From no formal IT to Cyber Essentials certified.

A construction business with no formal IT management, taken to certification in eight weeks: device management, a hosted VPN, written policies, patching, and a clean pass.

CertifiedCyber Essentials
8weeks start to finish

The challenge

The business ran on the sort of arrangement a lot of construction firms recognise. Things mostly worked, but there was no formal IT management behind them. No clear view of which devices were in use, no consistent patching, no written policies, and nothing that would stand up if a client or an insurer asked the firm to prove it took security seriously.

Increasingly, that proof was being asked for. Cyber Essentials had moved from a nice to have to a requirement for the work the firm wanted to win. The challenge was not just passing a certification. It was building the foundations that make certification meaningful, starting from very little, and doing it without disrupting a busy operation.

Our approach

We started by getting a proper handle on what the firm actually had, then put the basics in place in a sensible order. Device management came first, so every machine was known, controlled, and kept up to date rather than left to drift. We added a hosted VPN to give people a secure way of working wherever the job took them.

Alongside the technical work, we put the written policies in place that Cyber Essentials expects and that a real business benefits from having, and we got patching onto a regular, managed footing rather than something that happened when someone remembered. With the controls in and holding, we took the firm through to certification.

The outcome

The business went from no formal IT management to Cyber Essentials certified in eight weeks. The device management, the hosted VPN, the policies, and the patching are not just there to pass an assessment. They are the day to day shape of a properly run environment, and they keep doing their job long after the certificate is issued.

The firm can now answer the security questions its clients and insurers ask, with certification to back it up, and it is in a far stronger position than the standing start it began from.

Need Cyber Essentials, done properly?

We are a Cyber Essentials certification body, so the controls we put in are the ones we know stand up. We reply within one working day, and you will speak to an engineer, not a salesperson.

Reading, Berkshire  /  Cyber Essentials certification body  /  reply within one working day