ICAEW Registered Auditors  ·  90+ UK-Based Experts

Cyber Essentials Companies in the UK: Providers and Support Guide

AC
Acumon Chartered Accountants ·12 min read

Preparing for Cyber Essentials is not simply a matter of installing antivirus software or changing a few technical settings. For growing companies, corporate groups and regulated organisations, it often forms part of a wider review of cyber risk, operational controls, financial compliance and corporate security.

The UK has a broad mix of Cyber Essentials providers, from specialist cybersecurity consultancies to managed IT firms and wider compliance practices. Some focus mainly on certification, while others deal with technical remediation, risk reviews, staff awareness and longer-term security planning.

This guide highlights a selection of companies providing Cyber Essentials services in the UK. It is not a ranking. The aim is to give organisations practical context on how different providers work, what they cover and the type of support available before, during and after certification.

Acumon logo

Acumon

Acumon is a UK firm of chartered accountants and registered auditors providing Cyber Essentials services to companies, charities, and international corporate groups.

The firm works with organisations ranging from growing owner-managed businesses and charities through to larger corporate groups and regulated entities. Cyber Essentials engagements are delivered through a structured approach focused on reviewing technical controls, identifying security gaps, and preparing organisations for certification.

Acumon supports organisations working towards Cyber Essentials and Cyber Essentials Plus certification. The Cyber Essentials scheme focuses on five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. Cyber Essentials Plus includes additional technical verification of the controls implemented across the organisation.

For growing businesses, corporate groups, and regulated organisations, Cyber Essentials preparation extends beyond antivirus software or isolated IT settings. It forms part of a wider review of technology risk, financial compliance, operational resilience, internal controls, and corporate security. This broader approach helps ensure that cybersecurity responsibilities are aligned with governance structures, reporting processes, regulatory obligations, and the organisation’s overall risk framework.

In addition to its UK audit registration, Acumon also holds audit licences in several international financial centres, including the Cayman Islands, British Virgin Islands (BVI), Jersey, and Isle of Man. This experience enables the firm to support international corporate groups where entities, systems, and operational teams are located across multiple jurisdictions.

Acumon works with finance teams, IT teams, and boards to support Cyber Essentials certification while also helping organisations strengthen cybersecurity processes, governance arrangements, financial compliance, corporate security, and internal controls as they grow.

Cyber Essentials Capabilities:

Acumon provides Cyber Essentials services across a wide range of organisational structures and sectors.

These include:

  • UK limited companies and corporate groups
  • Public Interest Entities (PIEs) and regulated organisations
  • UK subsidiaries of international groups
  • charities and not-for-profit organisations
  • owner-managed businesses preparing for Cyber Essentials certification
  • offshore holding companies and investment vehicles

Cyber Essentials engagements are led by senior professionals with direct involvement throughout the engagement.

Regulatory Licences and Registrations:

Acumon holds several audit registrations that enable it to support organisations operating across multiple jurisdictions.

These include:

  • UK statutory audit registration
  • Public Interest Entity (PIE) audit licence
  • Jersey audit licence
  • Isle of Man audit licence
  • Cayman Islands audit licence
  • British Virgin Islands audit licence

These registrations support the firm’s work with groups that include entities in both the UK and key international financial centres.

Core Services:

In addition to Cyber Essentials support, Acumon provides a range of services that support cybersecurity, technology risk, and governance.

These include:

  • Cyber Essentials readiness reviews
  • Cyber Essentials certification support
  • Cyber Essentials Plus preparation
  • cybersecurity gap assessments
  • IT controls and technology risk reviews
  • internal audit and governance reviews
  • risk management and compliance support

Cyber Essentials work is delivered alongside discussions with management and boards regarding cybersecurity processes, technology controls, and governance frameworks.

Many organisations first encounter Cyber Essentials requirements when they begin working with public sector bodies, regulated clients, larger corporate customers, or supply chain partners that require recognised cybersecurity certification. 

Acumon works with businesses that are:

  • approaching their first statutory audit
  • preparing for external investment
  • expanding into international markets
  • operating within corporate group structures

Early engagement with a Cyber Essentials adviser helps ensure that systems, devices, user accounts, software updates, and security documentation are aligned with certification requirements and integrated into the organisation’s wider risk, financial compliance, and corporate governance framework.

Contact Information:

RSM UK logo

RSM UK

RSM UK is an audit, tax and consulting firm with a cyber risk practice within its wider risk and governance work. They examine how cyber threats affect strategy, business transformation and operational delivery, rather than treating security as an issue owned only by the IT department. Their work involves boards, senior executives and operational leaders with different responsibilities for managing risk.

Their cyber resilience services place particular weight on governance, accountability and continuity during an incident. They work with leadership teams to clarify oversight responsibilities, shape board-level discussions and review how security decisions are made across the organisation. This work sits alongside their broader consulting services in risk, governance, investigations and business transformation.

Key Highlights:

  • Cyber risk and resilience practice
  • Board and senior leadership focus
  • Governance-led approach
  • Operational resilience expertise
  • Risk and business transformation capabilities
  • Wider audit, tax and consulting knowledge

Services:

  • Cyber risk reviews
  • Cyber resilience planning
  • Board-level cyber governance
  • Leadership advisory
  • Operational resilience
  • Risk and governance consulting
  • Business transformation
  • Forensic and investigation services

Contact Information:

  • Website: www.rsmuk.com
  • Phone: +44 (0)161 830 4000                                                    
  • Address: Landmark, St Peter's Square, 1 Oxford Street, Manchester, M1 4PB
  • LinkedIn: www.linkedin.com/company/rsm-uk
  • Instagram: www.instagram.com/rsm.uk
PwC UK logo

PwC UK

PwC UK is a professional services firm working across audit, consulting, deals, risk and tax. They deal with public, private and third-sector organisations, bringing together technology, regulatory and sector knowledge for projects involving business change, compliance and risk. Their cyber security work forms part of a wider technology practice rather than operating separately from broader organisational priorities.

They approach technology work through both value creation and protection. This means looking at security alongside transformation, cost management, regulation and trust. Their teams work with organisations ranging from growing private businesses to public bodies and multinational groups, adapting the scope of each engagement to the systems, risks and governance structures involved.

Key Highlights:

  • Multidisciplinary professional services firm
  • Dedicated technology and cyber security capabilities
  • Work across public, private and third sectors
  • Combined technology and risk expertise
  • Regulatory and compliance knowledge
  • Access to broader audit and consulting teams

Services:

  • Cyber security services
  • Technology consulting
  • Risk consulting
  • Digital transformation
  • Regulatory compliance
  • Audit and assurance
  • Deals advisory
  • Tax services

Contact Information:

  • Website: www.pwc.co.uk
  • Phone: +44 (0)14 1355 4000
  • Address: 120 Bothwell Street, Glasgow, G2 7JS                     
  • Instagram: www.instagram.com/pwc_uk
  • Facebook: www.facebook.com/PwCUK
  • LinkedIn: www.linkedin.com/company/pwc-uk
S&W logo

S&W

S&W is an accountancy and advisory firm with a digital team specialising in cyber security. They combine technical, regulatory and business knowledge across strategy, protection, detection, response and recovery. Their consultants work across networks, applications and cloud environments, while remaining independent of individual technology vendors.

Their assignments range from individual technical reviews to complete security programmes. They assess existing controls, develop cyber strategies, design security architecture and deal with regulatory requirements across different industries. They also work with organisations during transactions, internal change, security incidents and periods of rapid growth, when systems and responsibilities often need closer review.

Key Highlights:

  • Independent cyber security advice
  • Partner-led delivery
  • Technical and regulatory expertise
  • Vendor-agnostic approach
  • Strategy, assurance and recovery capabilities
  • Experience with organisational and system change

Services:

  • Cyber strategy and transformation
  • Security architecture and engineering
  • Cyber governance, risk and compliance
  • Technical assurance
  • Security certification support
  • Identity and access management
  • Incident response
  • Resilience and recovery
  • Network, application and cloud security

Contact Information:

  • Website: www.swgroup.com
  • Phone: +44 117 233 2200
  • Address: 45 Gresham Street, London EC2V 7BG
  • Twitter: x.com/S_W_Group
  • LinkedIn: www.linkedin.com/company/swgroupuk
BDO UK logo

BDO UK

BDO UK is an accountancy and business advisory firm providing audit, tax, deals, consulting, risk and outsourcing services. They mainly work with entrepreneurial and growing organisations, covering businesses at different points in their development. Their advisory teams bring financial, operational and technical work together when clients are dealing with business change or more complex risk requirements.

Cyber security and data protection sit within BDO Digital, alongside their wider consulting and risk capabilities. Their work is informed by the organisation's operating model, regulatory duties and use of technology rather than security being considered in isolation. They also draw on audit, governance and outsourcing expertise where cyber controls affect reporting, accountability or third-party arrangements.

Key Highlights:

  • Accountancy and business advisory firm
  • Cyber security and data protection practice
  • Focus on growing and entrepreneurial organisations
  • Combined digital and risk capabilities
  • Wider audit and governance expertise
  • UK and Ireland office network

Services:

  • Cyber security services
  • Data protection services
  • Digital consulting
  • Risk consulting
  • Governance advisory
  • Audit and assurance
  • Outsourcing
  • Tax and deals services

Contact Information:

  • Website: www.bdo.co.uk
  • Phone: 0161 817 7500
  • Address: Eden Building, Irwell Street, Salford, Manchester, M3 5EN, United Kingdom
  • LinkedIn: www.linkedin.com/company/bdo-llp
  • Instagram: www.instagram.com/bdo_uk
Grant Thornton UK logo

Grant Thornton UK

Grant Thornton UK is an audit, tax and advisory firm working with organisations facing growth, regulation and operational complexity. Their advisory model places senior professionals directly into client work, with technology used to handle routine analysis while advisers focus on judgement, decisions and practical recommendations.

Cyber is one of the firm's core consulting areas, alongside financial services advisory, forensics, government work, restructuring and deals. Their cyber teams work within this broader advisory structure, drawing on knowledge from risk, regulation and business operations. This gives clients access to specialists beyond the immediate security engagement when wider organisational issues need attention.

Key Highlights:

  • Audit, tax and advisory firm
  • Dedicated cyber practice
  • Senior-led advisory work
  • Broad sector experience
  • Integrated risk and business expertise
  • Access to international capabilities

Services:

  • Cyber services
  • Consulting
  • Audit and assurance
  • Forensics and investigations
  • Financial services advisory
  • Government and public sector advisory
  • Deals
  • Restructuring
  • Tax services

Contact Information:

  • Website: www.grantthornton.co.uk
  • Phone: +44 (0)11 7305 7600                                                
  • Address: 2 Glass Wharf, Bristol BS2 0EL                                                
  • LinkedIn: www.linkedin.com/company/grant-thornton-uk
  • Instagram: www.instagram.com/gt_trainees
Fig Group logo

Fig Group

Fig Group is a UK compliance and cybersecurity business providing certification, assessment and governance services. They operate as an IASME-licensed certification body for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification at Levels 0 and 1. Their certification process uses published pricing, defined scopes and direct access to assessors, with a six-working-hour turnaround guarantee for compliant Cyber Essentials submissions.

Alongside certification, they run a governance platform that brings controls, evidence, risk registers, supplier assurance, incidents, policies and reporting into one system. They work with corporate teams, managed service providers and organisations in sectors including accountancy, financial services, education, healthcare and defence. Their platform also connects with external systems and maps evidence across multiple compliance frameworks.

Key Highlights:

  • IASME-licensed certification body
  • Cyber Essentials and Cyber Essentials Plus assessments
  • Defence Cyber Certification at Levels 0 and 1
  • Public pricing and defined assessment scopes
  • Governance platform for compliance, risk and evidence
  • Delivery models for corporate teams and MSPs

Services:

  • Cyber Essentials certification
  • Cyber Essentials Plus technical audits
  • Vulnerability testing
  • Defence Cyber Certification assessments
  • Control and evidence management
  • Supplier assurance and risk tracking
  • Incident and resilience management
  • Compliance reporting

Contact Information:

  • Website: www.figgroup.co.uk
  • Phone: +44 (0) 203 105 2335
  • E-mail: enquiries@figgroup.co.uk
  • Address: 167-169 Great Portland Street, London, W1W 5PF
URM Consulting Services logo

URM Consulting Services

URM Consulting Services is an information security and risk consultancy that is now part of Cooper Parry. They work across cyber security, data protection, business continuity and risk management, combining consultancy with technical testing, auditing, training and their Abriska risk management software. Their consultants include cyber essentials assessors, penetration testers, data protection specialists and ISO implementation and audit practitioners.

They are licensed by IASME to assess organisations for cyber essentials and cyber essentials plus. Their work covers preparation, remediation and formal certification, with technical testing available for networks, infrastructure, web applications, mobile applications and cloud environments. They also carry out internal audits, supplier audits and PCI DSS assessments, while helping organisations manage related standards such as ISO 27001, ISO 22301, SOC 2 and NIST.

Key Highlights:

  • IASME-licensed certification body
  • Cyber essentials and cyber essentials plus assessors
  • CREST-accredited testing provider
  • Information security and risk consultants
  • Integrated governance and technical expertise
  • Abriska risk management software

Services:

  • Cyber essentials certification
  • Cyber essentials plus certification
  • Certification preparation and remediation
  • Penetration testing
  • Information security consultancy
  • ISO 27001 implementation and auditing
  • Data protection consultancy
  • Business continuity planning
  • PCI DSS assessments
  • Internal and supplier audits

Contact Information:

  • Website: www.urmconsulting.com
  • Phone: 0118 206 5410
  • E-mail: info@urmconsulting.com
  • Address: Davidson House 1st Floor, The Forbury, Reading RG1 3EU
  • Facebook: www.facebook.com/URMConsulting
  • Twitter: x.com/URMconsulting
  • LinkedIn: www.linkedin.com/company/urm-consulting
  • Instagram: www.instagram.com/urmconsulting
ITWiser logo

ITWiser

ITWiser is a Yorkshire-based managed IT provider working with small businesses and larger organisations. They operate as a managed service provider, value-added reseller and IT solutions provider, looking after servers, networks and everyday technology requirements. Their delivery model is largely proactive, with remote monitoring used to identify technical problems before they disrupt normal work.

They also maintain in-house expertise across IT and network security and operate as a cyber essentials certification body. Their advice is not tied to individual vendors or sales targets, so they assess the wider market when recommending systems and security measures. Their managed services are adjusted around the size, infrastructure and practical needs of each client.

Key Highlights:

  • Yorkshire-based IT provider
  • Cyber essentials certification body
  • In-house IT security expertise
  • Proactive monitoring and maintenance
  • Vendor-independent advice
  • Services for organisations of different sizes

Services:

  • Cyber essentials certification
  • Managed IT services
  • Network management
  • IT security
  • Remote monitoring
  • Server maintenance
  • Infrastructure support
  • IT consultancy
  • Network advice
  • Technology procurement

Contact Information:

  • Website: itwiser.co.uk
  • Phone: 01274 924686
  • E-mail: info@itwiser.co.uk
  • Address: 34 Bradford Chamber, Business Park, New Lane, Bradford BD4 8BX
ITPS logo

ITPS

ITPS is a UK technology company delivering managed services, cyber security, cloud infrastructure, communications and data services. They work with public, private and not-for-profit organisations, handling both ongoing IT operations and complex technology projects. Their teams design and manage systems that give authorised users access to business data while maintaining security, availability and continuity.

Their cyber security practice includes cyber essentials services alongside wider protection, resilience and recovery work. They also provide cloud, network and data centre services, giving their security teams direct visibility of the infrastructure being assessed. Their work spans sectors such as healthcare, education, charities, housing, manufacturing, legal services and financial services.

Key Highlights:

  • UK technology and managed services provider
  • Dedicated cyber security practice
  • Experience across public and private sectors
  • Cloud and infrastructure expertise
  • ISO 9001, ISO 20000-1 and ISO 27001 certified
  • Security and operational services delivered together

Services:

  • Cyber essentials services
  • Cyber security
  • Managed IT services
  • Cloud services
  • Data centre services
  • Network services
  • Business continuity
  • Disaster recovery
  • Data and analytics
  • Communications solutions

Contact Information:

  • Website: www.itps.co.uk
  • Phone: 0191 442 8300
  • E-mail: enquiries@itps.co.uk
  • Address: Unit 5, Angel Park, Drum Industrial Estate, Chester-le-Street, County Durham, DH2 1AQ
  • LinkedIn: www.linkedin.com/company/itps

Conclusion

Choosing a Cyber Essentials provider depends on how much work needs to happen before the assessment. Some organisations are already close to meeting the required controls and mainly need certification. Others need a deeper review of systems, access, policies, staff practices and technical weaknesses before they are ready to proceed.

For growing companies, corporate groups and regulated entities, preparing for Cyber Essentials is not simply about configuring antivirus software. It often sits within a wider review of cyber risk, financial compliance, internal controls and corporate security. This guide helps organisations compare different providers by looking at how they work, what they assess and how much practical support they offer throughout the process.

Get in Touch

Ready for Accountants Who Move Your Business Forward?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch