How We Engage
Every engagement is different. Rather than a single rigid methodology, we adapt to the type of support you need — from formal CE/CE+ certification through our Certification Body partners, to strategic retainers and technical assessments. Below are the five engagement models we typically operate under.
CE/CE+ Consultation & Advisory
Pre-certification and advisory support for organisations preparing for Cyber Essentials or Cyber Essentials Plus. This is a pure advisory engagement — we assess your readiness, identify gaps, guide technical remediation, and prepare your team to meet the scheme requirements.
- Scope definition and boundary scoping guidance
- Gap assessment against current CE/CE+ question set
- Technical remediation guidance (patching, MFA, firewall rules, malware protection)
- Evidence preparation and document review
- Pre-assessment dry run and readiness sign-off
- Suitable for organisations approaching CE for the first time or preparing for renewal
CE/CE+ Delivery via Trusted Certification Body Partners
Where formal CE or CE+ certification is required, we deliver assessments through our trusted Certification Body (CB) partners. Wayne holds CE Assessor and CE+ Lead Assessor status, with the ability to conduct DCC Level 0 assessments. Formal certification is issued by the CB once the assessment is complete.
- Full CE or CE+ assessment conducted by Wayne as Lead Assessor
- DCC Level 0 assessments available
- Works alongside or independently of your internal IT team
- Access to multiple CBs for independence and flexibility
- IASME Governance assessed alongside CE+ where required
- Suitable for MOD supply chain, publicly funded bodies, or commercially mandated CE+
CE+ tools & readiness products
Productised readiness paths: Pre-Audit Checker for local endpoint evidence, fixed-scope endpoint readiness offerings, and Lead Assessor sign-offs when packs are already prepared.
- Desktop Pre-Audit Checker with HTML/JSON reports
- Optional readiness walkthrough and remediation sequencing
- Sign-off reviews with clear SLAs where advertised
- Lead magnet checklists and posture quiz for self-serve baselines
Security platforms
SaaS and portal products for compliance and workflow automation — Consent Platform, CE+ Certification Tracker (early access), and the Cyber Ask Platform.
- Self-serve or early-access product adoption
- Separate product client portal for CE-related SaaS
- Clear product scopes instead of open-ended programmes
Domains & secure hosting
Cyber Ask Domains: register and manage domains, DNS, renewals, and web hosting through a dedicated portal with security-minded operations.
- Domain search, registration, lock, EPP, nameservers
- Hosting packages with cPanel access where provisioned
- Invoices and support tickets in the Domains portal
- Separate login from the CE product client portal
Our Core Principles
Risk-Driven
We focus on material risks to your business. Recommendations are proportionate, not padded to justify fees.
Pragmatic
We work within your constraints — budget, team capacity, and existing technology. Advice is actionable, not theoretical.
Evidence-Based
Every finding is backed by evidence. Every recommendation has a clear rationale mapped to risk or requirement.
Independent
No vendor affiliations. No conflicts of interest. You get objective advice based solely on your needs.
Knowledge Transfer
We leave your team better equipped than when we arrived. Building internal capability is part of every engagement.
Principal-Led
Wayne delivers every engagement directly. No junior staff, no handover mid-project. One point of contact, consistent quality.
Not Sure Which Model Fits?
Get in touch and we’ll recommend the right engagement approach for your situation, budget, and timescales.