By Jamie Akhtar, Co-Founder and CEO at Cybersmart.
Much has changed in the ten years since June 2014, when the UK Government introduced Cyber Essentials, a certification framework for cybersecurity, aimed at being the tide which raised all boats from a cybersecurity protection perspective.
For one thing, cybersecurity compliance has become a much more highly regulated environment, with legislation such as 2018’s GDPR bringing more organisations into the realm of data protection for the PII they process, and the associated threats of fines which the legislation casts over even the smallest organisations who bear responsibility for processing EU data.
Another significant change, which everyone working in cybersecurity can agree upon, is an increased and diversified threat profile. The cyber landscape has dramatically shifted, becoming more complex as technological interconnectivity increases. This has facilitated a corresponding rise in the relevance of Cyber Essentials, as the threat of cybercrime becomes an ever more real risk for SMEs.
However, this relevance isn’t necessarily matched by Cyber Essentials’ ability to keep organisations safe. Cyber Essentials was pioneering at its inception, but today’s cyber threats—ranging from sophisticated ransomware to IoT vulnerabilities— require us to anticipate future vulnerabilities, not just keep pace with them. What’s more, the rise of ransomware as a service has also worked to turn a niche activity into a mainstream, multi-billion-dollar criminal industry.
The changing nature of MPs and cyber
In the same 10 years, another tangential change has happened, relating to the expected services included in Managed Service Providers offerings. At the time of the launch of Cyber Essentials, a Managed Service Provider – that is, an organisation that works to provide outsourced IT services and management to businesses – was expected to do just that; help their client base, made up overwhelmingly of small businesses, to manage their IT infrastructure appropriately. The benefits for businesses included the scalability and knowledge base of an MSP’s staff.
However, for all of the reasons outlined above, the life of an MSP is not this simple in 2024. Increasingly, they are now expected to not just provide their customers with traditional IT services, but also to work to ensure the cybersecurity of their customers, too. The heightened severity of the threat and regulatory landscape in 2024 means that MSPs are seeing increasing scrutiny on their ability to offer this kind of service. In many cases, they have had to adjust their business models accordingly, increasing security spend and working to hire new security-focused employees (where the skills gap will allow).
How does this relate to Cyber Essentials?
MSPs are in a position whereby they are expected to become security providers as well as IT experts, but the challenges of hiring new staff to facilitate this means that they are often behind the curve.
Cyber Essentials is a perfect illustration of this. Cyber Essentials, as a Government-backed certification, is an area which should be top of mind for MSPs, and should be a relatively easy win for them to provide to their customers. However, the messaging around Cyber Essentials still markets directly to businesses; this is illogical, considering 30% of all businesses in the UK use MSPs, and an even higher proportion of SMEs – A group which Cyber Essentials markets to extensively. A failure to communicate the process for certifying their customers for Cyber Essentials has led us to a situation whereby MSPs are turning to Reddit forums to understand how to do this, as opposed to learning directly from the Government.
The Government needs to step up in order to support SMEs engaging with Cyber Essentials. But, this is indicative of a more endemic problem as it relates to SMEs and security. The rapid shift towards becoming security providers has not just left a knowledge gap for the customers of MSPs but has left MSPs themselves vulnerable.
By failing to provide MSPs with the building blocks, governments fail to protect not only them but the millions of businesses within their own ecosystems. Cyber Essentials is one important point to illustrate this, but it’s fundamental that governments partner with industries to provide MSPs – who represent a huge driving force within our economies – with the right knowledge to stay safe and secure.
PCR Tech and IT retail, distribution and vendor news