Skip to main content
  • Media centre
  • Careers
  • Contact us
Select country and language
  • Hong Kong SAR
Other useful links
  • Media centre
  • Careers
  • Contact us
BSI

Making excellence a habit

Menu
  • Search BSI
  • Verify a certificate
Close Close button

Buy standards

Standards

Go to shopBSI Knowledge

See all related standards BSI Knowledge

Popular searches

  • ISO 27001 Information Security
  • ISO 14001 Environmental Management
  • ISO 9001 Quality Management
  • ISO 45001 Occupational Health and Safety Management
  • ISO 14064 Greenhouse Gas Verification

Suggestions

View all search results
  • Standards eg. ISO 9001
    Standards
    ... X

    Popular

    • Quality management >
      ISO 9001
    • Quality management for medical devices >
      ISO 13485
    • Environmental management >
      ISO 14001
    • Food safety management >
      ISO 22000
    • Business continuity >
      ISO 22301
    • Information security >
      ISO/IEC 27001
    • Occupational health and safety >
      ISO 45001 (OHSAS 18001)
    View all standards >

    Access and buy standards

    • How to access and buy >
    • Buy standards >
    • Standards subscriptions >
    • BSOL >
      Full standards collections
    • Compliance Navigatior  >
      Medical device standards

    About standards

    • What are standards? >
    • Get involved >
      Become a standards maker, join a committee
    • Have your say >
      Propose or comment on a standard
  • Services
    Services
    ... X

    Standards and information

    • Access and buy standards >
    • Develop a standard >
    • Online subscription services >
      BSOL, Compliance Navigator, Eurocodes PLUS, and BSI Membership

    Auditing, certification and training

    • Assessment, ISO certification and others: IATF, FSSC... >
    • Auditing and verification >
    • Product testing and certification >
      BSI Kitemark, CE marking and verification, Market access solutions
    • Validate BSI-issued certificates >

    • Training courses >
    • Medical devices services >
    • BSI Connect >
      Software tools and solutions for audit, risk, compliance and supply chain management
  • Sectors
    Sectors
    ... X
    • Built environment >
    • Government >
    • Manufacturing >
    • Energy >
    • Healthcare >
    • Transport and mobility >
    • Food and retail >
    • ICT >
  • Topics
    Topics
    ... X

    Industry reports, research and news

    • COVID-19 >
    • Digital construction >
      BIM, smart cities and connected assets
    • Future of mobility >
    • Global market access >
    • Health, safety and well-being >
    • Information security >
      Cybersecurity, privacy (GDPR) and compliance

    • Innovation >
    • Internet of things (IoT) >
    • Organizational resilience >
    • Sustainability >
    •    - Circular economy >
    •    - Net zero >
    View all topics >

    Blogs

    • Built environment >
    • Digital trust >
    • Food industry >
    • Healthcare >
    • View all blogs >
  • About
    About
    ... X
    • About BSI >
    • BSI impartiality >
    • Our accreditation >
    • Our clients and partners >
    • Our financial information >
    • Our governance >
    • Our legal information >
    • Our purpose, mission and vision >
    • Our Royal Charter >
    • UK National Standards body >
    • The global role of BSI as the national standards body >
    • Careers >
    • Events and webinars >
    • Media centre/press room >
    • Sustainability >
      Modern slavery statement
    • Contact us >
  • Media centre
  • Careers
  • Contact us
Select country and language
  • Hong Kong SAR
Other useful links
  • Media centre
  • Careers
  • Contact us
GO
Contact us
Contact us
  • Country Selector

Cyber Essentials can help to prevent 80% of cyber attacks

According to the UK Government, around 80% of cyber-attacks could be prevented if businesses put simple cyber security controls in place. However, not all organisations are getting these basics right. Only 58% have assessed themselves against the governments "10 Steps" cyber security guidance and only 30% of boards receive regular cyber security intelligence*.

The Cyber Essentials scheme is a key deliverable of the UK’s National Cyber Security Programme. Realising that the controls in the 10 Steps to Cyber Security were not being implemented effectively, and that no existing, individual standard met its specific requirement, the government developed the Cyber Essentials scheme. This scheme focuses on 5 key areas:

  • Secure Configuration
    Implementing security measures when building and installing computers and network devices to reduce unnecessary vulnerabilities
  • Boundary Firewalls and Internet Gateways
    Providing a basic level of protection where an organisation connects to the Internet.
  • Access Control and Administrative Privilege Management
    Protecting user accounts and helping prevent misuse of privileged accounts.
  • Patch Management
    Keeping the software used on computers and network devices up to date and resisting low-level cyber attacks
  • Malware Protection
    Protecting against a broad range of malware (including computer viruses, worms, spyware, botnet software and ransomware), including options for malware removal, which will protect your computer, your privacy and your important documents from attack.

*Department for Business and Innovation Skills Cyber Governance Health Check Jan 2015.

BSI Cyber Essentials >

Cyber resources

We have a wide range of resources available for you, including top tips, a free webinar, and a whitepaper.

View all Cyber resources

Cyber Essentials and Cyber Essentials Plus

The Cyber Essentials scheme requires the completion of a self-assessment questionnaire which you will be guided through in an intuitive online process to ensure your application is compliant. The application will then be formally assessed. On successful assessment, you will receive a Cyber Essentials certificate.

Cyber Essentials Plus requires the above assessment along with a technical audit performed by a regulated auditor. Again, you will be guided through a step-by-step checklist leading up to the audit which can be carried out remotely or on-site, to make the process as quick and straight-forward as possible.

Next steps

Contact us today to find out how we can support your business.


Cyber security top tips

Download our guide to reducing the risk of cyber-crime, for both consumers and businesses.

Download top tips (PDF) >

Government contracts

Crown Commercial Services

The Cyber Essentials scheme is mandatory for organisations handling personal information and providing certain ICT products and services to central government contracts. It is listed as a requirement to gain entry to many central government frameworks and has been mandated by the Crown Commercial Service since 2014.

 

MOD contracts and DEF STAN 05-138

Depending on the Risk level of a contract, the MOD can mandate certification to the Cyber Essentials scheme for the supplier.

MOD contracts are assigned one of five risk levels, which is determined on a per contract basis. These risk levels are: Not applicable, Very Low, Low, Moderate and High.

Only contracts with no MOD Identifiable Information can be classed as "Not applicable". Contracts that involve handling "Secret" or "Top Secret" information are expected to be classed as Moderate or High.

Not applicable – No certification requirements, but Cyber Essentials recommended as good practice

Very Low – Maintain Cyber Essentials certification

Low –Maintain Cyber Essentials Plus and 16 additional controls

Moderate – Cyber Essentials Plus, with thesame requirements as Low, but with 16 additional controls

High – Cyber Essentials Plus, with the same requirements as Moderate and Low, but with 12 additional controls

 

Full details of all of the controls can be found in DEF Stan 05-138 here.

How to turn potential cyber-attacks into opportunity

Our resident expert Stephen Porter recently wrote an article for the Telegraph. Cyber-terrorism has grown greatly over the last decade, but business continuity ensures that attacks do not affect operations...

Read more

BSI Shop

Buy copies of standards to assist with implementing Cyber Security in your business

ISO/IEC 27001 Information Security >
PAS 555:2013 Cyber security risk >
See all information security standards and books at the BSI Shop

Contact us

If there's any way we can help, please let us know

Call: +44 345 080 9000

Email us >
Contact us online >

Other areas you may be interested in

  • ISO 27001 Information security
  • CSA STAR Certification (cloud security)
  • Personal information management
  • ISO 22301 Business continuity
SHARE
Twitter Share Icon LinkedIn Share Icon Facebook Share Icon Email Share Icon
Linkedin Facebook Youtube Twitter
By Royal Charter
Find a Standard
  • ISO 9001 Quality Management
  • ISO 13485 Quality Management
  • ISO 14001 Environmental Management
  • ISO 22000 Food safety management
  • ISO 22301 Business continuity
  • ISO/IEC 27001 Information security
  • ISO 45001 Occupational Health and Safety
  • View all standards
Services
  • Access and buy standards
  • Develop a standard
  • Online subscription services
  • Assessment and ISO certification
  • Auditing and verification
  • Product testing and certification
  • Validate BSI-issued certificates
  • Training courses
  • Medical devices services
  • BSI Connect
  • View all services
Sectors
  • Built environment
  • Energy
  • Food and retail
  • Government
  • Healthcare
  • ICT
  • Manufacturing
  • Transport and mobility
Topics
  • Digital construction
  • Future of mobility
  • Global market access
  • Health and safety
  • Information security
  • Innovation
  • Internet of things (IoT)
  • Organizational Resilience
  • Sustainability
  •    - Circular economy
  • View all topics
About
  • About BSI
  • BSI impartiality
  • Our accreditation
  • Our clients and partners
  • Our financial information
  • Our governance
  • Our legal information
  • Our purpose, mission and vision
  • Our Royal Charter
  • UK National Standards body
  • The global role of BSI as the national standards body
  • Events and webinars
  • Sustainability
  • Modern Slavery Statement
Contact BSI +852 3149 3300
BSI Inspiring trust for a more resilient world.
Site Policy:
  • Privacy notice
  • Cookie policy
  • Terms of use
  • Accessibility
  • Site map

© The British Standards Institution (current year)

Impartiality is the governing principle of how BSI provides its services. Impartiality means acting fairly and equitably in its dealings with people and in all business operations. It means decisions are made free from any engagements of influences which could affect the objectivity of decision making.

As an accredited certification body, BSI Assurance cannot offer certification to clients where they have also received consultancy from another part of the BSI Group for the same management system. Likewise, we do not offer consultancy to clients when they also seek certification to the same management system.

The British Standards Institution (BSI, a company incorporated by Royal Charter), performs the National Standards Body (NSB) activity in the UK. BSI, together with its Group Companies, also offers a broad portfolio of business solutions other than NSB activity that help businesses worldwide to improve results through Standards-based best practice (such as certification, self-assessment tool, software, product testing, information products and training).