UK cyber regulation is tightening
Clients, insurers and new regulation all want proof. Know where you stand.
Clients ask for proof, insurers tighten terms and the Cyber Security and Resilience Bill adds duties. CyberPostura scores where you stand today, tells you what to fix first and in what order, and prepares you for Cyber Essentials certification.
Built on the UK's recognised security frameworks
Why now
The pressure is already measurable.
24 hrs
Incident reporting window
Initial notification to your regulator and the NCSC after becoming aware of a significant incident. Source: UK government impact assessment, Cyber Security and Resilience Bill.
4%
Maximum penalty
Proposed upper limit on fines, calculated against global annual turnover. Source: UK government impact assessment, Cyber Security and Resilience Bill.
5%
Hold Cyber Essentials
Only 5% of UK businesses hold Cyber Essentials, while clients and insurers increasingly ask for it. Source: DSIT Cyber Security Breaches Survey 2025/26.
~1,100
MSPs expected in scope
Estimated number of managed service providers expected to fall within scope of the new duties. Source: UK government impact assessment, Cyber Security and Resilience Bill.
Built for two audiences
Businesses and their IT providers
Same control framework, two points of view. Score your own business — and if you are an MSP, score what your clients depend on you for, so the conversation between you is based on evidence rather than assurances.
Asked for proof by clients and insurers
Tenders, contract clauses, supplier questionnaires and insurance renewals all now ask what security you actually have in place. A certification such as Cyber Essentials answers most of it in one line — this shows you how close you are and what stands in the way.
Held to a higher standard than your clients
Your clients pass their requirements straight to you, and new UK regulation is expected to place duties on larger providers directly. Score your own house, then use the same framework to show clients where they stand and what you are fixing for them.
Eight weighted domains
Scored against the standards
These are the eight areas clients, insurers and certification bodies actually ask about. Each is weighted by how strongly it drives real losses and real requirements, so your score reflects risk rather than a tick-box exercise.
Governance
Board ownership of cyber risk, policy, certification and assurance.
Regulation-relevantIdentity & access
Authentication strength, privilege control and joiner-mover-leaver hygiene.
Cyber Essentials coreDevices & endpoint
Endpoint protection, device management and configuration baselines.
Cyber Essentials corePatching & vulnerabilities
Update cadence, vulnerability discovery and remediation of exposure.
Cyber Essentials coreBackup & resilience
Backup coverage, immutability and proven restore capability.
Resilience coreIncident readiness
Response planning, exercising and regulator notification readiness.
Regulation-relevantSupply chain
Supplier assurance, critical dependency mapping and contractual control.
Regulation-relevantPeople
Security awareness, phishing resistance and reporting culture.
First line of defenceHow it works
A defensible starting point
Answer 20 questions
Two questions about your business, then 18 about your security, in plain English. No login, roughly six minutes.
See your score and exposure
A 0–100 score, an area-by-area breakdown, and a plain-English readout of what clients, insurers and incoming UK regulation will expect of you.
Get a prioritised roadmap
Your weakest areas become an ordered list of fixes, heaviest risk first, with the ones that matter for certification flagged.
Start now
Find out where you stand
The free check gives you a score, a plain-English breakdown and a prioritised list of fixes. When you want the proof your clients ask for, the detailed assessment is a one-off £299 +VAT, covering your company and up to 3 team members: every Cyber Essentials gap found before you apply, plus a roadmap you can track. Answer for your own business, and if your IT is outsourced, answer for what your provider does on your behalf.