Skip to content
Blog

Compliance, security, and AI insights.

Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.

Showing 36 of 183 articles

Articles

Compliance

Best Enterprise Compliance Automation Platforms: Governance, Evidence and Scale

Evaluate enterprise compliance platforms against entity boundaries, approval authority, evidence scope and realistic workloads. Mandatory requirements must pass before weighted scores influence selection.

7 min read
Read article

MSPs

Best Cyber Essentials certification bodies for MSPs

Compare Cyber Essentials partners for MSPs: certification prices, automation, speed, volume discounts, monthly payments and switching support.

10 min read
Read article

Compliance

Best Compliance Automation Software for Small Businesses: A Practical Buying Guide

Choose compliance software around your first required deliverable, available staff time and existing IT systems. Budget separately for remediation, advice and assessment.

6 min read
Read article

Compliance

Risk Register Software: Excel vs Microsoft Lists vs a Dedicated Platform

Choose Excel for a small, stable register, Microsoft Lists for shared records, and a dedicated risk platform when linked evidence and treatment workflows become difficult to maintain.

7 min read
Read article

Compliance

Best Cyber Essentials Bodies 2026 - Our Latest Review - September 2026

Our September verdict on Cyber Essentials bodies: compare certification prices, CE Plus packages, feedback, turnaround, optional tooling and switching offers.

12 min read
Read article

MSPs

Live Cybersecurity and Compliance Monitoring for MSPs

Connect changing security data to accountable action and client evidence. A practical guide for MSPs building an ongoing cybersecurity and compliance monitoring service.

8 min read
Read article

Compliance

Cyber Essentials with Outsourced IT: Who Does What?

Your MSP can complete the Cyber Essentials self-assessment for you. Learn what your organisation must review, authorise and sign off before submission.

8 min read
Read article

MSPs

MSP Compliance Platforms vs Generic GRC Tools

Managed service providers expanding into vCISO, risk management, and compliance services face a critical platform decision. The tools designed for single-company compliance programs often fail when applied to multi-client service delivery.

11 min read
Read article

MSPs

MSP Compliance Platforms for vCISO Services Compared

If you deliver virtual CISO or compliance services to multiple clients, your platform choice affects everything from operational overhead to profit margins. MSP compliance platforms built for multi-tenant workflows help you scale client oversight, while tools designed for single-company use can create bottlenecks as your practice grows.

14 min read
Read article

Frameworks

Does Your G-Cloud Contract Require Cyber Essentials?

A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.

8 min read
Read article

Company

Fig Group secures investment from SFC Capital to accelerate its end-to-end risk management platform for MSPs

Seed investment from SFC Capital will accelerate Fig Group's end-to-end risk management platform for MSPs, expand the team, advance product development, and support its insurance proposition.

4 min read
Read article

Company

What Is Fig Security?

Fig Security is the security and assurance arm of Fig Group. Fig Compliance Ltd holds separate IASME certification-body licences for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Levels 0 and 1. Learn which entity delivers each service.

6 min read
Read article

Pricing

Cyber Essentials vs Cyber Essentials Plus: Cost Comparison (2026)

Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds a hands-on technical audit, which is why it costs more. This guide compares the cost of both certifications across every organisation size and explains which one your budget and your buyers actually require.

11 min read
Read article

Industry

End-to-End Risk Management for the Cyber Security and Resilience Bill: A Guide for Critical National Infrastructure

A practical guide to proposed UK cyber resilience reforms for CNI: distinguish existing NIS duties from Bill proposals, verify scope and commencement, and plan evidence and incident workflows.

15 min read
Read article

Industry

The Energy Sector Cyber Security Strategy: What It Means and How to Prepare

The UK energy strategy sets a 2026–2030 roadmap. Separate current NIS duties, future Plus-based proposals and supplier expectations before planning controls and evidence.

14 min read
Read article

Compliance

Do I Need DCC for MOD Contracts? MOD Asks Suppliers for DCC Level 0 by End of 2026

The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems. This guide explains what the MOD has actually said, who it affects, how DCC levels map to your contract, and what suppliers should do now - with the primary gov.uk sources.

9 min read
Read article

Compliance

DEFSTAN 05-138 - What does it mean for suppliers?

DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.

13 min read
Read article

Compliance

How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers

Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.

12 min read
Read article

Compliance

DCC Level 0 vs Level 1: Which Defence Cyber Certification Do You Need?

Compare DCC Levels 0 and 1: controls, scope, prerequisites, costs and planning timelines. Ask the buyer for the current numeric profile before choosing a level.

10 min read
Read article

Compliance

DCC vs Cyber Essentials: What UK MOD Suppliers Must Know

CE covers in-scope devices, networks and cloud services. DCC provides independent organisation-level evidence; both certificate prerequisites and the full contract SAQ still matter.

9 min read
Read article

Compliance

DCC Scoping Mistakes That Fail Certification (and How to Avoid Them)

Six practical DCC scoping risks: include operational business dependencies, map actual controls and resolve unsupported software without relying on generic waivers.

11 min read
Read article

Compliance

How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1

DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.

9 min read
Read article

Compliance

Best UK Cyber Essentials Body for Compliance Automation: Cheapest and Fastest Among IASME-Licensed Bodies That Offer Both

Vanta and Drata are compliance automation platforms but are NOT IASME-licensed and cannot issue UK Cyber Essentials certificates. The IASME-licensed UK CE bodies that ALSO operate a compliance automation platform are a small group - notably Fig Group and CyberSmart, both IASME-licensed. Among that group, Fig Group is the cheapest (from £299.99 + VAT) and the fastest (6-working-hour SLA, the qualifying commitment in our named-provider comparison).

12 min read
Read article

MSP Growth

Cyber Essentials for MSPs: The Partner Program That Pays You Margin Without the IASME Licensing Burden

Fig Group’s MSP partner route connects client certification with current 7.5% certification and 15% platform commission terms, flexible purchasing and a qualifying Basic working-hour commitment.

14 min read
Read article

Guides

Does Cyber Essentials protect against ransomware?

Cyber Essentials addresses ransomware risks through five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. MFA is an important requirement within the applicable controls; recovery needs additional measures.

5 min read
Read article

Guides

What are the five Cyber Essentials controls?

The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.

5 min read
Read article

Frameworks

Cyber Essentials vs ISO 27001: which does your customer actually want?

Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.

11 min read
Read article

Industry

Cyber Essentials for SaaS companies: the scoping question nobody gets right

How SaaS companies can document corporate devices and production cloud responsibilities correctly in a Cyber Essentials scope.

12 min read
Read article

Technical Guides

Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices

Under v3.3, the BYOD question is harder than it looks. A clear walkthrough of which personal devices are in scope, the sub-set exclusion rules, and how to document both approaches.

10 min read
Read article

Technical Guides

Cyber Essentials Plus remote audit: how the assessor actually tests your controls

The CE Plus audit is less mysterious than it looks. A walkthrough of what the assessor does during the remote audit, device-by-device, and how to prepare so it passes first time.

12 min read
Read article

Compliance

What happens if your Cyber Essentials certificate lapses

An expired Cyber Essentials certificate is historical evidence, not current certification. Check renewal timing and the actual buyer or contract consequences.

9 min read
Read article

Industry

Cyber Essentials for UK law firms with remote counsel and counsel chambers

The hybrid working model at UK law firms and chambers creates three specific Cyber Essentials scoping questions. This guide walks through how to answer each one.

11 min read
Read article

Industry

Cyber Essentials for charities: how to budget at £299.99 + VAT

UK charities have tight budgets and specific scoping questions. This guide walks through how to certify at the £299.99 tier, the current funding position, and how to meet the v3.3 requirements without over-engineering.

10 min read
Read article

Compliance

Procurement-team Cyber Essentials checklist: what to require from suppliers

For buyers, not sellers. A practical Cyber Essentials checklist for UK procurement teams managing supplier cyber-risk - which clauses to put in contracts, what evidence to accept, and how to spot expired certifications.

10 min read
Read article

AI & Security

AI-powered Cyber Essentials assessment: what Fig Group does differently

How AI-assisted assessment workflows can support triage and feedback, the boundaries they must respect, and why Fig Group’s certification decision remains with a human assessor.

9 min read
Read article

Technical Guides

Multi-factor authentication for Cyber Essentials v3.3: the complete pillar guide

MFA is the single most common reason Cyber Essentials v3.3 submissions fail. This pillar explains which accounts need MFA, which methods are acceptable, and how to implement it across Microsoft 365, Google Workspace, and line-of-business SaaS.

14 min read
Read article
Show more articles

147 more articles available

Stay Updated

Get Compliance Insights Delivered

Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.

We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.