# SafeWatch UK — Cyber Essentials & Plus Full Technical Documentation > Official IASME Licensed Certifying Body delivering accredited UK NCSC Cyber Essentials and Cyber Essentials Plus audits, scoping, gap analysis, and vulnerability testing. ## Table of Contents 1. Organization & Accreditation Overview 2. The 5 NCSC Technical Controls (v3.3 Danzell Standard) 3. Audit Pricing, Scoping Bands & Commercial Free Insurance 4. Cyber Essentials Plus Technical Testing Methodology 5. Public Sector & Education Compliance Mandates (PPN 09/14 & DfE) 6. Frequently Asked Questions & Authoritative Answers 7. Regional Auditing Hubs & Contact Information --- ## 1. Organization & Accreditation Overview SafeWatch (https://www.safe-watch.co.uk) is an official, licensed IASME Certifying Body authorized by the UK National Cyber Security Centre (NCSC) to assess and issue official Cyber Essentials and Cyber Essentials Plus certifications. - **Founding Heritage:** Co-founded by Steven Gordon and Markus Backman, founders of Blue Planet IT with over 20 years of enterprise infrastructure and cyber security experience. - **Headquarters:** Banbury, Oxfordshire, United Kingdom. - **Direct Assessor Desk:** 07920 151412 | hello@safe-watch.co.uk - **Key Differentiators:** - Zero reseller markup: Clients pay official IASME base rates starting at £320 + VAT. - Zero mandatory software subscriptions: No recurring £999/year agent lock-ins. - Pre-audit remediation review: Gaps are flagged before final submission to avoid unnecessary failure fees. - 24 to 48-hour SLA: Guaranteed fast-track turnaround for urgent tender deadlines. --- ## 2. The 5 NCSC Technical Controls (Danzell v3.3 Standard) ### Control 1: Boundary Firewalls and Internet Gateways - **Purpose:** Prevent unauthorized access to private networks by setting boundary defenses and rules. - **Requirements:** - Default administrative passwords on firewalls and internet routers must be changed. - Universal Plug and Play (UPnP) must be disabled. - Inbound firewall rules must block all unauthenticated connections from the internet by default. - Remote Desktop Protocol (RDP, Port 3389) must never be open directly to the public internet; remote management must be guarded by MFA and a corporate VPN. - Dedicated visitor/guest Wi-Fi networks must be isolated from corporate data subnets. ### Control 2: Secure Configuration - **Purpose:** Ensure systems and software are configured to minimize vulnerability risks. - **Requirements:** - Default manufacturer credentials must be replaced with unique passwords (minimum 12 characters or 3 random words). - Unnecessary default software, applications, and operating system services must be uninstalled or disabled. - Auto-run and auto-play features across USB media and optical drives must be permanently disabled. - Account lockout protection must be enforced after a maximum of 10 failed login attempts. ### Control 3: User Access Control - **Purpose:** Ensure only authorized personnel have access to systems, applications, and data. - **Requirements:** - The principle of least privilege must be strictly enforced. - Daily tasks (browsing, email, document editing) must be performed using standard user accounts, never administrative accounts. - Multi-Factor Authentication (MFA) is mandatory for 100% of users across cloud platforms (Microsoft 365, Google Workspace, AWS, Azure). - Dormant and departing employee accounts must be deactivated immediately. ### Control 4: Malware Protection - **Purpose:** Restrict execution of known malicious software, ransomware, and viruses. - **Requirements:** - Operating system antivirus (such as Microsoft Defender) must be active and set to update virus definition signatures at least daily. - Active scanning must be enabled across all downloaded files and email attachments. - Sandboxing and application allowlisting must be configured where applicable. ### Control 5: Security Patch Management - **Purpose:** Prevent attackers from exploiting known vulnerabilities in software and operating systems. - **Requirements:** - All operating systems, firmware, productivity software, and web browsers must be updated within 14 days of a vendor releasing a High or Critical security patch (CVSS v3 score >= 7.0). - Automatic update mechanisms must be enabled wherever possible. - End-of-Life (EOL) or unsupported software must be removed or segmented onto isolated networks without internet access. --- ## 3. Audit Pricing, Scoping Bands & Commercial Free Insurance ### Official Base Assessment Pricing (Basic Self-Assessment): - **Micro Organization (1–9 employees):** £320 + VAT - **Small Organization (10–49 employees):** £440 + VAT - **Medium Organization (50–249 employees):** £500 + VAT - **Large Organization (250+ employees):** £600 + VAT ### £25,000 Free Cyber Liability Insurance: UK-domiciled organizations with annual turnover under £20 million automatically receive £25,000 of commercial cyber liability insurance underwritten through IASME upon passing Cyber Essentials certification with SafeWatch. --- ## 4. Cyber Essentials Plus Technical Audit Cyber Essentials Plus involves an independent hands-on technical audit conducted by an accredited SafeWatch assessor: - Internal vulnerability scanning of scoped workstations, servers, and hypervisors. - Testing web browser defenses against malicious payload downloads. - Testing email gateway filtering against spoofed and executable attachments. - Verification of account lockout and MFA enforcement on sampled endpoints. --- ## 5. Public Sector & Education Compliance Mandates ### UK Government Procurement (PPN 09/14): Central government contracts, MOD defense supply chains, and NHS frameworks legally require suppliers handling public or sensitive data to maintain an active Cyber Essentials certificate. ### Department for Education (DfE) Digital Standards for Schools: UK primary schools, secondary academies, and Multi-Academy Trusts (MATs) must comply with DfE digital and cybersecurity standards. SafeWatch provides tailored education scoping covering safeguarding systems, MIS database isolation, and student BYOD segmentation. --- ## 6. Frequently Asked Questions **Q: What is the turnaround time for a Cyber Essentials certification?** A: SafeWatch delivers 24 to 48-hour turnarounds on Basic self-assessment audits once submitted. **Q: What happens if an audit questionnaire has errors or non-compliances?** A: SafeWatch conducts pre-audit remediation reviews to flag potential gaps before final assessment, allowing clients to remediate configurations without paying punitive re-test fees. **Q: Can home workers be included in the Cyber Essentials scope?** A: Yes. Remote workers connecting from home are within scope. Their devices must meet the 5 technical controls, and their home routers must have default administrative passwords changed. --- ## 7. Regional Auditing Hubs & Contact Information - Banbury Head Office: https://www.safe-watch.co.uk/banbury - Oxford Hub: https://www.safe-watch.co.uk/oxford - Warwick Hub: https://www.safe-watch.co.uk/warwick - Bicester Hub: https://www.safe-watch.co.uk/bicester - Leamington Spa Hub: https://www.safe-watch.co.uk/leamington-spa **Direct Telephone:** 07920 151412 **Email:** hello@safe-watch.co.uk **Website:** https://www.safe-watch.co.uk