Compliance, security, and AI insights.
Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.
Showing 36 of 183 articles
Articles
Compliance
Cyber Essentials Renewal: What Happens After Year One?
Your Cyber Essentials certificate expires after 12 months. Here is what to expect from the renewal process, what changes year-to-year, and how to stay continuously compliant.
Read articleTechnical Guides
Cyber Essentials for Google Cloud (GCP): configuration guide
Configure GCP for Cyber Essentials v3.3 - Workspace identity, Organization Policies, Security Command Center, VPC firewalls, and OS Patch Management. Exact settings and the evidence assessors expect.
Read articleCompliance
Cyber Essentials for Government Contracts: The Complete Guide
PPN 014 applies Cyber Essentials controls proportionately to certain government and NHS contracts. This guide explains when certification or equivalent controls apply and how the tender determines the level.
Read articleCompliance
The Fastest Cyber Essentials Certification Body in the UK: Why Fig Group Stands Alone
Fig Group’s fastest positioning is based on its qualifying six-working-hour Basic commitment. Compare the current written terms, preparation and deadline needs of the named offers.
Read articleIndustry
Cyber Essentials for Estate Agents, Letting Agents, and Property Firms
Estate agents handle large volumes of personal data - IDs, bank details, AML documentation - and need appropriate safeguards. HMRC AML supervision depends on the activities and applicable legal scope. This guide covers how Cyber Essentials applies to property firms of all sizes and how it supports AML and client data compliance.
Read articleTechnical Guides
Cyber Essentials for AWS: configuration guide
How to configure an AWS account for Cyber Essentials v3.3 - IAM with MFA, SCPs, Security Hub baseline, Security Groups, and Systems Manager Patch Manager. Specific settings and evidence expectations.
Read articleGuides
Cyber Essentials Salisbury: a practical certification guide
Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.
Read articleTechnical Guides
Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.
Read articleFrameworks
Cyber Essentials to ISO 27001: Building Your Compliance Journey
Cyber Essentials is a foundation, but ISO 27001 is the gold standard for comprehensive security. This guide walks you through the progression path, explains when to move up, and outlines the practical steps to advance from basic compliance to certification.
Read articleIndustry
Indelible Data review: Cyber Essentials in 2026
A factual review of Indelible Data as a Cyber Essentials certification body - their regional volume model, pricing guidance, and where Fig Group differs on price, speed, and platform delivery.
Read articleAI & Security
AI-Powered Compliance: How Codex, Claude, and Copilot Support Security Operations
AI coding assistants like GitHub Copilot, OpenAI Codex, and Claude are changing how security teams and compliance professionals handle day-to-day operations. Discover how these tools enhance compliance operations and where Fig Group fits in the AI-powered security stack.
Read articleIndustry
Can you buy Cyber Essentials directly from IASME? (2026)
Can you buy Cyber Essentials directly from IASME itself, or must you go through a licensed certification body? The answer, plus how IASME's role as scheme operator compares to licensed CBs like Fig Group.
Read articleIndustry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleIndustry
Pentest People review: Cyber Essentials in 2026
A dated look at the Pentest People heritage within WorkNest Secure, its security services and the checks to make before comparing a Cyber Essentials quote with Fig Group.
Read articleCompliance
Why Does Cyber Essentials Certification Take So Long? It Does Not Have To.
Cyber Essentials timing depends on preparation, assessor review and any corrections. Fig Group publishes a conditional six-working-hour Basic guarantee after a complete, compliant submission; here is how to compare the clocks.
Read articleMSP Growth
Why MSPs Should Offer Compliance-as-a-Service in 2026
Compliance is becoming table stakes in the MSP industry. This article makes the business case for adding compliance monitoring and certification services to your MSP offering, with detailed margin analysis and go-to-market strategy.
Read articleIndustry
NormCyber review: Cyber Essentials in 2026
A factual review of NormCyber as a Cyber Essentials certification body - their MSSP model with SOC and managed services, pricing guidance, and where Fig Group differs.
Read articleGuides
Cyber Essentials Slough: a practical certification guide
Using professionally managed hosting does not automatically make an organisation Cyber Essentials compliant. For a Slough technology business, the important preparation step is to distinguish the facility, the hosted service and the controls that remain with the company using or administering them.
Read articleIndustry
QG Management Standards review: Cyber Essentials in 2026
A factual review of QG Management Standards as a Cyber Essentials certification body - their multi-standard certification body model, pricing guidance, and where Fig Group differs.
Read articleFrameworks
Cyber Essentials 2026: The Complete Certification Guide
Cyber Essentials remains the UK's benchmark for basic security. This comprehensive guide covers the v3.3 requirements, CE vs CE Plus, costs, certification timeline, and how to prepare.
Read articleIndustry
Cyber Essentials for Schools, Colleges, and Universities
Cyber Essentials is increasingly expected across UK education. DfE guidance, Jisc recommendations, and funder due diligence are pushing schools and further / higher education institutions toward certification. This guide covers how the controls apply to education-specific infrastructure.
Read articleIndustry
Cyber Security Associates (CSA) review: Cyber Essentials in 2026
A factual review of Cyber Security Associates (CSA) as a Cyber Essentials certification body - their Gloucester-based SOC + consultancy model, pricing guidance, and where Fig Group differs.
Read articleCompliance
The NIS2 Directive: What UK Businesses Need to Know in 2026
NIS2 guidance for UK businesses: determine entity, sector, size and jurisdiction, then separate EU national-law duties from contractual supply-chain requirements and UK legislation.
Read articleIndustry
URM Consulting review: Cyber Essentials in 2026
A factual review of URM Consulting as a Cyber Essentials certification body - their ISO 27001-heavy consultancy reputation, pricing guidance, and where Fig Group differs on price and speed.
Read articleIndustry
IT Governance review: Cyber Essentials in 2026
A factual review of IT Governance as a Cyber Essentials certification body - parent GRC International Group, consultancy and training reputation, pricing guidance, and where Fig Group differs.
Read articleIndustry
Bulletproof review: Cyber Essentials in 2026
A review of Bulletproof Cyber, now part of WorkNest Secure: its wider security services, how to check current Cyber Essentials terms, and where Fig Group differs.
Read articleIndustry
Cyber Essentials for Construction Companies and Contractors
Construction firms bidding for government infrastructure work, MOD contracts, or public-sector framework places are increasingly required to hold Cyber Essentials. This guide covers how the controls apply to construction-specific infrastructure, including site laptops, tablets, and BIM platforms.
Read articleIndustry
CyberSmart review: Cyber Essentials in 2026
A factual review of CyberSmart as a Cyber Essentials certification body - who they are, their platform and pricing model, where they excel, and where Fig Group differs on price, speed, and delivery.
Read articleIndustry
Cyber Essentials for NHS Suppliers and Healthcare Organisations
How Cyber Essentials, DSPT and NHS supplier assurance fit together. Check the current organisation profile, actual tender and clinical-system scope rather than assume a universal mandate.
Read articleCompany
Fig Group: The Story Behind the Name and Our Mission in MSP Compliance
The meaning of Fig Group today: a UK business connecting MSP compliance software, security services and licensed certification assessments.
Read articleTechnical Guides
Cyber Essentials Tender Deadline Emergency: The 48-Hour Playbook
You have 48 hours until the tender closes and you have just discovered it requires Cyber Essentials. This is the hour-by-hour playbook I give to every organisation in this situation. It works more often than you might expect.
Read articleIndustry
Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.
Read articleCompany
No, Fig Group Does Not Stand for Financial Institutions Group
Fig Group is the UK cybersecurity and compliance business behind an MSP platform and licensed certification services. Its name does not mean Financial Institutions Group.
Read articleIndustry
Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.
Read articleTechnical Guides
Cyber Essentials Scoping: What Is In, What Is Out, and How to Not Get It Wrong
Scoping is the single most misunderstood part of the Cyber Essentials submission. Get it wrong and your whole assessment is compromised. This guide covers remote workers, BYOD, cloud services, legacy systems, sub-set scoping, and the five scoping traps that most often fail assessments.
Read articleTechnical Guides
The 14-Day Patching Rule: What It Actually Says and How to Stay Compliant
The 14-day patching requirement is the single most common reason Cyber Essentials submissions fail first time. Here is what the rule actually says, when the clock starts, and how to evidence compliance when users are on holiday, vendors are slow, and legacy systems will not update.
Read article39 more articles available
Get Compliance Insights Delivered
Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.
We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.



































