Manufacturing Leeds, West Yorkshire 78 employees, 3 sites 6 weeks from kick-off to certification

Leeds manufacturer passes Cyber Essentials Plus first time to win a supply-chain contract

A 78-staff precision manufacturer in Leeds achieved Cyber Essentials Plus certification first time in six weeks, reaching 98% patch compliance within 14 days with no production downtime, and retained a supply-chain contract that required the certification.

A tier-two automotive supplier was told by its largest customer that Cyber Essentials Plus would become a condition of contract renewal within one quarter. An earlier self-assessment attempt had stalled on unsupported operating systems and inconsistent patching across the shop floor.

Client: 78-staff precision manufacturer. Name withheld under our confidentiality terms.

At a glance

Client
78-staff precision manufacturer
Sector
Manufacturing
Location
Leeds, West Yorkshire
Size
78 employees, 3 sites
Services
Cyber Essentials Plus, Vulnerability Management, EDR
Timeline
6 weeks from kick-off to certification
Headline result
100% — First-time pass at Cyber Essentials Plus

Measured results

First-time pass at Cyber Essentials Plus
100%First-time pass at Cyber Essentials Plus
From kick-off to certificate
6 weeksFrom kick-off to certificate
Patch compliance within 14 days, sustained
98%Patch compliance within 14 days, sustained
Production downtime during remediation
0Production downtime during remediation

The challenge

  • Contract worth a significant share of annual revenue was conditional on Cyber Essentials Plus certification.
  • Eleven shop-floor PCs ran an unsupported operating system tied to machine control software.
  • No central patching: workstations were updated ad hoc by a part-time IT contractor.
  • Local administrator rights were shared across production staff, failing user access control.

What we did

  1. 1

    Ran a gap assessment against the five Cyber Essentials controls and produced a costed remediation plan in week one.

  2. 2

    Segmented the eleven legacy machine-control PCs onto an isolated VLAN with no internet access, taking them out of scope in line with IASME guidance.

  3. 3

    Deployed managed patching across all in-scope endpoints and servers, with monthly compliance reporting.

  4. 4

    Removed standing local admin rights and replaced them with a request-based elevation process.

  5. 5

    Rolled out EDR with 24/7 SOC monitoring across every in-scope device.

  6. 6

    Compiled the evidence pack, submitted the self-assessment, and hosted the external Plus audit.

The outcome

  • The supply-chain contract was renewed on schedule.
  • Legacy machine-control systems stayed in production without blocking certification.
  • Patching moved from ad hoc to a measured monthly cycle with reporting the board can read.
  • Cyber insurance renewal completed at a lower premium the following year.
The customer deadline was not negotiable. Having someone scope it properly, tell us what was actually in scope, and then run the audit for us was the difference between renewing and not.
Operations Director, precision manufacturer, Leeds

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

How long does Cyber Essentials Plus take for a manufacturer with legacy equipment?

+

For this engagement it took six weeks from kick-off to certificate, including remediation. Legacy machine-control systems are the usual cause of delay, because unsupported operating systems cannot pass the malware protection and patch management controls. The practical route is nearly always network segmentation: the legacy device is placed on an isolated network with no internet access and no route to corporate systems, which removes it from assessment scope while keeping the machine in production. Where segmentation is not possible, the alternative is replacement or a supported upgrade, which lengthens the project. A gap assessment in week one is what makes a six-week timeline realistic rather than optimistic.

Does removing local administrator rights disrupt production staff?

+

It did not here, because the change was paired with a request-based elevation process rather than a flat removal. Production staff rarely need standing administrator rights; they need a small number of specific actions, such as installing an approved tool or changing a printer setting. We logged which elevated actions were actually used over a two-week baseline, allowed those by policy, and routed anything else through a request that IT approves within the working day. Standing local admin rights are one of the most common Cyber Essentials failures and one of the most effective ransomware controls to remove, so it is worth doing properly.

What does Cyber Essentials Plus cost a business of this size?

+

Cost has two parts: the certification body fee, which scales with the size and complexity of your estate, and the remediation work needed to pass. For a 78-staff manufacturer across three sites the audit fee sat in the low four figures, and the larger cost was the managed patching and endpoint protection introduced to meet the controls — services this business needed regardless of certification. Businesses that already run centrally managed patching, EDR and MFA typically pay little beyond the audit fee. We quote both parts separately after a gap assessment, so there is no open-ended remediation bill.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way