The Rybec Group

The Rybec Group We are an IASME Certification Body for Cyber Essentials, CE Plus & Cyber Assurance.

We help companies implement and obtain certification for ISO 9001 Quality Management ISO 27001 Information Security ISO 42001 AI Management Systems, MSSP services provider

Here’s the thing about IASME Cyber Essentials Plus that catches people out. It isn’t a harder standard. It’s the same fi...
04/09/2026

Here’s the thing about IASME Cyber Essentials Plus that catches people out. It isn’t a harder standard. It’s the same five controls you’ve already been assessed on, except this time somebody checks they’re genuinely working rather than taking your word for it.

Where it gets expensive is the timing. You have three months from your last Cyber Essentials certificate to get the Plus audit done. Miss that and you’re back at the beginning, redoing Cyber Essentials before you can even book the test.

There’s a second one worth knowing about. If a sample of devices fails on security updates, the retest doesn’t just revisit those devices. It pulls a fresh random selection too, so patching only the machines that got tested won’t save you. Fail twice and the Cyber Essentials certificate goes with it.

The carousel runs through the sequence and the housekeeping worth doing before audit day.

If Cyber Essentials Plus is on your list this year, comment GUIDE and I’ll send our Cyber Essentials Plus client guide over.

Cyber Essentials Plus is the version where an assessor actually checks your systems, rather than taking your word for it...
03/09/2026

Cyber Essentials Plus is the version where an assessor actually checks your systems, rather than taking your word for it.

It rarely goes wrong on the day. It goes wrong when nobody prepared.

The usual trip-ups are simple: a laptop behind on updates, an old account that should have been removed, MFA missing on one or two people. A bit of tidying up beforehand and testing day is painless. That's the whole trick.

Most of the stress around IASME Cyber Essentials comes from starting too late.A client asks for the certificate, a tende...
01/09/2026

Most of the stress around IASME Cyber Essentials comes from starting too late.

A client asks for the certificate, a tender needs it, and suddenly it's a panic. People rush, guess at answers, and hope.

A quick readiness check before you start sorts that out. You find the gaps while there's still time to fix them.

Give yourself a few weeks, not a few days. The certificate's the same. The experience is a lot calmer.

Got a deadline coming?

Email [email protected].

Your firewall did not click the link. A person did. And the answer is not blame, it is better preparation.Most phishing ...
27/08/2026

Your firewall did not click the link. A person did. And the answer is not blame, it is better preparation.

Most phishing works not because people are careless, but because the messages are convincing: well written, well timed, often from accounts that look legitimate. A once-a-year training module is no match for that.

We run practical staff awareness training that helps your team recognise real risks and know what to do when something looks wrong. Short, relevant, and built around the threats your sector actually faces.

Want to strengthen how your team handles phishing?

Email [email protected].

Cyber Essentials gives you 14 days to install important security updates. The clock starts when the update is released, ...
25/08/2026

Cyber Essentials gives you 14 days to install important security updates. The clock starts when the update is released, not when you get round to it.

The 2026 Cyber Essentials update made this stricter, so it's worth staying on top of.

Two habits cover it, switch on automatic updates where you can, and keep a note of what was done and when. Most patching problems come down to nobody owning the job. Sort that and you're most of the way there.

Here is a problem ISO 27001 builds in by design, the person who implements your ISMS cannot be the one who independently...
20/08/2026

Here is a problem ISO 27001 builds in by design, the person who implements your ISMS cannot be the one who independently audits it. Marking your own homework does not satisfy the standard, and it will not satisfy your certification body.

That is where an independent internal audit earns its place. We review your ISMS against the standard, check your evidence honestly, and give you clear findings to act on before the external auditor arrives.

No box-ticking, no 80-page report. Just a straight view of where you stand.

Internal audit due? Email [email protected].

Lots of businesses have an information security system on paper. Far fewer have one that actually does anything.The fold...
18/08/2026

Lots of businesses have an information security system on paper. Far fewer have one that actually does anything.

The folder of policies isn't the system. The system is the habits behind it: reviewing risks, checking controls still work, acting when something changes.

A real one has been looked at this year. A paper one was perfect on certification day and never touched again. The documents aren't the point. A business that makes good security decisions is.

Not every organisation needs, or can justify, a full in-house security team. But the work still has to happen, keeping a...
13/08/2026

Not every organisation needs, or can justify, a full in-house security team. But the work still has to happen, keeping an eye on things, chasing actions, making sure nothing important slips.

That is what ongoing support is for. Strategy and oversight from us, operational delivery through our accredited partner. Independent advice, reliable delivery, and one point of accountability rather than a stack of tools nobody is watching.

Want to talk through what you actually need? Email [email protected].

Buying a security tool and thinking you're now monitored is one of the most common mistakes we see.A tool just sends ale...
12/08/2026

Buying a security tool and thinking you're now monitored is one of the most common mistakes we see.

A tool just sends alerts. It'll happily flag a problem at 2am and wait for someone who isn't watching.

Monitoring is the bit people forget to pay for: someone whose job is to spot the alert and do something about it.

Ask one question of any tool you own: when it goes off, who sees it, and what happens next? If the answer's "nobody", that's worth fixing.

Cyber Essentials proves the basics are in place. For some organisations, customers and partners want to see more than th...
06/08/2026

Cyber Essentials proves the basics are in place. For some organisations, customers and partners want to see more than the basics.

IASME Cyber Assurance goes further. It looks at how you govern security, how your people are involved, and how you would cope if something went wrong. For businesses bidding for work or handling sensitive data, that wider assurance can be what wins trust.

We help you decide whether it is the right step and support you through the route to it.

Want to know if Cyber Assurance fits your situation? Email [email protected].

Address

Office 130, Louis Pearlman Centre, 94 Goulton Street
Kingston Upon Hull
HU34DL

Alerts

Be the first to know and let us send you an email when The Rybec Group posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to The Rybec Group:

Shortcuts

Share