Skip to content
Blog

Compliance, security, and AI insights.

Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.

Showing 36 of 183 articles

Articles

Technical Guides

MFA for Microsoft 365: the Cyber Essentials v3.3 configuration

Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.

10 min read
Read article

Technical Guides

MFA for Google Workspace: the Cyber Essentials v3.3 setup

Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.

8 min read
Read article

Technical Guides

MFA conditional access under Cyber Essentials v3.3: what works, what fails

Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.

9 min read
Read article

Technical Guides

Cyber Essentials v3.3: cloud services scope changes explained

v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.

9 min read
Read article

Technical Guides

Cyber Essentials v3.3 and passwordless authentication: what the scheme allows

Passwordless sign-in with FIDO2, Windows Hello, and mobile credentials is rising fast. This article explains how v3.3 treats passwordless authentication and what to declare in the self-assessment.

8 min read
Read article

Technical Guides

Cyber Essentials v3.3 and device unlock: what the scheme expects

Device unlock for Cyber Essentials v3.3: six-character device-only passwords or PINs, brute-force protection, biometrics and credentials also used for authentication.

8 min read
Read article

Technical Guides

Cyber Essentials v3.3 sub-set scoping: when and how to exclude

Cyber Essentials subset scope must be well-defined, separately managed and agreed with the certification body. Learn the firewall/VLAN boundary and stricter unsupported-software rule.

8 min read
Read article

Technical Guides

Cyber Essentials v3.3: admin account requirements and stronger authentication

Individual administrator credentials, separate day and admin accounts, effective MFA and optional phishing-resistant authentication and emergency-access hardening.

9 min read
Read article

Technical Guides

Cyber Essentials for remote and hybrid workforces: scope, home routers, and what v3.3 actually requires

Cyber Essentials scope for remote and hybrid teams: ordinary private home routers are excluded, organisation-supplied routers are included, and work devices and cloud services need applicable controls.

11 min read
Read article

Guides

Can a sole trader get Cyber Essentials?

Yes - sole traders can get Cyber Essentials. A one-person business qualifies for Fig Group's Micro tier at £299.99 + VAT. Buyers still decide eligibility against their contract, entity and scope requirements.

4 min read
Read article

Guides

Is Cyber Essentials a legal requirement?

Cyber Essentials is not a general UK legal requirement. Check the actual tender, MOD contract, insurer conditions and permitted equivalent controls.

4 min read
Read article

Guides

Does Cyber Essentials cover cloud services?

Yes - Cyber Essentials explicitly covers cloud services under v3.3. Microsoft 365, Google Workspace, AWS, Azure, and any SaaS application holding organisational data are all in scope, with specific configuration expectations around MFA, tenant settings, and managed updates.

5 min read
Read article

Technical Guides

Cyber Essentials and patch management (WSUS, Intune, third-party)

How to evidence Cyber Essentials v3.3 patching - 14-day SLA for high/critical CVEs, WSUS deployment patterns, Intune Update Rings, third-party patching (Action1, PDQ, NinjaOne), and the audit artefacts assessors want.

7 min read
Read article

Company

What Is Fig Group? The MSP Compliance Platform, Not Financial Institutions Group

What MSPs can do with the Fig Group platform: manage client compliance, risk, monitoring and evidence, with separately licensed certification services.

2 min read
Read article

Company

Fig Group vs Financial Institutions Group: Clearing Up the Confusion

Compare the investment banking term Financial Institutions Group with Fig Group, the UK cybersecurity and compliance business serving MSPs and other organisations.

2 min read
Read article

MSPs

Choosing a Cyber Essentials Certified MSP in the UK

If you need an MSP that is itself Cyber Essentials certified (and can help you achieve it), this guide explains what "CE-certified MSP" really means and how to evaluate one.

6 min read
Read article

Compliance

How Long Does Cyber Essentials Take? Honest Timelines for 2026

From readiness to certificate, how long does Cyber Essentials really take? This guide walks through every stage with realistic timelines and the factors that speed it up or slow it down.

5 min read
Read article

Financial Services

Cyber Essentials for Financial Services: FCA, PRA and Client Expectations

Financial services firms face unique scrutiny on cyber controls. Where does Cyber Essentials fit alongside FCA SYSC, PRA SS1/21, and client due-diligence expectations?

8 min read
Read article

Compliance

UK Cyber Essentials Certification Bodies Compared (2026)

There are dozens of IASME-licensed Cyber Essentials certification bodies. This guide compares them on price, turnaround, technology, and specialism to help you pick the right one.

9 min read
Read article

Industry

Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For

The Bar Standards Board does not formally require Cyber Essentials. Solicitor firms, CPS counterparts, institutional lay clients, and insurers are increasingly asking for it. This guide covers how CE applies to a criminal barristers’ chambers in London and why the certification has become a practical necessity even without a formal mandate.

12 min read
Read article

Guides

How to verify a Cyber Essentials certificate: the buyer and procurement-team guide (2026)

A supplier has sent you a PDF claiming to be their Cyber Essentials certificate. How do you confirm it is real, current, and issued to the organisation you are actually contracting with? This is the verification guide for procurement and tender-assessment teams.

8 min read
Read article

Guides

What size business needs Cyber Essentials?

Cyber Essentials applies to UK organisations of every size, from sole traders to enterprises. The scheme is tiered by headcount (Micro 1-9, Small 10-49, Medium 50-249, Large 250 - 9,999) and is most commonly required for SMEs bidding for procurement work or seeking cyber insurance.

4 min read
Read article

Guides

Does Cyber Essentials require a VPN?

No. Cyber Essentials does not mandate a VPN. Apply the scheme rules to each in-scope remote administration path, boundary firewall, account and cloud service; a VPN is one possible design.

5 min read
Read article

Technical Guides

Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)

Use password managers to support Cyber Essentials password controls: unique credentials, secure storage, MFA, breach monitoring, access management and useful evidence.

6 min read
Read article

Technical Guides

Security Update Management for Cyber Essentials v3.3: the complete pillar guide

Security Update Management is the quietest-looking pillar of Cyber Essentials and the one organisations most often fail on at renewal. This guide covers every v3.3 requirement - the 14-day rule, supported OS versions, mobile and firmware, cloud-service patching - and the evidence an assessor will now accept.

12 min read
Read article

Guides

Who needs Cyber Essentials Plus?

Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.

5 min read
Read article

Guides

Can I get Cyber Essentials Plus without Cyber Essentials?

No - Cyber Essentials Plus requires a current Cyber Essentials certificate first, or both can be completed in a single engagement. The self-assessment is identical for both levels; Plus adds hands-on technical testing by an assessor.

4 min read
Read article

Guides

Can small businesses get Cyber Essentials?

Yes - Cyber Essentials is designed for UK small businesses. Fig Group prices the Micro tier for organisations with 1-9 staff at £299.99 + VAT. An eligible scheme-level cyber-liability benefit is arranged separately by IASME and its insurance partner.

4 min read
Read article

Technical Guides

Cyber Essentials for Okta: configuration guide

Exactly how to configure Okta (Workforce Identity) to satisfy Cyber Essentials v3.3 - MFA policies, Authentication Policies, session lifetime, break-glass accounts, and evidence patterns.

7 min read
Read article

Technical Guides

What Is the Fastest Way to Get Cyber Essentials?

Getting Cyber Essentials quickly comes down to two things: being properly prepared before you submit, and choosing a certification body that does not keep you waiting. This guide covers both.

10 min read
Read article

Technical Guides

User Access Control for Cyber Essentials v3.3: the complete pillar guide

User Access Control is the pillar of Cyber Essentials that catches the most UK organisations out at assessment. This guide walks through every v3.3 requirement - individual accounts, MFA, admin separation, joiner-mover-leaver, third-party access - and the exact evidence assessors now expect.

12 min read
Read article

Guides

Can you fail Cyber Essentials?

Yes - you can fail the Cyber Essentials self-assessment submission. Fig Group includes three free re-submissions; feedback helps you correct gaps, subject to the applicable assessment window.

5 min read
Read article

Guides

Does Cyber Essentials cover GDPR?

No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; GDPR is a data-protection regulation covering lawful basis, rights, transfers, and accountability. They overlap at the technical-security boundary but neither replaces the other.

5 min read
Read article

Technical Guides

Cyber Essentials for Chromebook / ChromeOS: configuration guide

How ChromeOS maps to Cyber Essentials: supported updates, application controls, Google Admin policies and evidence. Chromebooks can be the easiest device class for a suitable managed fleet.

6 min read
Read article

Compliance

Best Cyber Essentials Certification Bodies in the UK (2026)

A straightforward comparison of IASME-licensed Cyber Essentials certification bodies in the UK. We look at published pricing, turnaround times, support, and what each body actually offers.

11 min read
Read article

Compliance

Cyber Essentials Certification Body Pricing Compared (2026)

We compare published pricing from IASME-licensed certification bodies across all organisation sizes. The differences are larger than you might expect.

9 min read
Read article
Show more articles

111 more articles available

Stay Updated

Get Compliance Insights Delivered

Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.

We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.