UK cyber regulation is tightening

Clients, insurers and new regulation all want proof. Know where you stand.

Clients ask for proof, insurers tighten terms and the Cyber Security and Resilience Bill adds duties. CyberPostura scores where you stand today, tells you what to fix first and in what order, and prepares you for Cyber Essentials certification.

Start the free posture check No login · ~6 minutes · 8 weighted domains

Built on the UK's recognised security frameworks

Cyber Essentials v3.3NCSC CAF v4.0CIS Controls v8.1DSIT Breaches Survey data

Why now

The pressure is already measurable.

24 hrs

Incident reporting window

Initial notification to your regulator and the NCSC after becoming aware of a significant incident. Source: UK government impact assessment, Cyber Security and Resilience Bill.

4%

Maximum penalty

Proposed upper limit on fines, calculated against global annual turnover. Source: UK government impact assessment, Cyber Security and Resilience Bill.

5%

Hold Cyber Essentials

Only 5% of UK businesses hold Cyber Essentials, while clients and insurers increasingly ask for it. Source: DSIT Cyber Security Breaches Survey 2025/26.

~1,100

MSPs expected in scope

Estimated number of managed service providers expected to fall within scope of the new duties. Source: UK government impact assessment, Cyber Security and Resilience Bill.

Built for two audiences

Businesses and their IT providers

Same control framework, two points of view. Score your own business — and if you are an MSP, score what your clients depend on you for, so the conversation between you is based on evidence rather than assurances.

Businesses of any sector

Asked for proof by clients and insurers

Tenders, contract clauses, supplier questionnaires and insurance renewals all now ask what security you actually have in place. A certification such as Cyber Essentials answers most of it in one line — this shows you how close you are and what stands in the way.

IT providers and MSPs

Held to a higher standard than your clients

Your clients pass their requirements straight to you, and new UK regulation is expected to place duties on larger providers directly. Score your own house, then use the same framework to show clients where they stand and what you are fixing for them.

Eight weighted domains

Scored against the standards

These are the eight areas clients, insurers and certification bodies actually ask about. Each is weighted by how strongly it drives real losses and real requirements, so your score reflects risk rather than a tick-box exercise.

Govweight 1.0

Governance

Board ownership of cyber risk, policy, certification and assurance.

Regulation-relevant
IAMweight 1.3

Identity & access

Authentication strength, privilege control and joiner-mover-leaver hygiene.

Cyber Essentials core
Endpointweight 1.0

Devices & endpoint

Endpoint protection, device management and configuration baselines.

Cyber Essentials core
Vulnweight 1.2

Patching & vulnerabilities

Update cadence, vulnerability discovery and remediation of exposure.

Cyber Essentials core
Backupweight 1.1

Backup & resilience

Backup coverage, immutability and proven restore capability.

Resilience core
IRweight 1.2

Incident readiness

Response planning, exercising and regulator notification readiness.

Regulation-relevant
Supplyweight 1.0

Supply chain

Supplier assurance, critical dependency mapping and contractual control.

Regulation-relevant
Peopleweight 0.9

People

Security awareness, phishing resistance and reporting culture.

First line of defence

How it works

A defensible starting point

01

Answer 20 questions

Two questions about your business, then 18 about your security, in plain English. No login, roughly six minutes.

02

See your score and exposure

A 0–100 score, an area-by-area breakdown, and a plain-English readout of what clients, insurers and incoming UK regulation will expect of you.

03

Get a prioritised roadmap

Your weakest areas become an ordered list of fixes, heaviest risk first, with the ones that matter for certification flagged.

Start now

Find out where you stand

The free check gives you a score, a plain-English breakdown and a prioritised list of fixes. When you want the proof your clients ask for, the detailed assessment is a one-off £299 +VAT, covering your company and up to 3 team members: every Cyber Essentials gap found before you apply, plus a roadmap you can track. Answer for your own business, and if your IT is outsourced, answer for what your provider does on your behalf.