On 23 September we're covering what Cyber Essentials actually involves, in plain English. No jargon or sales pitch - just what to expect and how long it takes.
Attendees will also have the chance to walk away with a pair of AirPod Pros 3!
If you're the one who ends up sorting this when a client asks, this is for you.
Link to sign up in the comments...
Two conversations with an insurer look quite different depending on one thing.
A Cyber Essentials certification is increasingly a starting point insurers expect, and it can bring premiums down at the same time.
Our session on 23rd September covers the cost, the saving, and what's actually involved in getting certified.
Also, all attendees have the chance to walk away with a pair of AirPods Pro 3's!
Link in comments...
Being able to say yes, without picking up the phone to check with IT, sounds like a dream.
Clients are increasingly asking whether companies they work with are Cyber Essentials certified.
If you're bidding for enterprise and public sector work, we're running a short, jargon-free session on 23 September on what's involved.
Link in comments...
If you're already signed up to our next webinar, you might walk away with a pair of AirPod Pro 3's!
It's on Cyber Essentials. More agencies and practices are being asked to produce Cyber Essentials certification, often with barely any notice.
On 23rd September we're running a short, jargon-free online session on what's actually involved and how long it really takes, so it's sorted before the next request lands on your desk.
Link to registration page in the comments...
A number worth knowing before your next insurance renewal.
Cyber Essentials certification now comes with ยฃ25,000 of cyber liability cover built in for organisations under ยฃ20m turnover.
Insurers are increasingly asking for the certification anyway before they'll even quote.
We're running a short, jargon-free session on 23 September on what it costs, what it saves, and what's involved.
Also, all attendees will be entered into a draw to win a pair of AirPod Pro 3's. Link in comments...
Increasingly, clients (especially bigger ones) are asking agencies and practices to prove they hold Cyber Essentials before a contract gets signed.
Not as a nice-to-have. As a condition. If you run the business, it's worth knowing what's actually being asked for, what it takes to get there, and what it protects against, before a client asks you directly.
We're covering all of it in a short, jargon-free session on 23 September.
You can also win a free pair of AirPod Pro 3's if you attend. Link in the comments...
The quickest route into an agency is usually an account nobody remembered to close.
User access control is the Cyber Essentials requirement that fails on process rather than technology. Leavers keep mailbox access. Freelancers hold admin on a shared drive from a project that ended two summers ago. Two people share one login for the design tool because the licence was expensive.
Since the April 2026 update, multi factor authentication on cloud services is mandatory. No MFA is an automatic fail. That has caught out a lot of teams who had it on email and not on file sharing, project management or finance tools.
Three questions worth putting to whoever handles your IT. Who has admin rights today. What happens to an account within 24 hours of someone leaving. Which cloud services still allow a password on its own.
Our Cubit Cyber Check scores Access and Identity as one of five areas. Link in the comments.
#CyberEssentials #MFA #ITSupport #ArchitecturePractices
A PBS station in Missouri has spent the last five months in court trying to get back 50TB of its own data. 70 years of archive footage, including their coverage of the 1993 Great Flood. Here's what happened.
Their cloud storage vendor quietly went bust.
No warning, no notice period, the contract just stopped working one day in March.
Turned out the vendor had been renting server space inside another company's data centre, and when they disappeared, that company wouldn't hand the data over without a court order, because legally the servers weren't the station's to take.
A judge has now ruled the station owns the data.
That took two separate lawsuits to establish. As of the most recent update, they still hadn't got it back.
This is the bit that should worry more businesses than it does. Owning your data and being able to access it are NOT the same thing.
If it lives with one vendor, on one system, with no independent copy you control, you are one insolvency away from being in exactly this position, minus the TV cameras.
The fix isn't complicated.
Know who actually holds your data, not just who you have the contract with.
Keep a copy you can actually restore. Test that restore before you need it, not during.
#CyberSecurity #DataBackup #ITSupport #BusinessContinuity
A backup you have never restored from is not a backup. It is a hope with a schedule attached.
Recovery and Resilience is the area where confidence and reality diverge most. Backups run nightly, the dashboard is green, and nobody has tested a restore since the system was installed.
Then a ransomware incident hits and the questions become specific. How far back does the clean copy go. How long does a full restore take. Does it include the shared drives, the project files, the CAD models, the mailboxes, or only the server.
For architecture practices this one carries weight. Project files are the deliverable and the liability, and a two week outage mid stage four is a client relationship problem before it is an IT problem.
The NCSC found organisations with Cyber Essentials made 92% fewer cyber insurance claims than those without. Recovery planning is a large part of why.
Cyber Check in the comments.
#CyberEssentials #Ransomware #BusinessContinuity #ITSupportLondon
Someone in your studio has already spotted something odd and decided not to mention it.
That is the part no tool fixes. People report suspicious emails it's easy, fast and free of embarrassment. They stay quiet when it means admitting they nearly clicked, or when the last person who raised something waited three days for a reply.
People and Culture is one of the five areas we score with our free IT check tool, and it is often where creative and PR agencies score lowest. And it's not the team's fault - in their defence, nobody has told them what to do, who to tell, or that speed matters more than certainty.
The fix is unglamorous. A named person or channel. A five second reporting route. A visible thank you when someone flags a false alarm, so the next person does it too.
Culture is a control. Treat it like one.
#Cybersecurity #CyberEssentials #Phishing #PRAgencies