Professional Services Harrogate, with fully remote staff 22 employees, fully remote 4 weeks to certification

Distributed consultancy achieves Cyber Essentials with a fully remote, BYOD workforce

A 22-person fully remote consultancy achieved Cyber Essentials certification in four weeks on a bring-your-own-device estate, bringing all 22 personal devices into compliance with no spend on replacement hardware.

A public sector framework required Cyber Essentials certification. With no office, no domain and consultants using their own laptops, the firm had been told by two providers that certification was not achievable without buying company hardware.

Client: 22-person management consultancy. Name withheld under our confidentiality terms.

At a glance

Client
22-person management consultancy
Sector
Professional Services
Location
Harrogate, with fully remote staff
Size
22 employees, fully remote
Services
Cyber Essentials, Cyber Security Assessment, Cyber Shield
Timeline
4 weeks to certification
Headline result
4 weeks — From first call to certification

Measured results

From first call to certification
4 weeksFrom first call to certification
Spent on replacement hardware
£0Spent on replacement hardware
Personal devices brought into compliance
22/22Personal devices brought into compliance
First-time pass
100%First-time pass

The challenge

  • A public sector framework application required current Cyber Essentials certification.
  • Every consultant worked from a personally owned laptop with no central management.
  • No office network, no server and no traditional IT infrastructure to certify.
  • Home routers and personal devices sat within assessment scope under BYOD rules.

What we did

  1. 1

    Mapped what was genuinely in scope: any device accessing organisational data, including personally owned laptops.

  2. 2

    Deployed a lightweight mobile device management profile covering only work data, leaving personal data untouched.

  3. 3

    Enforced disk encryption, automatic updates, screen lock and supported operating system versions through policy.

  4. 4

    Enforced MFA on Microsoft 365 and separated administrative accounts from day-to-day accounts.

  5. 5

    Documented the BYOD policy and acceptable use terms required as evidence.

  6. 6

    Completed the self-assessment and enrolled staff in monthly awareness training to hold the standard.

The outcome

  • The framework application proceeded with certification in place.
  • BYOD working continued, with a documented and enforceable policy behind it.
  • Work data can be wiped from a personal device on leaving, without touching personal files.
  • Annual recertification is now a maintenance task rather than a project.
Two other providers told us we would have to buy twenty-two laptops. We did not buy any.
Founding Director, management consultancy

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

Can you get Cyber Essentials with bring-your-own-device working?

+

Yes. BYOD is explicitly addressed in the Cyber Essentials scheme rather than excluded by it. Any personally owned device used to access organisational data or services is in scope and must meet the five controls: supported operating system, automatic updates, malware protection, screen lock and appropriate access control. Home routers supplied by an ISP are generally out of scope where the device itself has a properly configured software firewall. The practical requirement is being able to demonstrate and evidence those controls on each device, which is what lightweight device management provides without taking over a personal machine.

Does device management on a personal laptop give the employer access to personal data?

+

Not under the configuration used here. The profile applied is scoped to work data and device posture only: it confirms disk encryption is on, the operating system is supported and updating, malware protection is active and a screen lock is set. It does not grant visibility of personal files, browsing history, photos or personal applications. When someone leaves, the employer can remove work data and revoke access without wiping the device. Setting that boundary out clearly in the BYOD policy, and telling staff exactly what is and is not visible, is what makes rollout straightforward.

How quickly can a small remote business get certified?

+

Four weeks was realistic for 22 people with no legacy infrastructure to remediate, and small remote businesses often certify faster than larger ones with servers and legacy systems. The timeline breaks down as roughly one week for the gap assessment and scoping, two weeks to deploy device policies and gather evidence, and one week for submission and assessor queries. The most common cause of delay is discovering an unsupported operating system version or an application requiring local administrator rights. Where certification is tied to a tender deadline, we start with the gap assessment so the real timeline is known immediately.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way