Thursday, 1 October 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Cyber Essentials needs the IT provider, not just the business owner

The government is urging small firms to ‘lock the door’ with Cyber Essentials. But many small businesses outsource security to an IT provider, and the campaign barely speaks to them

Government campaign graphic reading ‘Government to support businesses against online threats’
Image: GOV.UK (OGL)
In brief
  • The DSIT and NCSC campaign launched on 17 February 2026 targets small business owners directly through social media, podcasts and radio.
  • Government research found only 12% of businesses were aware of Cyber Essentials, and some small firms leave accreditation decisions to their IT providers.
  • Customer demand has done more than advertising to drive certification, which points to IT providers and supply-chain requirements as the real levers.

On 17 February 2026 the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC) launched a campaign urging business owners to “lock the door” on cybercriminals. It will run across social media, podcasts, radio and business networks, and it points small and medium-sized firms toward Cyber Essentials, the government-backed certification built on five controls: firewalls, secure configuration, software updates, user access control and malware protection.

The announcement makes the case for urgency with numbers. The government puts the cost of cyber threats to UK businesses at £14.71bn a year and says half of small businesses suffered a breach or attack in the previous 12 months. A significant incident costs an average of £195,000, according to the release. Most attackers “don’t care about size, reputation or logos”, said Dr Richard Horne, chief executive of the NCSC.

The campaign comes with free help: an online readiness tool, a free preview of the Cyber Essentials question set and free 30-minute consultations with an NCSC-assured cyber advisor for SMEs preparing to certify.

All of that is useful. But the campaign is pointed at the wrong desk. Government survey data shows 62% of small businesses outsource their cybersecurity, and in some of them the decision on Cyber Essentials isn’t made by an owner who hears a radio advert. It is made, or never raised, by the outside IT provider that runs their systems. Until the government treats those providers as the route into small businesses, the scheme will keep reaching the firms that need it least.

How far awareness has drifted

The government’s own evidence shows how far there is to go. The Cyber Security Breaches Survey 2025, commissioned by DSIT and the Home Office and based on a random probability survey of 2,180 UK businesses between August and December 2024, found that only 12% of businesses were aware of Cyber Essentials, down from 16% in 2022. Among micro businesses the figure was 9%; among small businesses it was 23%. Just 3% of businesses said they adhered to the standard.

The controls themselves are not exotic. The same survey found 21% of businesses had technical controls in all five Cyber Essentials areas, rising to 47% of medium businesses and 59% of large ones. Its authors concluded that some organizations, especially medium and large businesses, were potentially already meeting the standard but not seeking certification. The gap is partly about security and partly about nobody asking for the certificate.

Who actually decides

The survey’s interviews show where that question sits. Some smaller businesses relied on third-party IT providers to decide whether they pursued accreditations such as Cyber Essentials, the report says, and not all of those providers told their clients about the potential benefits. It also observed that in some smaller businesses responsibility for cybersecurity was being passed to external contractors, which sometimes led senior managers to disengage from the topic.

That is the weak point in a campaign built around owners. An owner who has outsourced IT, and with it the thinking about security, is the person least likely to act on an advert about secure configuration. The likely response is to forward it to the provider, who has either already weighed up certification or has not raised it. Preparing a client for Cyber Essentials is work that someone has to scope, price and sell, and a campaign that never names that someone leaves the conversation to chance.

Larger firms show what happens when the push comes from elsewhere. The release says adoption of Cyber Essentials among larger companies has risen from 23% to 30%. In the breaches survey interviews, medium and larger businesses said client requirements determined whether they became accredited. Demand from customers did the persuading that awareness campaigns had not.

Where the pressure should go

The government already holds the arguments that move a small firm. Certification can help businesses win government contracts, according to the release. It says organizations with Cyber Essentials made 92% fewer insurance claims last year, and eligible firms can get free cyber insurance, including a 24/7 emergency helpline, through the scheme’s delivery partner.

Those are points an IT provider can put to a client at a quarterly review, with the client’s own systems on the table. They are much harder to land through a podcast advert. Baroness Lloyd of Effra, the cybersecurity minister, made the case herself in the launch announcement: “I know smaller firms don’t have large IT teams, and that is exactly why Cyber Essentials matters.” Firms without IT teams buy IT from someone. That is the route the campaign should be using.

Security leaders in larger organizations have a part to play too. The survey found that smaller businesses had limited knowledge of the full extent of their supply chains, while larger firms worried more about supplier risk. Writing Cyber Essentials into requirements for small suppliers, and asking which IT provider looks after them, turns a national campaign into a contract condition. The government says the Cyber Security and Resilience Bill will strengthen defenses through supply chains, so the direction of travel is clear.

Locking the door is sound advice. In many small businesses, someone else holds the keys.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Department for Science, Innovation and Technology, National Cyber Security Centre and Baroness Lloyd of Effra, “Businesses urged to “lock the door” on cyber criminals as new government campaign launches”, press release, 17 February 2026. https://www.gov.uk/government/news/businesses-urged-to-lock-the-door-on-cyber-criminals-as-new-government-campaign-launches
  2. Department for Science, Innovation and Technology and Home Office, “Cyber security breaches survey 2025”, official statistics, updated 19 June 2025. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →