Skip to content
Offrano
Choose country and language:

Cyber security

Cyber security: buying testing, certification and incident help

One local tradesperson gets your request – no ring-round.

Guide price according to gov.uk: Government procurement guidance (PPN 014, updated February 2025) expects Cyber Essentials certification for smaller companies to cost …

Your request: Cyber security

Step 1 of 5 · Project

Project

What exactly is it about? (required)
How many employees does your company have? (required)
What do you need? (required)
Is your company in scope of NIS2? (required)
items
How urgent is it? (required)
Approximate budget (required)

At least 20 more characters

Where is the project?

Free · no obligation · only one business gets your number

Cyber security is sold under many labels, and a vulnerability scan dressed up as a penetration test is easy to buy by mistake. This page sorts out what the common services are, how to scope them, which certifications mean something in the UK, and how the EU's NIS2 rules relate to a British business. If you are dealing with an attack right now, read the incident section first. Whatever you ask for, your request is passed to exactly one security firm.

  • Exactly one business. Your request is handed out once. After that, no other business sees it.
  • You know who will be in touch. Before the business receives your contact details, we send you its name, address and phone number.
  • Withdraw at any time. You can withdraw your consent at any time – using the link in our email.

Scan, test, audit or monitoring

A vulnerability scan is an automated check for known weaknesses. It is quick and repeatable, but it produces false alarms and misses anything that needs human judgement. A penetration test is a person, or a team, trying to break in within an agreed scope, then showing how far they got and how to fix it. A security audit reviews policies, configurations and processes against a standard. Monitoring, often called a security operations centre or SOC, is a service that watches your logs and alerts around the clock or in agreed hours.

They answer different questions. If you want to know whether your web application can be abused, commission a test of that application. If a customer's security questionnaire asks about your controls, an audit or certification fits better. If nobody would notice an intruder for weeks, monitoring is the gap.

Scoping a penetration test properly

Unauthorised access to computer systems is an offence under the Computer Misuse Act 1990, so a tester needs your written authorisation, naming exactly what may be tested and when. If your systems are hosted by a cloud or hosting provider, check its rules on testing too. A good firm will insist on this paperwork; be wary of one that does not.

Agree the type of test, such as an external network test, an internal test, a web application or an API, the test window, contact names in case something breaks, and whether a retest after fixes is included. The report should rank findings by real risk to your business and explain them so that your IT team or provider can act.

For public sector and critical national infrastructure systems, the NCSC runs the CHECK scheme for penetration testing companies. Industry accreditations such as CREST are also widely asked for in tenders. Ask which the firm holds and who will actually carry out the work.

  • the systems, addresses and applications in scope, and anything excluded
  • whether testers get user accounts or start with no access
  • testing hours and an emergency contact on both sides
  • how findings are rated and reported
  • whether a retest is included
  • how test data and the report are stored and deleted

Source: legislation.gov.uk

Make a request

Cyber Essentials and ISO 27001

Cyber Essentials is the government-backed baseline, delivered for the NCSC by IASME. It checks five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The basic level is a verified self-assessment; Cyber Essentials Plus adds remote and on-site vulnerability testing. Certificates must be renewed every 12 months, and certain central government and NHS contracts involving personal data require one of the two from suppliers.

ISO/IEC 27001 is broader: it certifies an information security management system covering risk assessment, policies, suppliers, incidents and continual improvement. It takes months rather than weeks and suits organisations whose customers demand it. For a certificate that is widely recognised, choose a certification body accredited by UKAS. Keep the consultant who helps you prepare separate from the body that certifies you.

Source: gov.uk

NIS2 and the UK position

NIS2 is an EU directive. It does not apply in the UK as UK law. What applies here are the Network and Information Systems Regulations 2018, which cover operators of essential services in energy, transport, health, drinking water and digital infrastructure, plus some digital services such as online marketplaces, online search engines and cloud computing services. Most businesses are outside their scope.

The Cyber Security and Resilience Bill, now before Parliament, would extend these rules to data centres and to medium and large managed service providers, and would tighten the deadlines for reporting incidents. It had not become law when this page was last updated. If your business provides services in EU member states, NIS2 may still reach that part of your activity through those countries' own laws, so check with an adviser who knows both regimes. When you fill in our form, answer the NIS2 question with that in mind, or choose "Don't know".

Source: legislation.gov.uk

If you are under attack now

Call for help before trying to repair anything yourself. Well-meant clean-up can destroy the evidence an investigator needs, and paying a ransom does not guarantee you get your data back. If you have cyber insurance, contact the insurer first: many policies require you to use their incident response panel. The NCSC also runs an assured scheme for cyber incident response companies.

If personal data is affected, UK GDPR requires you to report the breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to put people at risk. Fraud and cyber crime can be reported to Action Fraud in England, Wales and Northern Ireland, and to Police Scotland in Scotland. Choose "Emergency, right away" in the form, but be aware that we cannot promise how quickly a firm responds.

Source: legislation.gov.uk

One security firm sees your request

Security requests are sensitive, so we keep the description short and anonymous until a firm commits. We offer it without your company name or contact details to security firms in your region, and exactly one of them can buy it. Before that firm receives your details, we email you its name, address and phone number, and you can withdraw your consent at any time.

The service is free to you, and nobody is obliged to take the request; it is withdrawn if unsold after 21 days. Offrano checks that buyers are registered businesses. It does not verify security accreditations, so check CHECK, CREST or UKAS status with the scheme itself.

What does it cost?

  • Government procurement guidance (PPN 014, updated February 2025) expects Cyber Essentials certification for smaller companies to cost between £300 and £500+ VAT at basic level; the price of Cyber Essentials Plus depends on the size and complexity of the network.

    Source: www.gov.uk

  • Make a request

Related services

Guides on Cyber security

Frequently asked questions

Does NIS2 apply to UK companies?

Not as UK law. NIS2 is an EU directive; the UK has its own NIS Regulations 2018, which cover essential services and certain digital services. A UK company that provides services inside the EU may still fall under a member state's NIS2 law for that activity. The UK's Cyber Security and Resilience Bill would widen the domestic rules but was not yet law when this page was updated.

What is the difference between a vulnerability scan and a penetration test?

A scan is automated and looks for known weaknesses. A penetration test is carried out by people who try to exploit weaknesses, chain them together and show the real impact. Scans are useful between tests, but they are not a substitute for one.

Is Cyber Essentials enough?

It covers the basic controls that stop the most common attacks, and it is required for certain public sector contracts. It does not test your applications, check your suppliers or prepare you for an incident. Many businesses start with Cyber Essentials and add testing or ISO 27001 as customers ask for more.

Do we have to report a cyber attack?

If personal data is involved and people could be put at risk, you must tell the ICO without undue delay and, where feasible, within 72 hours, and in some cases the people affected. Organisations covered by the NIS Regulations have separate duties to report to their regulator. Reporting the crime to Action Fraud or Police Scotland is also advisable.

How long does ISO 27001 certification take?

It depends on how much is already documented and working. The management system has to run for a while before an audit can show it works, so plan in months. Choose a UKAS-accredited certification body so the certificate is widely accepted.

Who will see our security request?

Only the one firm that buys it sees your details, and we tell you who that is first. Other firms see only an anonymous summary until it is sold, and after the sale it disappears from our marketplace.

Ready to make your request?

Describe your project – your request goes to exactly one business.

Make a request

Popular services

New in the guides