Contents
Cyber Essentials vs Cyber Resilience: Introduction
If you work in a UK organisation, you have almost certainly been asked about Cyber Essentials, and you may well be certified. For a lot of boards it has quietly become the answer to the question “are we secure?”. The trouble is that attackers do not check whether you hold a certificate. They check whether they can get in.
The scale of that gap is easy to underestimate. The government’s Cyber Security Breaches Survey 2025/2026, published in April 2026, found that 43% of UK businesses had experienced a breach or attack in the previous twelve months, rising to 65% of medium and 69% of large businesses. Certification numbers keep climbing, and yet incidents remain common, which is precisely why the distinction between Cyber Essentials and cyber resilience is worth understanding.
Compliance, like cybersecurity, comes with a lot of jargon, so if a term here is unfamiliar, our A to Z cybersecurity glossary can help.
What Cyber Essentials does, and does well
It is worth being fair to the scheme before criticising how it is used. Cyber Essentials is the UK government-backed baseline for security, built around five technical controls covering firewalls, secure configuration, user access control, malware protection and security update management. Those controls block the most common internet-based attacks, the high-volume automated attempts that make up the bulk of what most businesses face.
There is real evidence it works. According to the NCSC’s 2024 Annual Review, organisations that implement the Cyber Essentials controls are 92% less likely to make a claim on their cyber insurance. So this is not meaningless paperwork, because it forces you to clean up obvious weaknesses, it reassures customers and suppliers, and it can reduce your insurance premiums. The problem is never Cyber Essentials itself, but rather it’s people treating it as the destination rather than the starting point.
Where Cyber Essentials stops
When the certificate becomes a badge rather than a framework, organisations tend to race to pass the assessment once a year, focus on the questionnaire rather than their actual risks, and then point to the certificate as proof they are secure. Several things get missed in that mindset.
It is a snapshot, not continuous security. Cyber Essentials is assessed at a single point in time, but threats change constantly. If your controls are only reviewed at renewal, a weakness introduced the week after certification can sit exposed for months while attackers scan for new openings within days.
It focuses on prevention, not response. The scheme is designed to keep common attacks out. It says nothing about how you detect a breach, contain it, or keep the business running while you recover. That omission is expensive when something does get through. IBM’s 2025 Cost of a Data Breach report put the average UK breach at £3.29 million once you count investigation, downtime, legal fees, fines and lost customers, which is the real cost of weak resilience rather than weak prevention.
It does not test whether anything actually works. This is the big one, because Cyber Essentials is a questionnaire and evidence submission, not a security assessment. It does not include penetration testing, threat-led attack simulation, monitoring, log review or recovery testing. A hands-on technical check only arrives with Cyber Essentials Plus, and even that is narrower than a full test. So you can have the certificate on the wall and still have exploitable weaknesses sitting quietly in your environment, unnoticed until someone else finds them. This is what we call checkbox security, and it is a trap. A form can say you are compliant, but an attacker can prove you are not.
The human element is still your biggest exposure. Cyber Essentials includes some access requirements, but it cannot train your people. Phishing remains the dominant way in, cited by 88% of the businesses that identified a breach in the 2025/2026 survey, and without regular awareness work one convincing email can undo a great deal of technical control.
Your supply chain is now the bigger risk
There is one weakness Cyber Essentials cannot see at all, and it happens to be the one growing fastest. Over the last decade organisations have outsourced almost everything, including IT support, cloud services, HR systems, payroll and document management, and every one of those providers is a potential entry point. Across manufacturing, professional services and aerospace alike, attacks increasingly arrive through a supplier rather than the target itself. Outsourcing a function feels like reducing risk, but in security terms it usually expands it.
Your certificate cannot measure your suppliers’ security, and it certainly cannot protect you from their mistakes. Because you cannot outsource responsibility, the only real answer is to actively verify the security of everyone in your digital supply chain, a theme we explore in supply chain cyber attacks.
What cyber resilience actually means
Cyber resilience goes beyond a compliance checklist. Where Cyber Essentials asks whether you have implemented a set of controls, resilience asks harder questions: how quickly can you detect an attack, how effectively can you limit the damage, how fast can you restore critical services, and how much disruption can the organisation absorb before it is in real trouble? Crucially, resilience assumes some attacks will get through, and sets out to make them survivable rather than fatal.
In practice it rests on a few connected capabilities:
- Risk assessment and business impact. Map your critical assets, systems and suppliers, and understand how different threats would affect operations. This turns security from a technical concern into board-level risk management.
- Continuous monitoring and testing. Put monitoring in place across endpoints, networks and cloud, run regular vulnerability scanning and risk-based patching, and use penetration testing to validate your defences under realistic conditions.
- Incident response planning. Document and rehearse a plan so that roles and decisions are clear before an incident, not improvised during one. Our guide to developing an incident response plan covers this in detail.
- Backup and disaster recovery. Keep regular, tested backups with offline or immutable copies, and align your recovery targets with what the business can actually tolerate, which matters most when you are responding to a data breach.
- Supply chain security. Identify which suppliers touch your systems and data, set minimum standards for them, and include them in your incident planning.
- Security awareness. Give people role-relevant training and build a culture where they feel able to report mistakes, because training genuinely reduces risk.
How to build resilience beyond Cyber Essentials
If Cyber Essentials is step one, these are the steps that follow.
- Validate your controls. Use independent penetration testing to check that your firewalls, access management and endpoint security hold up under a realistic attack, rather than assuming a passed questionnaire means they do. Understanding what an attack surface assessment reveals about your real exposure is a good place to start.
- Add monitoring. Invest in centralised logging and endpoint detection and response, because early detection is often what stops a minor incident becoming a major one.
- Build response capability. Create plans for identification, triage, escalation and containment, then run tabletop exercises so the people involved know their roles before they are under pressure.
- Assess your suppliers. Review third-party security, build minimum requirements into contracts, and make sure your response plans include supplier communication.
- Report cyber risk to the board. Move the conversation past technical metrics towards critical-service exposure, testing results and detection times, so leadership can make informed decisions.
Bringing it together
Cyber Essentials and cyber resilience are not rivals, and the honest answer to “which do I need?” is both, in order. Cyber Essentials gives you a genuine foundation: it removes the obvious weaknesses and demonstrates baseline security to the people who ask for it. Resilience is what you build on top, through testing, monitoring, incident response, supply chain assurance and board-level ownership. The neatest way to hold the two ideas together is this: Cyber Essentials is the evidence that you take security seriously, and resilience is the operational reality behind that evidence.
At Fortifi we spend most of our time helping organisations make that move from compliance to resilience. We validate Cyber Essentials controls with real penetration testing, find the weaknesses a questionnaire cannot, and help prioritise the fixes that strengthen both your security and your ability to keep running when something goes wrong. If you want to know how resilient your organisation really is, rather than how compliant it looks on paper, book a call and we will help you plan the next step.