CYBER READY

Build trust, assurance and resilience.

Strengthen controls, organise evidence and improve your organisation’s ability to withstand disruption. Prepare for relevant assurance requirements with clear priorities and practical progress.

From £500/month + VAT

Assurance outcomes

Are the right protections in place, are they working, and can we prove it?

Clear answers about the services your business runs on and the commitments you make to customers.

01

Understand the starting point

Establish the risks, requirements and current controls that matter to your organisation. Identify gaps and prioritise improvements proportionate to the business and its obligations.

02

Strengthen controls and evidence

Clarify responsibilities and organise evidence of how controls operate. Prioritise gaps, agree who will carry out the work, track progress and verify evidence when actions are completed. Implementation is separately scoped.

03

Build resilience and prepare for assurance

Consider how the organisation will respond to disruption and restore important work. Prepare for the certification or assessment target included in your scope. Preparation does not guarantee certification or replace an assessor’s independent decision.

What you receive

A clear, honest record of where you stand

01
A scoped control and evidence record
Including where evidence is insufficient or a control has not yet been assessed.
02
Findings and a prioritised action plan
Exceptions and actions, each with an accountable owner and a named person to verify it.
03
An evidence pack and readiness view
For your agreed target framework, with any additional requirements identified.
04
Ongoing updates
On material changes, open actions and your readiness over time.
CONTROL RECORDILLUSTRATION
CONTROLOWNERSTATUS
MFA on remote accessIT leadPASS
Supplier access reviewsOperationsATTENTION
Legacy file server patchingIT leadEXCEPTION
Offsite backup restore testIT leadFAIL
Card-data segmentation–N/A
AI agent permissionsService ownerNOT ASSESSED
Supplier access reviewsATTENTION
EVIDENCE REVIEWED
Supplier account list and the last access review sign-off
FINDING
Two supplier accounts no longer in use are still active
NEXT ACTION
Confirm the accounts are no longer required, remove access and verify completion by the agreed deadline.
OWNER · VERIFIER
Operations · IT lead
DEADLINE
14 days from the finding
FICTIONAL SAMPLE DATA

Each finding is supported by evidence and a clear next action.

What the statuses mean
PASS
Evidence shows the control is in place and working.
ATTENTION
A finding or evidence gap needs action. The control is not yet confirmed as fully effective.
EXCEPTION
A known gap formally accepted by an accountable decision-maker, with a recorded reason and a date for review.
FAIL
Not in place or not working; remediation is needed.
N/A
Does not apply to your organisation or scope.
NOT ASSESSED
Not yet checked. Shown so nothing is assumed.
CERTIFICATION READINESS

Prepare for certification. Keep the evidence working afterwards.

Where certification is your goal, Cyber Ready prepares your organisation against the agreed requirements: identifying gaps, coordinating improvements and verifying the evidence, so you approach the external assessment with a clear view of your readiness.

Cyber Ready does not issue certification or guarantee an external assessment outcome. Certification and assessment decisions remain with the relevant external body.

  1. 01
    Scope the target
  2. 02
    Close gaps and verify readiness
  3. 03
    Support assessment and maintain assurance
Frameworks covered

One control and evidence approach. Multiple frameworks.

Cyber Ready reuses relevant evidence across supported frameworks and helps you prepare for the certification or assessment your business needs. The requirements and additional work depend on your agreed target and scope.

FRAMEWORK OR REQUIREMENTHOW CYBER READY SUPPORTS YOU
Cyber Essentials
HOW CYBER READY SUPPORTS YOU

UK technical baseline. Controls, evidence and gaps mapped to the scheme requirements.

External route

Prepares you for scheme certification. Cyber Ready does not award the certificate.

CIS Controls, including IG1
HOW CYBER READY SUPPORTS YOU

Operational security safeguards and prioritised cyber hygiene.

External route

Control alignment and assessment, not a CIS certification.

ISO/IEC 27001
HOW CYBER READY SUPPORTS YOU

Security controls and evidence supporting your agreed information security management system scope. We identify the additional management-system work needed for certification and agree how it will be completed.

External route

Certification is decided by an independent certification body.

ISO/IEC 27002
HOW CYBER READY SUPPORTS YOU

Security-control guidance supporting implementation and mapping.

External route

Guidance supporting alignment, not a separate organisational certification.

NCSC Cyber Assessment Framework (CAF)
HOW CYBER READY SUPPORTS YOU

Outcome-based assessment of governance, protection, detection and response and resilience.

External route

Prepares you for the applicable assessment. Cyber Ready does not issue a CAF certificate.

UK NIS Regulations
HOW CYBER READY SUPPORTS YOU

Relevant security and resilience obligations for in-scope organisations.

External route

Applicability and supporting evidence, not certification or blanket compliance.

EU NIS2 requirements
HOW CYBER READY SUPPORTS YOU

Applicable jurisdiction, sector and supply-chain requirements.

External route

Separate from UK NIS, and scoped against the relevant national implementation.

PCI DSS
HOW CYBER READY SUPPORTS YOU

Payment-security overlay for relevant card-data environments.

External route

Prepares you for the applicable validation route.

NHS Data Security and Protection Toolkit (DSPT)
HOW CYBER READY SUPPORTS YOU

Evidence and additional requirements relevant to your health or social-care organisation.

External route

Prepares you for the relevant toolkit submission and assurance route.

UK GDPR and Data Protection Act
HOW CYBER READY SUPPORTS YOU

Technical and organisational security evidence supporting your data-protection responsibilities.

External route

Privacy obligations also need information-governance work beyond security controls.

UK Cyber Governance Code of Practice
HOW CYBER READY SUPPORTS YOU

Leadership ownership of cyber risk, strategy, response and assurance.

External route

Governance alignment and evidence, not a certification scheme.

Ongoing assurance

Assurance that keeps up with your business

Onboarding sets the baseline. After that, the cycle continues as your systems, suppliers and ways of working change.

  1. 01
    Understand the business
  2. 02
    Collect evidence
  3. 03
    Investigate exceptions
  4. 04
    Track remediation
  5. 05
    Verify
  6. 06
    Review change
↺ Each review starts from what has changed

Automated collection can reduce repeated requests for the same evidence. People remain responsible for investigating exceptions, applying business judgement and making decisions.

Scope and investment

Agreed with you before any paid engagement begins

Every organisation starts from a different position. We agree the scope, outcomes and investment before any paid engagement begins. Each Modern Working service can be purchased independently.

INVESTMENT

From £500/month + VAT

Agreed control and evidence review, an action and evidence register, progress and assurance reviews and preparation for the in-scope target form the service. Organisation, environments, reporting and frequency are confirmed in the proposal.

We confirm onboarding work and any separate fee, minimum commitment, billing and cancellation terms before you proceed. Remediation, security software, penetration testing, external assessment fees and specialist framework projects are separate unless expressly included. General IT support, 24/7 monitoring, SOC and incident response are not included.

What the starting assessment covers

We agree the systems and requirements in scope, establish authorised access to available evidence and assess the starting position. You receive a baseline of control status, missing evidence, gaps and exceptions, with a prioritised action plan, responsibilities and a review schedule.

What the ongoing service covers

We maintain the agreed control assessment and evidence register, review available evidence and outstanding actions, and hold regular assurance reviews. Relevant evidence is mapped to supported frameworks and assembled for your agreed assessment target.

Cyber Ready provides ongoing assurance. It is not a 24/7 security operations or incident-response service.

What is agreed separately

Remediation implementation, security software, external certification and assessment fees, penetration testing and MDR/SOC services are separate. Bespoke framework work, such as building a complete ISO management system, is scoped on its own.

Cyber Ready can be purchased independently. Its value extends across your organisation’s trust, controls, assurance and resilience, whether or not you are adopting AI.

Control coverage

95 controls across 13 families

The scope of what Cyber Ready looks at, not a score. Coverage is platform-neutral and proportionate to your business; particular products are implementation choices, not the definition of Cyber Ready.

Evidence is reused across applicable frameworks and refreshed as systems, requirements and circumstances change. Additional evidence or work is added where a framework requires it.

See all 13 control families
  • 01Asset Management
  • 02Vulnerability Management
  • 03Data Protection
  • 04Identity & Access
  • 05Endpoint & Device Security
  • 06Backup & Recovery
  • 07Network Security
  • 08Logging & Monitoring
  • 09Security Awareness
  • 10Incident Response
  • 11Supplier / SaaS Security
  • 12Governance & Assurance
  • 13AI Security & Governance
Questions

Common questions

What do you need to demonstrate?

Tell us about a customer requirement, certification goal or concern about your protections. We will help define the route to readiness.

Every organisation starts from a different position. We agree the scope, outcomes and investment before any paid engagement begins. Each Modern Working service can be purchased independently.

Cyber Ready can be purchased independently. Its value extends across your organisation’s trust, controls, assurance and resilience, whether or not you are adopting AI.

AI Ready builds the capability to change how your business works.

Scroll to Top