Skip to content
Blog

Compliance, security, and AI insights.

Expert guidance on compliance frameworks, security operations, AI-powered tooling, and building compliant MSP businesses. Read articles from Fig Group and industry leaders.

Showing 36 of 183 articles

Articles

Compliance

Cyber Essentials Renewal: What Happens After Year One?

Your Cyber Essentials certificate expires after 12 months. Here is what to expect from the renewal process, what changes year-to-year, and how to stay continuously compliant.

5 min read
Read article

Technical Guides

Cyber Essentials for Google Cloud (GCP): configuration guide

Configure GCP for Cyber Essentials v3.3 - Workspace identity, Organization Policies, Security Command Center, VPC firewalls, and OS Patch Management. Exact settings and the evidence assessors expect.

7 min read
Read article

Compliance

Cyber Essentials for Government Contracts: The Complete Guide

PPN 014 applies Cyber Essentials controls proportionately to certain government and NHS contracts. This guide explains when certification or equivalent controls apply and how the tender determines the level.

9 min read
Read article

Compliance

The Fastest Cyber Essentials Certification Body in the UK: Why Fig Group Stands Alone

Fig Group’s fastest positioning is based on its qualifying six-working-hour Basic commitment. Compare the current written terms, preparation and deadline needs of the named offers.

7 min read
Read article

Industry

Cyber Essentials for Estate Agents, Letting Agents, and Property Firms

Estate agents handle large volumes of personal data - IDs, bank details, AML documentation - and need appropriate safeguards. HMRC AML supervision depends on the activities and applicable legal scope. This guide covers how Cyber Essentials applies to property firms of all sizes and how it supports AML and client data compliance.

10 min read
Read article

Technical Guides

Cyber Essentials for AWS: configuration guide

How to configure an AWS account for Cyber Essentials v3.3 - IAM with MFA, SCPs, Security Hub baseline, Security Groups, and Systems Manager Patch Manager. Specific settings and evidence expectations.

7 min read
Read article

Guides

Cyber Essentials Salisbury: a practical certification guide

Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.

5 min read
Read article

Technical Guides

Cyber Essentials for Microsoft Azure: configuration guide

Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.

7 min read
Read article

Frameworks

Cyber Essentials to ISO 27001: Building Your Compliance Journey

Cyber Essentials is a foundation, but ISO 27001 is the gold standard for comprehensive security. This guide walks you through the progression path, explains when to move up, and outlines the practical steps to advance from basic compliance to certification.

9 min read
Read article

Industry

Indelible Data review: Cyber Essentials in 2026

A factual review of Indelible Data as a Cyber Essentials certification body - their regional volume model, pricing guidance, and where Fig Group differs on price, speed, and platform delivery.

5 min read
Read article

AI & Security

AI-Powered Compliance: How Codex, Claude, and Copilot Support Security Operations

AI coding assistants like GitHub Copilot, OpenAI Codex, and Claude are changing how security teams and compliance professionals handle day-to-day operations. Discover how these tools enhance compliance operations and where Fig Group fits in the AI-powered security stack.

5 min read
Read article

Industry

Can you buy Cyber Essentials directly from IASME? (2026)

Can you buy Cyber Essentials directly from IASME itself, or must you go through a licensed certification body? The answer, plus how IASME's role as scheme operator compares to licensed CBs like Fig Group.

5 min read
Read article

Industry

Cyber Essentials for Financial Services and Fintech

FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.

11 min read
Read article

Industry

Pentest People review: Cyber Essentials in 2026

A dated look at the Pentest People heritage within WorkNest Secure, its security services and the checks to make before comparing a Cyber Essentials quote with Fig Group.

5 min read
Read article

Compliance

Why Does Cyber Essentials Certification Take So Long? It Does Not Have To.

Cyber Essentials timing depends on preparation, assessor review and any corrections. Fig Group publishes a conditional six-working-hour Basic guarantee after a complete, compliant submission; here is how to compare the clocks.

6 min read
Read article

MSP Growth

Why MSPs Should Offer Compliance-as-a-Service in 2026

Compliance is becoming table stakes in the MSP industry. This article makes the business case for adding compliance monitoring and certification services to your MSP offering, with detailed margin analysis and go-to-market strategy.

8 min read
Read article

Industry

NormCyber review: Cyber Essentials in 2026

A factual review of NormCyber as a Cyber Essentials certification body - their MSSP model with SOC and managed services, pricing guidance, and where Fig Group differs.

5 min read
Read article

Guides

Cyber Essentials Slough: a practical certification guide

Using professionally managed hosting does not automatically make an organisation Cyber Essentials compliant. For a Slough technology business, the important preparation step is to distinguish the facility, the hosted service and the controls that remain with the company using or administering them.

5 min read
Read article

Industry

QG Management Standards review: Cyber Essentials in 2026

A factual review of QG Management Standards as a Cyber Essentials certification body - their multi-standard certification body model, pricing guidance, and where Fig Group differs.

5 min read
Read article

Frameworks

Cyber Essentials 2026: The Complete Certification Guide

Cyber Essentials remains the UK's benchmark for basic security. This comprehensive guide covers the v3.3 requirements, CE vs CE Plus, costs, certification timeline, and how to prepare.

10 min read
Read article

Industry

Cyber Essentials for Schools, Colleges, and Universities

Cyber Essentials is increasingly expected across UK education. DfE guidance, Jisc recommendations, and funder due diligence are pushing schools and further / higher education institutions toward certification. This guide covers how the controls apply to education-specific infrastructure.

11 min read
Read article

Industry

Cyber Security Associates (CSA) review: Cyber Essentials in 2026

A factual review of Cyber Security Associates (CSA) as a Cyber Essentials certification body - their Gloucester-based SOC + consultancy model, pricing guidance, and where Fig Group differs.

5 min read
Read article

Compliance

The NIS2 Directive: What UK Businesses Need to Know in 2026

NIS2 guidance for UK businesses: determine entity, sector, size and jurisdiction, then separate EU national-law duties from contractual supply-chain requirements and UK legislation.

9 min read
Read article

Industry

URM Consulting review: Cyber Essentials in 2026

A factual review of URM Consulting as a Cyber Essentials certification body - their ISO 27001-heavy consultancy reputation, pricing guidance, and where Fig Group differs on price and speed.

5 min read
Read article

Industry

IT Governance review: Cyber Essentials in 2026

A factual review of IT Governance as a Cyber Essentials certification body - parent GRC International Group, consultancy and training reputation, pricing guidance, and where Fig Group differs.

6 min read
Read article

Industry

Bulletproof review: Cyber Essentials in 2026

A review of Bulletproof Cyber, now part of WorkNest Secure: its wider security services, how to check current Cyber Essentials terms, and where Fig Group differs.

6 min read
Read article

Industry

Cyber Essentials for Construction Companies and Contractors

Construction firms bidding for government infrastructure work, MOD contracts, or public-sector framework places are increasingly required to hold Cyber Essentials. This guide covers how the controls apply to construction-specific infrastructure, including site laptops, tablets, and BIM platforms.

10 min read
Read article

Industry

CyberSmart review: Cyber Essentials in 2026

A factual review of CyberSmart as a Cyber Essentials certification body - who they are, their platform and pricing model, where they excel, and where Fig Group differs on price, speed, and delivery.

6 min read
Read article

Industry

Cyber Essentials for NHS Suppliers and Healthcare Organisations

How Cyber Essentials, DSPT and NHS supplier assurance fit together. Check the current organisation profile, actual tender and clinical-system scope rather than assume a universal mandate.

11 min read
Read article

Company

Fig Group: The Story Behind the Name and Our Mission in MSP Compliance

The meaning of Fig Group today: a UK business connecting MSP compliance software, security services and licensed certification assessments.

2 min read
Read article

Technical Guides

Cyber Essentials Tender Deadline Emergency: The 48-Hour Playbook

You have 48 hours until the tender closes and you have just discovered it requires Cyber Essentials. This is the hour-by-hour playbook I give to every organisation in this situation. It works more often than you might expect.

9 min read
Read article

Industry

Cyber Essentials for Recruitment Agencies: A Practical Guide

Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.

10 min read
Read article

Company

No, Fig Group Does Not Stand for Financial Institutions Group

Fig Group is the UK cybersecurity and compliance business behind an MSP platform and licensed certification services. Its name does not mean Financial Institutions Group.

2 min read
Read article

Industry

Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations

Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.

10 min read
Read article

Technical Guides

Cyber Essentials Scoping: What Is In, What Is Out, and How to Not Get It Wrong

Scoping is the single most misunderstood part of the Cyber Essentials submission. Get it wrong and your whole assessment is compromised. This guide covers remote workers, BYOD, cloud services, legacy systems, sub-set scoping, and the five scoping traps that most often fail assessments.

13 min read
Read article

Technical Guides

The 14-Day Patching Rule: What It Actually Says and How to Stay Compliant

The 14-day patching requirement is the single most common reason Cyber Essentials submissions fail first time. Here is what the rule actually says, when the clock starts, and how to evidence compliance when users are on holiday, vendors are slow, and legacy systems will not update.

14 min read
Read article
Show more articles

39 more articles available

Stay Updated

Get Compliance Insights Delivered

Receive new articles on compliance frameworks, security operations, and MSP growth delivered to your inbox.

We respect your privacy. Unsubscribe at any time. No spam, just timely, relevant insights.