FAQs2026-08-10T17:39:36+01:00

FAQs

In here you’ll find our frequently asked questions. If you don’t find your answer please contact us.

Cyber Security FAQs

Cyber security is difficult to understand, where do I start?2025-05-14T01:03:14+01:00

Cyber security solutions are not a one size fits all. Businesses need a layered approach to defence, monitoring and remediation.

Cyber security doesn’t have to be as difficult to manage and understand as most organisations think; we will guide you through best practices and solutions that will leave you better equipped to deal with the threats to your organisation.

What types of business are most at risk of a cyber-attack?2025-05-14T01:03:14+01:00

We unfortunately live in a time where all businesses, regardless of size or industry sector are at risk, whether directly or indirectly.

Whilst larger organisations are more likely to have technology, expertise, and processes in place to protect themselves against cyber-attacks, this isn’t always the case. Smaller businesses are less likely to have the necessary resources and so may find themselves at greater risk of attack from hackers.

I don’t need to worry about security, all my employees are remote workers.2025-05-14T01:03:14+01:00

Without the proper protections in place, this can increase the risk of attack as it opens up a number of factors and vulnerabilities.  Employees may be working on unsecured networks or in locations such as coffee shops.

I’m a small business, why would cyber criminals attack me?2025-07-21T13:18:05+01:00

Every business it at risk of a cyber-attack. Cyber criminals will regularly send out completely random attacks such as a phishing email for example. All it takes is one click and your business may be at risk from compromise.

Cyber Resilience Audit FAQs

What are the benefits of the CAF?2026-01-29T16:50:40+01:00

The Cyber Assessment Framework helps you demonstrate that you have an appropriate level of security in place for the risk level of your essential functions. Using the CAF will showcase your dedication to cyber security and resilience, and that you are effectively complying with legal and regulatory requirements.

How much does it cost?2026-01-29T16:49:26+01:00

Our NCSC-assured advisors will determine the price based on the level of requirements or assistance needed for your organisation. An initial discussion will determine your level of requirements.

What is a CAF Profile?2025-09-23T16:04:05+01:00

There are two CAF Profiles

  1. The Baseline (sometimes called Basic) Profile is sector-agnostic and defines a suggested target level for each of the CAF outcomes. This Profile represents a level of cyber resilience matched to basic attacker capability and unsophisticated threats.
  2. The Enhanced CAF Profile is a more tailored, sector-specific target level for the CAF outcomes. It corresponds to a level of cyber resilience matched to a moderate attacker capability moderately sophisticated attack.
Is this only for organisations within the UK Critical National Infrastructure?2025-09-23T16:01:19+01:00

It is primarily designed for organisations operating within Critical National Infrastructure such as Energy, Transport, Government, Healthcare and Digital Infrastructure. However, it can be used by any organisation of any size.

I am a small business can I use the Cyber Assessment Framework (CAF)?2026-01-15T12:32:53+01:00

Yes, the CAF is an outcome-based assessment that can be scaled to the size of your organisation to evaluate and improve your cyber resilience.

Virtual CISO as a Service FAQs

What is a vCISO?2026-01-29T15:44:37+01:00

A virtual Chief Information Security Officer gives you access to expert advice and decision-making from a trusted advisoras well as strategic risk management across your business’ people, processes and technology. It offers flexible access to an experienced consultant as and when you need, providing a budget-friendly option for those with less resources or full-time requirement.

How can a vCISO help my business?2025-07-21T13:24:41+01:00

In our experience, small and medium organisations do not always have the requirement for a full time CISO, but still require strategic leadership across the business to advise on risk and oversee governance and regulatory compliance in relation to information and cyber security.

A vCISO can optimise security plans and move from a tactical position to a more strategic one.

Will I get one dedicated consultant?2025-05-14T00:59:07+01:00

Yes, you will have an experienced consultant working with you throughout our time together, offering their extensive expertise and capability.

How much does vCISO as a Service cost?2025-05-14T00:59:13+01:00

At our initial discussion we will establish your requirements and then agree a subscription model that will be tailored to your needs. This flexible and cost-effective approach is unique to the specific needs and goals of your organisation and budget.

How long will I need this service?2025-08-18T15:11:10+01:00

Our service is flexible and will be based on our understanding of your business and your requirements. We have customers that have the service for an ongoing number of days per month or for the duration of a project. It can be scaled too, if your business grows.

Security Manager as a Service FAQs

How can Security Manager as a Service help my business?2025-05-14T00:59:32+01:00

You may not have the requirement to have a full-time Security Manager in place. Our service gives you the flexibility and access to a dedicated and experienced consultant to help manage information and cyber risk across your organisation whilst providing governance and regulatory assurance.

Will I get a dedicated consultant?2025-05-14T00:59:36+01:00

Yes, you will have a dedicated and experienced consultant with up-to-date knowledge of the latest standards, regulations, and technologies.

How much does Security Manager as a Service cost?2025-05-14T00:59:42+01:00

At our initial discussion we will establish your requirements and then agree a subscription model that will be tailored to your needs. This flexible and cost-effective approach is unique to the specific needs and goals of your organisation and budget.

How long will I need this service?2025-08-18T15:11:10+01:00

Our service is flexible and will be based on our understanding of your business and your requirements. We have customers that have the service for an ongoing number of days per month or for the duration of a project. It can be scaled too, if your business grows.

Defence Cyber Certification

What is the Defence Cyber Certification?2026-08-06T15:31:14+01:00

The Defence Cyber Certification (DCC) is a comprehensive, cyber security certification framework for UK Defence suppliers. Developed by the UK Ministry of Defence (MOD) and IASME, the certification is part of the broader initiative to enhance the cyber resilience of the UK’s Defence sector supply chain.

Do I need to achieve Cyber Essentials first?2026-08-06T15:29:46+01:00

All levels start with Cyber Essentials certification, with DCC levels 2 and 3 requiring Cyber Essentials Plus.

Can you provide implementation support and then certify our organisation?2026-08-06T15:28:31+01:00

The scheme does not allow certification bodies to provide both implementation consultancy and certification services. This allows for impartiality. Our consultants can either provide expert implementation guidance and hands on support, or we can certify you.

How do I know what level to certify to?2026-08-06T15:20:15+01:00

There are four levels available – each with a corresponding level of risk associated with a supplier’s role in the MOD supply chain. The MOD will inform suppliers of the level required and this is determined by the risk profile of the contract.

How long does the DCC process take?2026-08-06T15:23:49+01:00

This will depend on the level of cyber security maturity, your scope, and the level you are requiring certification for. We will work with you to create a realistic timeframe based on your requirements.

Cyber Essentials FAQs

Do I need Cyber Essentials?2026-02-02T12:27:34+01:00

Whilst it’s not essential for you to have Cyber Essentials unless you wish to apply for UK government contracts, we highly recommend you achieve certification for the basic protection of your organisation against cyber security threats.

What are the benefits of Cyber Essentials certification?2025-05-14T00:56:20+01:00

By having Cyber Essentials certification, you will be more protected against the most common security threats. It helps build trust with customers by demonstrating that cyber security is important in your organisation. All certified organisations are listed on the NCSC’s certification database. It also strengthens your supply chain. Finally, having Cyber Essentials will also allow you the opportunity to bid for UK Government and MOD tenders. You can read more about Cyber Essentials on our Cyber Essentials Certification Services page.

What is the difference between Cyber Essentials and Cyber Essentials Plus?2025-05-14T00:56:20+01:00

Cyber Essentials is a verified self-assessment certification that demonstrates an organisation has the required cyber security controls in place. Cyber Essentials Plus is based on the same technical requirements as Cyber Essentials, but it also includes a technical audit of your IT systems, to verify the controls are in place. This gives a higher level of assurance that an organisation has correctly implemented the controls. You can read more about the difference between Cyber Essentials and Cyber Essentials Plus on our Cyber Essentials Certification Services page.

What if we need some guidance with Cyber Essentials?2025-05-14T00:56:20+01:00

Shift Key Cyber are an Assured Service Provider for NCSC. The Cyber Advisors (Cyber Essentials) scheme is specifically aimed to help UK small and medium organisations by offering reliable and cost-effective cyber security advice, and where required, practical hands-on support to help guide businesses through the Cyber Essentials process and certification. You can find out more about our Cyber Advisor Service on our dedicated page.

How much does Cyber Essentials cost?2025-08-19T14:00:21+01:00

Cyber Essentials follows a tiered pricing structure depending on the size of your business. It is a verified self-assessment process which follows the pricing structure shown in the table below.

 

Business Size Cost

Micro organisations (0-9 Employees)

£320 + VAT

Small organisations (10-49 Employees)

£440 + VAT

Medium Organisations (50-249 Employees)

£500 + VAT
Large Organisations (250+ Employees) £600 + VAT
What is the difference between ISO 27001 and Cyber Essentials?2025-08-28T13:18:29+01:00

Both certifications establish controls needed to protect your business from cyber threats and are beneficial in their own rights, but also can co-exist together. Cyber Essentials provides you with five fundamental controls to protect against common threats, making it a reliable and cost-effective certification to demonstrate basic cyber compliance. ISO 27001 takes this a step further, offering a risk based and more comprehensive, in-depth set of optional controls that can be tailored to your organisation. You can find out more about the differences between ISO 27001 and Cyber Essentials in our dedicated blog.

ISO 27001 FAQs

How do I know if I’m ready for certification?2026-01-29T16:26:55+01:00

Your consultant will assess your business to determine the scope and preparations needed and guide you through to certification when you are ready.

What are the risks of not being ISO 27001 certified?2026-01-29T16:25:39+01:00

Without certification you may lack oversight of potential risks, including heightened security risks, data breaches, legal liabilities and reputational damage, as well as loss of opportunities to work with clients who require ISO 27001 compliance. Additionally, this could also reduce confidence from customers and stakeholders.

How much does it cost to implement ISO 27001?2026-01-29T16:16:14+01:00

The cost of your implementation will depend on several factors, including your business size, as well as how much needs to be implemented in preparation for certification. We will work with your existing controls and processes if they are already in place to keep costs down. Your consultant will provide a quote in the initial consultation stage.

What are the benefits of ISO 27001 certification?2026-01-29T15:53:37+01:00

ISO 27001 is an internationally recognised standard that, when implemented correctly, provides assurance of your commitment to protect your business information. Other benefits include improved information security, continuous improvement of your ISMS, and advanced strategy management and threat perception.

Is ISO 27001 only suitable for large organisations?2025-05-14T00:56:20+01:00

ISO 27001 can be implemented into organisations of any size, ranging from micro businesses to global enterprises. The standard is flexible to allow for the controls to be applied in a way that is relevant to you.

What is the difference between ISO 27001 and Cyber Essentials?2025-08-28T13:18:29+01:00

Both certifications establish controls needed to protect your business from cyber threats and are beneficial in their own rights, but also can co-exist together. Cyber Essentials provides you with five fundamental controls to protect against common threats, making it a reliable and cost-effective certification to demonstrate basic cyber compliance. ISO 27001 takes this a step further, offering a risk based and more comprehensive, in-depth set of optional controls that can be tailored to your organisation. You can find out more about the differences between ISO 27001 and Cyber Essentials in our dedicated blog.

ISO 9001 FAQs

How much does it cost to get ISO 9001 certified?2026-01-29T16:28:13+01:00

Certification costs will vary depending on the size and sector of your business. We will assess your existing policies and procedures to determine what else is neededand the cost will be agreed during your discussions with our team.

Can only large organisations certify to ISO 9001?2025-08-27T14:51:04+01:00

ISO 9001 can be implemented into organisations of any size from micro to enterprise.

I am a service provider and do not make a physical product, can I still gain ISO 9001 certification?2026-01-15T12:33:54+01:00

Yes, you can achieve certification whether you sell products or services the quality principles apply to delivering consistent and high-quality services or products.

Who carries out the ISO 9001 certification?2025-08-27T14:51:12+01:00

As part of the implementation stage, we will help you choose a suitable certification body and guide you through the process, we will also attend the audit if you would like us there.

Risk Consultancy FAQs

How does cyber risk management support business resilience?2026-08-10T17:30:18+01:00

Effective cyber risk management helps organisations understand their most critical risks, improve decision-making, and strengthen governance.

Why is good governance important for Cyber Security?2026-08-10T17:29:37+01:00

Clear governance helps everyone understand their responsibilities, improves accountability, and ensures cyber risks are managed effectively. It also helps leaders make informed decisions that support both security and business goals.

What is the benefit of improved risk reporting for boards and senior leaders?2026-08-10T17:28:34+01:00

Improved risk reporting gives boards and senior leaders a clearer view of the threats facing the organisation, helping them to make informed decisions, prioritise resources effectively, and strengthen overall business resilience.

Why is a threat-informed approach effective for risk management?2026-08-10T17:27:59+01:00

A threat-informed risk assessment helps you focus on the threats most likely to impact your organisation, rather than just known risks and compliance requirements. This provides clearer understanding of your real-world risk exposure.

Incident Management FAQs

What is an Incident Response Plan?2026-08-10T17:33:36+01:00

An Incident Response Plan is a documented framework that outlines how your organisation will prepare for, respond to, manage, and recover from cyber security incidents.

How is the plan tailored to my organisation?2026-08-10T17:33:20+01:00

We work with leadership and operational teams to understand your structure, risk profile, business requirements and regulatory requirements, and then create a plan that reflects your operations and business environment.

Why should I test my plan?2026-08-10T17:33:06+01:00

Testing your incident response plan will help identify any changes you need to make. As the threats to your business evolve, testing your incident response plan at least annually will help keep it up to date and current.

How long will it take to create a plan?2026-08-10T17:32:17+01:00

This depends on the size and complexity of your organisation.

Business Continuity FAQs

What is a Business Continuity Plan?2026-08-10T17:35:40+01:00

A Business Continuity Plan helps your organisation continue operating during and after a disruptive event, whilst minimising downtime and business impact.

What are the benefits of a Business Continuity Plan for my business?2026-08-10T17:35:31+01:00

Business Continuity Plans provide a clear framework for responding to incidents, helping your organisation minimise disruption, reduce risk exposure, recover critical operations quickly, and maintain the confidence of customers.

How often should I review the plan?2026-08-10T17:35:20+01:00

We recommend reviewing your plan at least annually or whenever significant changes occur within the business.

Do small businesses need a plan?2026-08-10T17:34:55+01:00

Businesses of all sizes can experience disruption, so having a plan in place will help minimise the impact, regardless of size.

Supply Chain Audits FAQs

What is a Supply Chain Audit?2026-08-10T17:36:50+01:00

A supply chain audit helps organisations assess a supplier’s security controls and practices, providing oversight and understanding of whether suppliers are managing cyber and information security risks appropriately.

How do you assess supplier risk?2026-08-10T17:36:44+01:00

This is determined by factors such as the services they provide, the sensitivity of the data they handle, and their level of access to your systems.

How can this help support compliance requirements?2026-08-10T17:36:35+01:00

A structured approach to supplier risk management can support compliance with standards and regulations such as ISO 27001, Cyber Essentials Plus, and sector-specific requirements.

How often should supply chain risks be assessed?2026-08-10T17:36:25+01:00

This should be an ongoing process of regular reviews, to allow for any business requirement changes, or if a supplier service changes.

Internal Audits FAQs

What is an Internal Audit?2026-08-10T17:38:36+01:00

It is an independent assessment of your processes, controls and policies, to determine if they are operating effectively and adequately supporting your risk management and business objectives.

What are the benefits of using a third-party auditor?2026-08-10T17:38:28+01:00

The main benefit is you get an objective perspective, allowing clear oversight of overlooked risks. This approach allows for impartial recommendations to strengthen controls.

Why are internal audits important for my business?2026-08-10T17:38:19+01:00

If you hold an ISO certification, it is a mandatory requirement of the standard. If you don’t hold an ISO certification, internal audits help identify risks and areas of improvement before they become much more significant to your business.

Can you support my business after the audit?2026-08-10T17:38:05+01:00

Yes, we can. We provide practical remediation advice and support to help you address the findings.

Go to Top