IASME 
Cyber Assurance

The IASME Cyber Assurance standard is a comprehensive, flexible, and affordable cyber security standard. It provides assurance that an organisation has put into place a range of important cyber security, privacy, and data protection measures.

What is IASME Cyber Assurance?

IASME Cyber Assurance offers a comprehensive, affordable framework for businesses to demonstrate cybersecurity credentials, serving as a recognized alternative to ISO 27001 for small and medium-sized enterprises. It’s an effective way to help demonstrate compliance with Bermuda’s PIPA regulations.
The certification aligns with the UK Government’s 10 Steps to Cyber Security and the NIS Directive, with two levels:

  • Level 1: A verified, self-assessment or basic audit focusing on fundamental security policies.
  • Level 2: An expert-led, fully audited certification providing a detailed review of security policies, procedures, and controls.

Key Benefits of Cyber Assurance

Why Certify With us?

Human Support
Our friendly and helpful team of experts will be on hand with insights and useful advice to help boost your chances of a first-time pass.

Best Price In UK
Cyber Tec offers a best-price guarantee on like-for-like Cyber Essentials packages – so you’re sure to find one that works for your budget.

Assured Pass
Our guided certification packages are designed to assure your business obtains a first-time pass, giving you added peace of mind.

Speedy Turnaround
We understand that getting certified is a matter of urgency. That’s why we strive to help businesses achieve certification within 24 hours.

Remote Auditing
We complete all auditing remotely, so you can get on with business as usual – without the extra hassle of arranging on-site visits.

The Thirteen Themes Of IASME Cyber Assurance

Attaining IASME Cyber Assurance certification helps your organisation prove to key stakeholders and clients that it takes cybersecurity seriously.

Identifying and protecting assets
Having a good understanding of your key information assets is essential in order to know what you need to protect.

Assessing and treating risks
In order to effectively apply the correct controls to protect your business assets, it is important to understand what the risks are to your business and to manage those risks to keep them at an acceptable level to you, your customers, and supply chain.

People
Thorough and consistent measures are required to screen and train all staff to enable them to understand and comply with the security responsibilities of their job.

Planning information Security
It is important to include information security considerations within your planning. You must also consider security when planning projects, procurement, contracting, suppliers, and when dealing with partners, and other interested parties.

Managing access
Best practice access control utilises the law of ‘least privilege’ which means giving users access to all the resources and data necessary for their roles, but no more.

Backup and restore
Regularly backing up information, and having the ability to restore the backup, may be one of the most effective methods of protecting your business from the effects of accidental or malicious tampering.

Resilience: Business continuity, incident management and disaster recovery
A resilient company is one that is able to respond to an incident, keep operating through it, and eventually recover.

Legal and regulatory landscape
Be aware of legal obligations, contractural requirements and agreements and ensure you are fulfilling your responsibilities.

Organisation
A clear structure within your organisation is the foundation for effective and successful security. This should include who is responsible for making information safe and who is accountable when incidents happen.

Physical and environmental protection
Protect your information assets from physical threats such as theft or loss and environmental harm such as damage from temperature or humidity

Policy realisation
Policies specify the rules, guidelines, and regulations that you require people to follow. They also reflect the values and ethics that are at the heart of your business.

Technical intrusion
It is important to develop capabilities to monitor and respond to unauthorised access and usage. This includes anti-malware solutions and measures to prevent insider threats.

Secure business operations: monitoring, review, and change management
Creating processes to track and monitor information systems is important in order to detect threats and take steps to analyse and act on this information.

Why Work With Us

Being the top third Certification Body in the UK, we pride ourselves on our Consultative, hands-on approach—there are no pre–populated dashboards or AI when working with us!

Don’t take our word for it, though –  our clients will tell you:

IASME Cyber Assurance Certification Packages

Reseller rates also available. Ask about reseller pricing.

* Assured pass assumes you follow our consultant’s advice and ensure that all the required controls are put in place.

Keep in constant Compliance with our Monthly Vulnerability Assessments at only £100/$130

Our Complementary Security Services

Cyber Insurance

A specialist cyber insurance policy can give your business maximum protection. Choose from a range of flexible options from market-leading providers.

Penetration Testing

Our monthly or one-off penetration tests simulate an attack on your systems to see how far hackers could go, followed by a detailed report and recommended remedies.

Vulnerability Assessment

Uncover potential gaps and weaknesses in your cybersecurity infrastructure before they can be exploited by online criminals with a vulnerability assessment. Use to stay compliant with cyber certificates such as CE and ICA

Managed Threat Detection

Our threat detection software protects your business against cyberattacks 24/7, with real-time monitoring, SOC analysis and CE Plus alignment.

Incident Response

By using the services of our CREST accredited incident response delivery partner, Pen Test Partners LLP, the impact of any breach or incident can be minimised and business continuity maintained by the provision of services in line with your company’s specific needs, regardless of your cyber maturity level.

Understanding IASME's Cyber Security Standard​

Find out how your business’ cyber risk profile is established and what areas you will be assessed on in order to meet the standard.

Lets get Secure together

Frequently Asked Questions

Here’s a combined list of frequently asked questions covering both the general and technical aspects of the IASME Cyber Assurance Levels 1 and 2 certifications. These FAQs provide a comprehensive overview for organizations looking to understand and possibly attain these important cybersecurity credentials:

IASME Cyber Assurance is a governance and risk management-based cybersecurity certification that assesses an organization’s overall security posture, including policies, processes, and technical controls.

Level 1 involves a self-assessment of cybersecurity governance and risk management practices, while Level 2 includes a more comprehensive external audit to provide a higher level of assurance.

The certification is suitable for any organization that wants to demonstrate a robust cybersecurity framework, particularly those handling sensitive data or operating in regulated industries.

Themes include risk management, staff training, physical and environmental security, incident response, asset management, access control, legal compliance, and technical intrusion protection.

Benefits include enhanced security practices, improved resilience against cyber threats, increased stakeholder confidence, and compliance with legal and regulatory requirements.

While it is based in the UK, IASME Cyber Assurance is respected internationally, particularly by organizations looking for a certification that includes both cybersecurity and governance aspects.

Assessments include data encryption, secure configuration, access control, malware protection, and network security practices.

Organizations must implement firewalls, intrusion detection systems, secure VPNs, conduct regular vulnerability scans, and apply network segmentation.

The certification requires up-to-date anti-malware solutions, regular scans, real-time protection, and staff training to recognize phishing and malware risks.

Access control policies enforce the principle of least privilege, managing user permissions, using strong authentication methods, and monitoring and logging access events.

Organizations must have a formal incident response plan that outlines procedures for responding to security incidents, including detection, reporting, and recovery processes.

The certification mandates developing and maintaining business continuity plans that address data backup, system redundancies, and disaster recovery processes, with regular testing to ensure effectiveness.

Level 1 can be completed in a few weeks, while Level 2 may take several months, depending on the organization’s readiness and the scheduling of the external audit.

Both levels require annual renewal, with Level 2 possibly involving a follow-up audit to confirm ongoing compliance with the standards.

Support can be obtained from accredited certification bodies authorized to deliver IASME Cyber Assurance. These bodies provide guidance, support, and assessments necessary for certification.

Download IASME Governance: Understanding the Standard​