
Cyber Essentials vs Cyber Essentials Plus: which one do you need?
A clear side-by-side comparison of scope, evidence and cost — and how to pick the right level.
Blog
The cyber security blog for UK, BVI and USA SMEs — straight answers on Cyber Essentials, phishing, ransomware, MDR and cyber insurance, written by the engineers who run our 24/7 UK SOC. No vendor fluff, no scare tactics.

A plain-English explainer of the UK's baseline cyber security certification — what it covers, who needs it, and how to know if it's right for your business.
Read articleCertification, costs and what UK SMEs need to pass.

A clear side-by-side comparison of scope, evidence and cost — and how to pick the right level.

What the certification actually covers, who needs it and how to prepare without the jargon.

Certification fees, hidden remediation costs and what UK SMEs typically pay end-to-end.

The recurring gaps assessors flag — patching, MFA, admin accounts — and quick fixes.
Stop modern phishing with simulation and awareness training.

A non-technical walkthrough of how modern phishing lands in UK business inboxes, with real anonymised examples — and what stops them.

What phishing looks like in 2026, why filters miss it and the signals to train your team on.

Annotated examples of recent attacks targeting UK SMEs — invoices, MFA prompts, supplier spoofs.

Practical steps combining email controls, MFA, training and simulations — week by week.
Prevent, contain and recover from ransomware attacks.

The controls that actually stop modern ransomware attacks in UK SMEs — explained in plain English, in priority order.

How modern ransomware works, why it targets smaller businesses and what an attack actually looks like.

The controls that stop most attacks — MFA, EDR, backups, segmentation — explained for non-IT leaders.

What to do, who to call and what not to touch in the first day of a ransomware incident.
Budget, priorities and risk for UK small businesses.

A pragmatic 5-step roadmap for businesses with no dedicated security team.

Benchmarks, typical line items and how to build a defensible budget for the board.

Where attacks are actually landing — and the controls that meaningfully reduce risk.

MFA, EDR, backups and training — the controls quietly becoming mandatory at renewal.
Endpoint protection and 24/7 managed detection.

Tooling vs service, in-house vs outsourced — a clear comparison for UK SME decision makers.

Why traditional antivirus no longer cuts it — and when EDR becomes essential.

A walkthrough of a live MDR investigation, from first alert to contained threat.
Two ways to get started
Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.