
To ensure the safety and security of our customer data, Human Focus maintains strict cybersecurity procedures in line with the Cyber Essentials scheme.
We are pleased to announce that our renewal application has been accepted by Cyber Essentials for the third year running. Human Focus now holds Cyber Essentials certification for the year 2025.
The Cyber Essentials scheme is supported by various industry bodies and the UK government. It was developed to help businesses protect against digital threats. Being certified by Cyber Essentials demonstrates our commitment to cybersecurity.
What is Cyber Essentials?
Cyber Essentials provides a framework for essential cybersecurity measures. It’s overseen by the UK National Cyber Security Centre (NCSC), which also certifies organisations that have proven a commitment and ability to protect their customers’ data.
Cyber Essentials accreditation covers the IT infrastructure currently used within Human Focus. This includes, but is not limited to:
- Servers
- Workstations
- Firewalls
- Hardware
- Anti-virus protection
- Software applications
Maintaining compliance with the government-backed Cyber Essentials scheme preserves the security and privacy of our clients’ data.
What is Cyber Essentials Certification?
Cybercrime is rising and personal data is increasingly valuable on the dark web. Online thieves are now constantly scouring the internet for vulnerable websites.
Cyber Essentials certification shows that a company cares about the data security of its customers and has defended itself against malicious cyber threats. This evidence is enough to deter many would-be hackers.
It also assures customers, insurers and other stakeholders that essential procedures are in place to guard against cyberattacks.
Why Does Human Focus Have Cyber Essentials Certification?
Human Focus believes participation in the Cyber Essentials scheme is vital.
Our goal is to provide our clients with peace of mind and the assurance that their personal data is protected. Human Focus is committed to preserving the security of our systems and the privacy of our users’ data, and will continue to renew our Cyber Essentials certification.
Below is our certificate for 2025:
Increasing Risk of Cyber Threats
Hackers are constantly adapting their methods to overcome security measures. The UK Government’s latest Cyber Security Breaches Survey 2024 shows that cyberattacks on UK businesses remain a serious concern, with nearly 50% of businesses experiencing some form of cyber breach or attack in the last 12 months.
Among medium-sized businesses, this figure rises to 70%, with 37% reporting attacks at least once a week. Phishing remains the most common threat, followed by impersonation and malware attacks. The financial impact is also significant, with the average cost of a cyber breach reaching £1,205 for smaller firms, and £10,830 for medium to large organisations.
The security measures required for Cyber Essentials certification prevent many of these types of cyberattacks. According to the NCSC, the Cyber Essentials scheme helps organisations become resilient, with certified organisations reporting 92% fewer insurance claims related to cyberattacks.
How Does Cyber Essentials Work?
Simply put, the Cyber Essentials scheme helps UK businesses protect themselves from cyber threats. In order to attain Cyber Essentials certification, a business must complete a self-assessment questionnaire (SAQ) and undergo an external vulnerability scan performed on its IP addresses.
The SAQ is first reviewed by the Cyber Essentials Online Team, then sent to the accreditation body, IASME (Information Assurance for Small and Medium Enterprises Consortium), for approval.
What Does Cyber Essentials Test For?
Cyber Essentials tests the following criteria:
- Firewalls and Internet Gateways: All networks must have an appropriately configured firewall.
- Virus and Malware Protection: Systems must have adequate protection against viruses and malware.
- Patch Administration: All systems should have the latest security patches installed.
- User Access Control Systems: Measures must be in place so that only authorised users can access the system.
- Secure Configuration: Configurations must be made secure. Default configurations can be vulnerable.
Is It Mandatory to Renew Your Cyber Essentials Accreditation?
Yes, it is mandatory to renew your Cyber Essentials certification annually. The purpose of Cyber Essentials is to help organisations continuously improve their security standards.
Cybercriminals are constantly evolving their tactics. IT systems must be updated to protect against the latest viruses and malware, and operators must be aware of current phishing methods.
To ensure that a business maintains an acceptable level of cyber-readiness, Cyber Essentials certification is only valid for a period of 12 months.