Share this article
Sometimes in business, simply doing the right thing isn’t enough; there are times an organisation needs to prove its credentials to the world. This is certainly the case when it comes to showcasing an ability to protect sensitive and personal data in modern business – because having the right credentials proves to other organisations that you can be trusted. Nothing gives customers or other stakeholders more confidence than a tangible demonstration that your business takes cyber security seriously by undertaking a recognised cyber security standard.
In the UK, Cyber Essentials is roughly the data security equivalent of a full clean driving licence and ISO 27001 certification is proof of an advanced and defensive driving qualification. Depending on your business, one or both may be appropriate. So, let’s take a closer look at Cyber Essentials vs ISO 27001.
Of course, it is not just about providing reassurance to customers and business partners that their data is secure with you. That is an added benefit to the prime purpose which is to provide a framework for organisations to build proactive cyber security measures into their organisational management to provide the best possible security for all the sensitive and personal data held.
Because the reality is that no one is safe. Although we all too frequently see news stories about data breaches, some may feel detached from the reality because the reports are of high-profile breaches affecting large international companies. Surely criminal masterminds are focusing on these high value targets rather than comparably smaller opportunities? But the reality is that few criminal masterminds or state-sponsored hackers expend their intellectual energy on vast corporations. The majority find it more energy-efficient to cast their net as wide as possible using strategies like phishing emails or network scans to identify and attack poorly protected targets.
Although we may have had the wake-up call of our lives with the Covid pandemic proving that events can overtake without warning, it appears that there are still a lot of businesses still dangerously under-prepared when it comes to cybersecurity. The latest Government statistics reveal that currently only 23% of businesses have cyber security policies which cover home offices and only 31% of businesses have business continuity plan that specifically cover cyber security.
This is the baseline UK Government-initiated standard which, through its five key requirements, provides clear guidance and a good level of security. If your business wants to compete for any UK Government contract, you must have Cyber Essentials certification, although it is equally relevant to other suppliers, customers and third parties. Essential elements include firewalls, secure configuration, access control, malware protection and the regular updating and patching of devices software and operating systems. It is a comparatively low-cost option which is suitable for many businesses.
Cyber Essential Plus provides a higher level of assurance as it is verified by an external independent assessor.
ISO27001 is an internationally recognised standard which aims to protect all information regardless of where it is found, including paper. It is more costly to achieve than Cyber Essentials and is significantly more rigorous in its requirements. There are ten clauses and 114 generic security controls grouped in 14 sections to adhere to and it takes time, investment and diligence to achieve. So why undertake such a challenge? What are the benefits of investing in this information security management system?
Organisations holding the ISO 27001 certification benefit from best practice across all areas of information security and the standard facilitates building data security into the core of all business processes. With requirements for regular penetration testing and business continuity planning, it provides an infinitely more robust defence against all types of breach and a well-planned strategy to minimise the impact of any attack. An experienced SRM ISO 27001 consultant can guide your through all aspects of preparing for accreditation – turning a daunting task into something more more accessible.
Factors such as the size of the organisation, the nature of the business and the amount of data processed will help to determine which is the best option for any business. In some instances, where both are required, Cyber Essentials can be the first step as the basic level upon which to build the more complex ISO 27001.
Steering through certification processes can be time-consuming and complex. Professional input from experienced consultants specialising in Cyber Essentials and ISO 27001 certification will guide you as to the best approach and will provide support and guidance to in-house CISOs or those with responsibility for data security. Whichever standard you follow, detailed guidance and practical support can be provided by the consultancy in a cost-effective manner. That is because scoping the project accurately at the outset means time and resource is never wasted on unnecessary steps, services or tools.
Looking to improve and prove your information security credentials. Get in touch with our team today. Contact us.