News

Cyber Essentials Plus at NOE CPC: More than just an annual audit

  • 09/10/2026
  • Written by Joe Speed

Keeping our devices and our software safe and operational are vital to what we do as an organisation – but how do we achieve our cyber security accreditation, and why is it so important?

Joe Speed, Data Services Manager, takes a closer look at the work that goes into achieving our Cyber Essentials Plus accreditation.

“When people hear that NOE CPC has successfully maintained its Cyber Essentials Plus accreditation, it can be easy to think of it as simply another certification exercise.

“In reality, Cyber Essentials Plus is one of the most visible outcomes of a year's worth of work to maintain the security of our systems, devices and data.

“As Data Services Manager, one of my key responsibilities is helping to ensure that the information entrusted to us by members, customers, suppliers and colleagues is protected appropriately. Cyber Essentials Plus provides an independent assessment of the controls we have in place and helps demonstrate that we continue to meet recognised standards of cyber security. We first achieved Cyber Essentials Plus in 2022 and have successfully maintained the accreditation ever since.

Understanding the Scope

“One of the most interesting aspects of Cyber Essentials Plus is deciding exactly what is in scope for assessment.

“NOE CPC employs around 135 colleagues across the organisation. However, not every part of the organisation falls within the scope of our Cyber Essentials Plus accreditation.

“The NOE CPC Hub environment is assessed as part of our Cyber Essentials Plus certification, while around 35 colleagues working within the NHS Supply Chain side of the business operate outside that assessed environment.

“That means one of the first tasks we undertake each year is making sure we clearly understand where the boundaries sit. Which users are in scope? Which devices are in scope? Which systems and services need to be assessed?

“Whilst that might sound relatively straightforward, organisations continually evolve. New colleagues join, devices are replaced, services change and systems are modernised. Maintaining a clear understanding of our environment is one of the foundations of maintaining good cyber security.

“In many ways, one of the biggest lessons I have learned through Cyber Essentials Plus is that you cannot secure what you do not understand.

Small Team, Big Responsibility

“Like many organisations, NOE CPC relies heavily on technology.

“On an average day our colleagues depend on laptops, mobile devices, Microsoft 365 services, business systems, cloud platforms and supplier-managed services to do their jobs effectively. If those services aren't available, or aren't secure, the impact can be significant.

“What makes this particularly interesting is that our internal Data Services team is relatively small. Alongside supporting colleagues with day-to-day issues, we are also responsible for cyber security, device management, business systems, Microsoft 365, Dynamics 365, reporting platforms, supplier engagement and a growing portfolio of digital projects.

“Cyber Essentials Plus provides a useful framework because it helps keep the fundamentals front and centre. Patch management, access control, device security, malware protection and secure configuration may not always be the most exciting topics, but they remain some of the most effective ways to reduce cyber risk.

The Audit Is the Easy Part

“People are often surprised when I say that the audit itself is probably the easiest part of Cyber Essentials Plus. The difficult part is everything that happens beforehand.

“Maintaining device compliance throughout the year, ensuring software is kept up to date, reviewing vulnerabilities, managing administrator access, implementing security controls and maintaining accurate records all require continual effort.

“By the time the assessor arrives, the hard work should already be done.

“Don't get me wrong, the audit itself is still a lot of work – and tends to uncover new vulnerabilities that need to be addressed – but I have found that each year the audit has been quicker and easier than the last.

“For me, Cyber Essentials Plus works best when it is viewed as an ongoing operational discipline rather than an annual project. The accreditation is effectively a snapshot of the work that has taken place during the previous 12 months.

Continual Improvement

“One of the benefits of undergoing an annual reassessment is that it encourages continual improvement.

“Each accreditation cycle gives us an opportunity to review our environment, challenge our assumptions and identify areas where we can strengthen our controls further.

“Over the years this has helped us improve visibility of our estate, modernise older components, refine our governance processes and ensure we continue to align with evolving cyber security standards.

“Cyber security is not something that can ever really be considered "finished". Threats change, technology evolves and organisations grow. What was considered best practice three years ago may not be sufficient today.

“That is one of the reasons why maintaining Cyber Essentials Plus remains so valuable. It gives us a structured way of regularly reviewing where we are and where we need to improve.

Security Is Everyone's Responsibility

“Although Cyber Essentials Plus focuses on technical controls, effective cyber security is never solely the responsibility of the IT team.

“Every colleague contributes to protecting the organisation through the decisions they make each day. Whether that's keeping devices updated, using multi-factor authentication, reporting suspicious emails or following good information governance practices, those actions all contribute to a stronger security culture.

“The certification provides assurance, but it is the collective efforts of colleagues across NOE CPC that help bring those standards to life.

Looking Ahead

“Cyber threats continue to evolve, and so must we.

“Maintaining Cyber Essentials Plus is not about collecting a certificate each year. It is about demonstrating a commitment to protecting our people, our systems and our information.

“For me personally, the accreditation is less about passing an audit and more about providing confidence. Confidence that we understand our environment. Confidence that we are managing risk appropriately. And confidence that NOE CPC continues to take cyber security seriously in an increasingly digital world.

“What I'm most proud of is not the certificate itself, but the fact that maintaining Cyber Essentials Plus has become part of how we operate. Security is no longer a separate exercise that happens once a year. It is embedded into how we manage devices, systems and projects every day.”

Get notifications for related news stories