In a bid to enhance cybersecurity for small businesses operating in sectors particularly susceptible to cyber threats, the National Cyber Security Centre (NCSC) has launched the Funded Cyber Essentials Programme.
This initiative aims to provide hands-on assistance to small companies in implementing crucial cybersecurity controls to mitigate the most common types of cyber-attacks.
Certain sectors face an elevated risk of cyber threats, either due to the nature of the sensitive information they handle or because they are perceived as easy targets for cybercriminals.
The Funded Cyber Essentials Programme concentrates on supporting small companies characterised by a low level of cyber maturity, dealing with sensitive data that could have a substantial impact if disrupted. The programme will extend Cyber Essentials Plus to specific high-risk sectors, rendering these services free of charge.
To be eligible for the program, companies must have 1 to 49 employees registered in the UK, actively engaged in the development of fundamental artificial intelligence (AI) technologies. Other criteria include not having participated in the NCSC Funded Cyber Essentials Programme before, lacking Cyber Essentials Plus (CE+) certification, not being awarded CE+ certification since January 2023, and not currently applying for CE+ certification.
The Funded Cyber Essentials Programme seeks to guide UK companies in meeting the five technical controls of Cyber Essentials – firewalls, secure settings, access controls, malware protection, and software updates. By identifying and implementing improvements tailored to the size and needs of the organisation, the programme aims to fortify cybersecurity measures.
Qualified companies will receive approximately 20 hours of remote support from a Cyber Advisor at no cost. However, it’s important to note that the NCSC and IASME will not provide any additional software or hardware identified as necessary by the advisor to achieve Cyber Essentials.
Through collaboration with IASME, organisations will benefit from hands-on support from a Cyber Advisor, aiding in the implementation of technical controls and making necessary configuration changes.
Recommended reading
- New research casts doubt on Scottish cyber-resilience
- How is the Cyber Essentials scheme faring?
- Bank of Scotland to help 10,000 businesses with digital skills academy
Even if Cyber Essentials Plus certification is not attainable, the Advisor will assist in implementing as many technical controls as possible and provide a clear list of additional actions required for compliance. While certification is not mandatory for program participation, a Cyber Essentials assessment must be completed before assessing for Cyber Essentials Plus.
Under the scheme, eligible organisations that sign up will receive support from one of IASME’s network of NCSC Assured Service Providers. All Cyber Advisors involved in delivering the Funded Cyber Essentials Programme undergo training, pass relevant assessments, and exams before participating in the program.





