
We are pleased to confirm that vIT4u has successfully renewed its Cyber Essentials Plus certification for another year.
That sounds impressive, but certificates and badges only matter when they mean something in practice.
So, what does Cyber Essentials Plus mean for us, for our customers and for organisations considering working with us?
What is Cyber Essentials Plus?
Cyber Essentials is a UK Government-backed scheme designed to protect organisations against the most common types of cyberattack.
It concentrates on five fundamental areas:
- Firewalls and secure internet connections
- Secure configuration of devices and software
- User access control
- Protection against malware
- Security updates and patching
Cyber Essentials Plus covers the same technical controls as the standard Cyber Essentials certification. The important difference is that it does not rely solely on a self-assessment.
An independent assessor carries out technical testing to verify that the controls have been implemented and are operating effectively.
In simple terms, we have not just said that our security measures are in place. They have been independently tested.
What does the renewal mean for vIT4u?
Renewing Cyber Essentials Plus requires us to examine our own systems, devices, accounts and security processes against a recognised standard.
It provides external evidence that we have fundamental protections in place across the technology we use to operate our business.
That matters particularly to us because, as an IT provider, customers trust us with access to systems, devices and commercially sensitive information.
Our renewal demonstrates that we:
- Apply recognised security standards within our own business
- Keep devices and software appropriately secured and updated
- Restrict access to systems and information
- Use technical measures to reduce exposure to common attacks
- Are prepared to have our controls independently examined
It also holds us accountable. Cyber Essentials Plus certification lasts for 12 months, so maintaining it is not a one-off exercise. It requires us to revisit our security every year and demonstrate that the controls remain effective.
What does it mean for our customers?
No certification can guarantee that an organisation will never experience a security incident.
Cyber Essentials Plus should not be presented as a guarantee of perfect security, nor does it replace wider controls such as staff training, monitoring, backups, incident response and business continuity planning.
What it does provide is independent assurance that important baseline protections have been checked.
For our customers, that means they do not simply have to take our word for it when we say that we take cyber security seriously.
They have evidence that:
- Our own environment has been assessed
- Common weaknesses have been addressed
- Fundamental technical controls have been independently tested
- We subject ourselves to standards similar to those we recommend to customers
Cyber Essentials is designed to reduce exposure to common internet-based attacks, including attacks that use widely available tools to exploit weak configurations, excessive permissions or outdated software.
For customers assessing the security of their supply chain, that evidence can make their due diligence simpler and more meaningful.
What does it mean for prospective customers?
Choosing an IT provider is a decision based heavily on trust.
An IT company may have administrative access to devices, cloud platforms, email systems, backups and sensitive business information. A weakness within the provider could therefore create risks for its customers.
Prospective customers should be asking questions such as:
- How does the provider secure its own systems?
- Are its claims independently verified?
- Does it follow the same advice it gives its customers?
- Can it provide evidence rather than reassurance alone?
Our Cyber Essentials Plus certification helps us answer those questions.
It shows that we are willing to be tested, not simply trusted.
It may also help organisations that have supplier-security requirements, work with regulated customers or intend to bid for certain public-sector contracts. Current UK procurement guidance requires Cyber Essentials or Cyber Essentials Plus for some contracts involving particular cyber risks, although the exact requirement depends on the contract.
Why should anybody care?
Most successful cyberattacks do not begin with highly sophisticated techniques.
They frequently begin with more ordinary weaknesses:
- Unpatched software
- Insecurely configured devices
- Unnecessary administrator access
- Poorly protected accounts
- Services exposed to the internet
- Inadequate malware protection
Cyber Essentials focuses on getting these foundations right.
The NCSC describes it as the minimum cyber security standard recommended by the Government for organisations of all sizes.
IASME also reports insurance data indicating that organisations holding Cyber Essentials certification are substantially less likely to make a cyber-insurance claim than organisations without it. This does not mean certification prevents every incident, but it does support the value of consistently applying basic controls.
Certification is evidence, not the finish line
We are proud to have renewed our Cyber Essentials Plus certification.
But the real value is not the logo.
It is the discipline behind it: reviewing our systems, correcting weaknesses, maintaining appropriate controls and allowing an independent assessor to verify the result.
Cyber Essentials Plus is one part of our wider approach to security. It does not mean that risk has disappeared, but it does demonstrate that we are taking practical, independently verified steps to manage it.
For our customers and prospects, the message is straightforward:
You should not have to rely on hope when choosing an IT provider. You should be able to ask: where is your proof?
Our renewed Cyber Essentials Plus certification is one part of ours.


