OpusBUSINESS EXPERT

The government built you a free security check. Run it before you pay anyone

Andy Shepherd4 min read

For most small firms, cyber security arrives as a question from somebody else. An insurance renewal wants to know whether you have had an "assessment". A big customer sends a supplier questionnaire with forty rows in it. And the natural response to an official-looking form you cannot answer is to find someone who sells answers, which is how a ten-person firm ends up pricing a consultant's audit before anyone has spent an hour on the basics.

The sequence is backwards. The National Cyber Security Centre, the bit of GCHQ that writes the advice those questionnaires are cribbed from, runs free tools built for exactly this situation. Start there, fix what they find, and only then decide what is worth paying for.

The toolkit your taxes already paid for

The newest is the Cyber Action Toolkit, launched last October for sole traders and small organisations. It asks about your business and produces a personal action list, ordered the way a sensible adviser would order it: highest impact and lowest effort first. The actions sit in three tiers, so you do the essentials before anything clever, and it tracks what you have done, which matters more than it sounds — a security to-do list with no memory is how the same gaps survive year after year.

It sits alongside the NCSC's older pair, the Cyber Action Plan and Check Your Cyber Security, which have been running since 2023. None of this is news, and that is rather the point. These services have existed for years, cost nothing, and the firms they were built for mostly still meet security for the first time in a renewal form. Free tools have no marketing budget; the people who ring you about security are the ones charging for it.

  1. 01Run the NCSC's free toolkit and get the action list
  2. 02Fix what it finds, essentials first
  3. 03Then decide what is left that is worth paying for

What a browser cannot see

An honest recommendation of these tools has to include their edge, because they have one. A questionnaire knows what you tell it. It cannot look inside your systems, and inside your systems is where the expensive assumptions live.

Three examples from estates we look after, none of which a self-assessment can catch:

Who actually holds global admin. In a Microsoft 365 tenant that grew up informally, the answer is often a departed contractor, a web company that set up the email years ago, or a login nobody has opened since. The toolkit can tell you admin accounts should be limited and protected. It cannot tell you that yours belongs to someone who left in 2021.

Whether MFA is enforced or merely available. "We have MFA" is true of nearly every Microsoft 365 tenant on paper. Whether every account, including the shared mailbox everyone forgot, is actually required to use it is a settings question, and self-assessments run on good intentions.

Whether a backup has ever been restored from. You can answer "yes, we have backups" in perfect good faith and still be unable to produce Tuesday's files. A backup nobody has restored from is a subscription, not a safety net, and the only way to know which you have is to test it.

A questionnaire knows what you tell it. The expensive assumptions live in the settings you have never looked at.

None of that makes the free check pointless. It makes it the filter: it clears the general ground cheaply, so that if you do pay someone, you are paying for the part that genuinely needs hands inside the systems, not for a PDF restating government guidance at consultancy rates.

The certificate rung

Above self-assessment sits Cyber Essentials, the certification version of the same basics. The free toolkit is explicitly designed as a runway towards it. You need the certificate on the day a customer or an insurer demands one, and not before; when that day comes, the work you did off the free action list is most of the preparation already done.

When paying is the right answer

Sometimes it is. If the action list turns up things you cannot do yourself — nobody in the firm knows where global admin lives, the backup test fails, the leaver process is a shrug — that is a defined job with a defined end, and a fair thing to pay for. What it is not is an open-ended "security review" bought under questionnaire pressure.

And sometimes the free check is enough, full stop. A firm that runs through the toolkit, fixes the list, enforces MFA and proves a restore has covered more ground than a good share of the SMEs those questionnaires get sent to. Someone whose business is selling audits has little reason to tell you that, which is why it is worth hearing from someone whose business is not: ours is running the systems where these gaps actually live, and the honest answer to "do we need a security audit" is quite often no.

The renewal form will come round again next year either way. The difference is whether you meet it with a blank box or a done list.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy