Cyber Security
Cyber Essentials, vulnerability management and penetration testing
Know where you are vulnerable. Fix what matters. Prove you are improving.
Cyber assurance that helps you improve, not just comply. Cyber Essentials support, monthly vulnerability scanning, dark web monitoring and guided remediation, delivered as a structured programme with quarterly reviews that show measurable progress.
Certification proves a point in time, not ongoing improvement
Passing an assessment tells you that your controls were in order on the day you were assessed. It says nothing about the vulnerabilities that appeared the following week, the credentials leaked in a breach three months later, or whether the gaps you found last year were ever actually closed. Most businesses have a certificate. Far fewer can show that their security posture is genuinely getting better, which is exactly what an insurer, a tender or a client assurance questionnaire now asks you to demonstrate.
Cyber Essentials is not the destination. It is the starting point.
A repeatable cyber improvement programme that builds assurance, closes gaps and proves progress quarter after quarter.
Is this you?
Building your cyber foundation
You are a 10 to 50 user organisation beginning structured cyber improvement and seeking Cyber Essentials support.
Needing higher assurance
You are a 30 to 100 user organisation that requires regular vulnerability scanning, testing and higher assurance.
Wanting clearer visibility
You need visibility of vulnerabilities, dark web credential exposure and practical remediation guidance.
Evidencing real improvement
Your leadership team wants clear evidence of cyber improvement, not just technical reports.
Outcomes for your business
Built around measurable business outcomes, not just technical delivery. Here is what you get out of the programme, in plain English.
Cyber Essentials confidence
You are supported through Cyber Essentials scope, gap analysis, readiness and certification preparation.
Vulnerability visibility
You receive regular visibility of external vulnerabilities and prioritised risk reporting.
Credential exposure awareness
Domain and credential exposure is monitored so leaked credentials can be addressed.
Prioritised remediation
Risk-based recommendations help you focus on what matters first.
Validated security improvement
Higher-assurance clients can validate controls through quarterly penetration testing.
Executive risk visibility
Your leadership team receives plain-English summaries of risk, progress and improvement actions.
Structured cyber maturity journey
You gain a repeatable improvement programme rather than a one-off tick-box exercise.
Two tiers, plus certification support
Two core monthly tiers, with Cyber Essentials Plus available as a separate one-off add-on when certification support is needed beyond the core service. Not sure which fits? We will help you choose based on your user numbers and risk needs.
YourFortify Essential
Best for 10 to 50 user organisations
Build the cyber foundation, achieve Cyber Essentials, gain visibility and fix key risks. Certification support, vulnerability scanning, dark web monitoring and guided remediation.
Cyber Essentials certification support
- Cyber Essentials gap analysis
- Remediation guidance
- Audit preparation support
- Certification readiness review
- Scope validation assistance
- Annual certification coordination
Vulnerability management
- Automated vulnerability scanning
- Monthly external vulnerability scans
- Prioritised risk reports
- Risk-based remediation recommendations
- Vulnerability trend reporting
Dark web monitoring
- Domain monitoring
- Credential breach monitoring
- Exposure reporting
- Risk notification and recommended next actions
Remediation allowance
- Up to 2 remediation hours per month
- Security-focused remediation support
- Cyber Essentials gap remediation guidance
- Vulnerability reduction activities
YourFortify Plus
Best for 30 to 100 user organisations
Continuous assurance and validation through testing and specialist review, for organisations that need ongoing testing and higher assurance.
Everything in Essential, plus the following
Quarterly penetration testing
- Quarterly testing using an approved penetration testing platform
- Internal and external testing of agreed targets
- Risk-ranked findings
- Testing summary and recommendations
- Trend visibility over repeated testing cycles
Enhanced vulnerability assurance
- Continuous vulnerability validation
- Verification of remediation activity
- Risk verification
- Security trend analysis
- Prioritised improvement recommendations
Enhanced remediation support
- Up to 4 remediation hours per month
- Vulnerability remediation support
- Risk reduction assistance and validation reviews
- Security improvement support
Quarterly specialist security review
- Security posture review
- Vulnerability review
- Remediation planning
- Strategic recommendations
- Cyber improvement roadmap discussion
Cyber Essentials Plus add-on
One-off add-on, not a monthly tierCyber Essentials Plus readiness is not included in Essential or Plus. It is provided as a separate one-off add-on rather than a monthly service tier, keeping the core service simple while letting you buy CE Plus support exactly when you need it.
Included in the add-on
- Cyber Essentials Plus readiness assessment
- Evidence gathering support
- Assessor coordination
- Test coordination
- Vulnerability verification review
- Remediation planning
- Certification preparation and management support
Not included in the add-on
- Certification fees unless explicitly included
- Auditor or assessor fees unless explicitly included
- Hardware replacement
- Major infrastructure remediation
- Large-scale remediation projects
- Third-party vendor professional services
Monthly inclusions comparison
| Included area | Essential | Plus |
|---|---|---|
| Cyber Essentials certification support | Included | Included |
| External vulnerability scanning | Monthly | Monthly |
| Dark web and credential monitoring | Included | Included |
| Prioritised risk reporting | Included | Included |
| Remediation allowance | Up to 2 hours per month | Up to 4 hours per month |
| Penetration testing | Not included | Quarterly |
| Continuous vulnerability validation | Not included | Included |
| Specialist security review | Not included | Quarterly |
| Cyber improvement roadmap discussion | Not included | Included |
| Quarterly review, Your IT 360 Framework | Included | Included |
Not sure which tier fits?
We will help you choose based on your user numbers, your risk profile and what your clients or insurers are asking you to evidence.
Book a Cyber Assurance ReviewHow the programme runs
A repeatable improvement cycle rather than a one-off exercise. Scanning and monitoring run every month, remediation happens as findings come in, and every quarter we step back with you to review progress and agree what to tackle next.
Scan & monitor
Monthly external vulnerability scanning, with domain and credential monitoring running continuously.
Prioritise
Findings are risk-ranked and reported, so you know what matters first rather than facing an undifferentiated list.
Remediate
Guided remediation support within your monthly allowance, covering vulnerability reduction and Cyber Essentials gaps.
Validate
Remediation is verified rather than assumed. Plus adds quarterly penetration testing to validate controls independently.
Report
Plain-English summaries of risk, progress and improvement actions for your leadership team, plus vulnerability trend reporting.
Review & plan
A quarterly review through the Your IT 360 Framework, where progress is assessed and the next priorities are agreed with you.
What we review every quarter
Reviews are run through the Your IT 360 Framework and answer the questions your leadership team actually asks.
Vulnerabilities
Are critical and high-risk issues reducing?
Cyber Essentials
Is certification status clear, and are controls being maintained?
Remediation progress
Are agreed actions being completed?
Dark web risks
Have any credentials or domains been exposed?
Penetration testing
What weaknesses have been identified and validated?
Security maturity
Is the organisation becoming more resilient over time?
Improvement roadmap
What should be tackled next?
Where this service fits
This service is focused on assurance, certification support and vulnerability management. Some related requirements are delivered through other parts of our portfolio, so you know exactly what is covered here and where to look for the rest.
Covered by this service
- Cyber Essentials support and readiness
- External vulnerability management
- Dark web and credential monitoring
- Penetration testing on the Plus tier
- Guided remediation support
- Quarterly assurance reviews
Handled elsewhere in our portfolio
Your Secure 365
- Microsoft 365 security governance
- Secure Score management
- Conditional Access management
Your Secure Defend
- 24x7 threat monitoring
- Managed detection and response
- Incident response
Your Workplace
- Desktop and laptop patching
- Application deployment
- Device management
Infrastructure management is delivered through Your Infrastructure, and major remediation projects are scoped separately under their own statement of work, so large pieces of work are quoted properly rather than absorbed into a monthly allowance.
Why businesses trust us with their cyber assurance
A dedicated security and compliance team, a structured improvement programme, and the same IT partner that already knows your systems.
A dedicated security practice
Led by Fern Ritchie, our Team Leader and Senior Security & Compliance Engineer, holding CompTIA Security+, a first class Applied Cyber Security degree and the Cyber Essentials Assessors Certificate. A focused team, not a side-of-desk capability.
Improvement, not just certification
Scanning, monitoring and remediation run every month, with quarterly reviews through the Your IT 360 Framework. You get evidence that your position is improving, not a certificate and a year of silence.
Built by your trusted IT partner
Delivered by Your IT Department Ltd, the team that already knows your business, your systems and your priorities. No handover to a third party, and no need to explain your environment twice.
Meet the practice lead
Fern Ritchie
Team Leader, Senior Security & Compliance Engineer
Fern joined Your IT as an apprentice in 2019 and has since become an integral part of the team. She completed her Level 3 Infrastructure Technician Apprenticeship in 2022, then specialised in cyber security, earning her CompTIA Security+ certification.
She has since completed an Applied Cyber Security degree, achieving a first, and holds the Cyber Essentials Assessors Certificate. Fern has been featured on Notts Today on Notts TV, has taken to the stage at Channel Futures in London, and regularly presents at live and online events for Your IT.
- Cyber Essentials Assessor
- CompTIA Security+
- BSc Applied Cyber Security, First Class
Ready to know where you are vulnerable?
A structured cyber assurance and vulnerability management programme for growing businesses. Talk to us about bringing it into yours.
- Cyber Essentials support and readiness review
- Monthly scanning and dark web monitoring
- Quarterly penetration testing on Plus
- Guided remediation every month
- Quarterly reviews, Your IT 360 Framework
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
Frequently Asked Questions
Let’s answer some of your frequently asked questions about Cyber Essentials and vulnerability management.
Do we need Cyber Essentials, or is this something more than that?
Both, depending on where you are. Cyber Essentials is a certification you achieve at a point in time, and we support you through scope, gap analysis, readiness and certification. This service continues after that, with monthly vulnerability scanning, dark web monitoring and guided remediation, so you can show your position is improving rather than presenting a certificate that was accurate on the day it was issued.
What is the difference between Essential and Plus?
Essential covers the foundation: Cyber Essentials support, monthly external vulnerability scanning, dark web and credential monitoring, prioritised risk reporting and up to two remediation hours a month. It suits organisations of roughly 10 to 50 users. Plus includes all of that and adds quarterly penetration testing, continuous vulnerability validation, a quarterly specialist security review and up to four remediation hours a month. It suits organisations of roughly 30 to 100 users, or anyone whose clients or insurers expect independent testing.
Is Cyber Essentials Plus certification included?
No, and that is deliberate. Cyber Essentials Plus readiness is a separate one-off add-on rather than part of the monthly service, so you only pay for it when you actually need it. The add-on covers readiness assessment, evidence gathering, assessor and test coordination, vulnerability verification and remediation planning. Certification and assessor fees are charged separately unless your quote states otherwise.
We already have antivirus and a firewall. Is this not covered?
Those are protective controls, and you should have them. This service answers a different question: where are you actually exposed right now, and is that improving? Scanning finds vulnerabilities on your external footprint, dark web monitoring picks up credentials leaked in third-party breaches, and penetration testing checks whether your controls hold up in practice. It is the assurance layer that sits over the defences you already have.
What happens if you find something serious?
You are notified with a risk-ranked assessment and a recommended next action, not just a raw scan report. Remediation support is included every month, two hours on Essential and four on Plus, so straightforward fixes are dealt with as part of the service. Anything larger is scoped and quoted separately, so a significant piece of work gets the attention it needs rather than being squeezed into a monthly allowance.