Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Remediation at scale

Getting a client base ready, not one client at a time

Certifying clients one by one means solving the same five problems repeatedly and billing for none of them. Solved once across the estate, it becomes a product.

Cyber Essentials for MSPs › Getting a client base ready

The usual pattern is reactive. A client is asked for Cyber Essentials, you scramble, you discover their estate has four problems, you fix them, you get the certificate, and eight weeks later a different client is asked for Cyber Essentials and you discover their estate has the same four problems.

After the third or fourth time it becomes obvious that the work is not client-specific. Roughly eighty per cent of what stops a small organisation passing is the same eighty per cent every time, and it is a function of how the estate was built rather than what the business does.

Which means it can be solved once, at the tenancy template level, and then rolled.

The failure points that repeat

Start from what actually causes trouble rather than from the five controls, because the controls are the framework and these are the findings.

Recurring blockers across a typical MSP client base
BlockerWhy it recursStandardise as
Standing local administrator rightsGranted during a migration and never withdrawn, or granted to stop a ticket recurringSeparate administrative accounts, no day-to-day account with local admin, a documented elevation route
Multi-factor authentication on some cloud servicesEnabled on Microsoft 365 and forgotten everywhere else, or enforced with legacy exclusions still liveA conditional access baseline applied per tenant, with an exclusion register reviewed quarterly
Unmanaged and personally owned devicesDirectors, contractors and sales staff who were never enrolledA single enrolment position per client, written down, with a named exception process
Software updating within fourteen daysOperating system patching is managed, third-party applications and browsers are notUpdate rings covering the operating system, browsers and the common third-party applications, with reporting
Unsupported operating systems or applicationsOne machine, usually attached to a specific piece of business softwareAn end-of-life register per client, reviewed against vendor roadmaps twice a year
Firewall and router configurationDefault credentials, remote administration left enabled, or no documented rule setA standard build for supported hardware, documented, with a configuration record per site
No asset registerNobody owned it, or it was accurate in 2021Inventory pulled from device management rather than maintained by hand
Leaver accounts still enabledThe joiners and leavers process is an email to the helpdeskA documented process with a named owner on the client side and a monthly reconciliation

Every one of those is a configuration position rather than a piece of bespoke work. That is the whole opportunity.

Build the baseline once

Before touching any client, write down what a compliant client looks like in your stack. Not a policy document for a shelf: the actual configuration, expressed in whatever you deploy with.

For most MSPs that means a device management baseline, a conditional access policy set, an update ring configuration, a standard administrative account model, a firewall build standard and a short set of written procedures the client owns rather than you. Give it a version number. You will change it, and you need to know which clients have which version.

Two things are worth deciding at this stage rather than per client. First, what your default position is on personally owned devices, because it is the single most expensive question to answer twice. Second, what you will do about clients who refuse part of the baseline, because you will have some, and an exception needs to be recorded rather than argued about annually.

Grade the book before you touch it

Run a short assessment across every managed client against the baseline, and sort them into three groups. This takes a couple of days for a book of thirty and it is the highest-value two days in the whole exercise.

Sorting matters because the temptation is to start with the client who is shouting, and the client who is shouting is usually in the third group. Starting there means your first attempt is your hardest one, and the project loses momentum before it has produced anything.

Run it in waves

Take the close group first, five or six clients together rather than sequentially. Apply the baseline, fix what the assessment found, submit them in the same fortnight. You get certificates on the board quickly, your team learns the questionnaire properly on the easiest cases, and you find out where your baseline is wrong while the cost of being wrong is low.

Then the second group, in waves of whatever your capacity supports. By the third wave the remediation is a checklist rather than a project, and the time per client falls sharply.

Leave the structural group until last and treat each as its own piece of work. Some of them will not certify this year, and knowing that early is worth more than a heroic effort that fails.

The asset register is the bottleneck

More certifications stall on knowing what is in scope than on any technical control. The questionnaire asks for counts of devices by type and operating system version, and the honest answer for a lot of small organisations is that nobody knows.

Solve this structurally and you solve it for every client at once. Inventory should come out of your device management platform, not out of a spreadsheet somebody maintains. Anything accessing organisational data and not appearing in that inventory is either an enrolment job or a scoping decision, and it is far cheaper to find those in a quarterly reconciliation than in the week before a submission deadline.

A book where every client has a current, tool-generated inventory can answer the scoping questions in minutes. A book where they do not will lose a day per client, every year, forever.

Turning it into a product

Once the baseline exists and the waves are running, the work is repeatable enough to price as a product rather than quoting it fresh each time. Three components cover most of it.

A fixed-fee readiness assessment

Your baseline check against one client’s estate, producing a written list of gaps, an estimate to close them and a realistic date. Sold on its own, it is a low-commitment first step for clients who are nervous. A formal gap analysis through us runs at £300 plus VAT direct, which gives you a reference point for what to charge for your own version or when to place ours instead.

A remediation package

Fixed scope, fixed price, tiered by which of the three groups the client landed in. This is the piece that carries the margin, and it is defensible precisely because the assessment produced a list rather than an opinion.

An annual recertification retainer

Cyber Essentials is annual. Sell the renewal as a small recurring line covering the baseline review, the evidence refresh and the submission, and it stops being a scramble every twelve months. It also fixes the renewal date in your system rather than the client’s inbox.

Price the certificate itself alongside those rather than inside them, so the client can see what they are paying for. Our direct prices are published by size band, from £320 plus VAT for one to nine staff, £440 for ten to forty-nine, £500 for fifty to two hundred and forty-nine and £600 for two hundred and fifty and over, plus £100 for urgent turnaround. Partner terms are preferential against IASME’s fee bands and are agreed with you directly.

What does not standardise

Be realistic about the limits. Scope boundaries in an organisation with subsidiaries or shared premises are a judgement call every time. Clients with an operational technology estate, a specialist line-of-business application or a regulated data set will need individual thought. So will anyone whose staff work substantially from personal equipment, where the answer is a policy decision the client has to make rather than a control you can deploy.

Everything else is the same work repeated, and repeated work is either a cost you absorb or a product you sell. It is entirely your choice which.

How long does it take to get a book of thirty clients certified?

Realistically six to nine months from a standing start, and most of that is client availability rather than technical work. The baseline takes a week or two to define properly, the grading pass a couple of days, and each wave of five or six clients runs over roughly a month. The structural group is unpredictable because it depends on budget conversations you do not control.

Should we certify ourselves first?

Yes, and not only for the obvious credibility reason. Running your own submission teaches your team what the questionnaire actually asks, which is different from what people assume it asks, and you will find gaps in your own estate that also exist in your clients’ estates because you built both the same way.

What do we do about a client who refuses part of the baseline?

Record it as a documented exception with the client’s decision and your advice against it, and reprice the account if it materially changes your risk. Some exceptions are compatible with certification and some are not, and knowing which is which before submission is the point of the readiness assessment. What you should not do is carry an undocumented exception forward.

Is it worth doing this for clients who have not asked for Cyber Essentials?

The baseline work, yes, because it reduces your support load and your own risk whether or not anybody certifies. The certification itself should wait for a reason: an insurance renewal, a tender, a large customer’s supplier review, or an MoD-linked client facing the Defence Cyber Certification deadline of 31 December 2026. Clients buy certificates when somebody asks them to.

Placing the work once the estate is ready

Assessment is within one business day of submission as standard, and the same day with the urgent option where the submission arrives before midday, which makes wave submissions practical. Tell us what your book looks like and we will send partner terms.