Our Services

Our services have been developed over the years to offer support to a diverse array of industries and create tailor made support plans for every company we work with.

Cyber Essentials Support London

Most businesses fail Cyber Essentials on things they did not know counted. Northern Star provides Cyber Essentials support in London, taking you from an honest gap assessment through to a pass, without the last minute scramble.

We have supported growing organisations for more than sixteen years. We handle the technical work, the evidence and the paperwork, and we tell you plainly what will fail before you submit.

Certification has become a commercial requirement

Cyber Essentials is now mandatory for most central government contracts involving sensitive data, and main contractors, insurers and corporate clients increasingly ask for it during procurement.

In London that pressure arrives early, because supply chains here are long and buyers are demanding. Our IT consulting team can help you decide which level you actually need.

What our Cyber Essentials support in London covers

Readiness assessment

We review your devices, cloud services, firewalls, accounts and software against the current IASME requirements, then give you a plain English report of what passes and what does not.

No surprises at submission, and no guessing at scope.

Remediation of the gaps

Finding problems is easy. We fix them, covering multi factor authentication, device encryption, admin account separation, unsupported software, patching schedules and firewall rules.

Work is scheduled around your business rather than dropped on a Monday morning.

The five control areas

Firewalls, secure configuration, user access control, malware protection and security update management are the five areas assessed. We bring each one to standard and document the evidence.

Self assessment and submission

We complete the questionnaire with you rather than sending it over and hoping. Answers are checked against what your systems actually do, which is where most first time failures come from.

Cyber Essentials Plus

Plus adds a hands on technical audit and external testing. We prepare your estate for it with vulnerability management and remediation ahead of the scan, so the audit confirms what we already know.

Annual renewal

Certification lasts twelve months, and estates drift. We track changes across the year so renewal is a formality rather than a rebuild.

Evidence pack for tenders

Once certified, most of the same evidence answers supply chain security questionnaires. We keep it documented so procurement requests do not become a fire drill each time one lands.

Staff training and ongoing security

Controls slip when people are not trained. We include awareness training and phishing simulations, because passing once means little if a member of staff hands over credentials the following month.

Why London businesses choose Northern Star

Our client satisfaction score sits at 95.4 across recent reviews, from sixty five responses in ninety days.

Clients stay because we do not treat certification as a form filling exercise. The controls stay in place after the badge arrives, account managers know the environment, and fixed monthly pricing spreads the cost across the year rather than landing it in one quarter.

We support organisations from five to two hundred and fifty users, including those with overseas offices that need to fall inside the certification scope.

How the process runs

Scope, assess, remediate, submit. Most organisations get from first conversation to certification in four to eight weeks, depending on how much needs fixing.

Where an environment is already in reasonable shape, we can move faster. Protection such as email security usually goes on early, since impersonation is the most common route in for London businesses.

Speak to Northern Star

Tell us your deadline and we will tell you honestly whether it is achievable and what it will take. Book a call with an experienced engineer, not a sales script.

Frequently asked questions

There are two separate costs. The certification fee itself is set by IASME and charged on a sliding scale by organisation size, starting at around three hundred and twenty pounds plus VAT for a micro business with up to nine employees, and rising for larger organisations.

Cyber Essentials Plus is charged separately and usually costs between one thousand five hundred and three thousand pounds plus VAT, depending on the number of devices and locations to be tested. The second cost is the preparation work, which varies enormously.

An organisation already running managed devices and multi factor authentication may need very little. One with unsupported operating systems, shared logins and no device management will need real remediation. Northern Star assesses first and quotes against what is actually there rather than a standard package.

Cyber Essentials is a self assessment. You answer a questionnaire covering the five control areas, and an accredited certification body reviews your responses. It is verified but not tested, which makes it quicker and cheaper, and it is enough for many public sector and supply chain requirements.

Cyber Essentials Plus covers the same controls but adds independent technical verification. An assessor carries out vulnerability scanning and hands on testing of a sample of your workstations, servers and mobile devices, and checks that malware protection and patching genuinely work rather than simply being described.

Plus is normally required where you handle sensitive data, work in a regulated sector, or a client has specified it contractually. Most organisations start with Cyber Essentials and move to Plus once a buyer asks for it.

Four to eight weeks is a realistic range for most London organisations, measured from the first conversation to the certificate. Scoping and the readiness assessment usually take one to two weeks. Remediation is the variable, and it can be a few days or several weeks depending on what the assessment finds.

Unsupported operating systems and end of life hardware are the most common causes of delay, because they require procurement rather than configuration. Once remediation is complete, submission and review typically take a few working days.

Cyber Essentials Plus adds a further two to four weeks, since the technical audit has to be scheduled and any findings resolved. If you have a tender deadline, tell us the date at the outset and we will work backwards from it.

The most common failures are predictable, which is why preparation matters more than the questionnaire itself. Unsupported software is the biggest single cause, typically an old Windows build, an unpatched router or an application the vendor no longer updates.

Missing multi factor authentication on cloud services is the second, particularly on administrator accounts. After that come shared or generic logins, administrator rights given to ordinary user accounts, mobile devices outside any management, and firewall rules nobody has reviewed for years. Scope errors also cause trouble, since organisations often exclude something that must be included.

Good Cyber Essentials support in London catches all of this before submission rather than after, because a failed assessment means paying again and, more painfully, missing the deadline the certification was needed for.

Yes, and this surprises people. All cloud services your organisation uses fall within scope, including Microsoft 365, Google Workspace and any software as a service platform holding your data, so multi factor authentication and access control apply to them too. Home working is also in scope.

Where staff work from home on company devices, those devices are assessed as normal, and the router supplied by their internet provider is generally out of scope provided the device firewall is enabled and configured. Personal devices used for work, including phones accessing company email, are in scope and need to meet the requirements. This is why bring your own device arrangements often need tightening before certification, usually through mobile device management rather than banning them outright.

Yes. Cyber Essentials must be renewed every twelve months, and the requirements themselves change periodically, so an environment that passed last year will not automatically pass this year. Northern Star manages renewal as part of ongoing support rather than treating it as a fresh project each time.

We track changes across the year, including new devices, new cloud services, staff joining and leaving, and software approaching end of life, and we flag anything that would fail well before the renewal date. That removes the annual rush and the expense of replacing hardware at short notice. Spreading the work across twelve months also spreads the cost, which is easier to budget for than a lump sum every spring.