Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to improve your cyber maturity

Most organisations that get hit by a serious cyber attack weren’t careless: Ransomware, supply chain attacks and identity-based breaches aren’t hypothetical risks anymore. They happen to businesses and public sector organisations of every size, across every sector. And the ones that come through them best aren’t necessarily those with the biggest security budgets.

How to assess your cyber maturity

Most organisations have more cybersecurity tools than they realise. However, having those things isn’t the same as being secure. At some point, someone, like a Board member, insurer or regulator, is going to ask you to demonstrate that your security works. Not just that you have policies in place, but you can detect an attack, respond to it and recover from it. When that moment comes, you’ll want to know the answer. That’s what a cyber maturity assessment is designed to find.

What does Cyber Essentials cover?

Cyber attacks cost UK businesses an estimated £14.7bn every year. The average cost of a significant breach for an individual business sits at almost £195,000. Half of all small businesses have experienced at least one attack in the past 12 months. For medium and large organisations, that figure rises to 82%. Those numbers should focus the mind.

How to pass Cyber Essentials Plus - Danzell v3.3 Standard

KEEP helps organisations large and small to achieve both Cyber Essentials (CE) and Cyber Essentials Plus (CE+), alongside some of the more stringent standards such as SOC2, though for this insight we will focus on how to ‘pass’ CE+. As you may be aware IASME introduced the Danzell v3.3 standard in mid 2026, which included a number of critical changes that aimed to set the bar ‘higher’ for an organisation who applied for a CE+ assessment.

What does a virtual CISO (vCISO) actually do?

A virtual CISO is your on-demand cybersecurity resource. We provide the same strategic leadership as an in-house CISO, without the full-time commitment. vCISOs are used by organisations that need experienced security leadership to meet their compliance requirements, manage cyber risk, and guide security decisions, but don’t yet have a permanent CISO, or may have an interim requirement for a vCISO.

NIS2 vs SOC2 - Core Differences

The NIS2 Directive is the EU-wide legislation on cybersecurity that came into force in 2023, following rules introduced in 2016 (NIS). NIS2 expanded the scope of sectors and entities who need to (legally) comply with the framework. The increased scope aimed to cover the “most” critical sectors, which are vital for the economy and society, though are heavily reliant on IT.

Cyber Security vs Blind Faith

As we KEEP do more and more work around the world for corporations, government departments and CNI providers we’re seeing a recurring and worrying trend; Blind Faith. Whilst some of this may be cultural, it can no longer be used as justifiable reasoning for the failure to secure core assets, understand the possible threats or at least implement basic protections. Why?

Cyber Security - Some Simple Facts

The simple fact(s) in cyber and information security is that there is NO right and wrong way to go about things. Yes there are frameworks / standards and guidance, which are good practices. BUT the right way for YOUR organisation may be totally different to that of another organisation. Yes you may have the same goal of strong security, but what does that ultimately mean?