Beyond Cyber Essentials: The Governance Gap Regulated Organisations Overlook
- Andrew Knight
- Jun 17
- 3 min read
For organisations in legal services, accountancy, education, and healthcare, Cyber Essentials (CE) and Cyber Essentials Plus (CE+) are recognised baselines for cybersecurity — and, in many cases, a contractual requirement.
But achieving CE+ is not the same as demonstrating ongoing assurance.
Leadership may assume cyber risk is "covered", while the organisation's ability to evidence control, accountability, and governance over time remains incomplete. The gap is rarely technical — it is almost always about how controls are governed, operated, and evidenced.

The Leadership Question
At board, trustee, or partner level, the question is straightforward:
"Are we managing cyber risk to an acceptable level — and can we evidence that if challenged?"
CE/CE+ contributes to that answer, but it does not provide continuous visibility, operational evidence, or assurance that risk is owned and reviewed over time. That disconnect between certification and assurance typically surfaces during audits, incidents, or client due diligence — when a certificate alone is not enough.
Why Organisations Get This Wrong
The issue is rarely carelessness. It is how CE/CE+ is positioned internally:
Unclear ownership — cyber risk is treated as an IT task, with no defined accountability at leadership level.
Certificate-led reporting — leadership sees a pass result, not control performance, exceptions, or trends.
Evidence gaps — controls exist in practice but lack a structured, retained evidence trail.
Change-driven drift — new systems, users, or suppliers gradually invalidate assessment-time assumptions.
Over-reliance on tooling — security products are in place, but supporting processes (patching discipline, access reviews, incident learning) remain informal.
These are not failures of Cyber Essentials — they are failures of integration between controls and governance.

What CE/CE+ Covers — in Context
CE/CE+ defines a focused set of technical controls: firewalls, secure configuration, access control, malware protection, and patch management. CE+ adds independent verification.
This is a valuable baseline — but it is intentionally narrow. It does not aim to address full lifecycle governance, risk management, or service assurance.
A Practical Example
A legal firm with a current CE+ certificate was asked during client due diligence to demonstrate patch compliance trends, evidence of privileged access reviews, and a tested incident response process.
The certificate confirmed baseline controls existed. The firm could not demonstrate how those controls were being operated, monitored, or improved.
The issue was not control failure — it was assurance failure.

Where CE/CE+ Leaves Gaps
For regulated organisations, CE/CE+ typically does not cover:
Risk management — formal registers, ownership, and risk acceptance linked to business impact.
Security governance — policies actively owned, reviewed, and embedded in operations.
Identity lifecycle — joiners/movers/leavers, privileged access governance, and periodic recertification.
Incident response — defined detection, escalation, response, and post-incident learning processes.
Business continuity — tested recovery aligned to defined objectives and dependency mapping.
Asset management — maintained registers and baselines linked to ownership.
Supplier assurance — structured oversight of third parties supporting systems and data.
These areas are central to ISO 27001 and ISO 20000-1 aligned environments, where repeatability, traceability, and evidence are expected.
What Good Looks Like
Effective assurance is less about adding tools and more about disciplined operation:
Defined ownership — each control has a named owner with clear accountability.
Structured reporting — leadership receives concise updates on risk, exceptions, and trends.
Formal exception management — risk decisions are documented, justified, and reviewed.
Access governance — privileged and critical access is periodically reviewed with evidence retained.
Tested recovery — backup and recovery processes are validated through real testing.
Incident management — response playbooks exist, are followed, and feed continual improvement.
Supplier assurance — third-party risk is assessed and monitored based on criticality.
Control monitoring — metrics demonstrate controls are operating effectively over time.
These behaviours turn control presence into continuous assurance, aligned to ISO 27001 and ISO 20000-1 principles.
Positioning CE/CE+ in Your Assurance Stack
A simple model:
CE/CE+ → Baseline technical hygiene
Operational governance (ISO-aligned) → How controls are embedded and sustained
Risk and assurance → How leadership understands exposure and makes decisions
Most gaps sit in the second and third layers — not the first.
Next steps
Cyber Essentials and CE+ remain important, credible baselines. But for regulated organisations, they should be understood as a starting point for assurance — not the end state.
The organisations that perform best under scrutiny are not those with the most certifications, but those that can consistently demonstrate ownership, control, evidence, and accountability.
Contact Us
If your organisation already holds CE or CE+, the next question is not "What certification do we need next?" — it is:
"Can we demonstrate control, assurance, and accountability at any point in time?"
At cyberISMS, we help regulated organisations move from certification-led thinking to evidence-based, governance-led assurance. Contact us to discuss your current position.




Comments