Why Cyber Essentials Plus Is an Opportunity for MSPs
Cyber Essentials Plus helps MSPs support customers’ certification, tender and compliance needs through an independent assessment partner.
Managed Service Providers are increasingly expected to do more than simply keep their customers' IT systems running.
Of course, the traditional responsibilities are still there. Supporting users, managing Microsoft 365, installing software, maintaining devices and fixing technical problems all remain important.
But the conversation has changed.
Customers are now asking their MSPs about cybersecurity, Cyber Essentials, Cyber Essentials Plus, tender requirements, supplier assurance and vulnerability management.
And that presents a real opportunity.
When a customer needs to improve its cybersecurity or achieve a recognised certification, the MSP is often the first organisation they turn to. After all, the MSP already understands their IT environment better than almost anyone.
Cyber Essentials Plus can therefore be an excellent opportunity for MSPs to provide additional value to customers, while working alongside a specialist independent assessment provider.
Why Cyber Essentials Plus matters to MSP customers
There are plenty of reasons why an organisation might need Cyber Essentials Plus.
Sometimes it is about winning business.
A customer may find a tender or contract that looks perfect for them, only to discover that Cyber Essentials or Cyber Essentials Plus is a requirement.
Other times, the requirement comes from a larger customer asking suppliers to demonstrate that they take cybersecurity seriously.
Supply-chain assurance is also becoming increasingly important. Organisations want greater confidence that the businesses they work with have appropriate cybersecurity controls in place.
And, of course, there is the security benefit itself.
Preparing for Cyber Essentials Plus can help an organisation identify areas that need attention and strengthen its cybersecurity baseline.
The important point for MSPs is this:
Your customer may initially want Cyber Essentials Plus because of a commercial requirement, but the process can also help improve their overall security.
MSPs are often perfectly placed to help customers prepare
This is where MSPs have a significant advantage.
You already know the customer's environment.
You may be managing their endpoints, Microsoft 365, firewalls, patch management, antivirus or EDR, backups, user accounts, remote access and servers.
That means you are often in the best position to help a customer prepare for Cyber Essentials Plus.
This could involve identifying unsupported software, addressing missing updates, reviewing user accounts, improving MFA deployment, checking security configurations or helping to remediate issues.
In other words, much of the groundwork is already closely aligned with the services an MSP provides.
But there is an important distinction.
Helping a customer implement and manage security controls is not the same thing as independently assessing those controls.
Why independent assessment matters
An MSP may quite legitimately tell a customer:
"We have implemented the required security controls."
A Cyber Essentials Plus assessment then asks a slightly different question:
"Can we independently and technically verify that the relevant controls meet the requirements?"
That separation is valuable.
The MSP remains responsible for implementing, managing and supporting the customer's technology and security controls.
The independent assessor provides technical verification as part of the Cyber Essentials Plus assessment.
These are complementary roles rather than competing ones.
In fact, having an independent assessment can provide additional reassurance for the customer and an objective perspective on the controls already in place.
The MSP has done the work to build and maintain the environment.
The independent assessor verifies the relevant controls.
The customer benefits from both.
Independent assessment should complement the MSP, not compete with them
A good Cyber Essentials Plus assessment partner should not be viewed as competition.
Quite the opposite.
An independent assessment can complement the MSP's existing service by helping to validate controls, identify issues requiring remediation and provide recognised independent assurance.
The assessor is not there to take over management of the customer's IT environment.
That remains the MSP's area of expertise and responsibility.
A good working relationship looks something like this:
The MSP manages and understands the customer's environment.
The specialist assessment provider independently assesses the relevant cybersecurity controls.
The customer receives the benefit of both services.
Simple.
Helping customers prepare for Cyber Essentials Plus
There are several areas where an MSP can provide significant value before a formal assessment takes place.
Knowing what is actually in the environment
Asset management is an obvious starting point.
Are all in-scope devices known?
Are there old or unmanaged devices still lurking somewhere on the network?
Are operating systems and applications still supported?
You cannot secure what you do not know exists.
Keeping systems up to date
Patch management is another important area.
Are updates being deployed successfully?
Are known high and critical vulnerabilities being addressed appropriately?
Are unsupported applications still being used?
These are the sorts of questions that are much easier to answer when an MSP already has good visibility and management of the customer's estate.
Authentication and MFA
Authentication is another area where the MSP can often help.
Is MFA correctly implemented?
Are administrator accounts properly protected?
Are appropriate authentication methods being used?
A surprising number of security issues come down to configuration and consistency rather than a complete lack of security technology.
Endpoint security
MSPs are also typically well placed to review endpoint protection.
Is appropriate malware protection deployed?
Are endpoints properly managed?
Are the relevant security controls actually operating as expected?
Deploying a security product is one thing. Making sure it is properly configured and working across the estate is another.
Firewall controls
Appropriate firewall protection is also an important part of a secure environment.
Again, this is an area where the MSP's knowledge of the customer's infrastructure can make the preparation process much smoother.
The dreaded tender deadline
Many MSPs will recognise this scenario.
A customer calls and says:
"We've found a contract we want to bid for, but we need Cyber Essentials Plus."
The next question is usually:
"When does the tender close?"
And that is when things can become interesting.
The customer may suddenly be working to a deadline, with a certification requirement that they had not previously planned for.
The MSP can add real value by helping the customer understand the technical requirements, prepare the environment, address issues and coordinate the assessment process.
Having an established relationship with an accredited Cyber Essentials Plus provider can make this much easier.
Rather than telling the customer to go away and find an assessor themselves, the MSP can provide a clear route through the process.
That creates a better experience for everyone involved.
Cybersecurity assurance is also a supply-chain issue
MSPs themselves are important suppliers.
Customers may trust their MSP with access to networks, endpoints, Microsoft 365 environments, backups, remote management platforms and administrative accounts.
That means cybersecurity assurance matters at several levels.
The MSP supports the customer's cybersecurity.
The customer may then need to demonstrate cybersecurity assurance to its own customers.
And those customers may have their own supply-chain requirements.
It quickly becomes a chain of trust.
Cyber Essentials Plus can provide recognised evidence that important cybersecurity controls have been independently and technically verified.
For customers operating in supply chains where cybersecurity assurance is increasingly important, that can be a significant advantage.
A partnership can create a much better customer experience
Without an established partnership, the process can sometimes look a little messy.
The customer speaks to the MSP.
The MSP tells them they need an independent assessor.
The customer then searches around for one.
Different organisations become involved.
Responsibilities are not always clear.
Communication gets fragmented.
Nobody is entirely sure who is doing what.
That is not ideal.
A good partnership creates a much clearer model.
The customer works with their MSP.
The MSP continues to manage and support the technical environment.
The accredited Cyber Essentials Plus provider carries out the independent assessment.
Everyone understands their role.
The assessor does not replace the MSP.
The MSP does not need to become an assessment body.
The customer gets a more straightforward experience.
Why partner with a Cyber Essentials Plus provider?
For many MSPs, partnering with a specialist provider makes much more sense than trying to build every possible cybersecurity capability internally.
A partnership can allow an MSP to:
Offer additional services
The MSP can help customers access Cyber Essentials Plus support without needing to develop the assessment capability themselves.
Keep the customer relationship
The MSP remains the customer's trusted IT provider and the organisation responsible for their day-to-day environment.
Access specialist expertise
The independent assessment is carried out by an appropriately qualified and accredited specialist.
Provide additional value
The MSP can help customers respond to cybersecurity requirements, tenders and contractual obligations.
Identify further opportunities
A Cyber Essentials Plus engagement may also highlight wider areas that the customer needs to address.
This could include vulnerability management, broader security improvements, penetration testing, Microsoft 365 security or ongoing security reviews.
Cyber Essentials Plus should not be the end of the journey
Achieving Cyber Essentials Plus is a great milestone.
But cybersecurity does not stop there.
The customer's environment will continue to change.
New devices will be introduced.
Users will join and leave.
Software will be updated.
New vulnerabilities will be discovered.
Technology will evolve.
That means ongoing security management remains essential.
The MSP can continue supporting areas such as patch management, vulnerability management, endpoint security, identity security, Microsoft 365 security, user management and device management.
Cyber Essentials Plus should therefore be viewed as part of an ongoing security journey rather than a one-off project that gets placed in a drawer and forgotten about until next year.
What should MSPs look for in a Cyber Essentials Plus partner?
Choosing the right partner matters.
After all, the MSP is introducing that organisation to its customer.
So one of the most important questions is probably:
"Will this provider make us look good in front of our customer?"
That is a perfectly reasonable question.
An MSP should look for a provider with appropriate accreditation, a clear understanding of the assessment process and experience of working alongside managed service providers.
Communication is important too.
The relationship should have a clear separation between preparation, implementation and independent assessment.
Responsibilities should be clearly defined.
Pricing should be straightforward.
And, most importantly, the cybersecurity provider should understand that the MSP already has an important relationship with the customer.
The aim should be to strengthen that relationship, not disrupt it.
How Plainsight Security works with MSPs
At Plainsight Security, we work with MSPs that want to provide additional cybersecurity services to their customers without having to build every specialist capability internally.
This can include:
- Cyber Essentials
- Cyber Essentials Plus
- Penetration testing
- Vulnerability assessments
- Other specialist cybersecurity services
Our role is to provide specialist cybersecurity expertise and, where appropriate, independent assessment.
The MSP remains central to the customer's relationship and understands the technical environment they manage.
We see this as a partnership.
MSPs do not need to become specialists in every single area of cybersecurity.
Just as they may work with specialist partners for telecoms, compliance, networking or other technical services, they can also work with cybersecurity specialists.
The combination can work extremely well.
The MSP understands the customer.
The specialist provides additional expertise and independent services.
The customer benefits from both.
Final thoughts
Cyber Essentials Plus represents a genuine opportunity for MSPs.
Customers are increasingly being asked to demonstrate that they take cybersecurity seriously, whether that is because of tenders, contracts, customer requirements or wider supply-chain assurance.
The MSP is often ideally placed to help the customer prepare by managing and improving the technical environment, implementing appropriate controls and addressing issues.
An independent Cyber Essentials Plus assessment can then provide technical verification of key controls.
That gives the customer additional confidence and recognised assurance.
By partnering with an accredited Cyber Essentials Plus provider, an MSP can extend the services it offers without having to build the assessment capability internally.
And that can be good for the MSP, good for the cybersecurity provider and, most importantly, good for the customer.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.