Penetration-grade scanning, triaged by AI you own.
We assess your estate with the same multi-engine tooling a red team uses, then have a private language model — running on hardware we control — prioritise every finding and map it to Cyber Essentials. No raw scanner dump. No data sent to a third party. A report you can act on and defend.
Tamper with one line of the log and the chain breaks — the evidence is verifiable, not just printable.
Cyber Essentials just got stricter, and it's no longer optional.
From 27 April 2026 UK assessments run against the v3.3 requirements (the Danzell question set). The bar moved, and certification is increasingly a condition of doing business.
MFA enforcement
Under v3.3, any internet-facing service that offers multi-factor authentication and hasn't enabled it is now an automatic failure — no warning, no pass.
Patch window
High and critical updates — including firmware — must be applied within 14 days across everything in scope. Unsupported software fails.
Public-sector tenders
Cyber Essentials is a baseline requirement on a growing list of UK government and enterprise contracts. No certificate, no conversation.
Insurers & clients
Cyber insurers and larger customers now ask for certification in due diligence. The NCSC's supply-chain guidance pushes it down to suppliers.
One assessment. Network and AI systems. Your hardware.
Most scanners hand you a wall of raw output and call it a report. We built an engine that does the hard part — fusing the scan, judging it, and tying it to the standard you're assessed against.
Breadth and depth
A fast full-range port sweep feeds precise service and vulnerability detection, alongside modern templated CVE, web and TLS checks. Coverage without the blind spots of a single tool.
Your data never leaves
Triage runs on a private model hosted on hardware we control — nothing is sent to a third-party API. The honest answer to the GDPR and confidentiality question your clients will ask.
Signal, not noise
The model flags likely false positives, ranks what to fix first, writes the business impact in plain terms, and maps each finding to the relevant Cyber Essentials control.
Red-team your LLM
Deploying a chatbot or AI feature? We probe it for jailbreaks, prompt injection and data leakage with industry red-team tooling — the attacker model stays local too.
Evidence you can defend
Every step of the assessment is cryptographically chained. The audit trail is verifiable end to end — defensible if a finding is ever challenged.
Mapped to the standard
Network findings and AI-security results land in a single Cyber Essentials view, with a clear status against each of the five controls and an honest note on what only a hands-on audit can confirm.
Hardware security keys — closing the control a scan can't.
Under Cyber Essentials v3.3, missing MFA on an internet-facing service is now an automatic failure — and the scheme actively pushes passwordless and FIDO2 passkeys. Passwords and SMS codes get phished; hardware keys are phishing-resistant by design. Deploying and supporting them is a core focus for us, from strategy to day-to-day lifecycle.
Audit & rollout plan
We map where strong authentication is missing, choose the right key (YubiKey 5, Security Key, Bio) and design the rollout — privileged accounts first, then the whole team.
Go passwordless
We configure phishing-resistant, passwordless sign-in — passkeys, FIDO2, PIV/smartcard, OTP — aligned with the v3.3 MFA requirement and passkey direction.
Into your stack
Microsoft Entra ID, Okta, Google Workspace, VPN, SSH and secret managers. The key works everywhere your team signs in.
Enrolment, recovery, break-glass
Issuance and return procedures, break-glass emergency accounts, policy, user training and lost-key support. Security that holds up in daily use.
We're a deployment and technical-support partner for hardware security keys — we advise on selection and procurement; key hardware is costed per model and headcount.
The five controls, scored against your real estate.
We map findings to each control and tell you the truth about coverage: an external scan can evidence some controls directly, while others need a hands-on audit or the questionnaire. We never tick a box the scan can't support.
Controls marked “audit & SAQ” can't be confirmed by an external scan alone — we flag them for hands-on verification rather than overstating readiness.
Premium, fixed-scope engagements. We don't discount security.
These are senior-level offensive-security engagements, priced accordingly. We confirm exact scope and a fixed quote before any work begins — the price is the price. When it comes to security, the cheapest assessment is the one that misses what matters.
CE Gap Analysis
- Multi-engine scan of agreed scope
- AI triage: priorities & false-positive filtering
- Mapping to all five CE v3.3 controls
- Plain-English remediation report
- Tamper-evident audit trail
Full Assessment + CE Support
- Everything in Gap Analysis
- Manual review by a red-team consultant
- CE / CE Plus readiness & evidence pack
- Guided support through certification
- Remediation re-test included
AI Security Gap Analysis
- Red-team of your LLM / chatbot
- Jailbreak, injection & leakage probes
- Mapped to OWASP-LLM categories
- Runs fully local — sovereign
- Findings in the same dashboard
YubiKey / FIDO2 Rollout
- MFA audit & strong-auth strategy
- FIDO2 / WebAuthn / passwordless setup
- Entra ID / Okta / Google integration
- Enrolment, break-glass, policy
- Team training & ongoing support
Managed Assurance
- Recurring scheduled scans
- Drift & new-exposure alerts
- Renewal preparation
- Quarterly posture review
- Priority remediation guidance
Each engagement is scoped and fixed before work begins; the floor prices above reflect senior-level work and are not discounted. Final price depends on the size and complexity of the in-scope environment. CyberSentinel Solutions Ltd provides Cyber Essentials readiness, assessment and remediation support; certification is issued by an IASME-accredited Certification Body.
From scope to certificate-ready, in a clear line.
Scope & authorise
We agree exactly what's in scope and capture written authorisation. The scope is the first link in the audit chain — assessment only ever runs against what you've approved.
Scan
Multi-engine discovery and vulnerability detection across hosts, services, web and TLS — plus AI-system red-teaming where relevant.
AI triage
A private model prioritises findings, filters noise, writes the business impact and maps each issue to the right Cyber Essentials control.
Report
You receive a dual report — an executive summary for the board and a technical breakdown for whoever fixes it — plus the consolidated CE dashboard.
Remediate & certify
We support the fixes, re-test, and walk you through certification with an accredited body. You end up certified, not just scanned.
A UK offensive-security practice, not a checkbox factory.
Find out where you stand — before an assessor does.
Send us your rough scope and we'll come back with a fixed quote and a date. Most gap analyses are scoped within a day.