Review of Cyber Essentials influence on cyber security attitudes and behaviours in UK organisations
Introduction
The NCSC commissioned BritainThinks to perform a baseline review of Cyber Essentials to look at how the scheme has influenced cyber security attitudes and behaviours on UK organisations to date. These findings will form a baseline that can be used to show the impact of the changes to the scheme in future.
Cyber Essentials is the NCSC’s assurance product aimed to help protect UK organisations from the most common cyber threats and to demonstrate their commitment to cyber security.
Cyber Essentials two overall policy goals:
- To be open to all organisations to help mitigate their cyber security risks, with the priority that it is an effective means for SMEs to protect themselves.
- To be an effective tool for large organisations, including HMG, to help manage third-party cyber security risks.
Key findings
1. Certified organisations are more likely than non-certified organisations to be B2B (Business-to-Business) rather than B2C (Business-to-Consumer)
- Both groups are mixed in terms of business size and sector beyond this, though very few sole traders in this sample hold CE/CE+
2. Certified organisations are more likely than non-certified organisations to recognise the cyber security threats to their organisation, but they are also more likely to feel protected against those threats
- Qualitative insight suggests that for some organisations this is a causal relationship (i.e. becoming certified has improved their understanding), but for others, this greater appreciation of cyber threats is the reason to become certified
3. Organisations with CE/CE+ are more likely than those without to take further steps to improve their cyber security, beyond technical controls. They are also more likely to have identified attacks
- Qualitative insight again suggests that the relationship between certification and behaviour change is complex. Smaller organisations are typically implementing controls for the first time in order to become certified, while larger organisations often already follow them
4. Among organisations who are already certified, CE/CE+ is seen to have a positive impact on a wide range of factors, ranging from how well protected they feel, to management’s understanding of risk
- Of all factors, being certified is felt to impact most positively on customer and investor confidence. For many organisations, reassuring and attracting clients is a key motivator for gaining certification
5. Awareness and views of CE/CE+ among non-certified organisations is mixed. More than a third of non-certified organisations say they have never heard of the scheme.
- Views of the cost and value for money of CE/CE+ are particularly uncertain for this audience
Key findings against the overall policy goals
Open to all organisations to help mitigate their cyber security risks, with the priority that it is an effective means for SMEs to protect themselves
The vast majority of certified organisations surveyed feel confident in their protection against cyber attacks and, of those which claim to have been targeted by attacks, most say Cyber Essentials aided their ability to respond.
- The vast majority of certified organisations surveyed (93%) say they are confident they are protected against common, internet-based cyber attacks
- Half of certified organisations surveyed (50%) report one or more occasion in which they have been targeted by a cyber attack in the past 12 months
- Two-thirds of this group (66%) claim Cyber Essentials had a positive impact on their ability to respond to the attack(s)
An effective tool for large organisation, including HMG, to help manage third-party cyber security risks
Most certified organisations also seek to procure services in their supply chains from organisations with Cyber Essentials - though it is important to note that HMG organisations were out of the scope of this evaluation
- Most certified organisations surveyed (61%) claim they are more likely to choose suppliers with Cyber Essentials or Cyber Essentials Plus, though only 26% of non-certified organisations surveyed agree with this
Conclusion
1. These findings paint a very positive picture for the impact of the Cyber Essentials scheme overall
- Certified organisations are more likely than their non-certified counterparts to be:
- Aware of the risks posed by cyber-attacks (including at a senior level)
- Confident that they are protected from these attacks
- Implementing cyber security controls, including taking steps beyond the technical controls required to become certified
- They also tend to be positive about the scheme, particularly its impact on customer and investor confidence
2. However, this evaluation does suggest that, for medium-sized and larger organisations in particular, CE/CE+ seems to be reinforcing existing attitudes and behaviours rather than driving them
- Genuine attitudinal or behavioural change as a result of becoming certified seems to be restricted to smaller and more newly established organisations. Larger organisations are more likely to see the scheme as a seal of approval of what they already do
3. The main barrier to more organisations becoming certified seems to be a lack of knowledge about the scheme overall, and about its costs and the value it represents
- A significant proportion of non-certified organisations know little to nothing about the scheme and give neutral or uncertain views about its costs and value. This is particularly true of smaller compared to larger organisations
4. Among the organisations who have (yet) to be certified, a significant minority feel that they are already following some or even all of the technical controls (with 25% claiming to follow all of them)
- There may therefore be potency in messaging that highlights CE/CE+ as providing external assurance of the steps organisations are already taking to protect themselves, both from the perspective of peace of mind, and customer confidence
- Lower levels of uptake among B2C organisations suggests the need to emphasise benefits for retail (as well as business) customers
The recommendations (e.g. raising awareness of the scheme) from the review will be reviewed with the new Cyber Essentials partnership between NCSC and IASME, to help define the way forward. The initial discussions have taken place in which IASME have taken on the task of producing a proposal on how the recommendations can be implemented and the steps needed to deliver these. Subsequently another external review will be held in the future (e.g. 2 years) to ascertain the impact of those changes made to the Cyber Essentials scheme, resulting in more evolution in the future.
Recommendations
1. Raise awareness and knowledge of CE/CE+ among non-certified businesses
- Lack of awareness and understanding (as opposed to negative perceptions) appears to be the key barrier to uptake
- There is space for certified organisations to testify or advocate on behalf of the scheme
- Messaging could be focused on the key benefits expressed by certified organisations – namely its impact on customer confidence and value for money
2. Encourage organisations to look for CE/CE+ across their supply chain
- The data shows certified organisations are most likely to see certification as having a positive impact on customer confidence, and qualitative evidence suggests that public sector organisations requiring CE/CE+ has proven to be a successful motivation for certification
- It may be possible to build on this success by encouraging certified organisations in the private and third sectors to look for or even require CE/CE+ in their supply chains to reduce their cyber risks, particularly if there are small businesses in their supply chain
3. Use certification as an opportunity to drive other behaviours and awareness
- Gaining CE/CE+ certification is one of the first occasions in which some smaller and more recently established SMEs engage with cyber security
- This could be an effective touchpoint to signpost them towards other advice and guidance offered by the NCSC, or indeed to promote certification to others or those in their supply chain (reinforcing points 1 and 2)
- Doing so may drive continued upkeep of cyber security behaviours, and could potentially drive uptake of controls beyond those required for certification


