Guidance

Guidance

Practical cyber security guidance from Be Secure Cyber on vCISO, Cyber Essentials, assurance, vulnerability assessment and security planning.

These guides are written for organisations that need practical cyber security guidance without a sales-led or overly technical explanation. They support the services described elsewhere on this site and are intended to help you understand common assurance, certification and security planning questions.

What is a vCISO?

A practical guide to virtual CISO services, what a vCISO does, when to use one and how it differs from ad hoc cyber security consultancy.

Read more

Cyber Essentials vs Cyber Essentials Plus

Understand the difference between Cyber Essentials and Cyber Essentials Plus, who needs each certification and how to decide the right next step.

Read more

How to prepare for Cyber Essentials Plus

A practical preparation guide for Cyber Essentials Plus, covering scope, devices, patching, MFA, malware protection and remediation planning.

Read more

What should a cyber security roadmap include?

A guide to building a useful cyber security roadmap that supports business decisions, assurance requirements and practical improvement.

Read more

What is a vulnerability assessment?

A practical explanation of vulnerability assessments, how they differ from penetration testing and how to use the findings.

Read more

How to respond to a supplier security questionnaire

Guidance for organisations responding to customer or supplier cyber security questionnaires, assurance requests and evidence requirements.

Read more

Microsoft 365 security checklist for small organisations

A practical Microsoft 365 security checklist covering MFA, administrator accounts, email security, external sharing, devices and monitoring.

Read more

What is IASME Cyber Assurance?

A practical guide to IASME Cyber Assurance, how it differs from Cyber Essentials and how it can support wider governance and assurance.

Read more

Cyber Essentials for MSPs and service providers

Guidance for MSPs and service providers considering Cyber Essentials, Cyber Essentials Plus and assurance requirements.

Read more

Is Microsoft 365 Copilot safe for business use?

Whether Microsoft 365 Copilot is safe for business depends less on the AI and more on how your tenant is configured. A practical look at the data questions and the real risk.

Read more

AI governance for professional firms

A practical starting point for AI governance in accountancy, legal and financial services firms: client confidentiality, regulatory duties and staff use of AI tools.

Read more

What is exposure management?

Exposure management explained for organisations that want to move beyond one-off vulnerability scanning and prioritise the security issues that matter most.

Read more