Pera Prometheus Consulting Ltd

Pera Prometheus Consulting Ltd Information Security Consulting - Defending Your Industry

The Three Controls Behind DCC Level 0, Explained.Most suppliers have now heard the headline. The Ministry of Defence (MO...
05/09/2026

The Three Controls Behind DCC Level 0, Explained.

Most suppliers have now heard the headline. The Ministry of Defence (MOD) has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, as confirmed on the Defence Digital blog.

Fewer know what Level 0 actually contains. At Pera Prometheus, we hear the same assumption almost every week: “Level 0 just means Cyber Essentials.” That is only a third of the answer. Level 0 is three separate controls, this weeks blog explains all three in plain English.

https://pera-prometheus.com/the-three-controls-behind-dcc-level-0-explained

Getting to Level 0 is straightforward once you know what the three DCC Level 0 requirements ask of you, but remember, the December 2026 deadline will be here in no time.

Stay Safe, Stay Secure

What are the three DCC Level 0 controls? Read our expert breakdown of Cyber Essentials, GDPR conformance, and resilience requirements for SMEs.

We often analyse failures by looking at the moment everything went wrong.But that's rarely where the story begins. Most ...
03/09/2026

We often analyse failures by looking at the moment everything went wrong.

But that's rarely where the story begins.

Most organisational failures develop quietly. Not because people stop caring, not because teams aren't capable, but because everyday decisions slowly move further away from their original intent.

Processes become workarounds.
Exceptions become normal practice.
Responsibilities blur.
Assumptions replace verification.

None of these changes feels significant on their own. Yet over time, they reshape how an organisation operates. That's why effective assurance isn't about searching for problems after they've appeared.

It's about regularly asking: "Has the way we work changed without us noticing?"

The strongest organisations don't wait for disruption to test whether their systems still reflect reality. They create space to challenge assumptions before circumstances do it for them.

Because resilience isn't simply about responding well, it's about staying aligned as organisations evolve.

What's one organisational habit you've seen gradually become accepted, even though everyone knew it wasn't the best way of working?

02/09/2026

DCC Level 0: The baseline every UK defence supplier needs to understand.

With the 31 December 2026 deadline approaching, now is the time for defence organisations to understand what DCC Level 0 actually requires.

The good news? It’s a straightforward baseline built around three key requirements:

✅ Cyber Essentials
✅ Compliance with UK GDPR
✅ Network Security & Resilience

To help organisations understand the new requirements and take their first steps towards certification, Make UK Defence is hosting a practical DCC Level 0 webinar this Thursday, 3 September.

Gareth Shaw, Founder at Pera Prometheus, will be delivering the session, covering what DCC Level 0 means for defence suppliers and what organisations need to do to get started.

If you’re part of the UK defence supply chain, this is an opportunity to get practical guidance on the requirements and the steps towards DCC Level 0.

Register for the webinar here:
https://members.makeuk.org/events/6a85c4f7207b630008e76869/description?ticket=6a85c4f7207b630008e76868&utm

Organisations don't experience security incidents because someone deliberately ignored risk.They happen because small de...
01/09/2026

Organisations don't experience security incidents because someone deliberately ignored risk.

They happen because small decisions become accepted as "the way we've always done things."

A delayed software update.
Assuming a supplier has the right controls in place.
Preparing for security only when an audit is approaching.
Treating compliance as the ultimate goal.
Believing security belongs exclusively to the IT team.

Individually, these decisions may seem insignificant. Collectively, they create the conditions where incidents become more likely.

Strong security isn't built through a single investment or one annual review.

It's built through consistent decision-making, clear governance, and a culture where risk is understood across the organisation, not just within technical teams.

Whether you're operating in the defence sector or a commercial business, the principle remains the same: the organisations that recover fastest are usually the ones that identified these behaviours before they became problems.

Which of these decisions do you encounter most often in your organisation or which one would you add to the list?

Your insights could help others recognise risks they may have overlooked.

If you're looking to strengthen your organisation's security governance before these small decisions become larger issues, we'd be happy to start a conversation.

Your 2026 Cyber Essentials Checklist: Before You ApplyThis weeks blog is thanks to Amy Osborne, ACSP, Head of Audit Serv...
28/08/2026

Your 2026 Cyber Essentials Checklist: Before You Apply

This weeks blog is thanks to Amy Osborne, ACSP, Head of Audit Services at Pera Prometheus.

Amy has a wealth of experience working with organisations of all sizes.

"I can confidently say that CE failures are rarely caused by poor security. More often, they are caused by gaps the applicant didn’t know were there; an unpatched laptop, a cloud account without multi-factor authentication, a firewall rule that nobody has reviewed in a year."

The blog walks you through what needs to be in place across your systems before you submit your application, including the changes introduced in April 2026. A checklist, enabling you to work through it first, address any gaps, in order to approach the assessment with confidence rather than uncertainty.

Read the full blog here ⬇️

https://pera-prometheus.com/your-2026-cyber-essentials-checklist-before-you-apply

As an approved certification body for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Level 0, Pera Prometheus helps organisations across many sectors prepare and get certified. Get in touch to discuss where you are and what you need to do next.

Stay Safe, Stay Secure.

+

Get ready for certification with our complete 2026 Cyber Essentials checklist. Discover the critical steps your SME must take before you apply.

A Business Continuity Plan shouldn't exist only to satisfy compliance requirements. It should give your team the confide...
27/08/2026

A Business Continuity Plan shouldn't exist only to satisfy compliance requirements. It should give your team the confidence to respond quickly, minimise disruption, and keep critical operations running when the unexpected happens.

In our latest carousel, we explore what separates a plan that only exists from one that's ready to perform under pressure.

If you're reviewing your continuity strategy or building one from the ground up, let's start a conversation: https://pera-prometheus.com/

When was the last time your Business Continuity Plan was tested in a realistic scenario and what did you learn from it?

25/08/2026

For many organisations, an audit becomes a high-pressure event.

Documentation is rushed, evidence is gathered at the last minute, and teams scramble to prove that processes are being followed. The stress often isn’t caused by the audit itself, it’s a sign that compliance hasn’t been embedded into day-to-day operations.

However, organisations with mature governance, risk and compliance practices approach audits differently. They’re not preparing for an audit, they’re operating in a way that keeps them audit-ready every day.

The result is more than a smoother audit process. It builds confidence in your controls, improves accountability, and creates a culture of continuous improvement rather than reactive compliance.

What’s the biggest challenge your organisation faces when audit season comes around?

🔵 New Blog: How to Align Your DCC Level with MOD Contract ExpectationsThis week, we’re breaking down some of the biggest...
21/08/2026

🔵 New Blog: How to Align Your DCC Level with MOD Contract Expectations

This week, we’re breaking down some of the biggest questions defence suppliers are asking about DCC and the MOD’s Cyber Security Model.

In this blog, we discuss:

🔷 The baseline everyone shares: DCC Level 0

🔷 How the MOD sets the CSM Cyber Risk Profile Level

🔷 What each DCC level requires, and why the jump from Level 0 to Level 1 is significant

🔷 Whether your subcontractors need the same level

🔷 How Pera Prometheus supports suppliers across all levels

Whilst answering some of the most frequently asked questions.

If you’re preparing for upcoming MOD opportunities, or simply want clarity on what DCC means for your organisation - this weeks blog will help you understand exactly where you stand and what comes next.

🔗 Read the full blog: https://pera-prometheus.com/how-to-align-your-dcc-level-with-mod-contract-expectations

Learn how to align your DCC Level with MOD contract expectations. Ensure your defence SME meets the exact cyber compliance standards to win bids.

Many of the terms shaping today's security conversations are often misunderstood or never fully understood in the first ...
20/08/2026

Many of the terms shaping today's security conversations are often misunderstood or never fully understood in the first place.

Knowing the difference between an attack surface and dwell time, or understanding what least privilege and zero trust actually mean, isn't just technical knowledge. It helps leaders ask better questions, make more informed decisions and strengthen their organisation's security posture.

We are breaking down 10 essential security terms in plain English without the jargon.

Whether you're responsible for IT, security or business strategy, understanding these concepts is the first step towards making better security decisions.

If any of these terms highlight a gap, let's start a conversation: https://pera-prometheus.com/

Which of these terms do you think is the most misunderstood and why?

The security conversations shaping 2027 won't start online.They'll start in the room.This September, Pera Prometheus wil...
19/08/2026

The security conversations shaping 2027 won't start online.

They'll start in the room.

This September, Pera Prometheus will be attending the International Cyber Expo 2026, connecting with organisations tackling today's biggest security, compliance and resilience challenges.

If you're responsible for:
✔ Cyber Security
✔ Compliance
✔ Risk Management
✔ Defence Supply Chains (Cyber Security Model)
✔ Operational Resilience & Security
This event is worth making time for.

If you're attending, let us know in the comments and we'd love to connect.

See you at Olympia London.
📅 29–30 September

Address

Kingston Upon Hull
HU106RJ

Alerts

Be the first to know and let us send you an email when Pera Prometheus Consulting Ltd posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Pera Prometheus Consulting Ltd:

Shortcuts

Share