Local

Why more Nottinghamshire tenders are asking for Cyber Essentials

By James 4 min read

Why more Nottinghamshire tenders are asking for Cyber Essentials

Cyber Essentials has been mandatory for central government contracts involving sensitive information since 2014. What has changed more recently, and what local businesses are noticing, is how often it now appears in places it was never required: private sector supplier questionnaires, framework applications, and professional indemnity insurance renewals.

The mechanism is straightforward. Larger organisations are being pushed to assess their own supply chain risk, and asking suppliers for a recognised certification is the cheapest way to do it. Once one large local employer starts asking, the requirement propagates down through everyone who supplies them.

For a Nottinghamshire small business, the practical effect is that certification stops being a nice-to-have and becomes a condition of bidding for a specific piece of work, usually at short notice, and usually with a deadline that does not accommodate three months of remediation.

That is the argument for doing the underlying work before anybody asks. The five controls Cyber Essentials checks: firewalls, secure configuration, user access control, malware protection and patching within 14 days, are worth having regardless. If you already meet them, certification is weeks rather than months, and it is a form-filling exercise rather than a project.

The businesses that struggle are the ones starting from scratch under a tender deadline. The common blockers are the same every time: an unsupported operating system on one machine, multi-factor authentication applied to most accounts but not all, administrator accounts used for daily email, and personal phones in scope that have not received a security update in two years.

If you supply larger organisations, or you bid for public sector work, the sensible move is a gap analysis now rather than a scramble later. It converts an unknown into a list, and the list is usually shorter than people fear.

What surprises most businesses is how tight the timescales are. A supplier questionnaire typically arrives with a return date measured in weeks, and if certification is a condition rather than a preference, three months of remediation is not an option you have.

The other thing worth knowing is that the certificate is dated and increasingly checked. Holding one from two years ago answers the question badly, and renewals are only quick if the underlying controls have been maintained rather than reassembled annually. That is the argument for treating the five controls as part of ordinary IT support rather than as a yearly compliance exercise.

If you supply larger organisations locally and have not been asked yet, the sensible assumption is that you will be. A gap analysis costs very little, converts an unknown into a list, and means that when the questionnaire does arrive you are filling in a form rather than starting a project.

Talk to us about IT support or a project

Tell us what is going on and we will tell you straight whether we can help, what it would cost, and how quickly we can be there. No hard sell.

Monday to Friday, 9am to 5:30pm