Incomplete estate discovery
Devices, accounts and cloud services are missing from the assessment evidence because nobody has mapped where organisational data is stored, processed or accessed.
Cyber security · Cyber Essentials
DumDum Digital helps UK organisations identify the complete estate covered by Cyber Essentials and implement the controls across their real devices, accounts and cloud services - then prepare for assessment without relying on optimistic answers, invisible SaaS or a last-minute policy exercise.
The outcome
Readiness work connects the five Cyber Essentials control areas to the organisation’s actual estate. That includes every cloud service hosting organisational data or services, even where the provider implements some of the controls. Gaps are identified before submission, remediation is prioritised, and ownership and evidence are left clear enough to support certification and continued compliance.
Who it is for
This support is for organisations using a mixture of cloud services, laptops, mobile devices, remote working, external IT support and - in some cases - volunteer or contractor access. The estate is often more complicated than the original policy or asset list suggests, particularly where teams have adopted SaaS products using organisational accounts or business email addresses.
The organisation may already have an MSP, antivirus, MFA and written policies. The difficult part is establishing the assessment boundary, discovering everything inside it, and proving that the applicable controls are met. Cloud services which host organisational data or services cannot be excluded; the shared-responsibility model only determines whether the organisation or provider implements each control.
Cyber Essentials should normally cover the whole IT infrastructure used to carry out the organisation’s business. Where a partial scope is genuinely necessary, it must be a well-defined and separately managed subset, agreed with the Certification Body. It’s not a way to remove inconvenient devices, services or users from an otherwise connected estate.
Readiness support is useful before opening an assessment, after an unsuccessful attempt, during a wider identity or device-management project, or when a previous certificate no longer gives leadership confidence in the underlying controls.
Recognisable problems
Devices, accounts and cloud services are missing from the assessment evidence because nobody has mapped where organisational data is stored, processed or accessed.
MFA is enabled for some people and platforms while shared accounts, legacy access or avoidable exceptions remain elsewhere.
Operating systems, applications, extensions, routers or firmware are not consistently supported and updated within the required timescales.
Everyday accounts have administrative access, former users remain active, or supplier access is broader and less visible than leadership expects.
Personal devices used by employees, volunteers or contractors are treated as automatically out of scope even though they access organisational data or services.
Written controls describe the intended position, but settings, inventories, records and working practice tell a different story.
How we can work together
Establish the assessment boundary, discover the complete in-scope estate and compare it against the applicable Cyber Essentials requirements.
Move from findings into practical changes across identity, devices, configurations and working practices.
Keep the controls visible between assessments rather than rebuilding the evidence once a year.
The process
Start with the whole organisation or define a well-defined and separately managed subset with a clear business unit, network boundary and physical location. Record and justify any infrastructure outside that boundary and agree the scope with the Certification Body before assessment.
Identify the users, end-user devices, networks, software, organisational accounts and cloud services that store, process or provide access to organisational data or services. Cloud services remain in scope even where a provider operates the underlying platform.
Review configurations, access, updates and evidence against the current requirements. For IaaS, PaaS and SaaS, establish which controls the organisation implements and which are evidenced through contractual clauses or provider documents referenced by the contract.
Address automatic-failure risks and foundational gaps first, support accurate assessment responses, and leave control owners with the records and routines needed to maintain the controls after certification.
Why DumDum Digital
An MSP is usually responsible for managed infrastructure and support. A software vendor is responsible for its own product. An agency is usually responsible for a defined creative or development brief.
DumDum Digital works in the gap between them: understanding the whole operational system, challenging assumptions and suppliers, making defensible technical decisions, and remaining involved through delivery.
Supporting insights
Cyber Essentials · Volunteer BYOD
Volunteer-owned devices enter scope when they access charity systems. Danzell makes that harder to evidence and leaves charities with four viable postures.
Read: When volunteer phones enter Cyber Essentials scopeCyber Essentials · Scope and definitions
The requirements define organisational data broadly, but the question set applies a narrower test. Charities and volunteers sit directly in the gap.
Read: The flaw in Cyber Essentials scopeCommon questions
No. Certification is issued through an IASME-licensed Certification Body. DumDum Digital provides independent readiness, remediation and implementation support before and around that assessment.
No responsible readiness provider can guarantee an assessment result. The work is designed to identify gaps early, implement justified fixes and make the organisation’s answers evidence-based. The Certification Body remains responsible for the assessment decision.
Cyber Essentials is a verified self-assessment. Cyber Essentials Plus applies the same control requirements but adds an independent technical audit by an approved assessor. Readiness can be planned with either destination in mind, but the external assessment remains separate.
No. If organisational data or services are hosted on a cloud service, that service must be in scope. This applies to IaaS, PaaS and SaaS. The provider may implement some controls, but the applicant remains responsible for ensuring every applicable control is met. Where the provider performs a control, its commitment must be supported by contractual clauses or documents referenced by the contract, such as an applicable security statement.
Cyber Essentials can cover a well-defined and separately managed subset where necessary, but the boundary must identify the business unit, network boundary and physical location and must be agreed with the Certification Body. Excluded infrastructure must be justified and segregated. Cloud services used to host data or services for the in-scope subset still cannot be excluded.
Employee, volunteer and trustee-owned devices that access organisational data or services are normally in scope. The limited exception is a mobile or remote device used only for native voice, native text or an MFA application. Readiness work must follow what the device actually accesses rather than labelling all personal devices as out of scope.
Unsupported in-scope software or devices cannot be solved with wording. The realistic options may include upgrading, replacement, removing access or properly segregating the legacy environment. Readiness work makes that decision visible early enough to plan it.
Start with the pressure, not the specification
Describe what is happening in operational terms. We can work out whether the next step is an audit, a defined project or ongoing ownership.
Start a conversation