The businesses that look strongest to a potential customer, supplier or procurement team have one thing in common: they can demonstrate, clearly and confidently, how their cyber security is being managed.
A policy on a website only goes so far in reassuring customers. Today, they increasingly expect more tangible proof, particularly when trusting another business with their data, systems access or a place in their supply chain. Recognised certification gives them that evidence.
Cyber Essentials and IASME Cyber Assurance provide two different layers of it. Cyber Essentials establishes the technical baseline, with the core controls accounted for and evidenced. Cyber Assurance furthers that foundation by covering the wider policies, responsibilities, people and processes that surround those controls.
For businesses looking to demonstrate a well-rounded approach to cyber security, the strongest position is usually to hold both.
Cyber Essentials is the UK Government-backed certification designed to help organisations protect themselves against common internet-based attacks.
The assessment covers five areas attackers routinely exploit:
From dormant user accounts and unnecessary administrator privileges to missed updates and poorly configured cloud services – the issues these controls are designed to cover may appear fairly minor in isolation. But spread across dozens of users, devices and applications, they can create considerably more exposure.
With Cyber Essentials certification in place, businesses have a defined way to bring those fundamentals under control.
Certification is awarded through a verified self-assessment questionnaire. Once submitted, the answers are reviewed by an accredited certification body and, where requirements have been met, the certificate will be issued.
For some businesses, the commercial reason for getting certified is immediate. Cyber Essentials is often specified in tenders, requested by customers or required before a supplier can join a particular supply chain.
As a business moves into larger or more demanding supply chains, Cyber Essentials can become an expected part of procurement. A larger prospect may ask for evidence of cyber controls, while supplier questionnaires can extend into how access, updates and devices are managed. What began as an internal security consideration then becomes a significant aspect of winning and retaining business.
Cyber Essentials gives people recognised evidence that the necessary safeguards have been addressed. But for those looking for more comprehensive proof, IASME Cyber Assurance is fast becoming the standard.
While the five technical controls laid out in Cyber Essentials can tell a customer a lot about the security of a business's IT, they can't show how cyber risk is handled across the entire organisation.
Once supplier due diligence moves beyond technical controls, procurement teams start looking at how cyber risk is handled across the business.
That is where IASME Cyber Assurance can help to demonstrate stronger protections.
Cyber Assurance looks at how cyber security is run across the organisation. Its themes cover risk assessment, legal and contractual obligations, staff training, policies, access management, monitoring, backup, incident response and business continuity.
For an SME, this is often the point where customer checks become more demanding. You may be asked to provide a risk assessment, explain how staff are trained, show who can approve access to sensitive information or confirm that backups can be restored. Each request needs evidence behind it.
It is easy to frame the two certifications as an either-or, but in practice, they are complementary.
Cyber Essentials provides the technical foundation on which Cyber Assurance can build. Organisations applying for IASME Cyber Assurance must already hold a valid Cyber Essentials or Cyber Baseline certificate during the certification process.
It is helpful to consider the position of a customer assessing a new supplier. First, they may want reassurance that common technical weaknesses have been addressed. Cyber Essentials gives them a recognised indicator of that. Their needs may go one further. For instance, they might ask how the supplier manages cyber risk, controls access to sensitive information, trains employees, handles an incident or maintains continuity if systems become unavailable.
Both certifications give a potential customer a clearer view of the organisation they are considering working with. If technical controls have been addressed, and there is evidence of a framework around the people, policies and decisions that keep those controls effective, they’re much more likely to have confidence in a business.
If a business doesn’t already have these certifications in place, Cyber Essentials is the best starting point, particularly if clients need to see evidence around patching, devices, firewalls and user access. However, for clear evidence of staff training, risk ownership, supplier management, written policies, backups or incident response, Cyber Assurance is a more comprehensive choice.
Look ahead as well: Moving into regulated sectors, larger corporate supply chains or contracts involving sensitive information usually means more detailed checks before appointment. Preparing the evidence in advance is far easier than hunting for them during a live tender.
For businesses already certified, the useful question is how far customer due diligence now goes. If the scope has widened beyond technical controls, Cyber Assurance may be the logical next step.
Few customers have the time, access or expertise to inspect a supplier’s security arrangements in detail. Certification provides an independent reference point they can recognise during procurement and supplier reviews.
For organisations trying to win or retain more demanding customers, fuller evidence can be significantly more persuasive. So, whether you already have Cyber Essentials and want to explore IASME Cyber Assurance, or you’re starting from scratch, Cyber Tec can help.
Book a readiness review to understand what you already have in place and what you may need next.