Skip to main content

Pathways: exploring a new way to achieve Cyber Essentials certification

For large, complex firms struggling with the prescriptiveness of Cyber Essentials, ‘Pathways’ will provide a new route to certification.

iStock.com/Yellow Duck

Now in its 10th year, the Cyber Essentials scheme continues to help organisations reduce the risk from internet-based, ‘commodity’ cyber attacks. 

For many years we struggled to properly measure its impact, but now we know; insurance data shows that organisations with Cyber Essential (CE) certification are 80% less likely to make a claim*.

However, we also know that some organisations struggle to provide evidence that the 5 technical controls required for CE certification have been met. For example, there are some legitimate reasons why organisations (a construction organisation, for example) must retain legacy software. Or why  - perhaps a university -  must support a bring your own device (BYOD) approach. Without CE certification, these organisations may struggle to access government contracts or grants. 

With this in mind, we worked with Cabinet Office on the latest version of the Cyber Essentials Policy Procurement Notice, which now allows for alternative evidence to be provided. That said, it still needs procurement folks to be able to assess and make a judgement on equivalency - which is not a trivial task, as I explained in my last blog post. 

So, we wanted to find a way forward that would help companies that struggle with the controls,  and also help take the burden away from procurement folks.

That was the genesis of our ‘Cyber Essentials Pathways’ experiment; to explore how organisations could gain a Cyber Essentials Certificate by demonstrating they were achieving the same overall outcome, rather than by implementing the individual security controls.

This effectively provides an alternative 'pathway' to achieving certification. Of course, Pathways isn’t going to replace the way organisations can get certified - the vast majority of organisations will continue to follow the existing routes.  Pathways will be a complementary solution for complex use cases, when the security controls cannot be evidenced. 

Threat models and capabilities

Cyber Essentials is based on what we term a ‘commodity capability’ threat model, equating to ‘Intermediate’ in the STIX Threat Actor Sophistication Definitions. We’ve adapted this model for Pathways, so we may be looking to detect or deter movement from (for example) an unpatched device used in BYOD implementation.

In this example, the question that arose was ‘What actions would fall within 'commodity capability’, and what would be considered more sophisticated? And of course, it gets more complicated when you look at attacks that include multiple compromises, where each compromise uses a commodity capability.

Ultimately, it is for the CE assessor to use their professional judgement and experience to determine when the capabilities deployed are moving into the territory of a more sophisticated threat actor. What they have to ask themselves is “Am I going further than I would if I was assessing Cyber Essentials Plus?” 

This clearly requires more expertise, and will affect the cost of Pathways (which I cover below). 

Where there was good alignment between the people responsible for achieving a certificate and those responsible for operating the system(s), the testing went pretty smoothly. Where there wasn’t that alignment things were less straight forward, and often took a lot longer.

Organisational governance

Our testing reinforced how essential it is for any organisation considering Pathways to ensure everyone is aligned and bought into the overall objective. In large, complex organisations, that often means buy-in at quite senior levels. That is particularly the case where investment may be needed to gain certification. This isn’t just an issue for Pathways; it’s not uncommon for the people responsible for gaining a certificate to have little influence over the things that need to be done to achieve it, leaving them in a no-win situation. 

The Pathways approach also needs more skilled and experienced practitioners to carry out the testing. Inevitably this will lead to higher costs for this type of assessment. Whilst we have been working with DSIT to help close the skills gap, inevitably these skills are highly sought after and demand a premium. 

We expect the Pathways route is most likely to be taken by organisations seeking government contracts who have struggled to gain a certificate via existing routes. It’s ultimately a business decision whether the contract value is worth the cost of the certificate.

Alternatively, it may be better to invest in fixing the things that prevented organisations gaining a certificate in the first place. In fact, whilst we were developing the Pathways approach, trial organisations participated in two rounds of ‘experiments’, allowing us to refine the testing process and then to fix problems. After the first round, a number of organisations managed to achieve certification through the traditional Cyber Essentials route. It would appear that the close engagement they had with their Certification Body during the first phase enabled them to resolve the issues that had prevented them achieving certification. 

Often Certification Bodies carry out an assessment without any prior discussions; indeed some may feel that having those discussions may introduce a conflict of interest. However, a closer engagement to help the organisation better understand the requirements (either pre-test support from the CB that carries out the assessment, or from a company offering the Cyber Advisor service) appears to have real benefit on a positive result. Perhaps even negating the need to take the Pathways route in certain circumstances! 

What’s next?

The results of the Pathways experiment have been really positive. It has taken a little longer than we first thought, but we wanted to ensure we had built a good evidence base on the efficacy of the approach and that any future service could be delivered in a consistent way by multiple organisations. We’ve still got more work to do on the latter but a follow-up Blog by Anne W will give more details as we now move to a wider Proof of Concept.

 

Chris Ensor
Deputy Director Cyber Skills and Growth

 

* Insurers data shows that companies with Cyber Essentials controls in place made 80% fewer claims than those without.
 

Written by

Chris Ensor

Deputy Director National Resilience Capabilities, NCSC

Published