When reassurance is no longer enough

Someone wants proof your business is secure. What now?

A customer, insurer or tender has asked a question that “we have antivirus” cannot answer. Before you rush into a certificate or another security product, establish what evidence they need, what is in scope and which recognised standard will actually satisfy the request.

Why the question appears

Six moments when informal reassurance stops being enough

The request is rarely just about technology. Someone needs a consistent, defensible answer before they accept risk, award work or renew cover.

01

A tender names Cyber Essentials

The opportunity is attractive, but certification has appeared as a pass-or-fail supplier requirement rather than an optional extra.

02

A customer sends a security questionnaire

Questions about devices, access, updates and cloud services expose how difficult it is to turn everyday IT into reliable evidence.

03

An insurer wants firmer answers

The renewal asks who has administrator access, how accounts are protected and whether important controls are actually enforced.

04

A larger client checks its supply chain

Your customer needs confidence that a weakness in a smaller supplier will not become a route into its information or systems.

05

The board asks for proof, not optimism

Leaders want a simple way to see whether the basics are owned, measured and maintained—not another collection of product names.

06

An old certificate is about to expire

Renewal reveals whether the controls became normal business practice or were treated as a one-off project for last year’s badge.

Before you promise anything

Three questions prevent a rushed and expensive answer

Start with the business requirement. The right evidence becomes much clearer once the request, scope and present position are understood.

A questionnaire is not the security work. It reveals whether the work has clear ownership and evidence behind it.

  1. 01
    What exact proof has been requested?

    Ask whether they require Cyber Essentials, Cyber Essentials Plus, answers to their own questionnaire or evidence of particular controls—and confirm the deadline.

  2. 02
    What must be included in scope?

    Map the people, devices, networks and cloud services involved. Cyber Essentials normally covers the whole organisation or a clearly defined and separately managed subset agreed with the Certification Body.

  3. 03
    Can every answer be evidenced today?

    Identify who owns each control, where the information comes from and which gaps need resolving before anybody signs or submits an assessment.

Match the proof to the request

“Are you secure?” can mean four different things

Cyber Essentials is the Government-recommended minimum cyber security standard and covers five technical controls. It is often the most useful recognised baseline, but the buyer may be asking for a different level or type of evidence.

Sources: NCSC Cyber Essentials overview and the current technical requirements.

Comparison of common cyber security assurance requests and sensible evidence routes
What they needWhat it should demonstrateSensible route
Basic reassuranceImportant controls are known, owned and documentedFocused security review with a clear improvement plan
Recognised baselineFive core technical controls meet an independently assessed standardCyber Essentials verified self-assessment
Higher assuranceThe same five controls have also been tested in practiceCyber Essentials Plus independent technical testing
Ongoing cloud evidenceMicrosoft 365 protections are monitored and maintainedA documented Microsoft 365 security standard
Build the evidence once

Make the next questionnaire easier than the first

The useful outcome is not a folder of screenshots. It is a small set of controls, owners and records that stay current between requests.

01

Create one reliable inventory

Know which devices, software, users, administrators and cloud services are in scope before trying to describe how they are protected.

02

Close the obvious control gaps

Prioritise secure configuration, updates, access control, malware protection and internet boundaries before polishing policies.

03

Name the evidence owner

Give one person responsibility for keeping answers, supporting records and renewal dates current rather than rebuilding them under deadline pressure.

5Cyber Essentials technical controls
2Levels of Cyber Essentials certification
20+Years of hands-on IT experience
Straight answers

Cyber security evidence questions, answered plainly

You can clarify the requirement and current gaps before committing to a certification project or a larger technology change.

Does Cyber Essentials prove that our business is completely secure?

No certification can prove that an organisation is immune from every incident. Cyber Essentials provides independently assessed evidence that five important technical controls are in place to reduce exposure to common internet-based attacks. It is a recognised baseline, not a claim of perfect security.

A customer has asked for Cyber Essentials. What should we do first?

Confirm the exact requirement, deadline and scope before purchasing an assessment. Then review the current environment against the Cyber Essentials questions and technical requirements, close the gaps and submit when the answers can be supported by evidence.

Does West View IT issue the Cyber Essentials certificate?

No. Certification is independently assessed through an IASME-licensed Certification Body. West View IT can help define the likely scope, prepare the environment, resolve practical gaps and support the assessment without pretending to mark its own work.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both levels cover the same five technical controls. Cyber Essentials combines a self-assessment with independent verification, while Cyber Essentials Plus adds hands-on technical testing by an independent assessor for greater assurance.

Can you help if another company already provides our IT support?

Yes. We can carry out a focused readiness review and work with your existing provider to gather evidence or close agreed gaps. If the exercise exposes a wider ownership problem, we will explain that clearly rather than using certification as a pretext for an unnecessary change.

Owen Williams Owen Williams · Managing Director

Turn the security question into a clear plan.

Book a relaxed 30-minute call with Owen. Bring the questionnaire, tender wording or insurer request and we will help you identify the proof, scope and sensible next step.

01449 798119 · enquiries@westviewit.co.uk

Get a clear evidence plan →