1import{r as c,y as G,R as he,p as N,j as e,o as q,s as Y,a6 as pe,w as z,q as K,a7 as me,g as E,a8 as ye,L as r}from"./index-rkFokeON.js";var fe=he[" useId ".trim().toString()]||(()=>{}),we=0;function V(t){const[a,s]=c.useState(fe());return G(()=>{s(n=>n??String(we++))},[t]),t||(a?`radix-${a}`:"")}var O="Collapsible",[ge,B]=z(O),[be,R]=ge(O),L=c.forwardRef((t,a)=>{const{__scopeCollapsible:s,open:n,defaultOpen:o,disabled:i,onOpenChange:l,...u}=t,[h,p]=N({prop:n,defaultProp:o??!1,onChange:l,caller:O});return e.jsx(be,{scope:s,disabled:i,contentId:V(),open:h,onOpenToggle:c.useCallback(()=>p(m=>!m),[p]),children:e.jsx(q.div,{"data-state":F(h),"data-disabled":i?"":void 0,...u,ref:a})})});L.displayName=O;var $="CollapsibleTrigger",Q=c.forwardRef((t,a)=>{const{__scopeCollapsible:s,...n}=t,o=R($,s);return e.jsx(q.button,{type:"button","aria-controls":o.open?o.contentId:void 0,"aria-expanded":o.open||!1,"data-state":F(o.open),"data-disabled":o.disabled?"":void 0,disabled:o.disabled,...n,ref:a,onClick:Y(t.onClick,o.onOpenToggle)})});Q.displayName=$;var H="CollapsibleContent",J=c.forwardRef((t,a)=>{const{forceMount:s,...n}=t,o=R(H,t.__scopeCollapsible);return e.jsx(pe,{present:s||o.open,children:({present:i})=>e.jsx(ve,{...n,ref:a,present:i})})});J.displayName=H;var ve=c.forwardRef((t,a)=>{const{__scopeCollapsible:s,present:n,children:o,...i}=t,l=R(H,s),[u,h]=c.useState(n),p=c.useRef(null),m=K(a,p),y=c.useRef(0),k=y.current,w=c.useRef(0),x=w.current,g=l.open||u,b=c.useRef(g),v=c.useRef(void 0);return c.useEffect(()=>{const d=requestAnimationFrame(()=>b.current=!1);return()=>cancelAnimationFrame(d)},[]),G(()=>{const d=p.current;if(d){v.current=v.current||{transitionDuration:d.style.transitionDuration,animationName:d.style.animationName},d.style.transitionDuration="0s",d.style.animationName="none";const I=d.getBoundingClientRect();y.current=I.height,w.current=I.width,b.current||(d.style.transitionDuration=v.current.transitionDuration,d.style.animationName=v.current.animationName),h(n)}},[l.open,n]),e.jsx(q.div,{"data-state":F(l.open),"data-disabled":l.disabled?"":void 0,id:l.contentId,hidden:!g,...i,ref:m,style:{"--radix-collapsible-content-height":k?`${k}px`:void 0,"--radix-collapsible-content-width":x?`${x}px`:void 0,...t.style},children:g&&o})});function F(t){return t?"open":"closed"}var ke=L,Ie=Q,qe=J,xe=c.createContext(void 0);function Se(t){const a=c.useContext(xe);return t||a||"ltr"}var f="Accordion",Oe=["Home","End","ArrowDown","ArrowUp","ArrowLeft","ArrowRight"],[M,Ae,Ce]=me(f),[A]=z(f,[Ce,B]),U=B(),X=c.forwardRef((t,a)=>{const{type:s,...n}=t,o=n,i=n;return e.jsx(M.Provider,{scope:t.__scopeAccordion,children:s==="multiple"?e.jsx(Pe,{...i,ref:a}):e.jsx(De,{...o,ref:a})})});X.displayName=f;var[Z,je]=A(f),[ee,Te]=A(f,{collapsible:!1}),De=c.forwardRef((t,a)=>{const{value:s,defaultValue:n,onValueChange:o=()=>{},collapsible:i=!1,...l}=t,[u,h]=N({prop:s,defaultProp:n??"",onChange:o,caller:f});return e.jsx(Z,{scope:t.__scopeAccordion,value:c.useMemo(()=>u?[u]:[],[u]),onItemOpen:h,onItemClose:c.useCallback(()=>i&&h(""),[i,h]),children:e.jsx(ee,{scope:t.__scopeAccordion,collapsible:i,children:e.jsx(te,{...l,ref:a})})})}),Pe=c.forwardRef((t,a)=>{const{value:s,defaultValue:n,onValueChange:o=()=>{},...i}=t,[l,u]=N({prop:s,defaultProp:n??[],onChange:o,caller:f}),h=c.useCallback(m=>u((y=[])=>[...y,m]),[u]),p=c.useCallback(m=>u((y=[])=>y.filter(k=>k!==m)),[u]);return e.jsx(Z,{scope:t.__scopeAccordion,value:l,onItemOpen:h,onItemClose:p,children:e.jsx(ee,{scope:t.__scopeAccordion,collapsible:!0,children:e.jsx(te,{...i,ref:a})})})}),[We,C]=A(f),te=c.forwardRef((t,a)=>{const{__scopeAccordion:s,disabled:n,dir:o,orientation:i="vertical",...l}=t,u=c.useRef(null),h=K(u,a),p=Ae(s),y=Se(o)==="ltr",k=Y(t.onKeyDown,w=>{if(!Oe.includes(w.key))return;const x=w.target,g=p().filter(P=>!P.ref.current?.disabled),b=g.findIndex(P=>P.ref.current===x),v=g.length;if(b===-1)return;w.preventDefault();let d=b;const I=0,j=v-1,T=()=>{d=b+1,d>j&&(d=I)},D=()=>{d=b-1,d<I&&(d=j)};switch(w.key){case"Home":d=I;break;case"End":d=j;break;case"ArrowRight":i==="horizontal"&&(y?T():D());break;case"ArrowDown":i==="vertical"&&T();break;case"ArrowLeft":i==="horizontal"&&(y?D():T());break;case"ArrowUp":i==="vertical"&&D();break}const ue=d%v;g[ue].ref.current?.focus()});return e.jsx(We,{scope:s,disabled:n,direction:o,orientation:i,children:e.jsx(M.Slot,{scope:s,children:e.jsx(q.div,{...l,"data-orientation":i,ref:h,onKeyDown:n?void 0:k})})})}),S="AccordionItem",[Ne,_]=A(S),se=c.forwardRef((t,a)=>{const{__scopeAccordion:s,value:n,...o}=t,i=C(S,s),l=je(S,s),u=U(s),h=V(),p=n&&l.value.includes(n)||!1,m=i.disabled||t.disabled;return e.jsx(Ne,{scope:s,open:p,disabled:m,triggerId:h,children:e.jsx(ke,{"data-orientation":i.orientation,"data-state":ce(p),...u,...o,ref:a,disabled:m,open:p,onOpenChange:y=>{y?l.onItemOpen(n):l.onItemClose(n)}})})});
1se.displayName=S;var ae="AccordionHeader",ne=c.forwardRef((t,a)=>{const{__scopeAccordion:s,...n}=t,o=C(f,s),i=_(ae,s);return e.jsx(q.h3,{"data-orientation":o.orientation,"data-state":ce(i.open),"data-disabled":i.disabled?"":void 0,...n,ref:a})});ne.displayName=ae;var W="AccordionTrigger",oe=c.forwardRef((t,a)=>{const{__scopeAccordion:s,...n}=t,o=C(f,s),i=_(W,s),l=Te(W,s),u=U(s);return e.jsx(M.ItemSlot,{scope:s,children:e.jsx(Ie,{"aria-disabled":i.open&&!l.collapsible||void 0,"data-orientation":o.orientation,id:i.triggerId,...u,...n,ref:a})})});oe.displayName=W;var ie="AccordionContent",re=c.forwardRef((t,a)=>{const{__scopeAccordion:s,...n}=t,o=C(f,s),i=_(ie,s),l=U(s);return e.jsx(qe,{role:"region","aria-labelledby":i.triggerId,"data-orientation":o.orientation,...l,...n,ref:a,style:{"--radix-accordion-content-height":"var(--radix-collapsible-content-height)","--radix-accordion-content-width":"var(--radix-collapsible-content-width)",...t.style}})});re.displayName=ie;function ce(t){return t?"open":"closed"}var Ee=X,Re=se,He=ne,le=oe,de=re;const Ke=Ee,Fe=c.forwardRef(({className:t,...a},s)=>e.jsx(Re,{ref:s,className:E("border-b",t),...a}));Fe.displayName="AccordionItem";const Me=c.forwardRef(({className:t,children:a,headingLevel:s=3,...n},o)=>{const i=`h${s}`;return e.jsx(He,{asChild:!0,className:"flex",children:e.jsx(i,{className:"flex",children:e.jsxs(le,{ref:o,className:E("flex flex-1 items-center justify-between py-4 text-sm font-medium transition-all hover:underline text-left [&[data-state=open]>svg]:rotate-180",t),...n,children:[a,e.jsx(ye,{className:"h-4 w-4 shrink-0 text-muted-foreground transition-transform duration-200"})]})})})});Me.displayName=le.displayName;const Ue=()=>()=>{};function _e(){return c.useSyncExternalStore(Ue,()=>!0,()=>!1)}const Ge=c.forwardRef(({className:t,children:a,...s},n)=>{const o=_e();return e.jsxs(e.Fragment,{children:[e.jsx(de,{ref:n,className:"overflow-hidden text-sm data-[state=closed]:animate-accordion-up data-[state=open]:animate-accordion-down",...s,children:e.jsx("div",{className:E("pb-4 pt-0",t),children:a})}),!o&&e.jsx("div",{hidden:!0,children:a})]})});Ge.displayName=de.displayName;const Ve=[{question:'How do I know if my business is "secure enough"?',answer:e.jsxs(e.Fragment,{children:[e.jsx("p",{children:`There's no such thing as perfect security. "Secure enough" means having controls that are proportionate to your size, industry, and risk. At a minimum, that usually includes MFA everywhere, managed and encrypted devices, prompt patching, tested backups, and someone actively paying attention to alerts.`}),e.jsx("p",{children:"If you're being asked questions you can't confidently answer, it's usually time for an independent sense-check."})]})},{question:"What causes most security incidents in small businesses?",answer:"Most incidents aren't sophisticated attacks. They're caused by basics being missed: phishing emails, missing MFA, unpatched systems, or poor backups. Getting the fundamentals right removes the majority of risk."},{question:"Do we need a dedicated security person?",answer:"Not usually. Many businesses with 2â250 users manage security with IT handling day-to-day tasks and external support for strategy, assessments, or incidents. A fractional or virtual CISO often makes more sense than a full-time hire."},{question:"What security tools do we actually need?",answer:"For most small businesses: device management, endpoint protection, email security, MFA, and reliable backups. More tools aren't better; properly configured tools, with someone paying attention, are what matter."},{question:"How often should we review our security?",answer:"At least annually, with some areas reviewed more often. Patching should be continuous, access reviewed quarterly, and security tools checked regularly. Any major business change should also trigger a review."},{question:"What should we do if we think we've had a breach?",answer:"Act calmly but quickly. Contain the issue if possible, preserve evidence, notify your cyber insurer early, and assess any legal reporting obligations. If you're unsure, get expert help."},{question:"Does GDPR apply to us?",answer:"If you process personal data of people in the UK or EU (customers, employees, or website visitors), then yes. Size doesn't remove the obligation, but expectations are proportionate to your scale and risk."},{question:"Do we need a Data Protection Officer?",answer:"Only in specific circumstances. Most small businesses don't legally need one, but having clear ownership of data protection responsibilities is good practice."},{question:"What happens if we have a data breach?",answer:"You must assess the risk to individuals. If there's a risk, the ICO must be notified within 72 hours. High-risk breaches also require notifying affected
1individuals. Everything should be documented, even if you decide not to report."},{question:"How long can we keep personal data?",answer:"Only for as long as you need it for the original purpose. Clear retention periods reduce risk and simplify compliance."},{question:"What is ISO 27001?",answer:e.jsxs("p",{children:["ISO 27001 is an international standard for managing information security risks through a structured management system. Certification means an independent auditor has verified that the system meets the standard. Our"," ",e.jsx(r,{href:"/insights/guide-to-iso-27001",className:"underline hover:no-underline",children:"ISO 27001 guide for small businesses"})," ","covers what that involves in practice."]})},{question:"Do we need ISO 27001 certification?",answer:"It depends. If customers, regulators, or investors are asking for it, certification can remove friction. If no one is asking, formal certification may not be necessary yet, but the framework is still useful."},{question:"How long does ISO 27001 take?",answer:"Typically 3â9 months for a small business, depending on your starting point and available resources. Rushing often creates problems later."},{question:"Can we do ISO 27001 ourselves?",answer:"Some can. Most bring in help because nobody in-house has the time, or has been through an audit before."},{question:"How do we handle customer security questionnaires?",answer:"Create a standard set of approved responses covering your controls, policies, and processes. Most questionnaires ask similar questions, just worded differently."},{question:"What do cyber insurers care about?",answer:"The basics: MFA, endpoint protection, patching, tested backups, and staff training. If you can't demonstrate these, expect higher premiums or limited cover."},{question:"A customer wants a SOC 2 report and we don't have one. What should we do?",answer:"Be transparent. Explain what you can provide instead and ask what they're actually trying to assess. If multiple customers are asking, it may be worth investing. If it's a one-off, negotiation is often possible."},{question:"Where should we start with security?",answer:"Start with visibility: what devices, systems, and data you have. Then focus on the basics. Don't try to do everything at once, prioritise by risk."},{question:"How do we know if we need external help?",answer:`If security questions are slowing sales, you've had a near miss, you're preparing for certification, or you're unsure whether you're "secure enough", external support usually pays for itself.`},{question:"Our IT provider handles security. Isn't that covered?",answer:e.jsxs(e.Fragment,{children:[e.jsx("p",{children:"Partly, and the part they cover matters. A good IT provider or managed service provider runs the tooling: patching, backups, endpoint protection, and access changes. That is real security work, and if they do it well you are further ahead than most."}),e.jsxs("p",{children:["What sits outside that arrangement is ownership. Deciding which risks the business accepts, answering a customer's security questionnaire, holding scope in an audit, and independently checking that the controls your provider runs are working are all things a provider cannot sign off on their own work for. That gap is what"," ",e.jsx(r,{href:"/services/cyber-security/fractional-ciso-services",className:"text-brand-red-dark",children:"a fractional CISO"})," ","fills, and we work alongside your existing provider rather than replacing them."]})]})}],Be=[{question:"Which of these do we actually need?",answer:e.jsx("p",{children:"Usually fewer than you'd think, and rarely all at once. We start from where you are and what's being asked of you, then point you to the area that fits. For most businesses that's cyber security first, with privacy and compliance added only when the need is real."})},{question:"Do we have to do all three?",answer:e.jsx("p",{children:"No. Cyber security, privacy, and compliance overlap, but most businesses only need one of them in focus at a time. We'll tell you which matters now, what can wait, and what you don't need at all."})},{question:"We're a small team with no security staff. Is that a problem?",answer:e.jsxs("p",{children:[" ","Not at all. We work specifically with small businesses where IT handles security alongside everything else. You work with an experienced practitioner throughout, not an account manager."," "]})},{question:"How much does it cost?",answer:e.jsxs("p",{children:["It depends on your size and what's involved. The"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","gives an indicative estimate, and a short discovery call will tell you what's needed."]})}],Le=[{question:"How do you decide how much security is enough?",answer:e.jsx("p",{children:"We start from your size, your sector, and what you need to protect, then match the controls to the real risk. The basics remove most of it. Bey
1ond a certain point, more security stops reducing meaningful risk, and we'll tell you when you've reached it."})},{question:"Where should we start?",answer:e.jsx("p",{children:"For almost everyone, Security Foundations: a baseline you can keep running with the team you have. Cyber Essentials proves it when a tender or insurer asks, and a fractional CISO adds senior leadership once you're past the basics."})},{question:"Do we need all three services?",answer:e.jsx("p",{children:"No. Most businesses only need one at a time, in the right order. We'll point you to the step that fits where you are, and if you don't need us yet, we'll say so."})},{question:"Nobody here does security full-time. Does that matter?",answer:e.jsxs("p",{children:[" ","No. Most of the businesses we work with have IT handling security alongside everything else, and the fixes at this level are configuration and habit rather than headcount. You work with an experienced practitioner throughout, not an account manager."," "]})},{question:"How much does it cost?",answer:e.jsxs("p",{children:[" ","Cyber Essentials support runs from £1,700 to £6,600 depending on how managed your devices are, on top of the IASME assessment fee. A fractional CISO is £2,000 to £8,700 a month depending on complexity, with a one-off onboarding fee. Security Foundations is a fixed fee for the assessment and implementation, then a monthly fee; the"," ",e.jsxs(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:[" ","pricing calculator"," "]})," ","gives a figure for your profile."," "]})}],$e=[{question:"What's the first thing you'd look at?",answer:e.jsx("p",{children:"Your data. Before anything else, we map what personal information you hold, where it lives, and why you have it. Almost every other decision, from policies and controls to whether you need a DPO, falls out of that picture."})},{question:"How do we know what privacy work we genuinely need?",answer:e.jsx("p",{children:"Privacy rules get interpreted at wildly different levels of rigour. We weigh the data you hold against your size and the scrutiny you're actually under, then aim for the level that's appropriate, rather than the heaviest one a consultant could sell you."})},{question:"Do we need a DPO or a certification?",answer:e.jsx("p",{children:"Not always. Plenty of businesses are well covered once the GDPR groundwork is solid. We'll tell you whether a DPO is required for your situation, and whether formal certification earns its cost or just adds paperwork."})},{question:"Nobody here is a privacy expert. Can you still help?",answer:e.jsx("p",{children:"That's the norm for the businesses we work with. We come at privacy from a security background, so the focus stays on how data really moves through your business. You deal with one experienced practitioner throughout, and where a question is genuinely legal, we bring in privacy specialists."})},{question:"How much does it cost?",answer:e.jsxs("p",{children:["It depends on your size and the data involved: onboarding for GDPR is a fixed fee scoped after a discovery call, the DPO service is a monthly fee on a 12-month term, and the"," ",e.jsxs(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:[" ","pricing calculator"," "]})," ","gives an indicative figure for both."]})}],Qe=[{question:"How do we know which certification we actually need?",answer:e.jsx("p",{children:"Start with the question being asked of you. A tender usually means ISO 27001, US buyers tend to ask for SOC 2, and AI governance points to ISO 42001. We work out exactly what satisfies the demand before committing you to a framework."})},{question:"Do we need formal certification at all?",answer:e.jsx("p",{children:"Not always. Sometimes good security practice and a clear evidence base is enough to satisfy the people asking. We'll tell you whether you're in that situation, or whether a formal certificate is the right move."})},{question:"How long does it take?",answer:e.jsx("p",{children:"It depends on the framework and where you're starting from, but we keep the work focused and the timelines realistic so progress doesn't stall against everything else the team has to do. We'll give you a clear view early on."})},{question:"What happens after we're certified?",answer:e.jsx("p",{children:"Certification isn't a one-off. The frameworks need ongoing evidence and periodic audits to stay valid, and keeping that current is where most businesses come unstuck. We maintain your documentation and evidence between reviews, keep you ready for the next audit, and flag anything that needs attention, so staying certified doesn't slide to the bottom of the list."})},{question:"We're a small team with limited time. Can we manage this?",answer:e.jsx("p",{children:"Yes. Compliance in an SME competes with everything else, so we shape the controls and documentation around how y
1our team already works. You work with consultants who've been on both sides of the audit, which means fewer surprises."})},{question:"How much does it cost?",answer:e.jsxs("p",{children:["ISO 27001 implementation runs from £12,000 to £46,000 depending on complexity, ISO 42001 from £9,000 to £36,000, and SOC 2 a little below ISO 27001; certification body and CPA fees are separate. The"," ",e.jsxs(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:[" ","pricing calculator"," "]})," ","gives a figure for your profile."]})}],Je=[{question:"What is a Security Foundations assessment?",answer:e.jsxs("p",{children:["A practical review of your security against what matters for your size and risk, followed by help fixing the gaps that count. You get a clear picture of where you stand, the quick wins done, and a proportionate baseline you can maintain, rather than a long report that sits on a shelf. Our"," ",e.jsx(r,{href:"/insights/security-foundations-checklist",className:"underline hover:no-underline",children:"security foundations checklist"})," ","shows what that baseline covers."]})},{question:"How long does it take?",answer:"The assessment and quick wins typically take 2 to 4 weeks, with deeper implementation over the following 2 to 3 months. Ongoing monitoring and support then runs on a 12-month minimum."},{question:"Is this the same as Cyber Essentials?",answer:e.jsxs("p",{children:["No. Security Foundations is about getting the right controls genuinely in place; Cyber Essentials is a formal certificate you can show customers and insurers. Foundations is the usual first step, and it sets you up to pass"," ",e.jsx(r,{href:"/services/cyber-security/cyber-essentials",className:"underline hover:no-underline",children:"Cyber Essentials"})," ","if and when you need it."]})},{question:"How much does it cost?",answer:e.jsxs("p",{children:["The assessment and implementation phases are fixed fees and ongoing support is a monthly fee. The exact figures depend on your size and what the assessment finds. The"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","gives an indicative estimate."]})}],Xe=[{question:"What's the difference between Cyber Essentials and Cyber Essentials Plus?",answer:"Cyber Essentials is a self-assessment verified by a certification body; Cyber Essentials Plus adds a hands-on technical audit that confirms the controls really are in place. Plus is stronger evidence, and some customers or contracts specifically ask for it. We scope you for whichever you actually need."},{question:"How long does Cyber Essentials take?",answer:"Certification typically takes 4 to 8 weeks depending on your starting point, with a further 2 to 4 weeks if you need the Plus audit. We then keep you ready for recertification on a 12-month cycle."},{question:"Is the certification fee included?",answer:e.jsxs("p",{children:["No. The assessment fees paid to the certification body (IASME, and any Plus audit) go directly to them and aren't included in our fee. The"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","covers our side of the work."]})},{question:"What changed in the 2026 update?",answer:e.jsxs("p",{children:["The scheme has tightened its requirements, including stricter rules on multi-factor authentication, a 14-day window for applying critical and high-risk security patches, and clearer treatment of cloud services and personal devices. We make sure you meet the current version before you submit, so an avoidable gap doesn't cause a fail. Our"," ",e.jsx(r,{href:"/insights/cyber-essentials-plus",className:"underline hover:no-underline",children:"Cyber Essentials Plus guide"})," ","covers the 2026 changes in more detail."]})}],Ze=[{question:"What does a fractional CISO actually do?",answer:"A fractional, or virtual, CISO provides senior security leadership part-time: setting the strategy, building and owning the risk register and roadmap, and reporting to the board. It's governance and direction rather than hands-on engineering, so you get the judgement of an experienced security leader without a full-time hire."},{question:"How is this different from hiring a full-time CISO?",answer:"You get the same seniority and accountability for a fraction of the cost and commitment. Most growing businesses don't yet have enough work to justify a full-time CISO, but still need someone senior to own security decisions. A fractional CISO fills that gap, and can scale up or step back as your needs change."},{question:"How much of their time do we get?",answer:"It's part-time and priced to an agreed scope, with a monthly check-in and the engagement reviewed each quarter. The minimum term is 6 months, which is enough to set direction and show progress, renewable quarterly after that."},{question:"Do you handle day-to-day security operations?",answer:"No. The role is leadership and governance, not operations. We don't run your tooling, write every procedure, or provide hands-on incident response or 24/7 cover. Where that work is needed, we help you put the right people or services in place."}],et=[{question:"What does the GDPR service deliver?",answer:e.jsxs("p",{children:["Onboarding delivers a defined set of documentation and evidence: your record of processing, a lawful basis review, privacy notices, a data protection policy and retention schedule, and procedures for data subject requests and breaches, along with supplier controls, a DPIA process, and staff training. The run service then keeps that set current and supports your team as requests and questions arrive. The aim is that you can show compliance to anyone who asks. For what UK GDPR actually asks of you, see"," ",e.jsx(r,{href:"/insights/gdpr-for-small-businesses",className:"underline hover:no-underline",children:"GDPR for small businesses"}),"."]})},{question:"How long does it take?",answer:"It starts with a discovery call to scope and map your data, then the documentation is typically built over 4 to 8 weeks. The run service carries on from there, keeping everything current month to month."},{question:"Is this a one-off project or ongoing?",answer:e.jsxs("p",{children:["Both, deliberately: a fixed-fee onboarding project puts the foundations in place, then a monthly run service keeps them current and supports your team through requests, breaches, and questions. Your team stays the owner throughout. If you'd rather hand privacy over entirely, or you're required to appoint a Data Protection Officer, the"," ",e.jsx(r,{href:"/services/privacy/data-protection-officer",className:"underline hover:no-underline",children:"DPO service"}
1)," ","is structured for that, and the same person can continue so your context carries over."]})},{question:"Do we also need a DPO?",answer:"Not always. A formal DPO is only legally required in specific cases, mainly large-scale monitoring or large-scale handling of sensitive data. Many businesses are well covered by this service alone, with the run service keeping them supported without a formal appointment, and we'll tell you whether a DPO is required for your situation."}],tt=[{question:"Do we legally need a Data Protection Officer?",answer:"Only in specific cases, mainly where your core activities involve large-scale monitoring of people or large-scale handling of sensitive data. Plenty of businesses appoint one anyway, simply because they'd rather privacy was owned by someone qualified and independent. We'll tell you which situation you're in."},{question:"Can a DPO be outsourced?",answer:"Yes. The law lets you appoint an external DPO, and for most small businesses that's the sensible option. You get a named, qualified, independent person who fills the role properly, without the cost of a senior full-time hire."},{question:"What does the DPO actually handle?",answer:e.jsxs("p",{children:["Day-to-day privacy: advice and compliance monitoring,"," ",e.jsx(r,{href:"/insights/subject-access-requests",className:"underline hover:no-underline",children:"data subject requests"}),", breach management, your record of processing, privacy notices and DPIAs, supplier oversight, staff training, and acting as your point of contact with the ICO. They report to your leadership and stay independent, as the law requires."]})},{question:"How is this different from the GDPR service?",answer:e.jsxs("p",{children:["The"," ",e.jsx(r,{href:"/services/privacy/gdpr",className:"underline hover:no-underline",children:"GDPR service"})," ","puts your documentation in place and keeps it current, but your team stays the owner: it runs requests and fronts the ICO, with our support behind it. The DPO service moves that ownership to us: a named, independent DPO operates privacy for you, manages requests and breaches to the legal deadline, and acts as your contact with the regulator."]})}],st=[{question:"What is ISO 27701?",answer:"ISO 27701 is the international standard for a Privacy Information Management System (PIMS). It turns the privacy obligations you already have into a governed, certifiable system, so you can show customers and auditors how privacy is managed, with the records behind it. Since the 2025 edition it is a standalone standard: you can certify it on its own or integrated with ISO 27001."},{question:"Do we need ISO 27001 first?",answer:e.jsxs("p",{children:["Not any more. The 2025 edition made ISO 27701 a standalone standard, with the information security controls a privacy management system needs built in, so you can certify without holding"," ",e.jsx(r,{href:"/services/compliance/iso-27001-information-security-management",className:"underline hover:no-underline",children:"ISO 27001"}),". The two still share most of their machinery, though: if you already hold ISO 27001 we extend it to privacy, and if you want both, we scope and run them together as a single, combined programme - usually the most efficient route."]})},{question:"How long does it take?",answer:"Implementation typically runs 3 to 6 months, followed by the external certification audit, then maintenance on a 12-month minimum. If we're doing it alongside ISO 27001, the combined timeline is scoped together."},{question:"How is ISO 27701 different from GDPR compliance?",answer:"GDPR is the law you have to meet; ISO 27701 is a certifiable management system that helps you meet it and prove it. The certificate gives customers independent assurance that your privacy practices are run properly, which GDPR compliance work on its own doesn't provide."}],at=[{question:"How long does ISO 27001 certification take?",answer:e.jsxs("p",{children:["Implementation typically takes 3 to 6 months, followed by the external certification audit. After that, maintenance runs on a 12-month minimum, covering the surveillance audits that keep the certificate valid. Our"," ",e.jsx(r,{href:"/insights/guide-to-iso-27001",className:"underline hover:no-underline",children:"ISO 27001 guide for small businesses"})," ","explains what drives the timeline."]})},{question:"How much does ISO 27001 cost?",answer:e.jsxs("p",{children:["Implementation is a fixed fee and maintenance is a recurring fee. The certification body's own audit fees are separate and paid directly to them. Exact figures depend on the complexity of your organisation and your starting point; the"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","gives an indicative estimate."]})}
1,{question:"Why are some ISO 27001 quotes so much cheaper?",answer:"Usually because they're a different product. Toolkit and template engagements hand you the documents and coach you through completing them - your team still does the real work, and the result still has to survive an auditor who has seen the same templates many times. Our fee is for building the management system with you and standing behind it at the audit. If a templated route fits how you work, we'll say so."},{question:"What happens after we're certified?",answer:"Certification isn't a one-off. The certificate is maintained through annual surveillance audits and a recertification audit every three years, which means keeping your evidence, risks, and policies current. We maintain that for you between reviews, so staying certified doesn't become a scramble before each audit."},{question:"What does the maintenance fee actually cover?",answer:"Running the ISMS, not a help desk. We plan and deliver the internal audits, prepare and attend management reviews, keep the risk assessment and evidence current, front the annual surveillance audit, and handle the security questionnaires that arrive in between. Cheaper ISO 27001 maintenance retainers typically buy advice on request and an annual document review - the scope is different, which is what the fee reflects."},{question:"Do we need ISO 27001, or is a security baseline enough?",answer:e.jsxs("p",{children:["It depends on what's being asked of you. If a customer or investor specifically wants certification, ISO 27001 answers it. If they just want to know you take security seriously, a strong baseline like"," ",e.jsx(r,{href:"/services/cyber-security/security-foundations",className:"underline hover:no-underline",children:"Security Foundations"})," ","may be enough. We'll tell you which one your situation actually calls for."]})},{question:"Does ISO 27001 cover our use of AI?",answer:e.jsxs("p",{children:["Partly. ISO 27001 governs information security across the business, including the data that flows into AI tools, but it doesn't cover AI-specific risks like model behaviour or automated decision-making. Our"," ",e.jsx(r,{href:"/services/ai-governance",className:"underline hover:no-underline",children:"AI Governance & Security"})," ","service adds those controls, and steps up to ISO 42001 using the same management-system structure you already run."]})},{question:"Do we need a consultant if we're buying Vanta or Drata?",answer:e.jsxs("p",{children:["The platforms are good at collecting evidence and monitoring controls, and we often pair our consultants with Drata. What they don't do is scope the system, make your risk decisions, or sit with you in the audit, so the question is whether someone in-house can own that judgment. Our"," ",e.jsx(r,{href:"/insights/compliance-platform-vs-consultant",className:"text-brand-red-dark",children:"guide to platforms versus consultants"})," ","covers how to decide."]})}],nt=[{question:"What is AI governance?",answer:"AI governance is the set of policies, risk assessments, and controls that keep a business's use of AI safe, lawful, and accountable. In practice it means knowing what AI is in use across the business, having clear rules for how staff use it, understanding the risks it carries, and being able to show customers and regulators how it's all controlled."},{question:"Does the EU AI Act apply to UK companies?",answer:"Often, yes. The EU AI Act applies to companies that place AI systems on the EU market or whose AI outputs are used in the EU, wherever the company is based. If you sell AI-enabled products or services into the EU, parts of the Act will apply to you, with obligations phasing in over several years. If you only use AI tools internally in the UK it generally won't apply, but UK data protection law still does."},{question:"Do we need an AI policy?",answer:"If your team uses AI tools at all, yes, and it doesn't need to be long. A good AI policy names the tools you've approved, says what data can and can't go into them, and tells people who to ask when something new comes up. One page that staff follow beats a long document nobody reads. If your AI use is minimal and no personal data is involved, a short policy you write yourselves may be all the governance you need."},{question:"What is ISO 42001?",answer:e.jsxs("p",{children:["ISO 42001 is the international standard for AI management systems: a certifiable framework that shows your AI is governed responsibly. It follows the same management-system structure as ISO 27001, so if you hold that, much of the machinery carries over. Our"," ",e.jsx(r,{href:"/services/compliance/iso-42001-ai-management",className:"underline hover:no-underline",children:"ISO 42001 service"})," ","takes you from scoping to certification when a customer or contract demands it; the foundations package on this page is the sensible first step if you're not there yet."]})},{question:"Does using AI raise data protection issues?",answer:e.jsxs("p",{children:["Usually. Putting customer or staff data into AI tools is processing under UK GDPR, AI processing often needs a data protection impact assessment (DPIA), and using AI to make decisions about people brings in the rules on automated decision-making. Where this applies, our"," ",e.jsx(r,{href:"/services/privacy/data-protection-officer",className:"underline hover:no-underline",children:"DPO as a Service"})," ","covers the privacy side, and we make sure the two join up."]})}],ot=[{question:"What is ISO 42001?",answer:"ISO 42001 is the international standard for managing artificial intelligence responsibly. It puts a management system around the AI you build or use, covering governance, risk, data, human oversight, and testing for bias and robustness, so you can show that your AI is properly governed."},{question:"Who needs ISO 42001?",answer:"Businesses building AI models, embedding third-party AI
1into their products, or using AI in decisions that affect people. It's most relevant when customers, investors, or regulators start asking how your AI is governed, or where AI is becoming central to what you sell."},{question:"How does it relate to the EU AI Act?",answer:"The two line up well. ISO 42001 gives you the governance structure that helps demonstrate the kind of responsible-AI practices the EU AI Act expects, which makes a certifiable management system a practical way to get ahead of that regulation rather than scrambling later."},{question:"Does ISO 42001 build on our existing security?",answer:e.jsxs("p",{children:["It assumes a reasonable security baseline is already in place and focuses on the AI-specific controls on top. If your foundations aren't there yet,"," ",e.jsx(r,{href:"/services/cyber-security/security-foundations",className:"underline hover:no-underline",children:"Security Foundations"})," ","is the better starting point, and ISO 42001 sits alongside frameworks like ISO 27001 rather than replacing them."]})}],it=[{question:"What's the difference between SOC 2 Type I and Type II?",answer:"A Type I report shows your controls are designed properly at a single point in time; a Type II report shows they have actually operated effectively over a period, usually several months. Type I is quick and gets a report in front of a buyer. Type II shows the controls working over months, and it's the one sophisticated buyers weight."},{question:"How long does SOC 2 take?",answer:"Implementation is a defined piece of work that gets your controls and evidence in place. A Type I attestation can follow fairly quickly, while a Type II covers a monitoring period, so we keep you continuously audit-ready rather than treating each one as a fresh project. Maintenance then runs on a 12-month minimum."},{question:"Do we need SOC 2 or ISO 27001?",answer:e.jsxs("p",{children:["It comes down to who's asking. SOC 2 is what US buyers tend to expect, while"," ",e.jsx(r,{href:"/services/compliance/iso-27001-information-security-management",className:"underline hover:no-underline",children:"ISO 27001"})," ","is the internationally recognised certification elsewhere. Some businesses eventually need both, and we'll help you work out which one satisfies the demand in front of you."]})},{question:"How much does SOC 2 cost?",answer:e.jsxs("p",{children:["Our implementation is a fixed fee, with ongoing maintenance after that. The CPA firm's examination fee is separate and paid directly to the auditor. The"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","gives an indicative estimate for our side."]})},{question:"Do we need a consultant if we're buying Vanta or Drata?",answer:e.jsxs("p",{children:["The platforms are good at collecting evidence and monitoring controls, and we often pair our consultants with Drata. What they don't do is scope the system, make your risk decisions, or sit with you in the audit, so the question is whether someone in-house can own that judgment. Our"," ",e.jsx(r,{href:"/insights/compliance-platform-vs-consultant",className:"text-brand-red-dark",children:"guide to platforms versus consultants"})," ","covers how to decide."]})}],rt=[{question:"Which PCI DSS questionnaire (SAQ) do we need?",answer:"It depends on how card data flows through your business. If a hosted payment page or a redirect handles the card data so it never touches your systems, you're usually on the shortest questionnaire, SAQ A. If your own systems store, process, or transmit card data, more requirements apply. Getting the scope right first is what decides this, and it's usually where the biggest savings are."},{question:"Do we need an external auditor, or can we self-assess?",answer:"Most small businesses (Levels 2 to 4) confirm compliance themselves with a Self-Assessment Questionnaire, supported by quarterly scans from an Approved Scanning Vendor. Only Level 1 merchants (broadly, over 6 million card transactions a year, or any business after a breach) need an independent Qualified Security Assessor to produce a Report on Compliance. We help you complete the SAQ properly so it holds up when your acquirer reviews it."},{question:"Can we reduce how much of PCI DSS applies to us?",answer:"Often, yes. The less card data touches your own systems, the shorter the questionnaire and the fewer requirements apply. Routing payments through a hosted page or a redirect to a compliant provider keeps most online businesses on the lightest route. Where you currently store card data, removing the reasons you hold it can move you to a far lighter route."},{question:"What happens after we get our attestation?",answer:"PCI DSS isn't a one-off. There are recurring obligations, typically quarterly external scans and an annual revalidation. We can keep the programme running, managing the scans, keeping evidence and policies current, and completing the annual SAQ or Report on Compliance refresh, so compliance doesn't lapse between deadlines."},{question:"Does PCI DSS overlap with ISO 27001 or SOC 2?",answer:e.jsxs("p",{children:["Yes, there's a lot of common ground in access control, policy, and risk management. If you hold or are pursuing"," ",e.jsx(r,{href:"/services/compliance/iso-27001-information-security-management",className:"underline hover:no-underline",children:"ISO 27001"})," ","or"," ",e.jsx(r,{href:"/services/compliance/soc-2",className:"underline hover:no-underline",children:"SOC 2"}),", much of the underlying work counts towards PCI DSS, so the second framework is considerably less work than the first."]})}],ct=[{question:"What's the difference between sell-side and buy-side due diligence?",answer:"Sell-side work prepares a company for the scrutiny of a raise or sale: fixing gaps, preparing evidence, and supporting the deal. Buy-side work assesses a target on behalf of the investor or acquirer. We do both, with the same team, which is why each side knows what the other will look for."},{question:"Do early-stage startups need security due diligence?",answer:"Rarely before Series A. Early rounds focus on team and product, and security seldom features. From Series A onwards the questionnaires get real, and by exit the scrutiny is detailed. If you're pre-seed, get the basics right and revisit this when a round is on the horizon."},{question:"Is security due diligence the same as a penetration test?",answer:"No. A penetration test probes systems for technical vulnerabilities. Due diligence reviews the whole security picture: governance, certifications, incident history, data protection, suppliers, and resilience. A recent penetration test is one piece of evidence within it, and we help scope one where it's needed."},{question:"How does due diligence relate to ISO 27001 and SOC 2?",answer:"Certificates answer some due diligence questions in advance, and buyers often expect them. A readiness asse
1ssment tells you whether your market expects certification and which one; if it does, our ISO 27001 and SOC 2 services deliver it as a separate engagement."}],lt=[{question:"What is security due diligence?",answer:"The review investors and acquirers run over a company's security and data protection before committing money: questionnaires, document requests, interviews, and on larger deals a specialist technical assessment. Findings feed directly into price and deal terms."},{question:"What do investors actually ask about security?",answer:"The questions are consistent: who owns security, which certificates you hold, when you were last tested, your incident history, access control, how code reaches production, how personal data is handled, supplier risk, resilience, and IP hygiene. Our readiness assessment covers the same ten areas."},{question:"When should we start preparing for due diligence?",answer:"Ideally 6 to 18 months before a raise or sale process. That leaves time to fix what should be fixed and let the evidence accumulate naturally. If the questionnaire has already arrived, we work to live deal timetables; starting later just means less room to negotiate."},{question:"How long does due diligence readiness take?",answer:"The readiness assessment takes 2 to 3 weeks. Remediation and evidence preparation is scoped from its findings and depends on your timetable. Live deal support runs for the duration of the process, flexing with how the work arrives."},{question:"Do we need ISO 27001 or Cyber Essentials before raising?",answer:"Not necessarily; it depends on your buyers and market. Cyber Essentials is quick and often achievable within a deal timetable. ISO 27001 or SOC 2 take longer and are worth starting before a fundraise rather than during it. The readiness assessment tells you which, if any, is worth pursuing."},{question:"What does the readiness assessment cost?",answer:"It's a fixed fee sized to the complexity of your business - structure, systems and how much evidence already exists; the pricing calculator gives an indicative range. Remediation guidance is scoped from the assessment's findings, and deal support is a monthly retainer sized to the process, so you only pay for the phases you need."}],dt=[{question:"What is cyber due diligence in M&A?",answer:"The assessment of a target company's security before an investment or acquisition completes. It tells the buyer what security debt, breach exposure, and regulatory risk they're taking on, so those can be priced into the deal rather than discovered after completion."},{question:"What does a cyber due diligence assessment cover?",answer:"Ten areas: governance, certifications, security testing, incident history, access control, secure development, data protection, third parties, resilience, and intellectual property hygiene. Each significant finding comes with an indicative cost and effort to remediate."},{question:"What's the difference between a red-flag review and a full assessment?",answer:"A red-flag review takes about a week and reports only deal-critical issues, using external analysis, documents, and a short interview. A full assessment takes 2 to 4 weeks and verifies evidence across all ten areas, with findings ranked and priced. Smaller deals often only need the red-flag review."},{question:"How long does cyber due diligence take?",answer:"About a week for a red-flag review; 2 to 4 weeks for a full assessment. We work inside exclusivity windows, and we'll tell you at the start if the timetable only allows a partial view, and what that view will and won't cover."},{question:"Can you assess a target before exclusivity?",answer:"Yes, with limits. Before the target cooperates we work outside-in: external attack surface, public records, and whatever documents you've been given. The report says clearly where evidence was limited. Once access opens up, we verify rather than infer."},{question:"What happens after completion?",answer:"We can run a first-100-days engagement: a baseline assessment of the acquired environment, a remediation plan for the risks you accepted knowingly, and the reporting schedule your investment committee expects. Ongoing needs usually transition to a vCISO engagement."}],ut=[{question:"How quickly will you get back to me?",answer:"Within one working day, and usually sooner. A real person reads every message, so you'll get a considered reply rather than an automated acknowledgement."},{question:"Is there any cost to get in touch?",answer:"None at all. The first conversation is free. We'd rather point you in the right direction than push you towards work you don't need."},{question:"What happens after I send this form?",answer:"One of our consultants reads it and replies by email, usually suggesting a short call to understand where you are. There's no script and no hard sell, just a straightforward chat about what you actually need."},{question:"Do you work with businesses like ours?",answer:"Almost certainly. We focus on growing businesses and startups rather than large enterprises, so the advice is sized to your stage and budget instead of a one-size-fits-all programme."},{question:"What if I'm not sure what I need yet?",answer:"That's completely fine, and it's how most conversations start. Tell us what's prompting this, whether it's a customer questionnaire, an audit, or just a nagging worry, and we'll help you work out the sensible next step."}],Ye={"ai-governance-framework":[{question:"What is AI governance?",answer:"AI governance is the set of decisions and rules that control how a business uses AI: which tools are approved, what data can go into them, which outputs need a human check, and who is accountable when something goes wrong. For a small business it comes down to an inventory, a short policy, a proportionate risk assessment, and a named owner."},{question:"What's the difference between AI governance and data governance?",answer:"Data governance controls the data estate itself: what you hold, where it lives, and who can access it. AI governance controls the tools and decisions that act on that data. They overlap, but they fail differently; a business with well-governed data can still have staff pasting it into unapproved chat assistants."},{question:"Do small businesses need AI governance?",answer:"If staff use AI at all, yes, in proportion to the risk. The minimum is an inventory of what's in use and a one-page policy. The framework should grow when personal data goes into prompts, AI output feeds decisions about people, AI is part of the product, or customers start asking for evidence."},{question:"Do we need a consultant for AI governance?",answer:"Not necessarily. The first-month version, an inventory, a policy, and an owner, is something most businesses can do themselves in an afternoon of focused work. Consultancy earns its keep when questionnaires are arriving, the EU AI Act applies to what you sell, or AI is touching decisions about people and the risk assessment needs experienced eyes."}],"ai-management-system":[{question:"Is an AI management system the same as ISO 42001?",answer:"Not quite. The AI management system is the thing you run: the policy, register, assessments, controls, and records. ISO 42001 is the standard an accredited body can audit that system against. The relationship is the same as an information security management system and ISO 27001."},{question:"Can we run an AIMS without getting certified?",answer:"Yes, and for many businesses that's the right call. The governance value comes from running the system; the certificate exists for the moment a customer, investor, or regulator needs independent proof. Build the system when the risk justifies it, and certify when someone needs to see it."},{question:"How is an AIMS different from an ISMS?",answer:"Same skeleton, different subject. An ISMS manages information security risk; an AIMS manages the risks of developing and using AI, and it adds impact assessments that ask what could go wrong for the people the AI affects, not just for the business. Holding one makes building the other faster because the management-system machinery is shared."},{question:"Is this the same as an AI document management system?",answer:"No. AI document or knowledge management systems are software products that use AI to organise files and information. An AI management system in the governance sense is the framework a business runs to control its own use of AI, and it's what standards like ISO 42001 and buyer questionnaires are referring to."}],"guide-to-iso-42001":[{question:"Is ISO 42001 mandatory?",answer:"No. It's a voluntary standard, not law. The pressure to hold it is commercial: enterprise procurement and investor due diligence increasingly ask for evidence of AI governance, and a certificate is the strongest generally recognised answer. Expect it to appear in more contract schedules the way ISO 27001 did."},{question:"Does ISO 42001 make us compliant with the EU AI Act?",answer:"No, and anyone claiming otherwise is overselling. The Act is law with its own obligations; ISO 42001 is a voluntary standard. What the certificate gives you is the governance machinery most of the Act assumes you have, which makes demonstrating compliance far easier, and it's strong evidence for UK and non-EU buyers too."},{question:"Do we need ISO 27001 before ISO 42001?",answer:"No. The two share the same management-system skeleton, so holding either makes the other cheaper and faster, and businesses whose product is AI sometimes sensibly go 42001-first. If buyers are asking about both
1security and AI governance, building the two systems together on shared machinery is the efficient route."},{question:"How much does ISO 42001 certification cost?",answer:"Our implementation fees run from £9,000 to £13,000 where the picture is straightforward, through £15,000 to £21,000 for a typical business, to £24,000 to £36,000 for the most complex, with an optional monthly fee if we run the system with you. The certification body's audit fees are separate and paid directly to them; while accredited ISO 42001 certification is young, budget in the same territory as an ISO 27001 audit and get more than one quote."}],"compliance-platform-vs-consultant":[{question:"Can we get ISO 27001 or SOC 2 with just Vanta or Drata?",answer:"Yes, plenty of businesses do. The platform handles evidence collection and monitoring; you still need someone with experience to scope the system, make the risk decisions, adapt the policies, and face the auditor. If that person exists in-house with time to spare, platform-alone is a reasonable route. If not, the subscription doesn't replace them."},{question:"Do we have to buy a platform to work with you?",answer:"No. We pair our consultants with Drata where it helps, we're happy working in Vanta or others, and we're equally happy with no platform at all. ISO 27001 predates all of these tools; a platform changes how evidence is collected, not whether you pass."},{question:"Is a consultant cheaper than a compliance platform?",answer:"They're different spending shapes rather than substitutes. A platform is a subscription that typically runs to five figures a year for as long as you hold the certification. Consultancy is a one-off project fee with an optional monthly run, and our fees are published in the pricing calculator, sized to the complexity of your organisation."},{question:"Which platform do you recommend?",answer:"It depends on your stack, your buyers, and who in your team will live in it day to day. We pair with Drata often enough that our service pages mention it, and we work in whatever you choose. Treat the platform choice as a separate decision from the consultancy one; conflating the two is how businesses end up owning a subscription that answered the wrong question."}],"soc-2-vs-iso-27001":[{question:"Is SOC 2 recognised in the UK?",answer:"It's understood, especially among tech buyers, but ISO 27001 is the default expectation in UK and European procurement. If your revenue is mostly UK or EU, ISO 27001 removes more friction; SOC 2 earns its keep when US enterprise deals are on the table."},{question:"Is SOC 2 cheaper than ISO 27001?",answer:"The implementation effort is comparable. Our published fees for SOC 2 sit a little below the ISO 27001 ones because the mandatory documentation is lighter, but a Type II report adds a monitoring period, and the CPA firm's attestation fees are separate, just as the certification body's audit fees are for ISO 27001. The pricing calculator prices both for your size."},{question:"Will US customers accept ISO 27001 instead of SOC 2?",answer:"Sometimes, and it's always worth asking before you commit to anything. Larger US enterprises increasingly accept ISO 27001, but plenty of procurement checklists still name SOC 2 specifically, and a checklist is rarely worth arguing with mid-deal."},{question:"Should we do SOC 2 Type I or go straight to Type II?",answer:"Type I gets a report into a buyer's hands quickly; Type II is the one sophisticated buyers weight, because it shows the controls operating over months. A common route is a Type I to unblock a live deal, with the Type II covering the following period, so the same work serves both."}],"cyber-essentials-cost":[{question:"How much does Cyber Essentials cost for a small business?",answer:"The IASME assessment fee runs from £320 to £600 plus VAT depending on your size, and if your controls are already in place that's close to the whole cost. With fixed-fee support to close the gaps and get the questionnaire right first time, expect £1,700 to £2,300 from us on top where the device estate is centrally managed, rising to £4,400 to £6,600 where it's mixed or unmanaged. Plus level adds the certification body's audit fee."},{question:"What does Cyber Essentials Plus cost on top?",answer:"The Plus audit fee is set by each certification body rather than fixed by IASME, and most small businesses pay £1,500 to £3,000 plus VAT, driven mainly by the size of the device sample being tested. The standard assessment still sits underneath it. Our Plus support fees include the Standard stage, but certification body fees are always paid directly to the body."},{question:"Can we just do the self-assessment ourselves?",answer:"Yes. If the five control areas are already in place, the questionnaire is very manageable and the assessment fee is the only cost. Support earns its keep when there are gaps to close, unmanaged devices to bring into line, or a deadline from a customer contract. The free Security Health Check will tell you which situation you're in."},{question:"Is Cyber Essentials an annual cost?",answer:"Yes, the certificate is valid for twelve months, so the assessment fee recurs each year. Bu
1sinesses that keep the controls running as normal practice find recertification quick; the expensive version is letting things drift and rebuilding every year."}],"virtual-ciso-cost":[{question:"How much does a virtual CISO cost per month in the UK?",answer:"Published UK benchmarks run £2,000 to £7,000 a month for most small and mid-sized businesses, with regulated mid-market firms paying more. Our fees are £2,000 to £2,800 a month for a straightforward organisation, rising with complexity - structure, estate, certifications to keep audit-ready - to £5,700 to £8,700 a month for the most complex, plus a one-off onboarding fee of £4,200 to £5,800."},{question:"How does that compare with hiring a CISO?",answer:"A full-time CISO in the UK typically earns £140,000 to £220,000 a year plus benefits, before recruitment cost and retention risk. A fractional arrangement gives you the senior judgment for a fraction of that, which is the right trade for businesses that don't need a security executive at a desk every day."},{question:"What does the onboarding fee cover?",answer:"The baseline: a stakeholder survey of where you stand, and the first version of your risk register and roadmap. It's what lets the monthly engagement start from evidence rather than assumptions."},{question:"Does the monthly fee include hands-on work like policies or incident response?",answer:"No, and that's deliberate. The fee buys leadership: strategy, the risk register and roadmap, board reporting, and direction for your team and providers. Writing policies, implementing controls, and hands-on incident response are separate work, done by your team or scoped separately, so you're never paying senior rates for delivery work."}],"iso-27001-certification-cost":[{question:"How much does ISO 27001 certification cost a small UK business?",answer:"Expect £12,000 to £18,000 in consultancy fees to implement where the scope is straightforward, £20,000 to £28,000 for a typical business, and £30,000 to £46,000 for the most complex, plus the certification body's audit fees on top (typically £3,000 to £10,000 for a business under about 100 people), plus a few hours a week of internal time over three to six months. Our pricing calculator gives a figure for your exact profile."},{question:"Are the certification body's audit fees included in consultancy fees?",answer:"No. The audit is carried out by an independent, accredited certification body and paid directly to them, which keeps the audit independent of the people who helped you prepare. Quotes vary between bodies more than most buyers expect, so ask two or three before committing."},{question:"Can we reduce the cost by doing some of the work ourselves?",answer:"Yes. The biggest savings come from having the security basics in place before you start and from running the system with your own team after certification. Where businesses come unstuck is copying template policies that don't match how they work; auditors notice that quickly."},{question:"Do compliance platforms like Vanta or Drata make ISO 27001 cheaper?",answer:"They can cut the time spent collecting evidence, and we work with them where they fit. They also add a subscription, and they don't scope your system, make risk decisions, or sit with you in the audit. For most small businesses the platform decision is separate from the consultancy decision."}],"gdpr-for-small-businesses":[{question:"Does GDPR apply to my small business?",answer:"Almost certainly. If you hold information that identifies living people, whether customers, staff, or suppliers, the UK GDPR applies. There is no small-business exemption, and your size makes little difference to the basic obligations."},{question:"Do I need a Data Protection Officer?",answer:"Usually not as a legal requirement. A formal DPO is only mandatory in specific cases, mainly large-scale monitoring of people or large-scale handling of sensitive data. Most small businesses fall outside that, though clear ownership of privacy still helps."},{question:"How much GDPR compliance is enough for a small business?",answer:"The standard is proportionate to your size and risk. A ten-person company does not need a bank's privacy programme. Get the basics right, data mapping, a lawful basis, a clear privacy notice, and the ability to handle requests, and you cover most of it."},{question:"What happens if we get GDPR wrong?",answer:"The headline fines are large, but for a small business the realistic consequences are more ordinary: a complaint to the ICO you cannot answer well, a customer asking for evidence you do not have, or a deal that stalls on a questionnaire. Being able to show your work protects against all three."}],"subject-access-requests":[{question:"How long do I have to respond to a DSAR?",answer:"One calendar month from receiving the request. You can extend by up to two further months if it is genuinely complex or the person has made several, but you must tell them, and why, within the first month."},{question:"Can I charge for a subject access request?",answer:"Not for a normal request. You can only charge a reasonable fee, or refuse, where a request is manifestly unfounded or excessive, which is a high bar that mere inconvenience does not meet."},{question:"Does a DSAR have to be in writing?",answer:'No. People do not have to use the words "subject access request" or fill in a form. A request by email, by letter, or even spoken out loud counts, and it can reach anyone in your business, so your team needs to recognise one.'},{question:"Can I withhold someone else's information?",answer:"A subject access request covers the requester's own data, not other people's. If returning their data would reveal information about someone else, redact the other person's details unless they have agreed or it is reasonable to disclose."}],"legitimate-interest-gdpr":[{question:"What is the legitimate interests test?",answer:"A three-part check: is there a real, specific interest behind the processing (purpose); is the processing necessary for it (necessity); and do the person's interests and reasonable expectations override yours (balance). If the balance goes against the individual, you need a different basis."},{question:"When can I rely on legitimate interest?",answer:"For processing people would reasonably expect that carries low risk to them, such as preventing fraud, keeping your systems secure, basic administration within a group of companies, and some marketing to existing customers."},{question:"Can I use legitimate interest for marketing emails?",answer:"Sometimes as the lawful basis, but electronic marketing also has separate rules under PECR that sit on top, so consent or the limited soft opt-in for existing customers usually still applies."},{question:"Do I need to write down a legitimate interests assessment?",answer:"It is strongly advisable. A short record of the interest, why the processing is necessary, and how the balance came out is your answer if a customer or the ICO ever asks why you relied on it."}
1],"special-category-data":[{question:"What counts as special category data?",answer:"Data about race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetics, biometrics used to identify someone, health, and a person's sex life or sexual orientation. Criminal offence data is handled with similar care under its own rules."},{question:"Can I rely on legitimate interest for special category data?",answer:"No. Special category data needs an additional condition specifically for it, on top of your ordinary lawful basis. Legitimate interest alone is not enough."},{question:"Where do small businesses usually hold special category data?",answer:"Most often in a few predictable places: health information for sick leave or workplace adjustments, dietary or accessibility needs for events, and equality monitoring. It is usually limited once you know to look for it."}],"cookies-and-pecr":[{question:"Do I need consent for cookies?",answer:"Yes, for any cookie that is not strictly necessary, including analytics and advertising, and the consent must come before the cookie is set. Only genuinely essential cookies are exempt."},{question:"What counts as a strictly necessary cookie?",answer:"Only cookies essential to provide what the visitor asked for, such as remembering a shopping basket or keeping someone logged in securely. Analytics, even your own, and anything for advertising do not count."},{question:"What does valid cookie consent look like?",answer:"A clear, affirmative choice: no non-essential cookies before the visitor agrees, no pre-ticked boxes, refusing as easy as accepting, and the ability to change their mind later."},{question:"How do PECR and GDPR relate?",answer:"PECR governs cookies and electronic marketing; the UK GDPR sets the wider rules for personal data. They overlap, and the ICO enforces both, so it is sensible to treat them as one job."}],"cyber-security-tips-small-businesses":[{question:"What are the most important cyber security steps for a small business?",answer:"Start by working out which systems would genuinely hurt the business if compromised, then protect those first. In practice that means multi-factor authentication on email and cloud services, managed and encrypted devices, tested backups, prompt patching, and short, regular staff briefings. The basics remove most of the risk."},{question:"Should we use SMS or an authenticator app for multi-factor authentication?",answer:"Use an authenticator app. SMS codes can be intercepted, whereas app-based codes generally cannot. It is one of the highest-value changes you can make, and most email and cloud platforms support it out of the box."},{question:"Do we need Cyber Essentials as a small business?",answer:"For most small businesses it is a sensible first step, and a quick way to show customers evidence of your security. It is not a complete programme, and it works best once your underlying controls are already in place, so certification becomes an evidence exercise rather than a scramble."},{question:"Why is ongoing maintenance the hard part of small business security?",answer:"Most controls can be put in place in a few focused weeks. The difficulty is keeping them working twelve months later, once the team has grown, people have joined and left, and devices have been replaced. Security usually fails through drift rather than one big decision, so someone needs to own it."}],"cyber-security-risk-assessments":[{question:"What is a cyber security risk assessment?",answer:"A structured review of the systems, data, and processes your business depends on, and the risks that could disrupt them. It sets out what you are protecting, what could realistically go wrong, what you already do about it, and where further effort is worth it."},{question:"Why are small businesses asked for a risk assessment?",answer:"The trigger is almost always external: a customer security questionnaire, an ISO 27001 project, investor due diligence, or moving into a regulated or data-sensitive area. Buyers increasingly expect suppliers to show that risks are understood and managed, even without a formal certification."},{question:"How long should a cyber security risk assessment report be?",answer:"Short enough that a leadership team can act on it without a translator. Long, heavily technical documents tend to sit unread. A good report says which risks matter most and why, which controls already reduce exposure, what to prioritise now, and what can reasonably wait."},{question:"Do we need a formal framework like ISO 27001 to assess risk?",answer:"Often not yet. A framework gives you a consistent way to identify and treat risk, and it makes later certification easier, but most growing businesses need proportionate structure rather than heavy governance. How much you need depends on customer expectations, regulation, and how sensitive your data is."}],"cyber-essentials-plus":[{question:"What is the difference between Cyber Essentials and Cyber Essentials Plus?",answer:"Standard Cyber Essentials is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus adds hands-on technical testing by an independent, IASME-accredited assessor, including a vulnerability scan of a sample of your devices and services, to confirm the controls are actually working."},{question:"Do I need standard Cyber Essentials before Cyber Essentials Plus?",answer:"Yes. You need to hold standard Cyber Essentials first, and the Plus audit has to be completed within three months of that certificate's date. Most businesses complete the two close together."},{question:"What changed under the 2026 Cyber Essentials requirements?",answer:"Two points are now pass-or-fail: multi-factor authentication has to be enabled on every cloud service that offers it, and high-risk or critical updates have to be applied within 14 days. It is worth knowing before you book, because that is where preparation time usually goe
1s."},{question:"Does my small business actually need Cyber Essentials Plus?",answer:"Sometimes, but often standard Cyber Essentials is enough. The deciding factor is usually commercial: if customers, procurement frameworks, or contracts ask for Plus, the choice is straightforward. If no one is asking, your time and budget may be better spent elsewhere."}],"iso-27001-vs-iso-27002":[{question:"What is the difference between ISO 27001 and ISO 27002?",answer:"ISO 27001 is the certifiable standard: it sets out the requirements for an information security management system, and it is what an auditor assesses you against. ISO 27002 is a guidance document that explains the individual security controls and how to apply them. One defines what has to be managed; the other helps you decide how."},{question:"Can you be certified against ISO 27002?",answer:"No. There is no such thing as ISO 27002 certification. Certification is against ISO 27001, and the certificate is issued by an accredited certification body after its auditor has assessed your management system. ISO 27002 simply informs the control decisions you make along the way."},{question:"Do you have to implement every ISO 27002 control?",answer:"No. The 2022 version describes 93 controls, but you are expected to look at your risks and decide which controls are appropriate for your business. What an auditor wants to see is that you can explain why each control was included, adapted, or left out, based on your risk assessment."},{question:"Which standard should a small business focus on?",answer:"If certification is the goal, focus on ISO 27001. It is the standard auditors assess and the one customers ask for by name. ISO 27002 stays useful in the background as practical guidance on the controls once you understand the risks they are meant to address."}],"cyber-security-audits-small-businesses":[{question:"What is a cyber security audit?",answer:"A structured review of how an organisation manages security in practice, and of the evidence behind it. Depending on the reason for the audit, it can cover access management, device security, backups, risk assessment, supplier oversight, staff awareness, and incident handling."},{question:"What is the difference between a cyber security audit and an assessment?",answer:"An assessment is usually an internal or advisory check of where you stand. An audit is a more formal review, often carried out by an external party, that tests your controls and the evidence for them against a defined standard."},{question:"What do auditors ask a small business to show?",answer:"Evidence rather than descriptions: who can access sensitive systems and who granted it, how access is removed when someone leaves, whether devices are encrypted and up to date, when backups were last tested, and when the main risks were last reviewed. A sensible process still has to be shown, not just described."},{question:"Does every small business need a formal cyber security audit?",answer:"No. A customer might want reassurance rather than a certificate, and a supplier questionnaire can often be answered with clear evidence of your baseline controls. Cyber Essentials is frequently a more sensible first step than ISO 27001 or SOC 2, and the right level of preparation follows the scrutiny you are actually under."}],"tech-due-diligence-checklist":[{question:"What is a tech due diligence checklist?",answer:"The list of technology, security, and data protection questions an investor or acquirer works through before a deal: governance, certifications, testing, incident history, access control, development practices, data protection, suppliers, resilience, and IP ownership."},{question:"What documents do investors ask for in due diligence?",answer:"Security policies, certificates such as ISO 27001 or Cyber Essentials, the latest penetration test report, an incident register, records of processing, processor agreements, supplier lists, insurance details, and IP assignment agreements, organised in a data room."},{question:"How long does tech due diligence take?",answer:"On smaller deals, a questionnaire and a call. On larger ones, a two-to-four-week specialist assessment during exclusivity. Preparing takes longer than responding: sellers who start 6 to 18 months out shape the process rather than react to it."},{question:"When should a startup start preparing for due diligence?",answer:"From Series A onwards, assume security questions will be part of any round, and start preparing 6 to 18 months before a raise or exit. Before that stage, focus on baseline security controls rather than due diligence packs."}],"soc-2-audit-for-small-business":[{question:"Can a UK company get a SOC 2 report?",answer:"Yes. The Trust Services Criteria are American, but the audit can be carried out remotely by any licensed CPA firm, and plenty of UK software businesses hold SOC 2 reports for their US customers."}
1,{question:"How long does a SOC 2 Type 2 observation period need to be?",answer:"Three months is the usual minimum for a first report, with 6 or 12 months typical after that. Some enterprise customers ask for a full 12-month period, so check what your buyers expect before choosing a short window."},{question:"Does SOC 2 require a penetration test?",answer:"The criteria don't mandate one by name, but most auditors and customers expect some evidence of vulnerability management, and a recent penetration test is the easiest way to show it. Testing is procured separately from the audit and from any readiness work, and it isn't something we do."}],"due-diligence-for-small-businesses":[{question:"What is the difference between due care and due diligence in cyber security?",answer:"Due care is the reasonable steps a business takes to protect what it's responsible for. Due diligence is the process of checking that those steps are in place and working. When a third party runs due diligence on you, they're testing your due care."},{question:"Do small businesses need ISO 27001 or SOC 2 to pass due diligence?",answer:"No. Reviewers expect controls proportionate to your size and customers, a named owner, and evidence. Certification becomes relevant when an investor or customer names it, which is more common from Series A onwards and in enterprise sales."},{question:"How long does cyber security due diligence take?",answer:"The review itself typically runs from a couple of weeks to a couple of months, depending on the deal. Preparation is best started 6 to 18 months earlier, so that gaps are fixed before anyone is looking."}],"investor-due-diligence":[{question:"Do seed investors check cyber security?",answer:"Some do and s
1ome don't. The ones that do ask a handful of concrete questions: who owns security, whether MFA is enforced, who can reach production, whether backups have been restored, and whether IP is assigned. From Series A the questions are broader and evidence is expected."},{question:"Does a startup need ISO 27001 or SOC 2 to raise a seed round?",answer:"No. Certification is rarely a condition at seed. It becomes relevant when customers or investors name it, which is more common from Series A and in enterprise sales."},{question:"How long before a round should a startup prepare for security due diligence?",answer:"Six to twelve months is comfortable for a seed or Series A round, and the work fits alongside building the product. Starting after a term sheet is signed means fixing things while the investor watches."}],"what-is-a-fractional-ciso":[{question:"What does a fractional CISO actually do?",answer:"They own security governance, strategy and risk for the business: deciding what the real risks are, what to do about each, and how to show it's working, then reporting on it monthly. They don't run the tools or the day-to-day work. Your IT team does that, against requirements the CISO sets."},{question:"How much time does a fractional CISO take?",answer:"For most small businesses, one or two days a month once the work is up and running, and a bit more in the first months while the picture is forming. The case for a full-time CISO is volume: as you grow, security eventually justifies someone in the chair every day."},{question:"Is a fractional CISO the same as a virtual CISO?",answer:"Yes. Fractional CISO, virtual CISO and vCISO are three names for the same arrangement: a part-time chief information security officer who owns governance and risk. What matters is what the role owns and where it stops, not the label."},{question:"Do we need a fractional CISO before we've done the basics?",answer:"No. If you've had little or no security input so far, a fractional CISO is the wrong first spend: they'd surface a long list of obvious gaps you didn't need a CISO to find. Get the foundations in place first, through a Security Foundations engagement or Cyber Essentials, then add the governance layer."}],"do-we-need-a-dpo":[{question:"Is paying the ICO fee the same as having a DPO?",answer:"No. The data protection fee is an annual registration that most organisations processing personal data have to pay. A Data Protection Officer is a role with legal duties: advising the business, monitoring its compliance and acting as the contact point for the ICO. A business can be fully paid up and still have nobody doing that job."},{question:"Can our founder or IT manager be our DPO?",answer:"Not for the formal role. The law requires a DPO to be free of conflicts of interest, so anyone who decides how personal data is used can't also be the person checking those decisions. That rules out most of a small leadership team and usually the head of IT. An external DPO is allowed, and for most small businesses it's the practical answer."},{question:"Do we need a DPO if we only have a few employees?",answer:"The test is about the data you hold, however many people you employ. The law asks whether your core activities involve large-scale monitoring of people or large-scale processing of special category data such as health or biometrics. Roughly one in four or five of the small businesses we talk to do meet it, nearly always because of what they hold rather than how many people they employ."},{question:"What happens if we should have a DPO and don't?",answer:"It's a breach of UK GDPR that the ICO can take enforcement action on. In practice the problem arrives sooner and from elsewhere: a customer questionnaire or an investor's due diligence asks who your DPO is, and there's no answer. Appointing one formally, publishing the contact details and telling the ICO closes both gaps."}],"third-party-cyber-security-risk":[{question:"Which suppliers need a security review?",answer:"The ones whose loss or breach would significantly hurt the business. For most small companies that's 10 to 20 suppliers out of hundreds: the cloud platform, the database, email and identity providers, the payment processor, and anyone with admin access to your systems. Everything else gets a register entry and not much more."},{question:"Do we need to do a security review of AWS or Microsoft?",answer:"Not a real one. A small business can't
1change a hyperscaler's processes and often can't stop using them, and their security practice is more established than yours will be for years. If you hold ISO 27001 you still need a light review on file: their SOC 2 or ISO report and a note of what data goes in. Save the scrutiny for niche suppliers and unusual uses of data."},{question:"How often should we review our suppliers?",answer:"Annually for each critical supplier, with a quarterly check that the list itself is still right. The annual review is four questions: are we still using it, has anything changed, are we doing anything different with it, and are we putting any new data into it. No change means an easy renewal."},{question:"What evidence should we ask a new supplier for?",answer:"Their current SOC 2 or ISO 27001 report, and a data processing agreement before any personal data flows. Alongside that, establish what data will go in and what access they'll have. A questionnaire of your own is rarely worth sending. A certificate tells you they passed an audit on a date, not what your data does inside their product."}],"cyber-security-vs-information-security":[{question:"Is cyber security the same as information security?",answer:"On paper, no. Information security covers information in any form, and cyber security is the part concerned with systems, networks and data. In practice the difference is mostly meaningless. Whatever you call it, the job is protecting people and value, and almost nobody uses the terms carefully."},{question:"What's the difference between cyber security and IT security?",answer:"IT runs the technology the company relies on, and some of that is running security controls. Security decides what the technology has to do to keep people and value safe, and checks that it does. If the security function isn't running a control, it should be assuring it."},{question:"Do we need separate cyber security and information security policies?",answer:"No. One short security policy that staff have read and acknowledged, one risk register, one named owner. If a questionnaire asks for an IT security policy and an information security policy, it wants the same document."},{question:"Is ISO 27001 cyber security or information security?",answer:"Information security. ISO 27001 is a standard for an information security management system, covering people, premises, suppliers and paper as well as systems, with the technical controls listed in ISO 27002. Cyber Essentials is the technical baseline underneath it. Whether you need ISO 27001 is a commercial question, and the usual trigger is a customer or investor asking."}]},ht=[{question:"Is the Health Check a real cyber security audit?",answer:e.jsx("p",{children:"No. It's a free 13-question self-assessment that gives you an instant baseline: a recommended security level and what to fix first. A cyber security audit is the consultant-led version, where we review your controls, policies and evidence, then hand you a prioritised report. The Health Check is the quickest way to find out whether paying for an audit is worth it yet."})},{question:"What does a cyber security audit involve?",answer:e.jsxs("p",{children:["We look at how your business actually runs: accounts and access, devices, data, key suppliers, policies, and what would happen in an incident. That means a few interviews and some evidence gathering rather than weeks of disruption. You get a prioritised list of findings and practical fixes: what matters now, and what can wait. Our"," ",e.jsx(r,{href:"/insights/cyber-security-audits-small-businesses",className:"text-brand-red-dark",children:"guide to cyber security audits"})," ","covers the process in detail."]})},{question:"How much does a cyber security audit cost?",answer:e.jsxs("p",{children:["It depends on your size and how much there is to review, but it's a fixed fee agreed before we start, and it doesn't change unless the scope does. The"," ",e.jsx(r,{href:"/pricing-calculator",className:"text-brand-red-dark",children:"pricing calculator"})," ","gives you an instant estimate without a sales call."]})},{question:"Do we need an audit, or a certification like ISO 27001 or Cyber Essentials?",answer:e.jsxs("p",{children:["If a customer or contract is asking for proof, you likely need"," ",e.jsx(r,{href:"/services/compliance/iso-27001-information-security-management",className:"text-brand-red-dark",children:"ISO 27001"})," ","or"," ",e.jsx(r,{href:"/services/cyber-security/cyber-essentials",className:"text-brand-red-dark",children:"Cyber Essentials"}),". If you want to know where you stand before committing to anything, start with the free Health Check above, then a consultant-led audit if you need more depth. Either way, you'll find out which certification is worth pursuing, if any."]})}];({...Object.fromEntries(Object.entries(Ye).map(([t,a])=>[`/insights/${t}`,a]))});export{Ke as A,Ye as B,Fe as a,Me as b,Ge as c,ut as d,Se as e,Le as f,Ve as g,ht as h,Qe as i,Je as j,Xe as k,Ze as l,et as m,tt as n,st as o,$e as p,at as q,ot as r,Be as s,nt as t,V as u,it as v,rt as w,ct as x,lt as y,dt as z};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.