Book a call
By LegalEdge News

Cyber Security Standards Explained


You may think that you have the right cyber security in place but are you confident that you are protecting your customers, employees and IP? Every business faces cyber security challenges, no matter their industry or size. To help you understand what you need to do, here’s cyber security explained by CyberSmart, cyber security specialists.

The cyber security sector is a heavily crowded space when it comes to the various standards, certifications, rules and regulations.

It can also cause a lot of confusion for those not familiar with the best practice. Founders and business owners often come to us and say they want to or have to get ISO 27001 certified. Hardly anyone knows when or how ISO 27001 makes sense for a small business and what other certifications can be achieved other than ISO 27001 or whether it can be used as a stepping stone towards achieving ISO 2700.

Here is a brief overview of the most common cyber security standards in the UK:

Cyber Essentials:

Cyber Essentials is a scheme that was designed by the UK government in 2014. It aims to get all UK businesses to be able to manage their IT security to a certain level. It helps companies to implement basic levels of protection against cyber attacks, demonstrating to their customers and suppliers that they take cyber security seriously.

Established in 2014, the purpose of this standard is to develop the necessary cyber security standards throughout an organisation. The standard is relatively technical and protects organisations from 80% of cyber-attacks. The most surprising factor we discovered was that most companies that had other standards, such as ISO 27001 or PCI-DSS implemented, would still fail under Cyber Essentials. The best use case for this standard is to implement it as a first defence and perimeter security before other standards are considered.

It is largely seen as a great first step towards data security, especially under GDPR. It serves as evidence that you have carried out basic steps towards protecting your business from internet-based cyber attacks.

Cyber Essentials Plus:

Cyber Essentials Plus is the audited standard of Cyber Essentials. Besides including some additional controls, the implementation needs to be assessed by a Cyber Essentials Plus auditor. This obligatory audit creates additional trust in the standard and it is safe to assume that once Cyber Essentials is well-established, Cyber Essentials Plus will increasingly become mandatory.

IASME- GDPR Readiness:

This standard goes further than Cyber Essentials and can be described as a “mini version of ISO 27001:2017”. IASME developed this standard with the government in order to create an affordable alternative to ISO 27001. The IASME standard is specially tailored towards SME’s and includes processes, people and technology. In May 2018, both IASME standards were expanded to include GDPR readiness. Both IASME standards require Cyber Essentials as part of the readiness as well. Similarly to Cyber Essentials, the IASME standard can serve as evidence to customers and suppliers that their information is being protected.

ISO 27001:

ISO 27001 is an international information security standard which includes more than 100 controls. The standard is often implemented by corporations or businesses dealing with the public sector. ISO27001 covers areas that include security policies, access control, operations security, human resources, cryptography and compliance. It does not cover GDPR, however, an organisation can voluntarily include GDPR in their ISMS (Information Security Management System) providing further security.

 A note on GDPR: GDPR is NOT a standard, it is a law. Hence we have excluded it here. ????

 If you have any questions about Information Security Standards or Cyber Security in general or just want to have a chat, drop us a line at hello@cybersmart.co.uk

 

 

Back To Blog Our Services
  • Share:

What do our clients think?

We’ll set up a cost-effective, efficient legal function for your business. You’ll have an experienced lawyer as your single point of contact who works as part of your operations team.

No duplication and no reinventing the wheel each time. We get to know your business quickly to manage your legal matters effectively and add value. And as your flexible in-house legal function, we can be scaled up or down depending on needs.

We analyse risk and prioritise what’s important, then manage and carry out the day-to-day legal work, all to a set budget. We’ve all worked as in-house lawyers in fast growth companies, so know what you need (and don’t need) to worry about. We’ll work with you to get deals and contracts done and help achieve your business goals.

“The fact that all their lawyers have worked inside businesses means they are commercial, pragmatic and know exactly how to prioritise what’s important.”

“We’re very pleased with the work LegalEdge are doing for us. We’re getting quick and decisive responses that are really helping us move forward.”

We work with small in-house legal teams that need additional support on a flexible basis without adding to headcount.

Whether it’s overflow work, a project or just a much-needed extra pair of hands we can help. We get the job done without supervision, working seamlessly as part of your team or behind the scenes, whatever works best for you. We don’t do endless negotiations on the clock or write long legal memos. We just help prioritise, find solutions and get it done.We understand the challenges and demands of small in-house teams because we’ve been there. We work as an extension to your team, get up to speed on business priorities quickly, and help you keep control of legal workflow and budget.

“The ideal solution for the busy in-house counsel who is unable to add a permanent head as you have the ability to flex support without the need to rely on expensive law firms.”

“LegalEdge has provided excellent, commercially focused advice as part of our in-house legal team that has helped us close contracts with our customers and partners.”