Skip to main content

Introducing Cyber Advisors...

Launching a new Industry Assurance scheme aimed at helping the UK’s small organisations.
Decorative image Image credit: iStock.com/Visual Generation
Image credit: iStock.com/Visual Generation

This blog marks a rather special moment; it’s not often we launch a new Industry Assurance scheme - particularly one that is specifically aimed at helping the UK’s SMEs… So, that’s why I’m excited to tell you more about the NCSC’s new Cyber Advisor scheme, which we are delivering in partnership with IASME. We formally launched Cyber Advisor as a permanent scheme at CYBERUK in Belfast this week.

First things first - what is the Cyber Advisor Scheme and who is it for?

Cyber Advisor is a targeted consultancy scheme aimed primarily at small organisations. Such organisations often lack in-house expertise or easy access to qualified people who can help them to secure their networks. And, because they often have limited time and funds to invest in security, it can be hard for a small organisation, whether it's a business, a school or a charity, to know where to focus what resources they do have.

This is where Cyber Advisors can help. In this first iteration, Cyber Advisors will provide cost-effective advice and, where required, hands-on help to implement the five Cyber Essentials Technical Controls. We are calling them Cyber Advisors (Cyber Essentials) to differentiate them from any future Cyber Advisors offering a different ‘specialism’.

Why link it to Cyber Essentials?

We believe the Cyber Essentials Technical Controls mitigate the majority of high volume, low-skill attacks perpetrated through the Internet. Therefore, one of the easiest ways to make the UK more secure is to help organisations to implement the Technical Controls at scale across the UK.

You might be wondering whether this is a way of increasing Cyber Essentials certificate numbers. Well, obviously, we love to talk about how many certificates have been issued but if you work with a Cyber Advisor, you are not then obliged to apply for a Cyber Essentials certificate – unless you want or need to.

Perhaps you are wondering how you’ll know the Advisors will be good and you’ll have a positive experience with them.

Every Cyber Advisor must pass an independent assessment - the catchily titled Certificate of Competence in Cyber Essentials Implementation. The assessment tests an individual’s knowledge and understanding of the Technical Controls, their competence in doing practical, hands-on IT configuration and support, and their ability to understand and work with small organisations.

But the assurance doesn’t end with the individual Advisor. All Cyber Advisors work for companies that have met our requirements and been accepted as an Assured Service Provider for the Cyber Advisor service.

At launch, more than 20 companies are ready to offer the Cyber Advisor (Cyber Essentials) service - there is at least one in every nation of the UK and in the Channel Islands too. However, there is potential and capacity for many hundreds more companies and Advisors to come on board so please do visit the webpages if you want to know more about joining the Scheme.

Companies of any size can apply to join and we particularly welcome companies located in or serving geographically remote or under-represented areas. Similarly, if your company is working hard to address issues of under-representation in the cyber security workforce, we’d love you to be part of the Scheme.

At the NCSC, we are taking action to remove artificial barriers to entry to all of our Schemes. So, if you spot something which you think unfairly prevents you from applying, please let us know.

Catherine H2
Head of Assured Professional Schemes, Industry Assurance

Written by

Catherine H Head of Assured Professional Services Schemes, Industry Assurance, NCSC