The challenge
Proving security controls were working in practice
The firm already held Cyber Essentials and had a number of established security controls in place.
However, larger clients were increasingly asking for stronger evidence during supplier reviews and due-diligence processes.
Cyber Essentials Plus offered that additional level of assurance, but it also meant the organisation's controls would be independently tested rather than assessed through self-certification alone.
With employees working across offices and remotely, the firm needed to make sure devices, user accounts and security settings were consistently configured before the assessment.
The priority was to identify any issues early and resolve them without creating unnecessary disruption for fee earners.