NCSC Cyber Essentials · Security Assessment · UK

Cyber SecurityHealth Check

A thorough, structured assessment of your security posture — covering your network, firewalls, user access and patch management — aligned to NCSC Cyber Essentials, with a written remediation roadmap delivered within five business days.

  • 1–3 day active assessment
  • NCSC Cyber Essentials aligned
  • Written remediation roadmap
1–3
Day Assessment Window
5
NCSC CE Controls Reviewed
5 days
Report Delivery
100%
Written Remediation Roadmap
Scope of Assessment

Five areas. One complete picture of your security posture.

Our health check maps directly to the five NCSC Cyber Essentials technical controls — the baseline standard the UK government requires for any business handling sensitive data or bidding on public sector contracts.

Firewalls & Internet Gateways

Review of your perimeter firewall rules, inbound/outbound policy, default deny posture and exposed services.

Secure Configuration

Audit of default credentials, unnecessary features and services, and baseline hardening on servers and network devices.

User Access Control

Review of admin account usage, principle of least privilege, MFA enforcement, and stale or orphaned accounts.

Malware Protection

Assessment of endpoint protection coverage, definition currency, sandboxing capability and web filtering.

Patch Management

Review of OS and application patch levels, end-of-life software, vulnerability scan results and patching cadence.

External Vulnerability Scan

Automated scan of your internet-facing attack surface — open ports, exposed services, known CVEs and misconfigurations visible from outside your network.

Internal Network Assessment

Internal scan covering lateral movement risk, unencrypted protocols, exposed admin interfaces and network segmentation weaknesses.

Privilege & Access Audit

Identify over-privileged accounts, shared credentials, dormant users and missing MFA across your identity estate.

How It Works

From kickoff to remediation roadmap in under a week

We keep the process low-friction. No lengthy scoping exercises or professional services engagements — just a clear, structured assessment with a useful output at the end.

Kickoff Call (30 min)

We confirm scope, agree access requirements and share the assessment schedule. No paperwork beyond a standard NDA.

Active Assessment (Day 1–3)

External and internal scans run. Our engineers review firewall policy, access controls, patch currency and configuration against the five CE controls.

Analysis & Report Writing (Day 3–5)

Findings are scored by severity (Critical / High / Medium / Low). Each finding gets a plain-English description, business impact and recommended fix.

Report Delivery & Walkthrough

You receive the written report and a 60-minute walkthrough call with the lead engineer. Every finding is explained in context, not just listed.

Optional: Remediation Support

ManagedByUs can implement the fixes — from firewall rule changes to MFA rollout — or support your internal team through the remediation work.

Common Questions

Cyber security health check — answered

Know where you stand before attackers do

Book a cyber security health check and receive a plain-English picture of your risk exposure — and exactly what to fix first.