Rossair
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
0333 335 5020letstalk@networklondon.co.ukRemote supportClient portal
Cyber Essentials is the UK government-backed certification that shows you have the basics in place. Network London holds Cyber Essentials Plus, and we take firms of 20 to 250 people through both levels: the five controls, the self-assessment, the Plus audit and the fixes in between.


Does any of this sound familiar?
Cyber Essentials is cheap. Getting your systems to pass it is the real work, and that's what you're paying a provider for.

Cyber Essentials checks five controls: firewalls, secure configuration, access control, malware protection and keeping software up to date. The basic level is a self-assessment questionnaire reviewed by an assessor. Cyber Essentials Plus adds a hands-on audit of a sample of your devices and your internet-facing systems, carried out by a certification body. The assessment fees are set by IASME, which runs the scheme for the National Cyber Security Centre. For 2026 the basic self-assessment is £320 plus VAT for firms with up to 9 staff, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 or more. Cyber Essentials Plus usually costs between £1,500 and £5,500 or more a year plus VAT, depending on the size of your organisation and how complex your IT is.
Our fee is for the work in between: listing what is in scope, checking every device and setting against the standard, fixing what fails, completing the self-assessment with you and booking the Plus audit when you're ready to pass it. For clients whose IT we already look after, most of that is work we do anyway. We hold Cyber Essentials Plus ourselves, so we know what the assessor looks for.
Tell us how many people and devices you have and we'll tell you what it would take to pass.
Tell us what you needWhen the assessment finds an unpatched laptop or an admin account without multi-factor authentication, the people who found it are the people who fix it, that week.
The scope is where firms go wrong: home workers, personal phones, old servers, cloud services. We list it all and decide with you what is in and out before anything is submitted.
Cyber Essentials expires every 12 months. Because we keep devices patched, access reviewed and malware protection in place all year, renewal is a form rather than a project.
Three of the 100+ businesses we look after, and what we do for them.
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
Everyday support for 180 people, with access reviews and backup testing built into how they work.
A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.
We list every device, user and cloud service in scope and check each of the five controls against it. You get a short written view of what already passes and what doesn't.
We put right what fails: updates, settings, accounts, malware protection. Then we complete the self-assessment questionnaire with you and submit it.
Once the basic certificate is issued we book the Plus audit. The assessor tests a sample of devices and your external systems. Pass, and the certificate and the listing follow.
Every device, account and setting checked against the five controls before anything is submitted, so you don't pay to fail.
The list the questionnaire asks for: every laptop, phone, server and cloud service, with its operating system and who uses it.
Updates, secure configuration, admin accounts, multi-factor authentication and malware protection, done by our engineers rather than listed for you to do.
We answer the questionnaire with you, in the assessor's language, with the evidence to back each answer.
We book the audit when you're ready, prepare the sample devices and sit with you while the assessor works.
Short, usable policies for passwords, devices, updates and access, which the questionnaire and your clients both ask about.
Firms with a turnover under £20 million that certify get cyber liability insurance included with the certificate, under the scheme's own terms.
Cyber Essentials lasts 12 months. We diarise the renewal, keep the controls in place through the year and repeat the process without the scramble.
Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.
Prefer to talk? Call 0333 335 5020. A real person answers, always.
LM04.202, The Leather MarketThank you. Your message has been received and we'll be in touch shortly.
Something went wrong sending that. Please call 0333 335 5020 or email letstalk@networklondon.co.uk.
Tell us who is asking and how many people you have. Jessica, our Operations Director, replies to every enquiry personally, the same day.
Tell us what you needFor the basic certificate, the assessment fee set by IASME is £320 to £600 plus VAT depending on your size, plus our work to get you through it. Cyber Essentials Plus usually costs between £1,500 and £5,500 or more a year plus VAT, depending on the size of your organisation and how complex your IT is. We give you a fixed quote after the readiness check. For firms whose IT we already look after, our part is small because the controls are already in place.
If your systems already pass, the basic certificate can be issued within days of submitting the questionnaire. If there are fixes to make, allow a few weeks. Cyber Essentials Plus has to be completed within three months of the basic certificate, and the audit itself usually takes a day.
Ask whoever is asking. Insurers and most tenders accept the basic level. Investors, larger clients and regulated firms increasingly specify Plus, because it is independently tested rather than self-declared. If you're going to be asked, Plus is the one that settles it.
No. Certificates are issued by accredited certification bodies under IASME. We prepare you, fix what needs fixing and manage the process; the assessor checks the result. We hold Cyber Essentials Plus ourselves.
You get the assessor's feedback and a short window to fix and resubmit. With Plus, failures found during the audit have to be put right and retested within the audit window. In practice, because we do a readiness check first, our clients go into the assessment expecting to pass.
Yes, if they access company data, and that is where most firms are caught out. Home laptops, personal phones with company email and cloud services are all in scope. We help you decide what is in and out, and get the devices that are in scope compliant.

ISO 27001 consultancy led by a lead implementer, from gap analysis to the audit.

Penetration testing scoped to what your clients asked for, with the findings fixed by the same team.

We look after your cyber security and help you answer the security questions your clients, insurers and investors send you.

Help with IT compliance, including Cyber Essentials, ISO 27001 and GDPR, from policies to the questionnaires your clients send.
Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.