Cyber security, compliance and certification
Senior-led cyber security consultancy for UK organisations. From ISO 27001:2022 and NIST CSF to PCI DSS, Cyber Essentials and vCISO leadership, we help you govern risk, prove assurance and build resilience.
Cyber Security, compliance and certification questions
Straight answers to the standards and frameworks most UK organisations ask about when they start a security improvement programme.
What is ISO 27001:2022 and why does it matter for UK organisations?
ISO 27001:2022 is the internationally recognised standard for information security management. It provides a systematic framework for identifying, managing and reducing risks to sensitive information. For UK organisations, it signals to clients, regulators and partners that security is governed proactively and is often a requirement for supply-chain contracts and public-sector tenders.
How does the NIST Cyber Security Framework (CSF) differ from ISO 27001?
The NIST CSF is a risk-based, outcome-focused framework organised around five functions: Identify, Protect, Detect, Respond and Recover. ISO 27001 is a certifiable management system with a defined set of controls. Many organisations use NIST CSF to assess maturity and prioritise gaps, then use ISO 27001 as the certification target. We help you choose the right path or blend both.
What is PCI DSS and which organisations need to comply?
PCI DSS (Payment Card Industry Data Security Standard) applies to any organisation that stores, processes or transmits cardholder data. It sets technical and operational requirements for protecting payment information. If you take card payments, work with a payment service provider or handle cardholder data in any form, PCI DSS compliance is a commercial and contractual obligation.
What is Cyber Essentials and is it mandatory?
Cyber Essentials is a UK government-backed scheme that sets out five baseline technical controls to protect against common cyber threats. It is mandatory for many central government suppliers and increasingly expected by insurers, clients and procurement panels. Certification is achieved through a self-assessment, with Cyber Essentials Plus adding independent technical verification.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment covering five controls: firewalls, secure configuration, access control, malware protection and patch management. Cyber Essentials Plus includes the same controls but an independent assessor verifies they are implemented correctly through vulnerability scans and hands-on testing of a sample of devices. Plus gives stronger assurance to clients and stakeholders.
Which security framework should my organisation adopt first?
The right starting point depends on your sector, clients and risk profile. Cyber Essentials is ideal for baseline assurance and many procurement requirements. ISO 27001 suits organisations that need a certifiable management system and work in regulated or enterprise supply chains. NIST CSF is valuable for maturity-based improvement and aligning with US or global partners. PCI DSS is mandatory where card data is involved. We assess your context and recommend a sequenced roadmap.
How can Intelligistica help with ISO 27001, NIST CSF, PCI DSS or Cyber Essentials?
We provide senior-led, fixed-scope consultancy from gap assessment through to certification or audit. Our services include scoping, risk assessment, control design, policy and evidence preparation, remediation prioritisation, assessor coordination and board-level reporting. We also embed vCISO leadership to keep security governance continuous after the initial accreditation.
