Skip to main content

Cyber Essentials Alignment

Supporting Cyber Essentials Plus requirements with documentation and drills.

Cyber Essentials Support

CrownSync Playbooks helps organisations preparing for Cyber Essentials and Cyber Essentials Plus (CE+) assessments by providing documented incident response procedures, drill evidence, and audit trails that assessors look for when evaluating your organisation's security posture.

Incident Response Documentation

While Cyber Essentials focuses primarily on technical controls (firewalls, secure configuration, access control, malware protection, and patch management), assessors increasingly expect organisations to demonstrate how they would respond to a security incident. CrownSync Playbooks provides:

  • Documented procedures— Customised playbooks that describe your organisation's specific response to common threats, including ransomware, phishing, and data breaches
  • Escalation paths— Clear documentation of who is responsible for what during an incident, aligned with your chosen incident command model
  • Communication plans— Pre-prepared templates for notifying regulators, staff, and affected parties

Cyber Essentials Plus Requirements

CE+ assessments include hands-on technical verification and often involve questions about your incident response capability. CrownSync Playbooks supports CE+ assessment evidence in several areas:

  • Malware response— Playbooks for ransomware, malware infection, and endpoint compromise demonstrate your documented response to malware incidents
  • Email compromise— The Business Email Compromise playbook shows your procedure for detecting and responding to email-based attacks
  • Access control incidents— Playbooks for credential theft and unauthorised access show your response to access control failures

Assessment Preparation

Before a CE+ assessment, run a drill against your most relevant playbooks. The drill report provides concrete evidence that your team has tested its incident response procedures, which assessors view favourably.

Drill Reports for Auditors

Tabletop exercises conducted through CrownSync's drill mode produce structured reports that demonstrate your team's preparedness. These reports include:

  • The scenario tested and its relevance to your risk profile
  • Team members who participated
  • Actions taken during the exercise
  • Time taken to complete each phase
  • Findings and improvement actions

Drill reports can be exported as signed PDFs with QR verification codes, providing tamper-evident documentation suitable for assessor review.

Audit Trail

The immutable audit log provides a continuous record of all platform activity, demonstrating that your incident response procedures are actively maintained and used rather than being shelf-ware. This is particularly valuable during CE+ assessments where assessors look for evidence of ongoing security management.

Cyber Insurance Renewals

Many cyber insurance providers now require evidence of incident response planning as part of their renewal process. CrownSync Playbooks provides the documentation, drill evidence, and audit trails that insurers look for when assessing your organisation's risk profile. The Executive Summary report is designed to be included in insurance renewal submissions.

Was this page helpful?