IASME Cyber Assurance
The IASME Cyber Assurance standard is a comprehensive, flexible, and affordable cyber security standard. It provides assurance that an organisation has put into place a range of important cyber security, privacy, and data protection measures.
What is IASME Cyber Assurance?
IASME Cyber Assurance offers a comprehensive, affordable framework for businesses to demonstrate cybersecurity credentials, serving as a recognized alternative to ISO 27001 for small and medium-sized enterprises. It’s an effective way to help demonstrate compliance with Bermuda’s PIPA regulations.
The certification aligns with the UK Government’s 10 Steps to Cyber Security and the NIS Directive, with two levels:
- Level 1: A verified, self-assessment or basic audit focusing on fundamental security policies.
- Level 2: An expert-led, fully audited certification providing a detailed review of security policies, procedures, and controls.
Key Benefits of Cyber Assurance
Legal and regulatory compliance (especially for PIPA)
Improved customer trust
Strengthened privacy and data protection
Competitive edge e.g. when bidding for contracts
Alternative to ISO 27001
Why Certify With us?
Human Support
Our friendly and helpful team of experts will be on hand with insights and useful advice to help boost your chances of a first-time pass.
Best Price In UK
Cyber Tec offers a best-price guarantee on like-for-like Cyber Essentials packages – so you’re sure to find one that works for your budget.
Assured Pass
Our guided certification packages are designed to assure your business obtains a first-time pass, giving you added peace of mind.
Speedy Turnaround
We understand that getting certified is a matter of urgency. That’s why we strive to help businesses achieve certification within 24 hours.
Remote Auditing
We complete all auditing remotely, so you can get on with business as usual – without the extra hassle of arranging on-site visits.
Human Support
Friendly faces and 1-2-1 support as you complete your assessment. For a techie company, we’re not big fans of robots!
Best Price In UK
We offer a best price guarantee on like-for-like Cyber Essentials packages so you can always get a great deal on certification.
Assured Pass
Our guided certification packages are designed to assure you a first time pass so you can have full peace of mind.
Speedy Turnaround
We know it's often a matter of urgency to get certified so we strive to help businesses achieve certification within 24 hrs.
Remote Auditing
No extra hassle organising on-site visits. We complete all auditing remotely so you can get on with business as usual.
The Thirteen Themes Of IASME Cyber Assurance
Attaining IASME Cyber Assurance certification helps your organisation prove to key stakeholders and clients that it takes cybersecurity seriously.
Identifying and protecting assets
Having a good understanding of your key information assets is essential in order to know what you need to protect.
Assessing and treating risks
In order to effectively apply the correct controls to protect your business assets, it is important to understand what the risks are to your business and to manage those risks to keep them at an acceptable level to you, your customers, and supply chain.
People
Thorough and consistent measures are required to screen and train all staff to enable them to understand and comply with the security responsibilities of their job.
Planning information Security
It is important to include information security considerations within your planning. You must also consider security when planning projects, procurement, contracting, suppliers, and when dealing with partners, and other interested parties.
Managing access
Best practice access control utilises the law of ‘least privilege’ which means giving users access to all the resources and data necessary for their roles, but no more.
Backup and restore
Regularly backing up information, and having the ability to restore the backup, may be one of the most effective methods of protecting your business from the effects of accidental or malicious tampering.
Resilience: Business continuity, incident management and disaster recovery
A resilient company is one that is able to respond to an incident, keep operating through it, and eventually recover.
Legal and regulatory landscape
Be aware of legal obligations, contractural requirements and agreements and ensure you are fulfilling your responsibilities.
Organisation
A clear structure within your organisation is the foundation for effective and successful security. This should include who is responsible for making information safe and who is accountable when incidents happen.
Physical and environmental protection
Protect your information assets from physical threats such as theft or loss and environmental harm such as damage from temperature or humidity
Policy realisation
Policies specify the rules, guidelines, and regulations that you require people to follow. They also reflect the values and ethics that are at the heart of your business.
Technical intrusion
It is important to develop capabilities to monitor and respond to unauthorised access and usage. This includes anti-malware solutions and measures to prevent insider threats.
Secure business operations: monitoring, review, and change management
Creating processes to track and monitor information systems is important in order to detect threats and take steps to analyse and act on this information.
Why Work With Us
Being the top third Certification Body in the UK, we pride ourselves on our Consultative, hands-on approach—there are no pre–populated dashboards or AI when working with us!
Don’t take our word for it, though – our clients will tell you:
“My Assessor fully explained everything he was doing. Provided additional information outside of the assessment criteria which will give additional security to our environment.“

Sarah
information Technology and Services
“Always a pleasure to go through CE, or CE+, with My Assessors and dealing with the Cyber Tec team in general.”

Andy
Information Technology and Services
“As always prompt and efficient service. Thank you once again guys for your excellent and informative support. We’ll be working with you again for the coming year.”

Martin
Hospital & Healthcare
“As always, My Assessor was professional and practical and good humoured – an ideal combination …”

Tim
Management Consulting
“Attention to detail, clear, constructive feedback, and plenty of patience. My Assessor was exceptional.”

Chris
Management Consulting
“The Assessment Team have been responsive and helpful with all their responses to questions we have”

Andrew
Pharmaceuticals

Louis
Real Estate
“Clear instructions and advice at all times.”

Karen
Legal Services
“Communication was timely, concise and clear; very grateful for the intimate support provided.”

Kevin
Research
“Easy, seamless and clear process”

Rich
Education Management
“Efficient and to the point”

Mikhail
Construction
“Everything was explained clearly, and it made the process very simple and straightforward.”

Feargal
Telecommunications
“Excellent service as always. The Assessors are fast, clear and efficient. Couldn’t fault anything”

Andy
Information Technology and Services
“Excellent team, helpful and responsive to ensure we passed first time with ease”

Dan
Entertainment
“Extremely helpful, and written clearly and in a friendly supportive tone”

Stephen
Sports
“Fast response – very patient and helpful – thanks”

Rebecca
Research
“Friendly, helpful staff – supporting all the way”

Margaret
Education Management
“Good feedback on initial submission”

Graham
Research
“Great communication and support throughout the whole process!”

Garratt
Information Technology and Services
“Great feedback during the process of submitting”

Aaron
Education Management
“Great levels of support and provided some excellent guidance to help us through certain areas where we were unclear as to what was required. Very responsive from a timescales perspective too and overall we felt well supported throughout the process.”

Steve
Financial Services
“Great overall experience. The assisted application process is a complete no-brainer as a lot of the questions are quite poorly structured/worded leading a variety of (mis)interpretations. Being guided through this was critical. The assisted process was incredibly fast, clear and very helpful. Bravo all round.”

Kristjan
Real Estate
“Great response and very helpful”

Helen
Management Consulting
“Great service”

Richard
Accounting
“Great support from beginning to end. So much easier having last years completed questionnaire as a template.”

Scott
Leisure, Travel & Tourism
“Help always comes promptly and right to the point”

Balazs
Information Technology and Services
“Helpful and attentive throughout”

Ahmed
Hospitality
“I got plenty of assistance all the way through. “

Victoria
Accounting
“It was a simple process – all good”

Andy
Information Technology and Services
“It was quick, efficient and helpful, and with useful insights.”

Jurate
Defence & Space
“It’s been an absolute pleasure to work with My Assessor – he reviewed our responses speedily and gave clear guidance on remediation. A huge thank you from us!”

Katie
Professional Training & Coaching
“I’ve rated highly due to the level of support that has been provided, not only from My Assessor and My Auditor, but also the sales and admin team , who have all assisted each year we work with you, to provide quick and informative answers to our technical and non-technical questions. Thank you all, looking forward to working with you for CE+ and beyond.”

Chris
Fundraising
“My Assessor and the auditor are always available and provide us with excellent advice”

Gareth
Information Technology and Services
“My Assessor was awesome. Very understanding and extremely helpful. Made the whole process smooth “

Abbas
Legal Services
“My Assessor was polite, courteous and very experienced.”

Hifzulrehman
Research
“My Assessor was very useful and explained in detail what needed to be done to get us up to standard.”

Ryan
Real Estate
“Provided the right level of support to enable me to complete the assessment quickly and accurately.”

Tom
Legal Services
“Quick and efficient.”

Graham
Machinery
“Quick response time, clear guidance. Whole process made very easy”

Andrew
Non-Profit
“Quickly answered any questions and available to speak when needed.”

Marcus
Industrial Automation
“Really helpful & clear guidance.”

Dave
Information Technology and Services
“Responses to our queries very quickly, review quick and good advice. Thank you”

Manuel
Insurance
“Smooth as!”

Colin
Information Technology and Services
“Strong communications and reminders before, during and following the process. My Auditor in particular performed way above and beyond our expectations during the CE+ stage of the assessment. Thank you for your service.”

David
Information Technology and Services
“Superb as always. Clear and to the point. 100% would come back”

Grant
Information Technology and Services
“The Assessors communications were clear, concise and to the point. They helped me use my time effectively and efficiently.”

Airan
Information Technology and Services
“The Assessor was very helpful”

Martina
Hospital & Healthcare
“The Sales Team and My Assessor were both professional and extremely patient.”

Marc
Management Consulting
“The support I had was great. As a non technical person, everything was communicated really clearly, which was much appreciated.”

Lis
Non-Profit
“Their notes clarified the details and requirements of the assessment. They made it make sense..”

Gregor
Information Technology and Services
“Thorough and helpful”

Shirley
Business Supplies & Equipment
“Very helpful and insightful when providing feedback to help us pass the assessment.”

Graham
Recreational Facilities and Services
“Very helpful and responsive in a timely fashion.”

Asaf
Information Technology and Services
“Very Helpful!”

Brandon
Information Technology and Services
“Very helpful, fast responses. Thank you.”

Victor
Research
“Very helpful, Quick to respond, Made the process easy”

Curtis
Information Technology and Services
“Very prompt review and submission process. Big thanks to the auditors as they ensured to always get back to me within 2 business days with friendly and informative replies… we will continue to use CyberTec in the future.”

Jordan
Non-Profit
“We as a company have downsized as I’m on the flight path to retirement. I am the only employee and renewing the certificate filled me with dread. But both My Assessors were very patient and professional. It actually turned out to be an almost enjoyable experience. Well done guys, I very much appreciate your guidance and help.”

Stephen
Staffing & Recruitment
“You do what you say and in a timely manner!”

Tom
Retail
IASME Cyber Assurance Certification Packages
Reseller rates also available. Ask about reseller pricing.
IASME Cyber Assurance Level 1:
Self-Assessment
- Align to IASME's standard including key security elements like incident response, staff training, planning and operations.
- Meet GDPR Requirements
- One re-attempt if you fail first time
- Help to demonstrate compliance to PIPA
- No support
From
£315
$409
IASME Cyber Assurance Level 1:
Guided Assessment
- All benefits of the Self-Assessment package and...
- Assured pass *
- Dedicated Account Manager
From
£469
$609
IASME Cyber Assurance Level 1:
Managed
- All benefits of guided assessment, and...
- 1-2-1 video calls and screensharing with assessor who will take you through the process step by step
IASME Cyber Assurance Level 2:
Audited Assessment
- All benefits of the Guided package and...
- Technical audit of governance processes and procedures
From
£POA
$POA
* Assured pass assumes you follow our consultant’s advice and ensure that all the required controls are put in place.
Keep in constant Compliance with our Monthly Vulnerability Assessments at only £100/$130
Our Complementary Security Services
Cyber Insurance
A specialist cyber insurance policy can give your business maximum protection. Choose from a range of flexible options from market-leading providers.
Penetration Testing
Our monthly or one-off penetration tests simulate an attack on your systems to see how far hackers could go, followed by a detailed report and recommended remedies.
Vulnerability Assessment
Uncover potential gaps and weaknesses in your cybersecurity infrastructure before they can be exploited by online criminals with a vulnerability assessment. Use to stay compliant with cyber certificates such as CE and ICA
Managed Threat Detection
Our threat detection software protects your business against cyberattacks 24/7, with real-time monitoring, SOC analysis and CE Plus alignment.
Incident Response
By using the services of our CREST accredited incident response delivery partner, Pen Test Partners LLP, the impact of any breach or incident can be minimised and business continuity maintained by the provision of services in line with your company’s specific needs, regardless of your cyber maturity level.
Cyber Insurance
A specialist cyber insurance policy can give your business maximum protection. Choose from a range of flexible options from market-leading providers.
Penetration Testing and Vulnerability Assessment
Our monthly or one-off penetration tests simulate an attack on your systems to see how far hackers could go, followed by a detailed report and recommended remedies. Uncover potential gaps and weaknesses in your cybersecurity infrastructure before they can be exploited by online criminals with a vulnerability assessment. Use to stay compliant with cyber certificates such as CE and ICA
ISO 27001
Safeguard your business and strengthen your online defences with ISO 27001 certification. Cyber Tec’s experts will provide helpful guidance at every step
Managed Threat Detection
Our threat detection software protects your business against cyberattacks 24/7, with real-time monitoring, SOC analysis and CE Plus alignment.
Incident Response
By Leveraging our relationship with our partner PTP - As a CREST-accredited incident response team, we will to help you minimise the impact of any breach or incident and maintain business continuity by providing services in line with your company’s specific needs regardless of your cyber maturity level.
Understanding IASME's Cyber Security Standard
Find out how your business’ cyber risk profile is established and what areas you will be assessed on in order to meet the standard.
Lets get Secure together
- Jersey: +44 1534 715260
- UK: +44 117 457 3331
- Bermuda: +1 441 279 7101
- [email protected]
-
Kensington Chambers, 46/50
Kensington Place, St Helier, Jersey JE1 1ET
Frequently Asked Questions
Here’s a combined list of frequently asked questions covering both the general and technical aspects of the IASME Cyber Assurance Levels 1 and 2 certifications. These FAQs provide a comprehensive overview for organizations looking to understand and possibly attain these important cybersecurity credentials:
What is IASME Cyber Assurance?
IASME Cyber Assurance is a governance and risk management-based cybersecurity certification that assesses an organization’s overall security posture, including policies, processes, and technical controls.
How do Cyber Assurance Level 1 and Level 2 differ?
Level 1 involves a self-assessment of cybersecurity governance and risk management practices, while Level 2 includes a more comprehensive external audit to provide a higher level of assurance.
Who should pursue IASME Cyber Assurance certification?
The certification is suitable for any organization that wants to demonstrate a robust cybersecurity framework, particularly those handling sensitive data or operating in regulated industries.
What are the key themes covered by IASME Cyber Assurance?
Themes include risk management, staff training, physical and environmental security, incident response, asset management, access control, legal compliance, and technical intrusion protection.
What business benefits does IASME Cyber Assurance offer?
Benefits include enhanced security practices, improved resilience against cyber threats, increased stakeholder confidence, and compliance with legal and regulatory requirements.
Is IASME Cyber Assurance recognized internationally?
While it is based in the UK, IASME Cyber Assurance is respected internationally, particularly by organizations looking for a certification that includes both cybersecurity and governance aspects.
What technical controls are assessed in IASME Cyber Assurance Level 1 and Level 2?
Assessments include data encryption, secure configuration, access control, malware protection, and network security practices.
What are the requirements for network security under IASME Cyber Assurance?
Organizations must implement firewalls, intrusion detection systems, secure VPNs, conduct regular vulnerability scans, and apply network segmentation.
How does IASME Cyber Assurance address malware and virus protection?
The certification requires up-to-date anti-malware solutions, regular scans, real-time protection, and staff training to recognize phishing and malware risks.
How is user access controlled under IASME Cyber Assurance?
Access control policies enforce the principle of least privilege, managing user permissions, using strong authentication methods, and monitoring and logging access events.
What incident response mechanisms are required for certification?
Organizations must have a formal incident response plan that outlines procedures for responding to security incidents, including detection, reporting, and recovery processes.
What does IASME Cyber Assurance require for business continuity and disaster recovery?
The certification mandates developing and maintaining business continuity plans that address data backup, system redundancies, and disaster recovery processes, with regular testing to ensure effectiveness.
How long does it take to obtain IASME Cyber Assurance certification?
Level 1 can be completed in a few weeks, while Level 2 may take several months, depending on the organization’s readiness and the scheduling of the external audit.
How often must the certification be renewed or reviewed?
Both levels require annual renewal, with Level 2 possibly involving a follow-up audit to confirm ongoing compliance with the standards.
Where can organizations get support for obtaining IASME Cyber Assurance?
Support can be obtained from accredited certification bodies authorized to deliver IASME Cyber Assurance. These bodies provide guidance, support, and assessments necessary for certification.