
Education charity and awarding organisation
ASDAN
Cyber Essentials and Cyber Essentials Plus, GDPR compliance support, continuity planning and policy resilience for a national education charity.
Case study in preparation
Strengthen technical controls, reduce avoidable human risk and create a clearer path towards recognised cyber standards.
Explore the two sides of resilience
Controls that reduce measurable exposure across identity, devices, networks and data.
Select a control area to explore
Technical protection
Controls that reduce measurable exposure across identity, devices, networks and data.
Control areas
Select a control area above to see what it may expose and how we strengthen it.
Strengthen technical controls, reduce avoidable human risk and create a clearer path towards recognised cyber standards.
Explore the two sides of resilience
Controls that reduce measurable exposure across identity, devices, networks and data.
Cyber Resilience Control Surface
Cyber resilience overview
Five connected areas. One resilient organisation.
Technical protection, people and working practices combine to reduce avoidable cyber risk.
Technical protection
Identity, devices, network and data controls
Human and operational resilience
Governance, people and working practices
Select a chip above to explore a control area.
Cyber resilience depends on technical protection and the way people work. Strengthening one without the other leaves avoidable gaps.
One connected
resilience model
Technical Protection
People & Practice
Why it matters
Technical controls and informed people work together. One without the other leaves the most exploited attack vectors open - strengthening both as a single programme is the only way to close avoidable gaps.
What Assured Digital does
We align your Microsoft security configuration, endpoint controls, network posture and data governance with clear policies, staff awareness and practical resilience planning - as one coordinated programme.
Result
A resilient organisation where technical controls reduce risk and people are equipped to recognise, report and recover from threats.
Clearer ownership
Named responsibilities for every security control
Reduced avoidable risk
Controls that actually operate, not just exist on paper
Stronger controls
Measured improvement across the five Cyber Essentials areas
Certification readiness
Aligned to Cyber Essentials, Cyber Essentials Plus and ISO 27001
Trusted in complex and high-assurance environments




Supporting organisations where resilience, assurance and operational continuity matter.
Logo display does not imply that every organisation has purchased every cyber capability listed on this page.
Cyber capabilities
Select a capability to see the risk it addresses, what Assured Digital does and the improvement it creates.
The pressure
Microsoft Defender and Conditional Access are frequently deployed but not configured - staff can bypass MFA, legacy authentication remains active and endpoint policies are not enforced. The controls exist on paper but are not protecting the organisation.
What Assured Digital does
We audit your Microsoft 365 security configuration against Cyber Essentials and established best-practice benchmarks, then configure Defender, Intune and Conditional Access to enforce the controls you already licence.
What improves
MFA enforced with no legacy bypass, endpoints enrolled and compliant, security configuration aligned to your operating model - using capability you are already paying for.
The pressure
Firewall rules are rarely reviewed after initial deployment. Default configurations, permissive inbound rules and unreviewed outbound traffic leave boundary controls weaker than they appear - particularly as the network perimeter has shifted toward cloud services.
What Assured Digital does
We review your network boundary controls, firewall rule sets and segmentation configuration against Cyber Essentials requirements, then produce findings and a prioritised list of improvements.
What improves
A clear picture of boundary exposure with a prioritised remediation list - giving the organisation confidence that controls reflect how the network is actually being used.
The pressure
Sensitive data is rarely classified before AI tools are deployed. Oversharing in SharePoint, permissive guest access and the absence of sensitivity labels create conditions for both accidental and deliberate exposure - and make it difficult to demonstrate compliance.
What Assured Digital does
We audit SharePoint permissions, sensitivity label coverage and data governance configuration through Microsoft Purview, then help establish classification policies that reduce exposure and improve compliance posture.
What improves
Sensitive information classified and governed, SharePoint access scoped appropriately, and a defensible record of data handling for compliance and insurance purposes.
The pressure
Without an independent perspective, cyber risk is often assessed by the people who built or manage the systems being reviewed. Governance gaps, undocumented supplier access and the absence of a tested incident response plan frequently go unnoticed until they are tested by an incident.
What Assured Digital does
We conduct independent cyber health checks and posture reviews that assess your current controls, governance and supplier access arrangements - then produce clear, prioritised findings with a practical remediation roadmap.
What improves
Documented risk posture, prioritised remediation roadmap and independent evidence suitable for boards, insurers, auditors and supply-chain assurance requirements.
The pressure
Human error remains the primary entry point for most incidents. Awareness programmes are rarely run consistently, phishing simulations are one-off rather than regular, and most staff have never practised what to do if primary systems become unavailable.
What Assured Digital does
We assess your current awareness posture, run controlled phishing simulations through Assured Secure, and help establish a regular programme - including clear reporting procedures and practical guidance for common threat scenarios.
What improves
Staff who recognise and report phishing attempts, a measurable baseline for ongoing improvement, and a security culture where protective behaviour is understood and practised - not just prescribed.
The pressure
Security policies often exist as inherited documents that have not been reviewed, do not reflect current working practices and are not communicated to staff. When an incident occurs, the absence of clear responsibilities and documented procedures amplifies the disruption.
What Assured Digital does
We review, update and where necessary write security policies, procedures and business continuity arrangements that reflect how the organisation actually operates - with clear ownership, communication and a practical review cycle.
What improves
Current, communicated policies with named ownership, documented procedures for common incident scenarios and a review cycle that keeps them aligned with how the organisation works.
The pressure
Microsoft Defender and Conditional Access are frequently deployed but not configured - staff can bypass MFA, legacy authentication remains active and endpoint policies are not enforced. The controls exist on paper but are not protecting the organisation.
What Assured Digital does
We audit your Microsoft 365 security configuration against Cyber Essentials and established best-practice benchmarks, then configure Defender, Intune and Conditional Access to enforce the controls you already licence.
What improves
MFA enforced with no legacy bypass, endpoints enrolled and compliant, security configuration aligned to your operating model - using capability you are already paying for.
Assured Secure combines tailored awareness training, controlled phishing simulations, policy management and exposed-credential monitoring in one managed programme.
Build stronger everyday security habits and clearer evidence for customers, insurers and supply-chain partners.
Pricing varies according to organisation size, selected capabilities and service requirements.
Assured Secure combines tailored awareness training, controlled phishing simulations, policy management and exposed-credential monitoring in one managed programme.
Build stronger everyday security habits and clearer evidence for customers, insurers and supply-chain partners.
Pricing varies according to organisation size, selected capabilities and service requirements.
Different organisations need different levels of assurance. We help improve the underlying controls and prepare the evidence appropriate to the requirement.

Certification support
What it establishes
Establishes that five essential technical controls are in place - firewalls, secure configuration, access control, malware protection and patch management.
When it may be relevant
Relevant when a contract, tender or supply-chain requirement asks for evidence of basic cyber hygiene - or as a structured first step in improving technical controls.
How Assured Digital supports
We identify the gaps between current configuration and Cyber Essentials requirements, remediate what needs fixing and prepare the evidence for the readiness assessment.
Practical next step
Start with a Cyber Essentials gap analysis to map current controls, identify what needs to change and understand what evidence will be required.
What it establishes
Establishes that five essential technical controls are in place - firewalls, secure configuration, access control, malware protection and patch management.
When it may be relevant
Relevant when a contract, tender or supply-chain requirement asks for evidence of basic cyber hygiene - or as a structured first step in improving technical controls.
How Assured Digital supports
We identify the gaps between current configuration and Cyber Essentials requirements, remediate what needs fixing and prepare the evidence for the readiness assessment.
Practical next step
Start with a Cyber Essentials gap analysis to map current controls, identify what needs to change and understand what evidence will be required.
Need broader GDPR, DPO or organisational compliance support?
Explore Governance & ComplianceMost engagements move through these stages in order. Some start later, depending on what has already been done.
What happens
We review the current environment, controls and business priorities through an independent assessment. This gives both sides an accurate picture of what is in place and what is not.
What you receive
Why it matters
Without an accurate baseline, remediation effort is applied to the wrong problems first.
What happens
We review the current environment, controls and business priorities through an independent assessment. This gives both sides an accurate picture of what is in place and what is not.
What you receive
Why it matters
Without an accurate baseline, remediation effort is applied to the wrong problems first.
It usually begins with a contract, an insurer, a Microsoft concern, an incident or a new use of data and AI.
What may be happening
The organisation is being asked to demonstrate Cyber Essentials or Cyber Essentials Plus before a contract is awarded or renewed. The five control areas required - firewalls, secure configuration, access control, malware protection and patching - are often partially in place but not evidenced. Configuration gaps are common and tend to be straightforward to fix once they are identified.
Where we would look
A practical next step
A structured Cyber Essentials gap analysis identifies the specific gaps, produces the remediation roadmap and generates the evidence required for a certification application.
Discuss certification readinessCustomer evidence
All named customer work is confirmed. Quotes are anonymous and role-attributed.
Case study in preparationConstruction and plant hire
The pressure
Contract and supply-chain requirements needed independently evidenced cyber controls across operations spanning multiple construction sites.
What changed
Cyber Essentials and Cyber Essentials Plus remediation, remote-access improvements and Microsoft Purview controls for operational and site data.
Result
Certification achieved, stronger remote access and clearer evidence for procurement and supply-chain requirements.

Education charity and awarding organisation
Cyber Essentials and Cyber Essentials Plus, GDPR compliance support, continuity planning and policy resilience for a national education charity.
Case study in preparation

We used the findings to structure our Cyber Essentials application. Having the gap analysis already done saved us several weeks.
Control areas we work across
Cyber Essentials and Cyber Essentials Plus
Gap analysis, remediation and certification readiness across the five control areas
Microsoft security configuration
Defender, Conditional Access and Purview activation for organisations with unused licences
Secure access and endpoint improvements
Remote access, MFA coverage and device management across distributed operations
Data protection and governance controls
Sensitivity labelling, permissions review and AI-readiness baseline for Microsoft 365
Outcomes differ by engagement and starting position. Our work begins with an accurate baseline - not assumptions.
Answer 15 practical questions across five connected areas. Your PDF report is generated instantly and sent directly to your inbox, giving you a clear view of your strengths, potential gaps and practical next steps.
No obligation. Your PDF report is generated and emailed to you immediately after completion.
Five assessment areas
Frequently asked questions