policies and procedures. Key resilience strategies are covered and include backing up data, business continuity planning and incident response. Legal and regulatory requirements are also addressed such as your country’s implementation of GDPR (in the UK this is the Data Protection Act). Furthermore, the IASME Cyber Assurance standard was developed over several years during a government funded project. This was in order to create an affordable and achievable alternative to the international standard, ISO 27001. You must have Cyber Essentials first in order to achieve Cyber Assurance.
At Level 2, Cyber Assurance maps well to ISO27001 for Cyber Resilience. A separate page describes this product, and the path to ISO27001.
Cyber Essentials and Cyber Liability Insurance
This only applies to UK organisations.
Any organisation with less than £20 million turnover that achieves Cyber Essentials is entitled to cyber liability cover, for claims up to £25000. This is a thank you for making your systems safer, and less likely to be hacked... and therefore less likely to make an insurance claim. In short, it means you are "lower risk". This is backed up by statistics that show that those with Cyber Essentials are 93% less likely to make a claim.
For a microbusiness, £25000 cover may be adequate. If it is a small business that is part of a supply chain, the liability could turn out to be higher. Insurance premiums can easily be extended at modest cost, to provide greater cover.
Regola Digital Consulting
Office 1.19, Torbay Business Centre, Lymington Road, Torquay, Devon, TQ1 4BD, United Kingdom
Regola are an NCSC approved Cyber Essentials Certification Body We offer a cost-effective service, based on many years experience of offering expert advice to SMEs so they cover the basics of technical security. We specialise in UK Government's Cyber Essentials (CE) and have assessed over 150 clients. As an accredited Certification Body for both CE and CE+, and IASME Cyber Assurance, we offer customised guidance to help businesses achieve valued cyber security certifications to assure partners and clients. The Cyber Essentials scheme also provides free Cyber Liability insurance up to £25000 for smaller UK companies who achieve certification. It is especially beneficial for SMEs aiming to secure government contracts or reassure clients that their information is well-protected.