← Home

Cyber security · Cyber Essentials

Cyber Essentials should describe how you work - not just how you answered the assessment.

DumDum Digital helps UK organisations identify the complete estate covered by Cyber Essentials and implement the controls across their real devices, accounts and cloud services - then prepare for assessment without relying on optimistic answers, invisible SaaS or a last-minute policy exercise.

The outcome

A defensible scope, working controls and an assessment the organisation can answer honestly.

Readiness work connects the five Cyber Essentials control areas to the organisation’s actual estate. That includes every cloud service hosting organisational data or services, even where the provider implements some of the controls. Gaps are identified before submission, remediation is prioritised, and ownership and evidence are left clear enough to support certification and continued compliance.

Who it is for

UK SMEs and charities that need certification to reflect operational reality.

This support is for organisations using a mixture of cloud services, laptops, mobile devices, remote working, external IT support and - in some cases - volunteer or contractor access. The estate is often more complicated than the original policy or asset list suggests, particularly where teams have adopted SaaS products using organisational accounts or business email addresses.

The organisation may already have an MSP, antivirus, MFA and written policies. The difficult part is establishing the assessment boundary, discovering everything inside it, and proving that the applicable controls are met. Cloud services which host organisational data or services cannot be excluded; the shared-responsibility model only determines whether the organisation or provider implements each control.

Cyber Essentials should normally cover the whole IT infrastructure used to carry out the organisation’s business. Where a partial scope is genuinely necessary, it must be a well-defined and separately managed subset, agreed with the Certification Body. It’s not a way to remove inconvenient devices, services or users from an otherwise connected estate.

Readiness support is useful before opening an assessment, after an unsuccessful attempt, during a wider identity or device-management project, or when a previous certificate no longer gives leadership confidence in the underlying controls.

Recognisable problems

Certification usually exposes ownership gaps before it exposes product gaps.

01

Incomplete estate discovery

Devices, accounts and cloud services are missing from the assessment evidence because nobody has mapped where organisational data is stored, processed or accessed.

02

Inconsistent authentication

MFA is enabled for some people and platforms while shared accounts, legacy access or avoidable exceptions remain elsewhere.

03

Unsupported or late-patched technology

Operating systems, applications, extensions, routers or firmware are not consistently supported and updated within the required timescales.

04

Uncontrolled privilege

Everyday accounts have administrative access, former users remain active, or supplier access is broader and less visible than leadership expects.

05

BYOD and volunteer blind spots

Personal devices used by employees, volunteers or contractors are treated as automatically out of scope even though they access organisational data or services.

06

Policy without evidence

Written controls describe the intended position, but settings, inventories, records and working practice tell a different story.

How we can work together

Start at the point between uncertainty and certification.

01

Readiness review

Establish the assessment boundary, discover the complete in-scope estate and compare it against the applicable Cyber Essentials requirements.

  • Whole-organisation or segregated subset boundary
  • Device, account and cloud-service inventory
  • Control-by-control gap analysis
  • Prioritised remediation plan
02

Readiness and remediation

Move from findings into practical changes across identity, devices, configurations and working practices.

  • MFA and access-control remediation
  • Secure configuration and update processes
  • Asset, software and account records
  • Evidence and assessment preparation
03

Control maintenance

Keep the controls visible between assessments rather than rebuilding the evidence once a year.

  • Ownership and review schedule
  • Joiner, mover and leaver controls
  • Update and exception monitoring
  • Recertification preparation

The process

Define the boundary. Discover the estate. Verify the controls. Fix the gaps.

  1. 01

    Define the assessment boundary

    Start with the whole organisation or define a well-defined and separately managed subset with a clear business unit, network boundary and physical location. Record and justify any infrastructure outside that boundary and agree the scope with the Certification Body before assessment.

  2. 02

    Discover everything inside it

    Identify the users, end-user devices, networks, software, organisational accounts and cloud services that store, process or provide access to organisational data or services. Cloud services remain in scope even where a provider operates the underlying platform.

  3. 03

    Verify responsibility and controls

    Review configurations, access, updates and evidence against the current requirements. For IaaS, PaaS and SaaS, establish which controls the organisation implements and which are evidenced through contractual clauses or provider documents referenced by the contract.

  4. 04

    Remediate and prepare

    Address automatic-failure risks and foundational gaps first, support accurate assessment responses, and leave control owners with the records and routines needed to maintain the controls after certification.

Why DumDum Digital

Independent of the product, but close enough to deliver.

An MSP is usually responsible for managed infrastructure and support. A software vendor is responsible for its own product. An agency is usually responsible for a defined creative or development brief.

DumDum Digital works in the gap between them: understanding the whole operational system, challenging assumptions and suppliers, making defensible technical decisions, and remaining involved through delivery.

Supporting insights

Explore the thinking behind the work.

Cyber Essentials · Volunteer BYOD

When volunteer phones enter Cyber Essentials scope

Volunteer-owned devices enter scope when they access charity systems. Danzell makes that harder to evidence and leaves charities with four viable postures.

Read: When volunteer phones enter Cyber Essentials scope

Cyber Essentials · Scope and definitions

The flaw in Cyber Essentials scope

The requirements define organisational data broadly, but the question set applies a narrower test. Charities and volunteers sit directly in the gap.

Read: The flaw in Cyber Essentials scope

Common questions

What organisations usually want to know first.

Does DumDum Digital issue the Cyber Essentials certificate?

No. Certification is issued through an IASME-licensed Certification Body. DumDum Digital provides independent readiness, remediation and implementation support before and around that assessment.

Can you guarantee that we will pass?

No responsible readiness provider can guarantee an assessment result. The work is designed to identify gaps early, implement justified fixes and make the organisation’s answers evidence-based. The Certification Body remains responsible for the assessment decision.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus applies the same control requirements but adds an independent technical audit by an approved assessor. Readiness can be planned with either destination in mind, but the external assessment remains separate.

Can we exclude cloud services that are managed by the provider?

No. If organisational data or services are hosted on a cloud service, that service must be in scope. This applies to IaaS, PaaS and SaaS. The provider may implement some controls, but the applicant remains responsible for ensuring every applicable control is met. Where the provider performs a control, its commitment must be supported by contractual clauses or documents referenced by the contract, such as an applicable security statement.

Can we certify only part of the organisation?

Cyber Essentials can cover a well-defined and separately managed subset where necessary, but the boundary must identify the business unit, network boundary and physical location and must be agreed with the Certification Body. Excluded infrastructure must be justified and segregated. Cloud services used to host data or services for the in-scope subset still cannot be excluded.

What about personal devices used by staff or volunteers?

Employee, volunteer and trustee-owned devices that access organisational data or services are normally in scope. The limited exception is a mobile or remote device used only for native voice, native text or an MFA application. Readiness work must follow what the device actually accesses rather than labelling all personal devices as out of scope.

What if we still rely on unsupported technology?

Unsupported in-scope software or devices cannot be solved with wording. The realistic options may include upgrading, replacement, removing access or properly segregating the legacy environment. Readiness work makes that decision visible early enough to plan it.

Start with the pressure, not the specification

What is becoming difficult, risky or frustrating?

Describe what is happening in operational terms. We can work out whether the next step is an audit, a defined project or ongoing ownership.

Start a conversation