Cyber Essentials: A Good Start, But Is It Enough?

If you work in legal, accountancy, or financial services, the chances are you've either achieved Cyber Essentials certification, are working towards it, or have been asked about it by a client or regulator. But does it amount to true protection? This article explores the scope of Cyber Essentials, what it covers, and the elements of cyber safety it is not designed to address.

Share this post

Cyber Essentials is the UK government’s baseline standard for cyber security. Introduced in 2014, its adoption by UK businesses continues to become more widespread in response to the growing threat of cyber crime. If you work in legal, accountancy, or financial services, the chances are you’ve either achieved Cyber Essentials certification, are working towards it, or have been asked about it by a client or regulator.  

Organisations frequently ask Mitigo: “We’ve got Cyber Essentials, are we covered?” 

The honest answer is no. Not fully. Understanding why this is the case is vital for professional services firms. 

We discussed this in depth during a recent episode of our Cyber Uncovered webinar series, hosted by Mitigo’s Head of Business Development, Kerrie Machin, and Head of Service Delivery, Tristan Hodgson.  

As Kerrie explained, “If you haven’t done anything when it comes to looking at your cyber risk management, we certainly think you should start there. But if you’re thinking that once you’ve got Cyber Essentials, you’re fully covered, unfortunately that is a misconception…you are highly likely to have undiscovered risks that sit outside of the scope of Cyber Essentials”. 

Cyber Essentials vs Cyber Essentials Plus 

Cyber Essentials is a government-backed scheme, overseen by the NCSC and administered by IASME. Its purpose has never changed: setting a minimum standard of cyber security for organisations of all sizes, particularly SMEs. 

The scheme is built around five technical controls: 

  • Firewalls – managing the boundaries between your devices and the internet. 
  • Secure configuration – setting up devices appropriately to minimise risk. 
  • Patch management – keeping operating systems and software up to date. 
  • User access control – restricting who can access specific data and services. 
  • Malware protection – preventing malicious software from running on devices. 

There are two levels to the scheme: Cyber Essentials Basic is a self-assessed questionnaire, reviewed by an accredited auditor. Cyber Essentials Plus involves a hands-on technical assessment to verify those controls are in place and working as intended. 

While both certifications are worth having, neither represents comprehensive cyber resilience. 

What’s changed in 2026 

The scheme undergoes regular amendments to keep in line with the changing cyber security landscape. The previous iteration (known as Willow) has been replaced by Danzell, effective April 2026. 

As with most updates to the scheme, it has been an evolution not a revolution, and the practical impact for most firms is limited to two areas: 

1. MFA on cloud services is now mandatory. The requirement to have multi-factor authentication on all cloud services – including software-as-a-service tools – has existed for several years, but failure to implement this was considered a non-compliance. That is no longer the case, with MFA now considered an automatic failure for both admins and standard users if absent. 

2. Patching within 14 days is now a strict requirement. Critical and high-severity updates have always needed to be applied within 14 days, but as with cloud MFA this was always another non-compliance. This is now another strict requirement; applying these patches within 14 days of release is essential for certification. 

There is also a subtler change worth noting: A submission now commits the organisation not just to the accuracy of its answers on the day of submission, but to maintaining the Cyber Essentials standard going forward. Practically speaking, this changes little, but it signals a shift in expectation towards ongoing compliance rather than a point-in-time exercise. 

If you are an existing holder of Cyber Essentials that has always worked to meet all requirements in the past, these changes should not present a challenge. If you haven’t, now is the time to address it before your next renewal. 

A common misconception 

Achieving Cyber Essentials is a meaningful step. It demonstrates basic cyber hygiene and gives clients, existing and prospective, visible evidence that you take security seriously. Increasingly, it’s a minimum requirement for supply chain relationships and government contracts. 

However, Cyber Essentials is deliberately designed to be a one-size-fits-all baseline. It covers technical controls only – and only a defined subset of them. That means a myriad of risks exist outside the scope of Cyber Essentials. For professional services firms, those gaps not only carry regulatory and legal weight, but also leave the door ajar to cyber criminals.  

Consider what Cyber Essentials does not cover: 

  • People and behaviour. Around 85% of cyber crime involves a human being doing something they shouldn’t. This could include clicking a phishing link, sharing credentials, or bypassing a process. Technical controls do not effectively prevent this. Security awareness training and simulated phishing exercises do, as part of a wider cyber risk management strategy, but that sits entirely outside the Cyber Essentials framework. 
  • Policy and governance. Cyber Essentials does not assess policies that govern how staff handle data, what they can and can’t do on company systems, and how incidents are escalated. Yet under UK GDPR, you are legally required to have these things in place. 
  • Supply chain management. Threat actors increasingly target organisations through their suppliers and technology vendors – those with access to your systems or data. The infamous 2025 cyber attacks on Marks & Spencer, The Co-Operative and Jaguar Land Rover demonstrate this perfectly. Despite the threat it poses, Cyber Essentials says nothing about how you assess and manage supply chain risk. 
  • Incident response. With 43% of businesses experiencing cyber crime each year, there is an increasing need for firms to consider what they are going to do when they are attacked, rather than if. Effective cyber risk management requires a strong, tested incident response plan. This is something around 75% of businesses do not have, according to Government data, and cannot be provided through Cyber Essentials. 
  • Independent oversight. Many firms rely solely on their IT provider’s assurance that they are cyber secure. But IT providers are marking their own homework and cannot provide an objective assessment. Independent cyber risk assurance – a third-party expert looking across the whole business, not just the technical layer – represents a far greater scope of cyber risk management, not remotely covered by Cyber Essentials.   
  • Operational Resilience. Data backups, disaster recovery and business continuity planning are all critical factors in ensuring a strong and resilient business in the face of increasing cyber crime, and none of these topics make up the requirements of Cyber Essentials. The scheme does promote good practices and offers guidance on getting set up, but does not include it in the assessment. 

Regulator expectations 

For firms in legal, accountancy, and financial services, the bar is higher than Cyber Essentials alone. 

The ICO has made this explicit, particularly in the case of Tuckers Solicitors – a law firm that suffered a ransomware attack in 2021. The ICO stated in its judgment that, given the nature of the firm’s data, “their security should have not only met but surpassed the basic requirements of Cyber Essentials”. This, effectively, was a prominent regulator telling a professional services firm that Cyber Essentials, on its own, was not enough. As highlighted in our Cyber Uncovered webinar: 

“If you’re a professional services firm relying solely on Cyber Essentials, with no cyber risk management assurance beyond that scope, then your strategy needs to be revisited”. 

Moreover, UK GDPR requires you to carry out a risk assessment of the data you hold, implement controls across people, technology, and governance, and continually test and evidence the effectiveness of those controls. Cyber Essentials only addresses some of this. 

The government’s Cyber Governance Code of Practice, published in 2025, goes further. Board-level accountability, documented risk assessments, incident response plans, and independent assurance are all outlined as important for cyber safety – reflecting the growing scope of regulatory expectation. 

Building on the foundation 

None of this means Cyber Essentials isn’t worth doing. It absolutely is, but it should be treated as the starting point it was designed to be. 

If you’ve got Cyber Essentials and you’re asking what comes next, the answer starts with understanding your specific risk profile, beyond technical controls. That means looking at your people, your processes, your supply chain, and your governance alongside your IT. 

At Mitigo, we work with professional services firms to do exactly this – starting with an independent risk assessment that maps your current position against regulatory expectations and identifies the gaps that need attention. The end result is a cyber risk management strategy that provides effective, comprehensive protection against cyber threats.  

Cyber Essentials is a solid foundation, but one that must be built upon. For true cyber safety, it must be treated as the beginning of a journey, not the destination. 

To find out more about how Mitigo can help your firm move beyond Cyber Essentials, contact us today. 

The full webinar is also available to watch on demand: https://www.youtube.com/watch?v=2O1Z2OSULGo

Would you like to speak to Mitigo?

Please complete your details and we will contact you to discuss your needs.

Share this post