Frequently asked questions about cybersecurity, certifications and how YDC works.
Straight answers to the questions businesses ask before they commit to a route — covering certifications, security testing, fractional CTO and how engagements work.
Usually quite quickly once the route is clear. The larger variable is often how ready the current controls, documentation and ownership already are.
For organisations with reasonable existing controls, preparation typically takes two to four weeks — the main variable is how much gap closure is needed before the assessment. The assessment itself, once submitted, can usually be completed within the same day or the next working day. It is the preparation that takes time, not the submission. CE+ takes longer due to the technical audit component. YDC scopes the preparation work so the timeline is realistic before any commitment is made.
Cyber Essentials is a self-assessed certification verified remotely. Cyber Essentials Plus adds an independent technical audit where an assessor tests the controls directly on your systems. Both cover the same five technical controls, but CE+ provides stronger evidence that those controls are working in practice rather than described on paper. If a buyer or contract asks for independent technical assurance, CE+ is usually the right route.
Cyber Essentials focuses on five specific technical controls designed to reduce the most common cyber attack vectors. ISO 27001 is a broader management system standard covering risk management, governance, supplier oversight, incident management and continual improvement. They are not direct alternatives — many organisations hold Cyber Essentials for technical baseline assurance and pursue ISO 27001 when commercial expectations grow to require a broader governance framework.
Level 1 uses verified self-assessment and is suitable where basic assurance is needed. Level 2 adds independent audit and is appropriate where buyers, public sector frameworks or supply chain contracts require independently evidenced assurance rather than a self-described position. The decision is usually driven by what your commercial environment is asking for rather than technical complexity.
This depends on what is driving the requirement. If a buyer, contract or regulatory framework specifically asks for ISO 27001, then that is the route. If the requirement is for credible, independently audited governance assurance without prescribing the standard, IASME Cyber Assurance Level 2 can often satisfy it at a more proportionate cost and effort. A short scoping conversation usually clarifies which route addresses the actual commercial pressure.
All certifications require annual renewal, and the controls they rely on need to stay current between renewals. The gap between achieving certification and the next audit is where many organisations lose ground — controls drift, ownership becomes unclear, and evidence stops being maintained. Protects is the platform YDC uses to keep evidence, actions and ownership live after the initial certification work is complete. It reduces the overhead of maintaining a certification position without a dedicated internal resource.
That depends on the trigger. Vulnerability scanning is useful for breadth and ongoing hygiene, while penetration testing is better when buyers, compliance or risk profile require deeper manual validation.
A penetration test involves a skilled security professional attempting to exploit vulnerabilities in your systems, applications or infrastructure in a controlled way. The goal is to determine whether weaknesses are actually exploitable — not just present — and to understand what an attacker could achieve. The result is a report identifying confirmed vulnerabilities, their severity and recommended remediation. Scope is agreed in advance and all activity is authorised.
No. CE+ does not require a penetration test — it involves independent technical testing of the five Cyber Essentials controls, which is a more focused assessment than a full penetration test. That said, a preparatory vulnerability assessment before CE+ is a practical idea. It identifies weaknesses in the five control areas before the formal assessment, so there are no surprises during the audit. Some of the activities involved in a vulnerability assessment overlap with CE+ preparation in useful ways.
Annual testing is the standard practice for most organisations, and it is the baseline expected by frameworks such as ISO 27001 and DORA. Testing should also be triggered by significant change — a major infrastructure update, a new application going into production, a cloud migration, or a change in the threat profile of the business. Annual testing that is never supplemented by change-triggered testing leaves gaps that attackers can exploit in between cycles.
It varies by need. Some businesses need a small monthly retainer for ongoing leadership input, while others need more concentrated support during a project, transition or period of uncertainty.
A fractional CTO makes sense when the business needs senior technology leadership but not enough to justify a full-time salary, equity, and the overhead of a permanent executive hire. This is common in earlier-stage businesses, in organisations going through a defined transition or project, and in situations where the technology agenda is important but not yet complex enough to warrant a full-time role. A full-time CTO hire makes sense when the technology agenda is continuous, complex, and central enough to require dedicated daily leadership — and when the business can support the cost and commitment of a permanent appointment.
Most engagements start with a short conversation to understand the current technology situation, what decisions are pending, and what the business most needs from senior technology input. From there, YDC proposes a scope — which might be a defined project, an ongoing advisory retainer, or a combination of both. There is no lengthy discovery process or proposal phase before it is clear whether there is a fit. The first meaningful output usually arrives in the first week.
Yes. Clarifying the right route is a core part of the work, especially where buyers are under deadline pressure and want to avoid overbuying or choosing the wrong option.
No. The model is designed to be proportionate to the need, whether that means a short piece of work, a defined package or a more ongoing advisory relationship.
Engagements are scoped to fit the need rather than sold as fixed packages applied regardless of context. The starting point is always a conversation to understand the actual requirement before a proposal is made. There is no pressure to commit before the scope is clear.
Yes. Deadline-driven work is a common trigger. A customer is asking for certification. An investor wants to see governance evidence. An audit is approaching. YDC is structured to respond quickly where the commercial pressure is real. The first step is understanding the deadline, what is driving it and what is actually required — which usually takes a short call rather than a lengthy discovery process.
If your question is not here, a short call usually answers it.
Most businesses find that a 20-minute conversation clarifies fit, timeline and next steps more quickly than any FAQ page can. No sales pressure — just straight answers.