Stronger Together: How Cyber Essentials Builds Collective Cyber Defence

Aug 6, 2026 | Cyber Essentials

Cyber security is often framed as a private problem: my systems, my data, my incident response plan. But the reality is messier – and more interconnected.

Every organisation sits inside a web of customers, suppliers, partners, shared platforms, outsourced services, and third-party logins. When one link in that chain is weak, attackers don’t have to break down the front door of a big organisation – they can slip in through a smaller, less protected one. In that sense, cyber resilience isn’t just an organisational goal; it’s a form of collective defence.

And that’s where SMEs matter.

SMEs aren’t ‘small targets’—they’re critical links

There are approximately 5.7 million SMEs (small and medium-sized enterprises) in the UK. This massive group accounts for 99.9% of all private sector businesses in the country, making up the backbone of the UK economy and supply chains. They build, deliver, maintain, advise, design, manufacture, support, and connect the services the rest of us rely on. They also hold the data and access that keep bigger organisations moving: customer details, project plans, financial records, credentials, shared folders, and privileged access to systems.

Attackers understand this. Many high-volume attacks are opportunistic: phishing, credential stuffing, malware, exploitation of unpatched vulnerabilities. They don’t require elite skill – just scale, automation and a steady supply of organisations that haven’t put the basics in place.

So the question is, Can we afford for basic security to be patchy across the supply chain?

Cyber Essentials: over a decade of focusing on fundamentals

It’s now twelve years since the UK Government launched Cyber Essentials – a baseline scheme designed to help organisations of all sizes demonstrate they have the most important technical controls in place, and to support the ambition of making the UK the safest place to do business online.

Cyber Essentials is annually renewable and centres on five technical controls that protect organisations from the most common internet-based attacks.

For organisations that want stronger assurance, Cyber Essentials Plus is based on the same requirements but adds a technical audit of the applicant’s IT systems to verify the controls are in place.

The scheme focuses on a small set of fundamental controls. But getting those basics right – across every device, account, and supplier touchpoint – can materially reduce risk.

The scheme was built to do three things: Protect, Educate, Certify

1) Protect: reduce vulnerability to common attacks

Cyber Essentials is designed to reduce an organisation’s exposure to common, high-volume threats – including ransomware. The impact of getting these fundamentals right can be dramatic. When one of the UK’s largest pensions and life companies mandated Cyber Essentials Plus certification for more than 2,800 independent businesses in its network, it reported an 80% reduction in cyber security incidents.

Put simply: when organisations consistently apply baseline controls, a large proportion of opportunistic attacks stop working.

2) Educate: make cyber risk a leadership responsibility

One of the most important ideas behind Cyber Essentials is also the most uncomfortable: you can’t outsource responsibility for cyber risk.

IT suppliers, security tools, and managed service providers can help—but the accountability sits with the organisation’s leadership. Cyber Essentials supports that shift by making the basics concrete. It encourages organisations to actively engage with ‘what good looks like’, and to embed the fundamentals into everyday practice.

Many organisations describe working toward certification as highly educational – a practical checklist that helps them make progress without getting lost in complexity.

3) Certify: provide a trusted baseline others can rely on

Annual assessment gives organisations a repeatable way to review their security against an approved framework and to demonstrate to customers and suppliers that they can be trusted with the information they hold.

Today, Cyber Essentials is widely recognised as an industry standard and is frequently requested when bidding for contracts or applying for funding.

Collective resilience: why ‘the basics’ matter nationally

The National Cyber Security Centre (NCSC) has described the threat landscape as “diffuse and dangerous” – with both the number of incidents and their impact increasing. What’s striking is that many attacks still rely on well-known techniques and vulnerabilities we already know how to defend against.

And yet, basic cyber security practices are too often ignored. The NCSC has warned that the severity of the threat is underestimated across sectors, and that we need to ‘wake up’ and treat cyber security as a core part of operational resilience – and a driver for growth, not a necessary evil.

Cyber Essentials directly supports that shift because it scales what works: baseline controls that reduce common avenues of attack. When those controls are adopted widely across the country, the UK becomes harder to attack.

In other words: mass adoption is a national advantage.

Supply chains: assurance that’s robust and achievable

Modern supply chains are digital and complex, with data and access flowing across organisational boundaries. For many organisations, assessing the cyber security of every supplier in detail is unrealistic.

Cyber Essentials certification provides a tangible way to build confidence that suppliers and third parties have implemented fundamental controls – without requiring every customer to reinvent their own assessment framework.

‘Strengthened by the storm’: why fundamentals still win

This year at CyberUK, NCSC CEO Richard Horne described driving through a Florida storm with near-zero visibility—an experience that forced him to focus on the fundamentals: hands on the wheel, foot ready to brake, eyes scanning for risk.

The lesson translates directly to cyber security. We are operating in what can feel like a perfect storm: rapid technological change, rising geopolitical tension, and adversaries that increasingly use automation (and AI) to find and exploit weaknesses at scale.

Cyber Essentials is built for exactly these conditions. When you can’t see far ahead, resilience doesn’t come from guessing what’s around the corner; it comes from doing the basics well—consistently, everywhere.

As GCHQ Director Ann Keast-Butler put it in this year’s GCHQ Annual Lecture: “We stay safe by being prepared. And we stay safe, by staying together.”

That’s the value of Cyber Essentials: a shared baseline that strengthens the UK’s collective cyber defence—whatever the storm brings.