Rescue2: building supply chain assurance with Cyber Essentials Plus

Aug 11, 2026 | Cyber Essentials, Cyber Essentials Case Study

Cyber Essentials Plus has helped Rescue2 independently verify its cyber security controls, protect sensitive information and provide stronger assurance to customers working across critical infrastructure and high-risk industries.

The requirementA major customer operating as a national gas distributor required suppliers to achieve Cyber Essentials Plus.
The assessmentIndependent technical testing examined controls including multi factor authentication, firewall exposure and device vulnerabilities.
The resultRescue2 corrected third party system issues, reduced unnecessary exposure and strengthened its overall cyber security position.

Rescue2 is built around safety, responsibility and trust

Rescue2 is a company that provides specialist confined space rescue support for customers across water utilities, power generation, national infrastructure and other demanding sectors. They also deliver accredited and bespoke confined space training through their West Sussex facility, customer sites and mobile training provision.

That focus on safety extends beyond operational rescue. Customers also need confidence that the information, systems and documentation connected with every project are being managed securely.

Rescue2 has grown considerably. Over a four year period, turnover increased from approximately £2 million to around £8 million. This brought more employees, customers, suppliers, systems and information into the organisation, together with a greater level of cyber risk.

For Paul Hilder, Head of Finance at Rescue2, who also oversees information technology and cyber security, the key question was clear. How could Rescue2 make certain that it did not become a weak point within an increasingly connected supply chain?

Why did Rescue2 pursue Cyber Essentials Plus?

Rescue2 began its Cyber Essentials journey in 2018, when a training customer required certification as part of a tender. Achieving Cyber Essentials provided a practical framework for strengthening the company’s core technical controls.

The expectations placed on the supply chain later increased. Another major customer operating as a national gas distributor raised its own cyber security standards and required suppliers to hold Cyber Essentials Plus. Cyber Essentials Plus is based on the same five technical controls as Cyber Essentials but adds independent technical testing to confirm that the controls are operating properly in practice. Both levels of certification are renewed annually.

For Rescue2, the certification was not simply an item to complete for a tender. It was a way to maintain customer trust and provide credible assurance to organisations responsible for critical infrastructure, operational safety and sensitive personal information.

Why does cyber security matter within the confined space supply chain?

Rescue2’s training and rescue services create different, but closely connected, cyber security responsibilities.

The training business holds delegate information, including medical information where this is relevant to participation and safety. A loss of that information could affect individuals, interrupt service delivery and damage the confidence that customers place in Rescue2. Even where data is less sensitive, losing access to systems or having accounts misused can still disrupt operations, delay payments, and impact customers—so the need for assurance goes far beyond the type of data held.

Rescue operations involve a different pattern of information exchange. Before a specialist team attends a customer site, competence records, certificates and supporting documents may need to be provided. These files are often shared by email or through external portals.

The confined space rescue sector includes many smaller specialist providers that work for large organisations with demanding security and assurance requirements. Every transfer of information creates a point that must be understood and controlled.

Paul explained, “Our biggest security concerns were complete encryption of our data and a loss of personal data, so we took action.”

He also summarised Rescue2’s approach to supply chain responsibility, “Somewhere in that chain, there is going to be a risk. All we can do is make sure it is not us.”

How was the Cyber Essentials Plus assessment completed?

Rescue2 worked with Remo Belisari of RB Consultancy Ltd as its Certification Body and involved its external information technology provider to support technical changes and corrective work.

Paul’s background in statutory audit meant that he immediately recognised the value of verification. Organisations can have strong intentions and good documentation, but what matters is how controls operate across live systems day to day.

The assessment provided a practical view of Rescue2’s security posture—checking assumptions, exploring findings openly, and confirming improvements before certification was awarded.

What did the assessment identify?

The assessment highlighted three areas where this additional assurance made a tangible difference, strengthening Rescue2’s overall security posture with targeted, practical changes.

Multi factor authentication within external portals

Most Rescue2 systems already used multi factor authentication (MFA) correctly. The more difficult issues arose within portals supplied and managed by other organisations.

One portal was believed to have multi factor authentication in place, but the assessment showed that it could be bypassed. Another portal was thought not to offer the feature, although further investigation confirmed that it was available.

Resolving these findings required sustained contact with suppliers. In one case, mandatory multi factor authentication had previously been introduced, but had later been made optional following resistance from customers.

As the deadline for corrective action approached, Rescue2 escalated the issue. The required changes were completed within 24 to 48 hours. The bypass route was removed and single sign on was introduced to bring the service into compliance.

The important outcome was that Rescue2 no longer had to rely on an assumption. The controls protecting its cloud services had been tested, corrected and independently verified.

Router and firewall exposure

The assessment also examined router and firewall settings. It identified open ports that were not ultimately being used, but which were visible from the internet.

This prompted useful questions about why they were open, whether they served a current purpose and what information they could reveal to somebody examining the network from outside.

Rescue2 chose to close anything that was not required, reducing the number of possible routes into its systems and improving its overall security position.

Remo explained, “If something cannot be seen from the outside, it cannot easily be used as information to help shape an attack.”

Improvements beyond the certification minimum

Device vulnerability testing identified additional low and medium risks. Rescue2 could have focused only on the items required to achieve certification, but chose to address the wider findings as well.

This meant that Cyber Essentials Plus became more than a pass or fail exercise. It provided an opportunity to improve the organisation’s wider cyber security position and reduce risks that could otherwise have remained unresolved.

Why is independent verification useful when a business has an information technology provider?

Rescue2, like many SMEs, uses an external information technology provider and, like most businesses, expects its specialist suppliers to provide accurate advice and implement appropriate controls.

However, the assessment identified areas where information submitted about the systems did not fully match the controls that were operating in practice. This did not remove the value of the provider, but it demonstrated the benefit of independent scrutiny. Paul reflects, “Having that third party set of eyes helps identify and improve the processes.”

How did Rescue2’s culture of trust support the process?

Trust and transparency are central to Rescue2’s culture. This helped the organisation approach the assessment as an opportunity to learn rather than as a fault finding exercise.

Paul explained, “We cannot fix a problem if we do not know it exists. When we know it exists, we talk about it and find a solution.”

That willingness to examine weaknesses, challenge assumptions, involve suppliers and complete corrective work was essential. It also reflects the same approach that Rescue2 brings to operational planning, risk assessment, specialist team provision, equipment, standby rescue support, training and ongoing customer coordination.

What advice does Rescue2 have for other organisations?

Paul recommends that businesses consider Cyber Essentials even when they are not confident that they would pass immediately.

“Cyber Essentials is something I would strongly recommend every organisation to look at and try, even if you are unsure you will pass first time. Once you go through the audit process, you realise how fundamental cyber security is to almost every business today.”

He also believes that customer relationships make cyber security a commercial issue as well as a technical one.

“Any business lives and dies by the relationship it has with its customers. If a cyber issue is even remotely linked to one of your customers, some businesses will not recover from it.”

Paul also praised the service provided by Remo during the assessment, “I cannot fault the service that Remo provided. His knowledge, skill set and ability to communicate with me and the team were exemplary.”

What comes next for Rescue2?

Rescue2 is introducing new systems and continuing to improve efficiency as the company prepares for further growth. Cyber Essentials Plus now provides an important point of assurance for customers, particularly those operating within critical infrastructure and other highly regulated environments.

The certification also supports Rescue2’s wider commitment to helping customers manage risk from beginning to end.

Paul explained, “We are not relying only on our training and rescue services. We give our customers confined space education and practical guidance, while also sharing useful lessons in areas such as information technology and cyber security. The more openly we discuss this, the more people will understand the value of what we are doing, not only for Rescue2, but for the entire supply chain.”

By independently testing its controls and acting on the findings, Rescue2 has strengthened its own resilience while providing customers with clearer evidence that cyber security is being treated with the same seriousness as operational safety.