Cyber Essentials for Professional Services Firms
How Cyber Essentials helps solicitors, accountants and consultants protect client information, meet requirements and demonstrate security.
Professional services firms are built on trust. Clients share confidential information, financial records, contracts and commercially sensitive plans because they trust their advisers to handle that information responsibly.
That makes cybersecurity a business issue, not simply an IT concern.
Whether you run a solicitors’ practice, accountancy firm, consultancy, financial advisory business or architectural practice, Cyber Essentials provides a practical way to reduce common cyber risks and demonstrate that important security controls are in place.
Cybercriminals do not only target large companies
It is easy to assume that cybercriminals are primarily interested in banks, multinational businesses and government departments. In reality, attackers are often more interested in the information an organisation holds than the size of the organisation itself.
A professional services firm may hold:
- Confidential client correspondence
- Contracts and legal documents
- Financial records
- Payroll and tax information
- Personal data
- Payment instructions and bank details
- Intellectual property
- Details of mergers and acquisitions
- Access to client systems
This information can be used for fraud, extortion, identity theft, phishing and further attacks against clients or suppliers.
A compromised professional services firm can also provide attackers with something particularly valuable: credibility.
An email sent from the genuine account of a solicitor, accountant or consultant is much more likely to be trusted. That can make the firm a useful stepping stone for attacks against clients and other organisations in its supply chain.
Trust is fundamental to professional services
Clients do not only pay professional advisers for their knowledge. They also trust them to handle sensitive information carefully.
A cyber incident can therefore cause considerably more than a temporary technical problem. It may lead to:
- Loss of client confidence
- Reputational damage
- Disruption to chargeable work
- Missed court, filing or contractual deadlines
- Financial loss
- Regulatory or contractual consequences
- Difficult questions from clients and insurers
Even when an incident is contained, the firm may have to spend significant time investigating what happened, restoring systems, contacting affected clients and demonstrating that the problem has been addressed.
Cyber Essentials provides a recognised way to show that the firm takes fundamental cybersecurity controls seriously. It does not promise that an organisation can never experience an attack, but it helps close many of the common routes attackers use.
The common attacks facing professional services firms
Many successful cyber incidents do not begin with a highly sophisticated technical attack. They begin with a convincing email, a stolen password, an unpatched application or an account that should have been removed months ago.
Common threats include:
- Phishing emails designed to steal Microsoft 365 credentials
- Business email compromise
- Fraudulent requests to change payment instructions
- Malware delivered through attachments or links
- Password spraying attacks
- Attacks using passwords exposed in previous data breaches
- Exploitation of unpatched software
- Compromise of remote-working devices
- Ransomware
- Unauthorised access through dormant or poorly managed accounts
Payment fraud is a particularly important risk. An attacker who gains access to a genuine mailbox may spend time monitoring conversations before intervening at the right moment.
They might send new bank details during a property transaction, redirect a supplier payment or impersonate a senior member of the firm. Because the message comes from a legitimate account and refers to a genuine transaction, it can be extremely convincing.
Cyber Essentials helps firms address the underlying weaknesses that make many of these attacks possible.
What does Cyber Essentials actually cover?
Cyber Essentials focuses on five technical control areas. These are not obscure security measures intended only for large IT departments. They are practical controls that every modern business should have in place.
Firewalls and internet gateways
Firewalls help control connections between the firm’s devices and the internet.
This includes ensuring that unnecessary access is not exposed, default passwords have been changed and the equipment protecting the network is still receiving security updates.
The objective is straightforward: systems should not be reachable from the internet unless there is a genuine business reason for them to be.
Secure configuration
New computers, applications and network devices are not always secure straight out of the box.
Default accounts, unnecessary applications and unused services can all create avoidable opportunities for attackers. Devices should be configured for their intended business purpose rather than simply left with their original settings.
For a professional services firm, this might include removing unwanted software, disabling unused accounts and ensuring that security features have not been turned off for convenience.
Security update management
Attackers routinely exploit publicly known vulnerabilities in operating systems, web browsers, business applications and internet-facing equipment.
Supported software must be kept updated, and important security fixes need to be applied promptly. Unsupported software should be replaced because the manufacturer may no longer provide security updates for newly discovered vulnerabilities.
This applies to more than Windows. Browsers, Microsoft Office applications, mobile devices, firewalls, routers and other business software all need to be considered.
User access control
Employees should have access only to the systems and information they need to perform their roles.
Administrator privileges should be restricted because an attacker who compromises an administrator account may gain far more control over the organisation. Administrative work should also be carried out using separate accounts rather than through an employee’s ordinary email and day-to-day account.
Accounts must be reviewed and removed when employees leave or no longer require access.
Malware protection
Firms need suitable controls to prevent malicious software from running.
This may include anti-malware software, built-in operating system protection and controls that allow only approved applications to run. Whichever approach is used, it needs to be active, properly configured and kept up to date.
Together, these five control areas reduce many of the everyday weaknesses targeted by cybercriminals.
Microsoft 365 is often at the centre of the risk
For many professional services firms, Microsoft 365 has become the centre of the business.
It may contain:
- Email and client correspondence
- Shared documents
- Calendars and contact details
- Teams conversations
- OneDrive files
- SharePoint sites
- Sensitive attachments
- Links to other business applications
Microsoft is responsible for securing the underlying cloud service, but it is not responsible for every aspect of how an individual organisation uses it.
The firm remains responsible for its users, authentication methods, permissions, connected devices and security configuration.
Important measures include:
- Enabling multi-factor authentication
- Using separate administrator accounts
- Removing dormant and former employee accounts
- Reviewing external file sharing
- Controlling access from personal devices
- Restricting administrative privileges
- Keeping installed Office applications supported and updated
Simply moving email and files into Microsoft 365 does not automatically make them secure. The available security controls still need to be configured and managed properly.
Remote and hybrid working must be included
Professional services work is no longer confined to a single office.
Employees may work from home, client premises, court buildings, hotels, shared workspaces or while travelling. That flexibility is useful, but it also changes the firm’s security boundaries.
Laptops, mobile devices, home routers, remote-access services and personally owned equipment may all affect the scope of Cyber Essentials.
A device does not become less important because it is away from the office. If it can access company email, documents or systems, it may provide a route into the business.
Firms preparing for Cyber Essentials should understand:
- Which devices access business information
- Who owns and manages those devices
- Whether they still receive security updates
- How users authenticate
- Whether personal devices are permitted
- How remote access is controlled
- What happens when a device is lost or an employee leaves
The security of the firm should not depend on where somebody happens to be working that day.
Supporting client due diligence
Clients increasingly want evidence that suppliers and professional advisers are protecting their information.
Cybersecurity questions may appear during:
- Supplier security reviews
- Tender submissions
- Client onboarding
- Panel appointments
- Contract renewals
- Cyber insurance applications
- Supply-chain assessments
Saying that the business has “good IT security” is unlikely to provide much reassurance on its own. Cyber Essentials gives the firm a recognised certification that clients and procurement teams can understand.
Certification does not guarantee that a firm will win a particular contract. It can, however, remove a potential obstacle and provide useful evidence when security forms part of the selection process.
It may also help the firm respond to security questionnaires more consistently, rather than trying to gather information from scratch whenever a client asks.
Cyber Essentials does not replace regulatory duties
Cyber Essentials is an important security baseline, but it does not replace the firm’s wider legal, regulatory and professional responsibilities.
It does not remove the need for:
- UK GDPR compliance
- Data protection policies
- Professional body requirements
- Client confidentiality procedures
- Security risk assessments
- Incident response planning
- Business continuity arrangements
- Staff awareness and training
Instead, Cyber Essentials supports these responsibilities by requiring important technical controls to be implemented in practice.
Policies describe what a firm intends to do. Cyber Essentials examines whether specific security measures are actually in place.
A policy may say that accounts are removed when employees leave, for example. The Cyber Essentials preparation process may reveal whether that happens consistently across Microsoft 365, remote-access platforms and other business systems.
Certification can reveal hidden weaknesses
One of the most useful parts of preparing for Cyber Essentials is discovering issues that have gradually developed within the business.
These might include:
- Unsupported computers
- Old mobile phones or tablets
- Unpatched business applications
- Excessive administrator privileges
- Forgotten user accounts
- Unmanaged home-working equipment
- Incomplete device and software records
- Inconsistent multi-factor authentication
- Software installed without business approval
These problems do not necessarily mean that the firm has been careless. IT environments change over time. Employees join and leave, new applications are introduced, businesses merge and temporary arrangements have a habit of becoming permanent.
Finding these weaknesses during preparation gives the firm an opportunity to correct them before they contribute to a security incident.
Cyber Essentials or Cyber Essentials Plus?
Both certifications are based on the same five technical control areas, but the assessment methods are different.
Cyber Essentials
Cyber Essentials is a verified self-assessment. The organisation answers questions confirming that the required controls are in place, and the answers are reviewed by an assessor.
It may be suitable for a firm that:
- Wants to establish a recognised security baseline
- Has been asked for certification by a client
- Needs certification for a tender
- Is beginning a wider cybersecurity improvement programme
- Wants to demonstrate that fundamental controls are in place
Cyber Essentials Plus
Cyber Essentials Plus applies the same requirements, but an independent assessor technically tests a sample of systems to verify that the controls have been implemented correctly.
It may be appropriate where:
- Clients require stronger assurance
- The firm handles particularly sensitive information
- Certification is needed for valuable contracts
- Management wants independent technical verification
- The firm wants to distinguish itself from competitors
The additional testing gives clients greater confidence because the controls have been independently checked rather than supported solely by the organisation’s own declaration.
Cyber Essentials is achievable for smaller firms
Cyber Essentials is not limited to large organisations with dedicated security departments.
Small professional services firms can achieve certification with:
- Clear responsibility for the process
- An accurate inventory of devices and software
- Support from their IT provider
- Management involvement
- Early identification of unsupported systems
- Specialist guidance where necessary
The assessment fee is based on organisation size, helping to make the scheme accessible to micro and small businesses.
Smaller firms may even find that their environment is easier to understand and manage. The key is to establish exactly which devices, users, cloud services and working arrangements are within scope before completing the assessment.
Preparation involves more than the IT provider
An MSP or outsourced IT provider can offer valuable technical support, but the certification process should not simply be handed over without management involvement.
Information may be needed from:
- Directors or partners
- Internal IT staff
- The external IT provider
- HR
- Office management
- Data protection staff
- Employees working remotely
Management may need to confirm which personal devices are permitted, how access is approved, what happens when somebody leaves and who is responsible for keeping equipment updated.
The firm being certified remains responsible for the accuracy of its answers. Those answers should therefore reflect how the organisation actually operates, not how people assume its IT has been configured.
A practical investment in client confidence
Professional services firms depend on information, technology and trust. A weakness in any one of those areas can quickly affect the others.
Cyber Essentials provides a practical framework for reducing common cyber risks. It can help identify unsupported systems, improve account management, strengthen remote working and provide clients with recognised evidence that fundamental protections are in place.
For firms handling confidential, financial or commercially sensitive information, that makes Cyber Essentials more than a certificate. It is a practical investment in resilience, professional responsibility and client confidence.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.