Free demo
Brief
What the 2026 breaches survey says about small organisations
Download the briefWorking demo
Three views, an approval chain and an activity log, on sample data
Open the Approvals demoRead more
Phishing awareness for staff and tabletop exercises for leadership teams
See the team workshopsSecurity advice often comes from the firm that would be paid to act on it.
What we do
Every gap goes on one ranked list, with its evidence and an owner.
If you cannot say which cloud services your staff sign in to, which of them ask for a second factor, or which former staff still have an account, you cannot say where you are exposed. For Cyber Essentials assessment accounts created after 26 April 2026, a missing second factor on a cloud service that offers one, or a high-risk or critical update still uninstalled more than 14 days after its release, is an automatic fail.
We review the settings, accounts and suppliers you rely on, and the code we build or take over, against public standards and guidance: the NCSC's 10 Steps, the five Cyber Essentials controls, OWASP ASVS and the government's Software Security Code of Practice.
You receive a ranked list of what to fix, the evidence behind each item and a note of what the review did not cover. We also build and maintain software, and when a finding could lead to work for us, the record says so.
The answer to a gap may be a setting you change yourself, a product you buy, a fix we make in a system we built, or a recorded decision to change nothing.
We do not certify, carry out Cyber Essentials assessments, run penetration tests or respond to live incidents, and for each of those we name the public register of licensed, assured or accredited providers.
Four figures from the government's breaches survey
The survey only includes the breaches or attacks that organisations were able to identify and willing to report. In its own words, there are likely to be hidden attacks and other breaches that go unidentified, so the findings may underestimate the full extent of the prevalence of cyber breaches and attacks. All four figures are self-reported, from a random probability telephone and online survey of 2,112 UK businesses and 1,085 UK registered charities carried out between August and December 2025 and weighted to be statistically representative. Sole traders, public-sector organisations and businesses with no IT capacity or online presence are outside its scope. The 24% counts businesses that said they have all five of: network firewalls, security controls on company-owned devices, admin rights restricted to specific users, up-to-date malware protection and a policy to apply software updates within 14 days. It is not an assessment. Official Statistics, published 30 April 2026, retrieved 19 September 2026.
What we review, prepare, plan and teach
The work runs in three phases, and each piece can be taken on its own. Each ends with a written record you keep, including what the work did not cover. We review, prepare, plan and teach. Where you need a certificate, a penetration test or help during a live incident, we name the public register that lists licensed, assured or accredited providers.

Cyber security baseline review
Check your organisation against the NCSC's 10 Steps and the five Cyber Essentials controls, and get a list of what to fix, ranked by risk and by effort. We look at the settings themselves, not only the policies that describe them.
- Admin roles, sign-in rules and sharing settings in your cloud email and office suite, such as Microsoft 365 or Google Workspace
- Multi-factor coverage on every account that can sign in from the internet
- SPF, DKIM and DMARC records for each domain you send email from
- Update status of laptops, phones, routers and firewalls against the 14-day window in Cyber Essentials
- One restore from your backups, carried out with you and written up
Access and identity review
Map who can reach which system and data, remove access nobody needs, and make access follow the role as people join, move and leave. The work follows the NCSC's identity and access management guidance and the user access control requirements in Cyber Essentials.
- An access map of people, roles, systems and data
- Separate admin accounts, used for admin work only
- Passkeys or multi-factor sign-in on every internet-facing account
- Shared, dormant and former-staff accounts listed for removal
- A joiners, movers and leavers checklist, with single sign-on options over SAML or OpenID Connect
Supplier and integration risk review
List every supplier, software service, API key and integration that holds or moves your data, rank them by risk and put the right questions to the ones that matter. The questions come from the government's Software Security Code of Practice and the NCSC's guidance on supply chain security.
- A register of suppliers, software services and integrations, with the data each one holds or moves
- OAuth scopes, API keys and service tokens listed by age, owner and reach
- A sweep for passwords and keys shared in email, chat or spreadsheets
- Supplier questions drawn from the Code's 14 principles, including a published vulnerability disclosure route and a year's notice before support ends
- Suppliers that process personal data flagged for your data protection lead
Cyber Essentials readiness
Prepare for a Cyber Essentials assessment under the v3.3 requirements introduced in April 2026: set the scope, list everything inside it and close the gaps control by control. The assessment and the certificate come from the IASME-licensed Certification Body you choose. We do neither.
- The scope boundary, the legal entities inside it and the areas left out, which the April 2026 rules ask you to describe
- An inventory of devices, software and cloud services in scope, with end-of-support dates
- Multi-factor authentication on every cloud service that offers it, one of the checks that now fail an assessment outright
- A routine for installing high-risk and critical updates within 14 days of release, where a miss now also fails an assessment outright
- A gap list against the five controls, and the evidence each one needs
Application and AI security review
Review the design and code of bespoke software we build or take over, and of the AI features inside it, through threat modelling and checks against OWASP ASVS and the OWASP Top 10 for LLM Applications 2025. Cyber Essentials v3.3 leaves the bespoke and custom parts of web applications out of scope, and this review looks at those parts. It is a design and code review, not a penetration test.
- A threat model of each data flow and trust boundary
- Checks against OWASP ASVS at a level agreed with you
- Prompt injection, sensitive information disclosure and excessive agency in AI features, from the OWASP list for LLM applications
- A dependency and secrets check of the code repository
- A self-assessment against the Software Security Code of Practice
Incident response planning and exercises
Write the plan before you need it, then rehearse it with the people who would make the decisions. We draft the plan with you and run a tabletop exercise on a ransomware, phishing or supply chain scenario. The plan cites ICO guidance on personal data breaches; the decision to report stays with you and your advisers.
- Roles, contacts and escalation rules, following the NCSC's incident management guidance
- A first-hour checklist: who decides, what is isolated and who is told
- The 72-hour limit for reporting a notifiable personal data breach to the ICO, which runs from when you become aware of it, and who decides whether a breach is notifiable
- An incident response company chosen in advance from the NCSC's list of assured Cyber Incident Response providers
- A tabletop exercise built on the NCSC's Exercise in a Box, and a written list of the gaps it exposed
What you get
What you can name, rank and rehearse
- You can name every account, device, service and supplier you rely on, and who can reach each one.
- Every gap has a named owner, a rank by risk and effort, and the evidence behind it.
- Rehearse the first hours of an incident before one happens: who decides, who you call and what gets written down.
Check it yourself
Fifteen questions from Cyber Essentials and the 10 Steps
The five Cyber Essentials controls and the ten areas of the NCSC's 10 Steps, written as yes-or-no questions about your own organisation. Each 'no' or 'not sure' is a line on the fix list a baseline review produces.
0 of 15 in place
Nothing you tick is sent anywhere. It stays in this page.
Paraphrased from public guidance. These are not the Cyber Essentials question set, and a yes to all fifteen is not a certificate. The NCSC aims the 10 Steps at medium to large organisations with someone dedicated to cyber security, suggests its Cyber Action Toolkit as a better place for smaller ones to start, and says the principles apply to all organisations.
How it runs
The review, stage by stage
- 01
Scope and access
Agree what is in scope, which standard the work checks against and who we speak to. We ask for read-only access through named accounts that you create and remove when the work ends.
- 02
Evidence
Check the settings, accounts, devices, suppliers or code in scope, and record the evidence for every finding: a setting, a log entry, a line of code or a supplier's answer.
- 03
Ranking
Rank each finding by likelihood and impact against the effort to fix it, and name an owner for each.
- 04
Handover
Walk through the findings with the people who will act on them. The written record lists what we checked, what we found, what we did not check and where to go for the work we do not do.
- 05
Re-check
Look again at the items marked as fixed, on a date agreed at handover, and update the record.
Read and try
Read the research. Open the demo.

Brief
Cyber security for small organisations: the 2026 figures
A short brief built only from primary sources: the DSIT and Home Office breaches survey with its caveat, the controls gap by organisation size, the April 2026 Cyber Essentials changes, ten questions mapped to the NCSC's 10 Steps, and the public registers of licensed, assured or accredited providers.
Download the brief
Working demo, on sample data
- Three views, Requester, Approver and Finance, over the same set of requests.
- An approval chain set by amount and request type, with the rule that chose it written out.
- An activity log that records every action with a time, on fictional requests and suppliers.
Worth asking first
- Which cloud services do your staff sign in to, and does every one of them ask for a second factor?
- If a member of staff left today, which systems would still let them in tomorrow?
- When did you last restore a backup, and did you check what came back?
- Which suppliers can reach your data or your systems, and what did you ask them before you signed?
- In the first hour of an incident, who decides whether to switch systems off and whether the ICO must be told?
Talk to us if
- A customer, funder or tender asks for Cyber Essentials and you do not know how far you are from it.
- Staff have joined and left faster than anyone has removed their accounts.
- Your software was built by a supplier or developer who has since moved on, and its code and access have not been reviewed since.
- You are adding AI features to a system that holds customer or staff data.
- You have no written incident response plan, or one nobody has rehearsed.
- You have changed IT provider and cannot say which admin accounts and keys the old one still holds.
Questions
Questions buyers ask
Do you certify organisations for Cyber Essentials?
No. We prepare you for the assessment: the scope, the inventory, the gap list and the evidence each control needs. The assessment and the certificate come from an IASME-licensed Certification Body, which you choose from IASME's published list.
Do you run penetration tests?
No. A review reads the design, the configuration and the code; a penetration test attacks the running system. They answer different questions. For a test, look for a CREST-accredited company, or, for government departments, public sector bodies and critical national infrastructure, a provider under the NCSC's CHECK scheme.
Can you help while we are under attack?
No. We do not monitor systems, respond to live incidents or carry out forensic investigations. The NCSC recommends an assured Cyber Incident Response provider and lists them on its website, and gov.uk/report-cyber shows where to report an incident. Your incident response plan should name a provider before you need one.
Could a finding lead to work for you?
Sometimes, and the written record says so whenever a finding could lead to work for us. We also build and maintain software. The answer to a gap may equally be a setting you change yourself, a product you buy, a fix we make in a system we built or maintain, or a recorded decision to change nothing.
Does a review make us compliant or stop attacks?
No review can promise either. It shows where you stand against named public standards on the day we look, what to fix first and what we did not check. Whether you meet a legal duty, such as reporting a personal data breach under UK GDPR, is for you and your advisers to decide.
We can say how far you are from Cyber Essentials.
We check your accounts, devices, email, backups and suppliers against the NCSC's 10 Steps and the five Cyber Essentials controls, and hand you a ranked list of what to fix first.
Request a baseline review