Under CSM v4, Cyber Essentials is Non-Negotiable 

Cyber Essentials

Key Takeaways  There is a persistent misconception across the UK defence supply chain that the Cyber Security Model (CSM v4) has replaced Cyber Essentials. It hasn’t. Since CSM v4 became mandatory in December 2025, some defence SMEs have quietly dropped their Cyber Essentials renewals on the assumption that the new framework covers the same ground. That assumption costs […]

MOD Formally Confirms DCC as Proof of DEFCON 658 Conformance

Gareth Shaw, MD Pera Prometheus Key Takeaways Defence Cyber Certification (DCC) launched in May 2025, but its validity as proof of conformance with the Cyber Security Model (CSM) was not formally acknowledged by MOD until now (30 Mar 2026). In addition, there has been a degree of confusion as to the scope and breadth of […]

No Framework, No Safety: Information Security and Cyber Resilience for UK SMEs

Key Takeaways Most businesses have some form of information and cybersecurity in place. Antivirus software, reasonably strong passwords, maybe a firewall. The problem is that having a handful of tools is not the same as having a plan. Without something to connect them, a framework, you end up with security that covers the obvious things […]

IPSA Is Not an HR Process, It’s Your First Line of Defence Against Insider Threat

Key Takeaways Picture this. A small defence contractor spends months earning their IPSA (Industry Personnel Security Assurance) accreditation. The processes in the PRF have been accepted by the Industry Security Assurance Centre (The Authority) and you can now manage your own security clearances. Then, twelve months later, a member of staff with security clearance leaves […]

ISO 27001 Checklist: Giving Information Assurance to potential Clients

ISO 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). In the defence supply chain, it can carry particular weight because the information you handle, technical drawings, project timelines, personnel data, classified correspondence etc. often have implications that go well beyond your own organisation. Your clients need to have confidence your business […]

Cyber Essentials is Changing in April 2026: Is Your Organisation Ready?

Key Takeaways Cyber Essentials has always been more than a box-ticking exercise. For organisations working within the UK Defence supply chain, it is a baseline contractual requirement and one of the first things a procurement team will check before a contract is awarded. But the scheme is not static. From 27 April 2026, a new […]

IPSA Requirements Explained: What MOD Contractors Must Demonstrate

Key Takeaways • People First: IPSA (Industry Personnel Security Assurance) focuses on the management and aftercare of vetted staff, distinct from physical security. • Mandatory Roles: You must appoint a Board Level Contact (BLC) and a Personnel Security Controller (PSC). • Prerequisite for FSC: If you require Facility Security Clearance to store assets, you must […]