Skip to main content
Cyber23
  • Home
  • Packages
  • Services
  • FAQ
  • About
  • Contact
  • Blog

Recent Posts

  • Cyber Essentials Plus – Why It’s Worth Considering
    25 Sep, 2025
  • MoJ Legal Aid Portal Breach – Lessons for Law Centres
    25 Sep, 2025
  • Windows 10 End of Life – What It Means for Your Cyber Essentials
    25 Sep, 2025
  • Turning Downtime into Resilience
    17 Sep, 2025
  • How Cyber Essentials Helps You Win Government Contracts
    31 Jul, 2025
  • Cyber Essentials vs Cyber Essentials Plus – Which Is Right for You?
    31 Jul, 2025
  • What Is Cyber Essentials and Why Do SMEs Need It?
    31 Jul, 2025

Stay Cyber Aware

We share straightforward security insights, threat updates, and practical tips to help you protect what matters most.

Whether you need advice on staying safe online or want to understand the latest risks, you’ll find clear guidance here.

Check back regularly — or reach out if you want to talk through your security needs today.

Cyber Essentials Plus – Why It’s Worth Considering

25 Sep, 2025, No comments

Cyber Essentials (CE) is a solid foundation. It shows that your organisation follows good practice and takes cyber security seriously. But there’s a step further — Cyber Essentials Plus (CE+).

CE vs CE+

  • Cyber Essentials – a self-assessment, signed off internally.

  • Cyber Essentials Plus – an independent audit, including vulnerability scans and hands-on testing.

What we’ve found at Cyber23

In our first full year of operating, every single CE+ audit uncovered high-risk vulnerabilities that were not known beforehand. These ranged from missing patches to weak configurations — issues that could have been exploited in the real world.

This highlights a key point: MSPs often meet their contractual obligations, but those contracts aren’t always aligned with security standards like CE. CE+ provides that external check.

Why CE+ makes a difference

  • Uncovers hidden risks – scans reveal what day-to-day IT management can miss.

  • Gives you evidence – a clear report you can share with your MSP to close gaps.

  • Raises assurance – clients, funders, and regulators see proof of best practice in action.

🎉 Celebrating One Year of Cyber23

To mark our first year of operation, we’re offering a free single-workstation vulnerability scan during September 2025.

  • The scan produces a report similar to CE+ just on a single workstation device.

  • In most cases, we expect high-risk issues to be revealed.

  • With that evidence, you can challenge your MSP and strengthen your security.

📩 To claim your scan, email before 31st October 2025.

Bottom line

Cyber Essentials tells the world you take cyber seriously. Cyber Essentials Plus proves it.

MoJ Legal Aid Portal Breach – Lessons for Law Centres

25 Sep, 2025, No comments

Earlier this year, the Ministry of Justice (MoJ) took down its legal aid portal following a significant cyber incident. Many law centres across the UK rely on this system daily, and the disruption has been widely felt.

What happened

  • The MoJ confirmed that unauthorised access had been detected.

  • The portal was taken offline while investigations and remediation took place.

  • As of September 2025, access issues and delays are still being reported.

Why this matters for law centres

The breach exposed a weakness that many of you have already flagged in your Cyber Essentials assessments: the lack of multi-factor authentication (MFA).

  • MFA is a core Cyber Essentials requirement.

  • Some law centres were frustrated that their own assessments showed non-compliance, while the government system they rely on didn’t support it at all.

The bigger picture

Even central government systems can fall short. But that doesn’t mean you should lower your own standards.

  • MFA reduces risk – adding it to accounts makes a breach significantly harder.

  • Cyber Essentials sets a baseline – a consistent standard that applies whether you’re a law centre, MSP, or government body.

  • Awareness is power – assessments don’t just generate a certificate, they highlight real risks you can address.

Takeaway

The MoJ incident is a reminder that you can only control what’s within your own organisation. Apply the strongest controls you can, insist on best practice from your MSP, and don’t assume “big systems” are immune.

Windows 10 End of Life – What It Means for Your Cyber Essentials

25 Sep, 2025, No comments

Windows 10 support ends on 14 October 2025. After that date, Microsoft will stop releasing security updates for the operating system. For organisations maintaining or working towards Cyber Essentials certification, this is a major red flag.

Why Windows 10 matters for Cyber Essentials

Cyber Essentials requires that all software in use is:

  • Supported by the vendor, and

  • Receiving security updates.

From 14 October 2025, Windows 10 will no longer meet those criteria. Any Cyber Essentials self-assessment submitted with Windows 10 devices present will automatically fail.

The wider cyber risk

Unsupported systems quickly become magnets for attackers. We’ve seen this before:

  • In 2017, the WannaCry ransomware outbreak crippled NHS systems running outdated Windows, causing cancelled operations and widespread disruption.

  • With millions of UK devices still running Windows 10, there’s potential for a repeat — but on a much larger scale.

What to do next

  1. Audit your devices – find every machine still on Windows 10.

  2. Plan the transition – upgrade to Windows 11 or a supported alternative.

  3. Work with your MSP – don’t assume they’ve scheduled this; ask the question.

  4. Mitigate legacy needs – if business-critical apps require Windows 10, consider containment strategies like network isolation.

Final word

Windows 10 retirement isn’t just a compliance milestone — it’s one of the biggest cyber security events of the next 12 months. Act now, and don’t leave your organisation exposed.

Turning Downtime into Resilience

17 Sep, 2025, No comments

A Call to JLR Supply Chain Partners

The recent cyber attack on Jaguar Land Rover (JLR) has forced operations to a standstill for more than a week—and supply chain partners are feeling the impact. Production lines are halted, orders delayed, and many organisations across the network are waiting anxiously for systems to come back online.

While this disruption is frustrating, it also presents a unique opportunity. If your organisation is experiencing downtime, now is the perfect moment to strengthen your own cyber defences.

Why Act Now?

When a major player like JLR is attacked, supply chain partners are often the next target. Cyber criminals know that smaller suppliers may have weaker protections, making them a gateway into larger ecosystems. By acting now, you can:

  • Use downtime productively to assess your network security

  • Close gaps that attackers could exploit in the future

  • Return to business stronger, more resilient, and ready for compliance demands from OEMs and regulators

How Cyber23 Can Help During the Downtime

At Cyber23, we specialise in helping manufacturing and automotive supply chain organisations strengthen their cyber posture. During this pause in operations, we can help you:

🔹 Achieve Cyber Essentials – Demonstrate to partners and customers that you take cyber security seriously by meeting government-backed standards.

🔹 Upgrade to Cyber Essentials Plus – Gain independent assurance that your protections are effective against real-world threats.

🔹 Conduct a Secure Innovation Review – Identify vulnerabilities in your systems, processes, and digital products, and create a roadmap for security-by-design.

Preparing for the Restart

When JLR systems come back online, the supply chain will need to move quickly to recover lost time. By investing in cyber security now, you ensure that your organisation is not only ready to restart operations but also more resilient against future attacks.

Don’t let this downtime go to waste. Instead, use it as an opportunity to build strength where it matters most: your cyber resilience.

👉 Contact Cyber23 today to turn this disruption into a step forward for your business.

How Cyber Essentials Helps You Win Government Contracts

31 Jul, 2025, No comments

Introduction

For many small businesses, landing government contracts is a game‑changer. But strict security requirements can be a barrier. Cyber Essentials certification is often the first step to meeting these requirements — and it’s simpler to achieve than you might think.

Why Government Contracts Require Cyber Essentials

Government departments and the MOD handle sensitive information. Cyber Essentials provides assurance that suppliers follow basic security practices, reducing the risk of breaches in the supply chain.

Benefits Beyond Compliance

  • Wider Market Access: Eligibility for contracts you couldn’t previously bid on.

  • Client Confidence: Demonstrates professionalism and reliability to all customers, not just government.

  • Competitive Advantage: Sets you apart from competitors who lack certification.

How Cyber23 Makes It Simple

We guide businesses through the certification process — from preparation to final approval. Our step‑by‑step support ensures minimal disruption to your operations and fast results.

Ready to Start Bidding?

If you want to open the door to government contracts, Cyber Essentials certification is essential. Start your journey with our Store page and choose the right package for your business.

Cyber Essentials vs Cyber Essentials Plus – Which Is Right for You?

31 Jul, 2025, No comments

Introduction

Cyber Essentials and Cyber Essentials Plus are two levels of the same government‑backed certification scheme. Both improve your organisation’s cyber security, but they offer different levels of assurance. Understanding the difference helps you choose the right path.

Cyber Essentials: The Basics

This is the entry‑level certification. It involves a self‑assessment covering the five key security areas. It’s cost‑effective and suitable for businesses looking to demonstrate essential cyber hygiene.

Cyber Essentials Plus: Higher Assurance

Cyber Essentials Plus includes all the requirements of the basic certification but adds an independent technical audit. This audit tests your systems to confirm that the measures you claim are in place actually work.

Which Should You Choose?

Choose Cyber Essentials

  • You’re new to certification and need a quick, cost‑effective solution.
  • Your clients don’t specifically require a higher level of assurance.

Choose Cyber Essentials Plus

  • You handle sensitive data or work with high‑value contracts.
  • Your clients, especially in public sector or MOD, require independent verification.

Getting Certified

Cyber23 supports both certification types and can help you decide which is right for your business. Learn more on our Services page.

What Is Cyber Essentials and Why Do SMEs Need It?

31 Jul, 2025, No comments

Introduction

Cyber security is no longer just a concern for large corporations. Small and medium‑sized businesses (SMEs) are increasingly targeted by cyber criminals — often because their defences are easier to breach. The UK government’s Cyber Essentials scheme provides a clear, cost‑effective way to protect your organisation and demonstrate your commitment to security.

What Is Cyber Essentials?

Cyber Essentials is a UK government‑backed certification that sets out five basic security controls every organisation should have in place:

  • Firewalls and secure internet gateways

  • Secure configuration of devices and systems

  • User access control

  • Malware protection

  • Patch management

Meeting these controls shows that your business can prevent most common cyber attacks.

Why SMEs Should Care

  • Client Trust: Many customers and suppliers check for Cyber Essentials before working with new partners.

  • Contract Eligibility: Required for many government and MOD contracts.

  • Risk Reduction: Significantly lowers your risk of data breaches and business disruption.

  • Reputation: Certification signals that you take security seriously, which can set you apart from competitors.

The Certification Process

The standard certification involves a self‑assessment questionnaire. With guidance from experts like Cyber23, most SMEs can achieve certification quickly — often within a few days.

Next Steps

If you’re ready to protect your business and boost client confidence, explore our Services page to see how we can guide you through Cyber Essentials certification.

Cyber23 Launches New Website in Partnership with Mountain Forty Nine

28 Jul, 2025, No comments

We are thrilled to announce the launch of our brand-new Cyber23 website, created in collaboration with digital specialists Mountain Forty Nine. The new site has been designed to reflect our growing range of cyber security services and make it easier than ever for businesses to access the support they need to stay secure.

This partnership with Mountain Forty Nine marks an exciting step forward for us, combining their expertise in modern, user-focused web design with our commitment to delivering trusted Cyber Essentials and Cyber Essentials Plus certification services. Together, we’ve built a platform that not only looks great but also provides clear information, guidance and resources for organisations looking to strengthen their cyber security posture.

Take a look around the new site and discover how Cyber23 can help you protect your business from evolving online threats.

Cart

Cart is empty.

Created by Mountain Forty Nine ©2026

Cyber23 is registered in England, Company No. 14375436

Terms | Privacy | Cookie Policy | Services

Pera Business Park, Nottingham Road, Melton Mowbray, Leicestershire, LE13 0PB