Cyber Essentials readiness and gap review
A review of where your systems stand against the five Cyber Essentials controls.
Dead Simple Computing is an NCSC Assured Service Provider under the National Cyber Security Centre's Cyber Advisor scheme. Through an independent assessment run by IASME, NCSC's delivery partner for the scheme, we are assured for our competence to give practical advice and support on implementing the Cyber Essentials technical controls, for small and medium organisations.
If a tender, a regulator, or your own supplier due diligence asks whether your Cyber Essentials support comes from an independently assured advisor, we can answer yes. The NCSC listing says Dead Simple Computing "currently meets the standards required under Cyber Advisor scheme", and names Daniel McClure Fisher as the Qualified Advisor. Verify our listing on ncsc.gov.uk (opens in new tab).
The Cyber Advisor scheme exists so small and medium organisations can find help implementing the Cyber Essentials technical controls from someone whose competence has been checked. Assessment is run independently by IASME, NCSC's delivery partner for the scheme.
There are two parts: the individual qualifies, and then the firm becomes an Assured Service Provider.
An individual becomes a qualified Cyber Advisor by passing an IASME-run assessment, then receives a Certificate of Competence in Cyber Essentials Implementation.
A firm becomes an NCSC Assured Service Provider by employing at least one qualified Cyber Advisor, holding Cyber Essentials certification, and running a quality management system. We meet those through our certification body status and our ISO 9001 quality management system, certified by a UKAS-accredited certification body.
Assured status is upheld by continuing to meet the scheme's requirements, not granted once and then forgotten.
The assurance answers one specific due diligence question: if you are choosing help to get your Cyber Essentials controls in place, for a tender, a supply-chain requirement, or simply to close a risk, the competence behind that help has been checked by someone other than us.
The assurance is specific: practical help implementing the Cyber Essentials technical controls for small and medium organisations, provided through our Cyber Advisor service. It sits on top of our Cyber Essentials certification body status, because the people advising you on the controls are the people appointed to assess them. We are also an appointed certification body for Defence Cyber Certification at Level 0, where Cyber Essentials is one of the required controls.
Behind it sits our ISO 9001 quality management system, certified by a UKAS-accredited certification body and one of the scheme's requirements, and Daniel McClure Fisher, CISSP and MCIIS-qualified, leads the security work.
That is deliberately narrower than "we do all your cyber security". Our ISO 27001 consultancy, risk management, governance and audit and incident response are separate services backed by our other credentials, not by this assurance.
Here is what that help looks like in practice.
A review of where your systems stand against the five Cyber Essentials controls.
Support putting the controls in place, firewalls, secure configuration, access control, malware protection and update management, done with you rather than handed over as a checklist.
We take you through to certification, and because we are a certification body we know what the assessment expects.
Advice pitched at a small or medium organisation, focused on the controls that close the most risk.
It is an organisation assured under one of the NCSC's assurance schemes. Dead Simple Computing is assured under the Cyber Advisor scheme, which covers advice and support on implementing the Cyber Essentials technical controls for small and medium organisations. An organisation earns it by employing at least one qualified Cyber Advisor, holding Cyber Essentials certification, and running a quality management system, all assessed independently by IASME, NCSC's delivery partner.
It is an NCSC scheme, delivered by IASME, that assures advisors to give small and medium organisations help implementing the Cyber Essentials technical controls. An individual qualifies by passing an IASME assessment of their knowledge of the controls, their implementation competence, and their ability to work with smaller organisations, and receives a Certificate of Competence in Cyber Essentials Implementation.
They check different things. The Cyber Advisor assurance confirms the competence of the person advising you on implementing the Cyber Essentials controls. Cyber Essentials certification confirms the controls are in place in an IT estate, and we are a certification body for it. ISO 27001, where we are certified by a UKAS-accredited certification body, certifies that we run a documented information security management system. All three are independently checked.
The Cyber Advisor assurance is about Cyber Essentials implementation support for small and medium organisations, which is exactly what many tenders and supply-chain requirements ask for. It is not a general government-consultancy credential.
Large, complex or nationally significant work, including GovAssure engagements, sits under a separate, higher-tier scheme, the Assured Cyber Security Consultancy scheme, which is distinct from Cyber Advisor. If you are unsure which your contract needs, ask us.
Check IASME's directory of assured providers (opens in new tab), which lists organisations assured under the Cyber Advisor scheme, or ask us and we will confirm it directly. We would rather you verified it independently, that is the point of the scheme.
Tell us what you need to satisfy, a tender, a supply-chain requirement, or simply getting the basics right, and we will set out what the assurance covers and how our Cyber Essentials, ISO 27001 and ISO 9001 credentials fit around it.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.