Cyber Essentials Plus – Why It’s Worth Considering
Cyber Essentials (CE) is a solid foundation. It shows that your organisation follows good practice and takes cyber security seriously. But there’s a step further — Cyber Essentials Plus (CE+).
CE vs CE+
-
Cyber Essentials – a self-assessment, signed off internally.
-
Cyber Essentials Plus – an independent audit, including vulnerability scans and hands-on testing.
What we’ve found at Cyber23
In our first full year of operating, every single CE+ audit uncovered high-risk vulnerabilities that were not known beforehand. These ranged from missing patches to weak configurations — issues that could have been exploited in the real world.
This highlights a key point: MSPs often meet their contractual obligations, but those contracts aren’t always aligned with security standards like CE. CE+ provides that external check.
Why CE+ makes a difference
-
Uncovers hidden risks – scans reveal what day-to-day IT management can miss.
-
Gives you evidence – a clear report you can share with your MSP to close gaps.
-
Raises assurance – clients, funders, and regulators see proof of best practice in action.
🎉 Celebrating One Year of Cyber23
To mark our first year of operation, we’re offering a free single-workstation vulnerability scan during September 2025.
-
The scan produces a report similar to CE+ just on a single workstation device.
-
In most cases, we expect high-risk issues to be revealed.
-
With that evidence, you can challenge your MSP and strengthen your security.
📩 To claim your scan, email before 31st October 2025.
Bottom line
Cyber Essentials tells the world you take cyber seriously. Cyber Essentials Plus proves it.