BLUE STROKES DIGITAL SOLUTIONS
  • Home
  • Services
  • Pricing
  • Free Check
  • About
  • Training
  • Insights
  • Contact
Free Scoping Call
🏠 Home 🛡️ Services 💷 Pricing 📊 Free Readiness Check 👥 About 🎓 Training 📰 Insights 📞 Contact
Cyber Essentials · Security · IT Support

Strong Security,
Simply Delivered.
For teams without a security team.

We guide small organisations and charities through Cyber Essentials certification, close the gaps that put you at risk, and keep your defences current — with fixed pricing, plain English, and no unnecessary complexity.

Book a Free Scoping Call Free Readiness Check →
5
Controls to certify
2–4
Weeks typical
£25k
Insurance included*
100%
Remote delivery
✅
Certification
Cyber Essentials
🔐
Cloud Accounts
MFA Enabled
🔄
Security Updates
Within 14 Days
🏛️ Government-backed scheme
📋 Current Danzell question set (v3.3)
💷 Fixed-fee quotes
🤝 Reduced charity rates
💻 Delivered remotely
Cyber Essentials Cyber Essentials Plus IASME Cyber Assurance ISO/IEC 27001 UK GDPR NIST CSF CIS Controls Microsoft 365 Google Workspace NIS2 Cyber Essentials Cyber Essentials Plus IASME Cyber Assurance ISO/IEC 27001 UK GDPR NIST CSF CIS Controls Microsoft 365 Google Workspace NIS2
Why It Matters

Most attacks aren't sophisticated.
They're opportunistic.

The overwhelming majority of incidents that affect smaller organisations don't involve advanced techniques. They involve a missing multi-factor prompt, an unpatched laptop, a shared password, or a convincing email on a busy Friday afternoon.

Cyber Essentials exists precisely because these basics stop most of it. Getting certified forces the fundamentals into place — and gives you something concrete to show clients, funders, insurers and boards.

  • Win contracts that require certification as a supplier condition
  • Give trustees and directors documented assurance
  • Reduce the human and technical gaps attackers actually use
  • Build a foundation you can extend to ISO 27001 later
What You Get

A certification, and a security posture worth certifying.

Some providers will walk you through a questionnaire and leave. We'd rather your answers be true. That means fixing what's broken first, then certifying — so the badge on your website reflects reality.

🎯
Scoped Properly
We define what's in scope before you pay for anything
🔧
Gaps Fixed
Hands-on remediation, not just a list of problems
📄
Submission Support
We help you answer accurately and evidence it
🔁
Annual Renewal
We keep you certified year after year
The Framework

The Five Controls That Stop Most Attacks

Cyber Essentials is built on five technical controls. Get these right and you close the door on the overwhelming majority of common internet-borne threats.

Control 01
🧱
Firewalls
Boundary and device firewalls configured to block unnecessary inbound traffic.
Control 02
⚙️
Secure Configuration
Default passwords removed, unused accounts and services disabled, devices hardened.
Control 03
🔄
Security Update Management
Critical and high-severity patches applied within fourteen days. Unsupported software removed.
Control 04
🔐
User Access Control
Least privilege, separate admin accounts, and multi-factor authentication on cloud services.
Control 05
🦠
Malware Protection
Anti-malware, application allow-listing or sandboxing across in-scope devices.
2026 update: New assessments now use the Danzell question set against version 3.3 of the requirements. Multi-factor authentication is mandatory for cloud services wherever it's available, cloud services can no longer be excluded from scope, and the fourteen-day patching window is strictly enforced. Several of these are automatic failures — which is exactly why preparation matters.
What We Do

Services Built Around Smaller Organisations

Everything below is scoped and priced for teams that don't have a dedicated security function — and delivered by people who explain things properly.

🛡️
Cyber Essentials Certification

End-to-end support: scoping, gap assessment, hands-on remediation, and guided submission under the current Danzell question set.

Learn more →
🏅
Cyber Essentials Plus

Readiness preparation and remediation for the independently audited tier, including pre-audit testing so there are no surprises.

Learn more →
🔍
Security Posture Assessment

A clear picture of where you stand, what your real risks are, and a prioritised roadmap you can actually afford to work through.

Learn more →
☁️
Microsoft 365 & Cloud Hardening

MFA rollout, conditional access, secure baselines and licence-appropriate configuration for the platforms your team lives in.

Learn more →
📋
Data Protection & GDPR

Data mapping, impact assessments, policies that people will actually read, and ongoing data protection officer support.

Learn more →
🎓
Security Awareness Training

Short, practical staff training and phishing simulations that build judgement rather than just ticking a compliance box.

Learn more →
View All Services
Who We Work With

Organisations That Need Security to Be Practical

Different sectors, same underlying problem: real obligations, real risk, and no in-house security team to hand it to.

💚
Charities & Non-Profits
Donor and beneficiary data, grant conditions, and trustee accountability — on a tight budget.
⚖️
Professional Services
Law, accountancy and consultancy firms holding confidential client information.
🏥
Health & Care Providers
Sensitive personal data with strict regulatory and commissioning requirements.
🎓
Education & Training
Schools, colleges and training providers protecting learner records and safeguarding data.
💻
Tech & SaaS Startups
Early-stage teams needing certification to unblock enterprise sales conversations.
🏗️
Trades & Manufacturing
Suppliers required to certify as a condition of contracts further up the chain.
How It Works

Four Steps From Where You Are to Certified

No lengthy discovery phases or open-ended retainers. A clear path with a fixed price agreed before we start.

01
Free Scoping Call
Thirty minutes to understand your setup, devices, cloud services and deadlines. You get a fixed quote — no obligation.
02
Gap Assessment
We check your environment against every requirement and produce a plain-English list of exactly what needs to change.
03
Remediation Support
We help you close the gaps — configuration changes, MFA rollout, patching routines, policy documents.
04
Certify & Maintain
Guided submission, certification, and an annual renewal plan so the badge never quietly goes stale.
Our Commitment

How We Work

We're a young practice, and we'd rather earn your trust with clear commitments than borrowed credibility.

💷
Fixed fees, quoted upfront
You'll know the total cost before we begin, including the certification fee. No hourly creep, no surprise invoices.
🗣️
Plain English, always
If we can't explain a risk in a way that makes sense to a trustee or an office manager, that's our failing — not yours.
🚫
No unnecessary upsell
If you don't need Cyber Essentials Plus, we'll tell you. If a free tool does the job, we'll point you at it.
🤝
Charity rates as standard
Registered charities and non-profits get a reduced rate on every service, not a token discount on request.
📞
A named person to call
You deal with the same consultant throughout, not a rotating ticket queue.
🔒
Confidentiality by default
Every engagement is covered by an NDA and handled on a strict need-to-know basis.
Get Started

Not Sure Where You Stand?

Book a free thirty-minute scoping call. We'll tell you honestly whether you're close to certification or whether there's groundwork to do first.

Take the Free Readiness Check Book a Scoping Call
Our Services

Practical Security, Properly Delivered

From your first certification to ongoing protection — scoped for smaller organisations and priced so it's actually achievable.

🔍
All Certification Assessment IT & Cloud People
🛡️
Cyber Essentials Certification

Complete support to get you certified: scoping your environment, assessing every requirement, fixing what's non-compliant, and guiding your submission through to a pass.

  • Scope definition and asset inventory
  • Full gap assessment against v3.3
  • Hands-on remediation support
  • Guided submission and resubmission cover
🏅
Cyber Essentials Plus Readiness

The Plus tier adds independent technical testing of your devices and cloud accounts. We run a pre-audit against the same test specification so you go in knowing you'll pass.

  • Internal pre-audit simulation
  • Device sampling and vulnerability scanning
  • Remediation of audit blockers
  • Certification body liaison
📘
ISO 27001 Foundations

For organisations ready to go beyond baseline certification. We help you build a right-sized information security management system without drowning in documentation.

  • Readiness gap analysis
  • Risk assessment and treatment plan
  • Proportionate policy set
  • Internal audit preparation
🔍
Security Posture Assessment

A structured review of your people, processes and technology, producing a prioritised roadmap ranked by risk reduction per pound spent.

  • Technical and organisational review
  • Risk register aligned to your context
  • Costed, prioritised remediation plan
  • Board-ready summary report
🎯
Vulnerability Assessment & Testing

Practical testing of your external footprint, internal network, web applications and cloud configuration — with findings written so you can act on them.

  • External and internal vulnerability scanning
  • Web application and API testing
  • Cloud configuration review
  • Prioritised remediation guidance
📋
Data Protection & GDPR

Understand what personal data you hold, why you hold it, and what your obligations actually are — then put proportionate controls around it.

  • Data mapping and records of processing
  • Data protection impact assessments
  • Privacy notices and internal policies
  • Outsourced data protection officer support
☁️
Microsoft 365 & Cloud Hardening

Most small organisations run on Microsoft 365 or Google Workspace. We configure them properly — which alone resolves a large share of certification failures.

  • Multi-factor authentication rollout
  • Conditional access and admin separation
  • Secure baseline configuration
  • Licence-appropriate control tuning
🖥️
Managed IT Support

Reliable day-to-day IT for teams without an internal function — device management, patching, onboarding and offboarding, and someone to call when it breaks.

  • Endpoint management and patching
  • Starter and leaver processes
  • Backup verification
  • Responsive user support
🚨
Incident Response & Recovery

When something goes wrong, the first few hours matter most. We help you contain it, understand it, recover from it, and meet any reporting obligations.

  • Containment and triage
  • Root cause investigation
  • Recovery and hardening
  • Regulatory notification support
🎓
Security Awareness Training

Short, memorable sessions built around the threats your staff will actually encounter, backed by phishing simulations that teach rather than punish.

  • Role-relevant training sessions
  • Realistic phishing simulations
  • Progress reporting over time
  • New-starter induction module
👔
Trustee & Board Briefings

Non-technical sessions for boards and trustees covering what cyber risk means for governance, what questions to ask, and where accountability sits.

  • Cyber risk in governance terms
  • Regulatory and fiduciary duties
  • Incident oversight expectations
  • Assurance questions to ask your IT provider
📝
Policies That People Read

A proportionate policy set written for your organisation's size and reality — short enough to be read, specific enough to be useful.

  • Acceptable use and device policies
  • Access control and password standards
  • Incident reporting procedures
  • Supplier and third-party requirements
No services match your search. Try a different term.

Tell Us What You're Trying to Achieve

A contract requirement, a funder condition, a board question, or just a nagging sense that things aren't as tight as they should be — all valid starting points.

Start a Conversation
Pricing

Transparent, Fixed-Fee Pricing

You'll get a firm quote after a free scoping call. The figures below are typical starting points for a small organisation.

Guided
For organisations with reasonable IT already in place who mainly need direction and a reviewed submission.
£499
from, plus VAT · includes certification fee
  • Free scoping call
  • Gap assessment against v3.3
  • Written remediation checklist
  • Submission review before you file
  • One resubmission included
  • Hands-on remediation
  • Ongoing monitoring
Enquire
Most Popular
Managed
For organisations that want the gaps actually closed rather than just identified. Most small teams choose this.
£899
from, plus VAT · includes certification fee
  • Everything in Guided
  • Hands-on remediation support
  • MFA and cloud configuration work
  • Policy pack tailored to you
  • Staff awareness session included
  • Named consultant throughout
  • Independent technical audit
Enquire
Plus Pathway
For organisations that need the independently audited tier, usually to satisfy a specific contract requirement.
£1,999
from, plus VAT · audit fee varies by scope
  • Everything in Managed
  • Internal pre-audit simulation
  • Device sampling and scanning
  • Audit blocker remediation
  • Certification body liaison
  • Post-certification review
  • Annual renewal planning
Enquire
💚
Registered charities and non-profits
We apply a reduced rate to every service for registered charities, community interest companies and non-profits. Sensitive data and tight budgets shouldn't be a reason to go uncertified — just mention your registration number when you get in touch.
Ask About Charity Rates
What's included in the certification fee. The assessment fee is set by IASME and varies by organisation size, starting at around £320 plus VAT for the smallest organisations. Our packages include this fee. Organisations under £20m turnover that certify their whole organisation are also entitled to cyber liability insurance arranged through the scheme — worth checking against your existing policy.
Choosing a Tier

Cyber Essentials or Cyber Essentials Plus?

Most small organisations start with standard certification. Plus is usually driven by a specific customer or contract requirement.

 Cyber EssentialsCyber Essentials Plus
How it's verifiedReviewed self-assessment questionnaireIndependent hands-on technical audit
Technical controls coveredAll fiveAll five — same requirements
Typical timeline2–4 weeks4–8 weeks after standard certification
PrerequisiteNoneMust already hold standard certification
Typical total costLower — assessment fee plus supportSignificantly higher — audit is priced by scope
Usually required whenDemonstrating baseline good practiceA public sector or enterprise contract mandates it
Certificate validity12 months12 months
A note on timing. Once you hold standard certification you have a limited window to complete Plus before you'd need to recertify. If Plus is on your roadmap, it's worth sequencing both from the start rather than treating them as separate projects.

Get a Fixed Quote

Tell us roughly how many staff and devices you have and which cloud services you use. That's usually enough for us to quote accurately.

Request a Quote
About Us

Security Expertise, Sized for Smaller Organisations

Blue Strokes Digital Solutions exists because good security advice has historically been priced and packaged for large enterprises — leaving smaller organisations and charities to either overpay, or go without.

We work exclusively with organisations that don't have a dedicated security team. That focus shapes everything: how we scope engagements, how we price them, and how we explain things. No frameworks for their own sake, no tooling you don't need, no reports written to impress rather than inform.

Our work centres on Cyber Essentials because it's genuinely well designed — five controls that stop most real-world attacks, at a cost a small organisation can justify. It's a foundation, not a ceiling, and we help organisations build on it when they're ready.

Work With Us Our Services →
NK
Lead Consultant
Cyber Security Consultant · Cyber Essentials · ISO 27001

Our practice is led by a cyber security consultant with hands-on experience across governance, risk, compliance and technical security work. That combination matters: certification questions are rarely purely technical or purely procedural, and the useful answer usually sits between the two.

View LinkedIn Profile →
Cyber Essentials Cyber Essentials Plus ISO/IEC 27001 UK GDPR NIST CSF CIS Controls
🎯
Focused
Smaller organisations only
💷
Transparent
Fixed fees, quoted upfront
🗣️
Clear
Plain English, no jargon
🤝
Committed
Long-term, not transactional
Our Capabilities

What We Bring to an Engagement

Four areas of capability that cover what a smaller organisation actually needs.

CE
Certification
Cyber Essentials & Plus
Scoping · Gap assessment · Submission support
GR
Governance & Risk
GRC & Data Protection
Risk assessment · Policy · GDPR
TS
Technical Security
Assessment & Hardening
Cloud config · Vulnerability testing
IT
IT Operations
Support & Management
Endpoints · Patching · Backup
Why Blue Strokes

Why Organisations Choose Us

Three things smaller organisations consistently tell us they struggle to find elsewhere.

🔍
We scope honestly

Plenty of providers will sell you a bigger engagement than you need. We'd rather quote for the work that actually moves your risk, and tell you what can wait.

🛠️
We do the work, not just the report

A findings document you can't action isn't much use. Our packages include hands-on remediation, because that's the part most small teams don't have capacity for.

📆
We stay after certification

Certificates lapse and environments drift. We build annual renewal into the relationship so your certification keeps reflecting reality.

Frameworks & Standards We Work With

Cyber Essentials Cyber Essentials Plus IASME Cyber Assurance ISO/IEC 27001 ISO/IEC 27005 UK GDPR NIST CSF CIS Controls NIS2 SOC 2 PCI DSS v4.0

Let's Talk About Your Situation

No sales script, no pressure. Just a straight conversation about where you are and what would genuinely help.

Book a Free Call
Training

Build Security Judgement Across Your Team

Technology stops a lot. People stop the rest. Our training is short, practical, and built around what your staff will actually encounter.

Certification Readiness
Cyber Essentials Readiness Workshop

A working session that takes your team through each of the five controls, what evidence you'll need, and where organisations most commonly fail.

  • The five controls explained practically
  • Common automatic-fail mistakes
  • Evidence gathering walkthrough
  • Live Q&A on your environment
⏱ Half dayBook →
Whole Organisation
Security Awareness for Staff

Role-relevant sessions covering the threats your people meet daily, delivered without condescension and backed by simulations that build judgement.

  • Recognising phishing and pretexting
  • Passwords, passkeys and MFA
  • Safe handling of personal data
  • Ongoing simulated phishing campaigns
⏱ Ongoing programmeGet a Quote →
Governance
Cyber Risk for Trustees & Boards

A non-technical briefing for people accountable for the organisation but not for its IT. What you're responsible for, and what to ask.

  • Cyber risk in governance terms
  • Regulatory and fiduciary duties
  • Overseeing incidents without micromanaging
  • Assurance questions for your IT provider
⏱ 90 minutesBook →
Data Protection
Practical GDPR for Small Teams

Data protection stripped back to what a small organisation genuinely has to do — with worked examples rather than legislative recitation.

  • Lawful bases in plain terms
  • Handling subject access requests
  • When a DPIA is actually needed
  • Breach assessment and reporting
⏱ Half dayBook →
Technical
Microsoft 365 Security Essentials

Hands-on training for whoever administers your tenant, covering the configuration decisions that most affect both security and certification.

  • MFA and conditional access setup
  • Admin role separation
  • Sharing and external access controls
  • Audit logging and alerting
⏱ 1 dayBook →
Preparedness
Incident Response Tabletop

A facilitated scenario exercise that walks your team through a realistic incident, surfacing the decisions and gaps you'd rather find now than later.

  • Scenario tailored to your sector
  • Decision-making under pressure
  • Communication and escalation paths
  • Written findings and action plan
⏱ Half dayBook →

Training That Fits Around Real Work

Sessions are delivered remotely and sized so they don't consume a whole working day. Tell us your team size and we'll suggest a format.

Enquire About Training
Insights

Guidance Worth Reading

Practical articles on certification, security fundamentals and data protection — written for people who have other jobs to do.

🔍
📭

No articles found

Try a different search or check back soon.

FAQ

Frequently Asked Questions

Cyber Essentials is a government-backed certification scheme developed by the National Cyber Security Centre and delivered by IASME. It covers five technical controls — firewalls, secure configuration, security update management, user access control and malware protection. Certifying demonstrates that you have baseline protection against the most common internet-borne attacks, and it's increasingly requested by clients, funders and insurers.
For a reasonably well-organised small team, two to four weeks is typical. The assessment itself is quick — most of the time is spent closing gaps such as enabling multi-factor authentication everywhere, tightening your patching routine, or retiring devices that can no longer receive updates. We'll give you a realistic timeline after the scoping call rather than an optimistic one.
The certification fee itself is set by IASME according to organisation size and starts at around £320 plus VAT for the smallest organisations. Support costs sit on top of that and depend on how much help you need. Our packages bundle both into a single fixed fee so you're not comparing moving parts. Cyber Essentials Plus costs considerably more because it involves an independent technical audit priced by scope.
New assessments now use the Danzell question set against version 3.3 of the requirements, replacing Willow. The headline changes are that multi-factor authentication is mandatory for cloud services wherever it's available, cloud services can no longer be excluded from scope, and critical or high-severity security updates must be applied within fourteen days. Several of these now cause an automatic failure, so answers that passed under the previous question set may not pass now.
Yes, and it's a significant part of what we do. Charities typically hold sensitive donor and beneficiary information, face funder and regulator expectations, and have neither the budget nor the in-house expertise that larger organisations take for granted. We apply reduced rates across all services for registered charities and non-profits.
Usually only if a customer or contract specifically requires it — commonly certain public sector work or larger enterprise supply chains. Standard Cyber Essentials satisfies most requirements and is a verified self-assessment. You must hold standard certification before you can pursue Plus, and there's a limited window between the two, so it's worth planning both together if Plus is likely.
It shouldn't come to that — the point of a proper gap assessment beforehand is that you only submit when you'll pass. If something does come back for correction, our packages include resubmission support, and we'll work through whatever the assessor has flagged with you at no additional cost.
Yes. Scoping, assessment, remediation support, submission and training are all delivered remotely. That keeps costs down and means geography isn't a constraint on who we can work with.
Every engagement is covered by a mutual non-disclosure agreement before any information is shared. We work on a need-to-know basis, hold client data only for as long as the engagement requires, and are happy to work within your own security and data handling requirements.

Thinking about certification?

A free thirty-minute scoping call will tell you how close you are and what it would take.

Book a Free Call See Pricing
Free Tool

Cyber Essentials Readiness Check

Twelve questions, about three minutes. You'll get a readiness score, a breakdown across the five controls, and a clear list of anything that would fail you today.

Before You Start

Answer honestly — it's more useful that way

This check mirrors the areas assessors actually look at under the current Danzell question set. Nothing you enter is submitted anywhere unless you choose to request the full report at the end.

  • Covers all five technical controls
  • Flags the three requirements that cause automatic failures
  • Tells you which package would suit you
  • No email required to see your result
Not sure about something? Choose "Partly / not sure" — an honest uncertain answer gives you a more accurate picture than an optimistic guess, and unknown assets are the single most common reason certification attempts stall.
Question 1 of 12 Firewalls
Nothing is saved until you choose to
0
Readiness

Breakdown by control
Want the detailed report?
We'll send a written breakdown of every gap, what evidence an assessor would expect, and a fixed-fee quote based on your answers. No obligation, and we won't pass your details to anyone.
✅ Thank you — we'll send your detailed report within one working day.
See Pricing →
Get In Touch

Let's Work Out What You Need

Tell us a little about your organisation and we'll come back within one working day.

Contact Information
However you'd prefer to reach us.
📧
Email
hello@bluestrokesdigital.com
📞
Phone
+44 20 3000 0000
💻
Delivery
Remote-first — wherever your team works
🕐
Hours
Mon–Fri, 09:00–17:30
⏱️
Response Time
Within one working day
Connect on LinkedIn
Send Us a Message
The more context you give us, the more useful our first reply will be.
✅ Thank you — your message has been received. We'll be in touch within one working day.
BLUE STROKES DIGITAL SOLUTIONS

Cyber Essentials certification and practical security support for small organisations and charities. Fixed fees, plain English, delivered remotely.

in ✉️
Get occasional practical guidance
✅ Thanks — you're subscribed.

Services

Cyber Essentials Cyber Essentials Plus Posture Assessment Data Protection Cloud Hardening Managed IT

Company

About Pricing Training Insights Contact

Resources

Readiness Check FAQ CE vs CE Plus NCSC Cyber Essentials ↗ IASME ↗
© Blue Strokes Digital Solutions. All rights reserved.
Privacy Policy Terms of Service Cookie Policy