Skip to content
Case study · Cyber Essentials Plus

Achieving Cyber Essentials Plus for a defence-sector engineering consultancy

For a business working with government and defence clients, cyber security certification isn't optional — it's often the gate to being considered for the work at all. Here's how we helped them pass the audit.

Or call us on 0117 958 5964

Client

Engineering & safety consultancy (government, defence, industrial)

Project

Cyber Essentials Plus certification, working alongside internal cyber security team

Approach

M365 hardening, mobile device management, virtual desktops for associates

Outcome

Cyber Essentials Plus certification achieved, with reduced ongoing attack surface

The challenge

Our client, a long-standing engineering and safety consultancy supporting government, defence and major industrial clients, needed to achieve Cyber Essentials Plus — the higher, independently-audited tier of the UK's flagship cyber security certification.

For a business operating in this sector, certification isn't a nice-to-have; it's frequently a contractual requirement to even be considered for the work. And the "Plus" standard means every claim has to be independently tested and verified by an assessor, not simply declared.

What we did

We worked closely alongside the client's own internal cyber security team and senior leadership throughout, acting as an extension of their existing expertise rather than an outside contractor parachuted in.

Together we reviewed and reconfigured their Microsoft 365 environment to meet both general best practice and the specific technical controls Cyber Essentials Plus requires — covering areas like access control, secure configuration and account permissions across the whole organisation.

The Plus certification's defining feature is its vulnerability and patching audit, which meant every device on the network had to be checked and verified as fully patched and up to date — not just laptops and desktops, but the company's entire fleet of managed mobile phones used by a largely remote workforce. We used an enterprise mobile device management platform, paired with the manufacturer's business enrolment programme, to bring every company-owned mobile device under proper policy control and confirm its patch status ahead of assessment.

One of the trickier challenges was the client's use of third-party associates — specialists who work alongside the consultancy's own staff but aren't direct employees. Extending full network and data access to associates the way you would an employee increases risk unnecessarily. Instead, we designed and deployed cloud-hosted virtual desktops for these associates to use, so they could do their work without ever having company data land on a personal or unmanaged device.

This significantly reduced the amount of sensitive data leaving the business and shrank the overall attack surface, while still giving associates everything they needed to do their jobs.

The outcome

The certification was achieved successfully, giving the client's leadership, staff and — critically — their government and industry clients real assurance that security is built into daily operations, not just paperwork produced once a year.

Beyond the certificate itself, the client came away from the project with a materially reduced attack surface: mobile devices under proper policy control, associate access moved off personal machines and onto managed virtual desktops, and Microsoft 365 hardened to a defensible baseline.

The controls we put in place

Six areas covered end-to-end, then evidenced for the independent auditor.

Microsoft 365 hardening

Access control, secure configuration and account permissions reviewed and tightened across the organisation.

Mobile device management

Entire fleet of company mobiles brought under enterprise MDM, with manufacturer business enrolment.

Vulnerability & patching audit

Every device on the network verified as fully patched and up to date ahead of independent assessment.

Virtual desktops for associates

Third-party specialists work in cloud-hosted desktops so company data never lands on unmanaged machines.

Reduced attack surface

Sensitive data leaving the business meaningfully cut; associate access moved off personal devices.

Partnered with internal cyber team

Worked alongside the client's own security specialists rather than displacing them.

The lesson for other businesses

For any SMB working towards Cyber Essentials or Cyber Essentials Plus: start with your own leadership and any internal expertise you already have rather than working around them. Treat mobile devices with the same seriousness as laptops. And think carefully about how contractors and associates access your systems — the biggest risks are often not your own staff, but the people working alongside them.

Ready to talk about Cyber Essentials?

Whether you're aiming for basic Cyber Essentials or the audited Plus tier, the first scoping call is free. We'll tell you honestly where you stand and what it will take to get there.

Or call us on 0117 958 5964