There's a fair question any client should ask a security provider: who checks your security?
We're pleased to answer it properly. Pablosec Solutions is now certified to both Cyber Essentials and Cyber Essentials Plus the UK Government-backed scheme developed by the National Cyber Security Centre and delivered through the IASME Consortium.
The second one is the part that matters.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials covers five technical controls that, applied properly, block the overwhelming majority of commodity internet attacks:
- Firewalls controlling what reaches your systems from the internet
- Secure configuration removing default accounts, unnecessary services and needless exposure
- Security update management patching supported software within defined timescales
- User access control least privilege, administrative account separation, multi-factor authentication
- Malware protection detection and prevention across endpoints
Standard Cyber Essentials is a self-assessment. You answer the questionnaire, a Certification Body reviews it, and you're certified.
Cyber Essentials Plus is different. The same five controls, but an independent assessor comes in and tests them hands-on. Authenticated vulnerability scans against a sample of our workstations, servers and mobile devices. Simulated malicious files delivered by email and web download. Verification that account separation and MFA actually work the way we said they do — not the way we hoped they did.
It's the difference between describing your controls and having someone try to get past them.
Why we did it
We build and manage security for other organisations. We deploy firewalls, harden configurations and design segmentation for networks that support critical infrastructure across Ireland, the UK and the EU. Holding ourselves to a lower standard than the one we recommend to clients was never a defensible position.
There's also a practical dimension. Security is increasingly assessed at the supply chain level, and rightly so. If you engage a managed security provider, that provider becomes part of your attack surface with privileged access to your infrastructure. Under NIS2, entities in scope are explicitly accountable for the security of their supply chain, and that scrutiny flows downward to providers like us.
Cyber Essentials Plus doesn't make anyone NIS2-compliant, and we won't pretend otherwise. What it does is give our clients independently verified evidence about the security posture of a company that holds keys to their environment instead of asking them to take our word for it.
For clients tendering for UK public sector work, it's more direct still: Cyber Essentials is a mandatory requirement for a range of central government contracts, and Plus is required where more sensitive information is handled.
What this means for you
If you're already a client: the controls protecting the systems we use to manage your infrastructure have been independently tested, not self-declared. Our certification documentation is available on request for your own supplier assurance and vendor risk processes.
If you're evaluating providers: ask every one of them for their certification status, and check whether it's Cyber Essentials or Cyber Essentials Plus. The two words are not interchangeable, and the gap between them is a technical audit.
If you're pursuing certification yourself: we've now been through the full assessment as a candidate, not just as an advisor. That experience including where the assessor pushed hardest, and the things organisations routinely underestimate is something we bring to clients working towards their own Cyber Essentials or Cyber Essentials Plus certification.
Both certifications are valid for twelve months, and we'll be recertifying annually. Security posture is a current state, not an achievement, and a certificate that isn't renewed says very little.
Working towards Cyber Essentials, or reviewing your supply chain assurance? Get in touch we're happy to talk through where you stand and what the assessment actually involves.





