Compliance, security, and AI insights.
Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.
Showing 36 of 183 articles
Articles
Technical Guides
MFA for Microsoft 365: the Cyber Essentials v3.3 configuration
Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.
Read articleTechnical Guides
MFA for Google Workspace: the Cyber Essentials v3.3 setup
Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.
Read articleTechnical Guides
MFA conditional access under Cyber Essentials v3.3: what works, what fails
Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.
Read articleTechnical Guides
Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.
Read articleTechnical Guides
Cyber Essentials v3.3 and passwordless authentication: what the scheme allows
Passwordless sign-in with FIDO2, Windows Hello, and mobile credentials is rising fast. This article explains how v3.3 treats passwordless authentication and what to declare in the self-assessment.
Read articleTechnical Guides
Cyber Essentials v3.3 and device unlock: what the scheme expects
Device unlock for Cyber Essentials v3.3: six-character device-only passwords or PINs, brute-force protection, biometrics and credentials also used for authentication.
Read articleTechnical Guides
Cyber Essentials v3.3 sub-set scoping: when and how to exclude
Cyber Essentials subset scope must be well-defined, separately managed and agreed with the certification body. Learn the firewall/VLAN boundary and stricter unsupported-software rule.
Read articleTechnical Guides
Cyber Essentials v3.3: admin account requirements and stronger authentication
Individual administrator credentials, separate day and admin accounts, effective MFA and optional phishing-resistant authentication and emergency-access hardening.
Read articleTechnical Guides
Cyber Essentials for remote and hybrid workforces: scope, home routers, and what v3.3 actually requires
Cyber Essentials scope for remote and hybrid teams: ordinary private home routers are excluded, organisation-supplied routers are included, and work devices and cloud services need applicable controls.
Read articleGuides
Can a sole trader get Cyber Essentials?
Yes - sole traders can get Cyber Essentials. A one-person business qualifies for Fig Group's Micro tier at £299.99 + VAT. Buyers still decide eligibility against their contract, entity and scope requirements.
Read articleGuides
Is Cyber Essentials a legal requirement?
Cyber Essentials is not a general UK legal requirement. Check the actual tender, MOD contract, insurer conditions and permitted equivalent controls.
Read articleGuides
Does Cyber Essentials cover cloud services?
Yes - Cyber Essentials explicitly covers cloud services under v3.3. Microsoft 365, Google Workspace, AWS, Azure, and any SaaS application holding organisational data are all in scope, with specific configuration expectations around MFA, tenant settings, and managed updates.
Read articleTechnical Guides
Cyber Essentials and patch management (WSUS, Intune, third-party)
How to evidence Cyber Essentials v3.3 patching - 14-day SLA for high/critical CVEs, WSUS deployment patterns, Intune Update Rings, third-party patching (Action1, PDQ, NinjaOne), and the audit artefacts assessors want.
Read articleCompany
What Is Fig Group? The MSP Compliance Platform, Not Financial Institutions Group
What MSPs can do with the Fig Group platform: manage client compliance, risk, monitoring and evidence, with separately licensed certification services.
Read articleCompany
Fig Group vs Financial Institutions Group: Clearing Up the Confusion
Compare the investment banking term Financial Institutions Group with Fig Group, the UK cybersecurity and compliance business serving MSPs and other organisations.
Read articleMSPs
Choosing a Cyber Essentials Certified MSP in the UK
If you need an MSP that is itself Cyber Essentials certified (and can help you achieve it), this guide explains what "CE-certified MSP" really means and how to evaluate one.
Read articleCompliance
How Long Does Cyber Essentials Take? Honest Timelines for 2026
From readiness to certificate, how long does Cyber Essentials really take? This guide walks through every stage with realistic timelines and the factors that speed it up or slow it down.
Read articleFinancial Services
Cyber Essentials for Financial Services: FCA, PRA and Client Expectations
Financial services firms face unique scrutiny on cyber controls. Where does Cyber Essentials fit alongside FCA SYSC, PRA SS1/21, and client due-diligence expectations?
Read articleCompliance
UK Cyber Essentials Certification Bodies Compared (2026)
There are dozens of IASME-licensed Cyber Essentials certification bodies. This guide compares them on price, turnaround, technology, and specialism to help you pick the right one.
Read articleIndustry
Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For
The Bar Standards Board does not formally require Cyber Essentials. Solicitor firms, CPS counterparts, institutional lay clients, and insurers are increasingly asking for it. This guide covers how CE applies to a criminal barristers’ chambers in London and why the certification has become a practical necessity even without a formal mandate.
Read articleGuides
How to verify a Cyber Essentials certificate: the buyer and procurement-team guide (2026)
A supplier has sent you a PDF claiming to be their Cyber Essentials certificate. How do you confirm it is real, current, and issued to the organisation you are actually contracting with? This is the verification guide for procurement and tender-assessment teams.
Read articleGuides
What size business needs Cyber Essentials?
Cyber Essentials applies to UK organisations of every size, from sole traders to enterprises. The scheme is tiered by headcount (Micro 1-9, Small 10-49, Medium 50-249, Large 250 - 9,999) and is most commonly required for SMEs bidding for procurement work or seeking cyber insurance.
Read articleGuides
Does Cyber Essentials require a VPN?
No. Cyber Essentials does not mandate a VPN. Apply the scheme rules to each in-scope remote administration path, boundary firewall, account and cloud service; a VPN is one possible design.
Read articleTechnical Guides
Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)
Use password managers to support Cyber Essentials password controls: unique credentials, secure storage, MFA, breach monitoring, access management and useful evidence.
Read articleTechnical Guides
Security Update Management for Cyber Essentials v3.3: the complete pillar guide
Security Update Management is the quietest-looking pillar of Cyber Essentials and the one organisations most often fail on at renewal. This guide covers every v3.3 requirement - the 14-day rule, supported OS versions, mobile and firmware, cloud-service patching - and the evidence an assessor will now accept.
Read articleGuides
Who needs Cyber Essentials Plus?
Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.
Read articleGuides
Can I get Cyber Essentials Plus without Cyber Essentials?
No - Cyber Essentials Plus requires a current Cyber Essentials certificate first, or both can be completed in a single engagement. The self-assessment is identical for both levels; Plus adds hands-on technical testing by an assessor.
Read articleGuides
Can small businesses get Cyber Essentials?
Yes - Cyber Essentials is designed for UK small businesses. Fig Group prices the Micro tier for organisations with 1-9 staff at £299.99 + VAT. An eligible scheme-level cyber-liability benefit is arranged separately by IASME and its insurance partner.
Read articleTechnical Guides
Cyber Essentials for Okta: configuration guide
Exactly how to configure Okta (Workforce Identity) to satisfy Cyber Essentials v3.3 - MFA policies, Authentication Policies, session lifetime, break-glass accounts, and evidence patterns.
Read articleTechnical Guides
What Is the Fastest Way to Get Cyber Essentials?
Getting Cyber Essentials quickly comes down to two things: being properly prepared before you submit, and choosing a certification body that does not keep you waiting. This guide covers both.
Read articleTechnical Guides
User Access Control for Cyber Essentials v3.3: the complete pillar guide
User Access Control is the pillar of Cyber Essentials that catches the most UK organisations out at assessment. This guide walks through every v3.3 requirement - individual accounts, MFA, admin separation, joiner-mover-leaver, third-party access - and the exact evidence assessors now expect.
Read articleGuides
Can you fail Cyber Essentials?
Yes - you can fail the Cyber Essentials self-assessment submission. Fig Group includes three free re-submissions; feedback helps you correct gaps, subject to the applicable assessment window.
Read articleGuides
Does Cyber Essentials cover GDPR?
No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; GDPR is a data-protection regulation covering lawful basis, rights, transfers, and accountability. They overlap at the technical-security boundary but neither replaces the other.
Read articleTechnical Guides
Cyber Essentials for Chromebook / ChromeOS: configuration guide
How ChromeOS maps to Cyber Essentials: supported updates, application controls, Google Admin policies and evidence. Chromebooks can be the easiest device class for a suitable managed fleet.
Read articleCompliance
Best Cyber Essentials Certification Bodies in the UK (2026)
A straightforward comparison of IASME-licensed Cyber Essentials certification bodies in the UK. We look at published pricing, turnaround times, support, and what each body actually offers.
Read articleCompliance
Cyber Essentials Certification Body Pricing Compared (2026)
We compare published pricing from IASME-licensed certification bodies across all organisation sizes. The differences are larger than you might expect.
Read article111 more articles available
Get Compliance Insights Delivered
Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.
We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.



































