secure

Cyber security
& certification.

Secure your systems. Understand your risks. Show the evidence.

An appointed Cyber Essentials and Cyber Essentials Plus certification body, with NCSC assurance under the Cyber Advisor scheme. We help put controls in place and assess them against the relevant standard.

Reading, Berkshire. Supporting organisations across the UK.

secure

Security controls, technical assessment and certification.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor scheme MicrosoftCertified Expert

Daniel McClure Fisher holds CISSP, MCIIS and Cyber Essentials Assessor credentials. Our team and credentials.

12 risks identified.
All twelve remediated.

A professional services firm asked us to review where it was exposed. A security assessment found twelve distinct risks, several critical.

We confirmed each finding, explained its business impact and worked through the priorities until every risk was closed.

Read the security assessment case study
Assessment
Twelve risks identified in one professional services engagement.
Remediation
The findings were confirmed, prioritised and addressed.
Evidence
A documented record of what was found and what changed.

Appointments and their scope

Cyber Essentials Plus certification body

Cyber Essentials and Cyber Essentials Plus

We are appointed to assess and certify other organisations for both schemes. Preparation, remediation and formal assessment have separate records and responsibilities. Certification follows a successful assessment.

NCSC Assured Service Provider under the Cyber Advisor scheme

NCSC Cyber Advisor assurance

Our Cyber Essentials implementation support is assured under the NCSC Cyber Advisor scheme, assessed by IASME. It helps smaller organisations put the five technical controls into practice.

What the assurance covers
Defence Cyber Certification body

Defence Cyber Certification Level 0

We are an appointed Defence Cyber Certification body for Level 0. This appointment is specific to that level.

What DCC Level 0 involves

Security services

Start with the contract, risk or technical problem you need to address. Implementation support, ongoing monitoring and formal assessment have defined scopes.

Cyber Essentials and Cyber Essentials Plus

The baseline supply chains and contracts ask for. Preparation, remediation and formal assessment are separate pieces of work, whether you take Cyber Essentials or Cyber Essentials Plus, which adds a technical audit where an assessor tests a sample of your devices and accounts.

  • Readiness review
  • Controls in place
  • Plus audit
  • Annual renewal
Explore Cyber Essentials

Cyber Advisor

Help putting the five Cyber Essentials technical controls in place, for small and medium organisations, from an advisor assessed by IASME. We work on your systems alongside your team.

  • Five controls
  • On your systems
  • SME focused
  • IASME assessed
See the Cyber Advisor service

NCSC Assured Service Provider

The assurance behind that support: we are an NCSC Assured Service Provider under the Cyber Advisor scheme, assessed by IASME. Supplier due diligence can name the scheme and check the record.

  • Cyber Advisor
  • IASME assessed
  • CE implementation
  • SME focused
See our NCSC assurance

ISO 27001

A full information security management system, the proof larger clients and regulators look for. We run ISO 27001 ourselves and are certified by a UKAS-accredited certification body, and support you from gap analysis through an assessment by your chosen certification body.

  • Gap analysis
  • ISMS build
  • Internal audit
  • Certification support
Plan your ISO 27001 path

Email and endpoint security

Protect the inbox and the devices your people work on. We configure and run the protection, usually on licences you already pay for, and keep it that way.

  • Anti phishing
  • Multi factor authentication
  • Endpoint protection
  • Data controls
Explore email and endpoint security

Threat detection and response

Managed detection and response investigates alerts and supports threat containment. Tooling, monitoring, investigation and response hours are agreed in your service schedule.

  • Continuous monitoring
  • Agreed MDR cover
  • Threat containment
  • Clear reporting
See how monitoring works

Incident response

For managed clients with agreed incident-response cover, a senior responder coordinates containment, recovery and a record of what happened. The response window, responsibilities and third-party dependencies follow the service schedule.

  • Containment planning
  • Senior responder
  • Recovery
  • Post incident report
Talk to us about response

Defence Cyber Certification Level 1.

Support across the 101 controls, from scope and gap analysis to evidence preparation. Discuss the level your contract requires and the work needed to prepare for assessment.

Explore DCC Level 1

Cyber certification, explained.

32 seconds · Silent explainer. Preparation and formal assessment have distinct roles.

From readiness to a recorded assessment.

A readiness review identifies gaps against the relevant standard. Remediation puts the required controls in place and records the evidence.

Formal assessment has separate responsibilities and records. Cyber Essentials Plus adds technical testing. Certification depends on the assessment result.

Controls and evidence need to stay current between assessments. Explore Cyber Essentials Plus

Read the service explanation

Cyber Essentials or Plus? The same five controls, with different levels of verification.

Cyber Essentials is a verified self-assessment. An assessor checks your answers.

Plus adds technical testing of devices and accounts. Cyber Essentials comes first.

Agree the scope and address any gaps. Preparation and formal assessment are separate steps.

Certification follows a successful assessment. Dead Simple Computing. Talk to our certification team.

How an engagement works

  1. Assess

    Review your systems, risks and the standards that apply to the agreed scope.

  2. Prioritise

    Record the findings, business impact and work needed to address each gap.

  3. Implement and monitor

    Put agreed controls in place. Define monitoring, MDR cover and the human response window in the service schedule.

  4. Assess and record

    Prepare the evidence and, where commissioned, arrange the separate formal assessment and record its outcome.

Discuss your next security step.

Tell us about the risks you want to review, the standard being requested and any assessment deadline. We will explain the relevant scope and next steps.

0118 359 2220

Monday to Friday, 9am to 5.30pm.
Reply within one working day.