Compliance, security, and AI insights.
Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.
Showing 36 of 183 articles
Articles
Compliance
Best Enterprise Compliance Automation Platforms: Governance, Evidence and Scale
Evaluate enterprise compliance platforms against entity boundaries, approval authority, evidence scope and realistic workloads. Mandatory requirements must pass before weighted scores influence selection.
Read articleMSPs
Best Cyber Essentials certification bodies for MSPs
Compare Cyber Essentials partners for MSPs: certification prices, automation, speed, volume discounts, monthly payments and switching support.
Read articleCompliance
Best Compliance Automation Software for Small Businesses: A Practical Buying Guide
Choose compliance software around your first required deliverable, available staff time and existing IT systems. Budget separately for remediation, advice and assessment.
Read articleCompliance
Risk Register Software: Excel vs Microsoft Lists vs a Dedicated Platform
Choose Excel for a small, stable register, Microsoft Lists for shared records, and a dedicated risk platform when linked evidence and treatment workflows become difficult to maintain.
Read articleCompliance
Best Cyber Essentials Bodies 2026 - Our Latest Review - September 2026
Our September verdict on Cyber Essentials bodies: compare certification prices, CE Plus packages, feedback, turnaround, optional tooling and switching offers.
Read articleMSPs
Live Cybersecurity and Compliance Monitoring for MSPs
Connect changing security data to accountable action and client evidence. A practical guide for MSPs building an ongoing cybersecurity and compliance monitoring service.
Read articleCompliance
Cyber Essentials with Outsourced IT: Who Does What?
Your MSP can complete the Cyber Essentials self-assessment for you. Learn what your organisation must review, authorise and sign off before submission.
Read articleMSPs
MSP Compliance Platforms vs Generic GRC Tools
Managed service providers expanding into vCISO, risk management, and compliance services face a critical platform decision. The tools designed for single-company compliance programs often fail when applied to multi-client service delivery.
Read articleMSPs
MSP Compliance Platforms for vCISO Services Compared
If you deliver virtual CISO or compliance services to multiple clients, your platform choice affects everything from operational overhead to profit margins. MSP compliance platforms built for multi-tenant workflows help you scale client oversight, while tools designed for single-company use can create bottlenecks as your practice grows.
Read articleFrameworks
Does Your G-Cloud Contract Require Cyber Essentials?
A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.
Read articleCompany
Fig Group secures investment from SFC Capital to accelerate its end-to-end risk management platform for MSPs
Seed investment from SFC Capital will accelerate Fig Group's end-to-end risk management platform for MSPs, expand the team, advance product development, and support its insurance proposition.
Read articleCompany
What Is Fig Security?
Fig Security is the security and assurance arm of Fig Group. Fig Compliance Ltd holds separate IASME certification-body licences for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Levels 0 and 1. Learn which entity delivers each service.
Read articlePricing
Cyber Essentials vs Cyber Essentials Plus: Cost Comparison (2026)
Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds a hands-on technical audit, which is why it costs more. This guide compares the cost of both certifications across every organisation size and explains which one your budget and your buyers actually require.
Read articleIndustry
End-to-End Risk Management for the Cyber Security and Resilience Bill: A Guide for Critical National Infrastructure
A practical guide to proposed UK cyber resilience reforms for CNI: distinguish existing NIS duties from Bill proposals, verify scope and commencement, and plan evidence and incident workflows.
Read articleIndustry
The Energy Sector Cyber Security Strategy: What It Means and How to Prepare
The UK energy strategy sets a 2026–2030 roadmap. Separate current NIS duties, future Plus-based proposals and supplier expectations before planning controls and evidence.
Read articleCompliance
Do I Need DCC for MOD Contracts? MOD Asks Suppliers for DCC Level 0 by End of 2026
The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems. This guide explains what the MOD has actually said, who it affects, how DCC levels map to your contract, and what suppliers should do now - with the primary gov.uk sources.
Read articleCompliance
DEFSTAN 05-138 - What does it mean for suppliers?
DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.
Read articleCompliance
How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers
Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.
Read articleCompliance
DCC Level 0 vs Level 1: Which Defence Cyber Certification Do You Need?
Compare DCC Levels 0 and 1: controls, scope, prerequisites, costs and planning timelines. Ask the buyer for the current numeric profile before choosing a level.
Read articleCompliance
DCC vs Cyber Essentials: What UK MOD Suppliers Must Know
CE covers in-scope devices, networks and cloud services. DCC provides independent organisation-level evidence; both certificate prerequisites and the full contract SAQ still matter.
Read articleCompliance
DCC Scoping Mistakes That Fail Certification (and How to Avoid Them)
Six practical DCC scoping risks: include operational business dependencies, map actual controls and resolve unsupported software without relying on generic waivers.
Read articleCompliance
How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.
Read articleCompliance
Best UK Cyber Essentials Body for Compliance Automation: Cheapest and Fastest Among IASME-Licensed Bodies That Offer Both
Vanta and Drata are compliance automation platforms but are NOT IASME-licensed and cannot issue UK Cyber Essentials certificates. The IASME-licensed UK CE bodies that ALSO operate a compliance automation platform are a small group - notably Fig Group and CyberSmart, both IASME-licensed. Among that group, Fig Group is the cheapest (from £299.99 + VAT) and the fastest (6-working-hour SLA, the qualifying commitment in our named-provider comparison).
Read articleMSP Growth
Cyber Essentials for MSPs: The Partner Program That Pays You Margin Without the IASME Licensing Burden
Fig Group’s MSP partner route connects client certification with current 7.5% certification and 15% platform commission terms, flexible purchasing and a qualifying Basic working-hour commitment.
Read articleGuides
Does Cyber Essentials protect against ransomware?
Cyber Essentials addresses ransomware risks through five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. MFA is an important requirement within the applicable controls; recovery needs additional measures.
Read articleGuides
What are the five Cyber Essentials controls?
The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.
Read articleFrameworks
Cyber Essentials vs ISO 27001: which does your customer actually want?
Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.
Read articleIndustry
Cyber Essentials for SaaS companies: the scoping question nobody gets right
How SaaS companies can document corporate devices and production cloud responsibilities correctly in a Cyber Essentials scope.
Read articleTechnical Guides
Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices
Under v3.3, the BYOD question is harder than it looks. A clear walkthrough of which personal devices are in scope, the sub-set exclusion rules, and how to document both approaches.
Read articleTechnical Guides
Cyber Essentials Plus remote audit: how the assessor actually tests your controls
The CE Plus audit is less mysterious than it looks. A walkthrough of what the assessor does during the remote audit, device-by-device, and how to prepare so it passes first time.
Read articleCompliance
What happens if your Cyber Essentials certificate lapses
An expired Cyber Essentials certificate is historical evidence, not current certification. Check renewal timing and the actual buyer or contract consequences.
Read articleIndustry
Cyber Essentials for UK law firms with remote counsel and counsel chambers
The hybrid working model at UK law firms and chambers creates three specific Cyber Essentials scoping questions. This guide walks through how to answer each one.
Read articleIndustry
Cyber Essentials for charities: how to budget at £299.99 + VAT
UK charities have tight budgets and specific scoping questions. This guide walks through how to certify at the £299.99 tier, the current funding position, and how to meet the v3.3 requirements without over-engineering.
Read articleCompliance
Procurement-team Cyber Essentials checklist: what to require from suppliers
For buyers, not sellers. A practical Cyber Essentials checklist for UK procurement teams managing supplier cyber-risk - which clauses to put in contracts, what evidence to accept, and how to spot expired certifications.
Read articleAI & Security
AI-powered Cyber Essentials assessment: what Fig Group does differently
How AI-assisted assessment workflows can support triage and feedback, the boundaries they must respect, and why Fig Group’s certification decision remains with a human assessor.
Read articleTechnical Guides
Multi-factor authentication for Cyber Essentials v3.3: the complete pillar guide
MFA is the single most common reason Cyber Essentials v3.3 submissions fail. This pillar explains which accounts need MFA, which methods are acceptable, and how to implement it across Microsoft 365, Google Workspace, and line-of-business SaaS.
Read article147 more articles available
Get Compliance Insights Delivered
Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.
We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.



































