Attackers don't hack in. They log in.
Stolen credentials, partial multi-factor authentication, misconfigured Conditional Access. Most UK SMEs are exposed not because they lack tools, but because the tools they have aren't properly tightened.
43% of UK businesses identified a breach or attack last year.
Stop hoping. Start proving.
Malwise is a Salisbury-based UK Cyber Security consultancy and licensed IASME Certification Body. We certify Cyber Essentials and Cyber Essentials Plus, test what defends you, and harden the environments your business actually runs on. Whether a customer is asking, a renewal is due, or you simply want to know where you stand.
Source: Cyber Security Breaches Survey 2025/26, DSIT and Home Office

30 minutes with a Senior Consultant. No commitment. No sales pitch.
Start with the wording in your contract, renewal notice or testing brief. These services answer different questions.
An independently verified self-assessment of essential technical controls. First certification or annual renewal.
From £320 + VAT
By organisation size · assessment only
Technical verification of a sample of the certification controls. Understand scope, preparation and the total cost.
From £1,415 + VAT
Cyber Essentials and Plus together
Manual, scoped testing of an application or environment. Practical findings for your business and IT provider.
From £1,600 + VAT
Two tester-day minimum · scope agreed
Based in Salisbury. Working across Wiltshire, Dorset, Hampshire, Bristol, Portsmouth and the wider UK.
An IT provider with a client who needs certifying? How we work with IT providers →
The patterns we see again and again, across UK businesses of every size.
Stolen credentials, partial multi-factor authentication, misconfigured Conditional Access. Most UK SMEs are exposed not because they lack tools, but because the tools they have aren't properly tightened.
Required for certain government and defence supply chain contracts, and increasingly requested by commercial customers and insurers. Most failures aren't from lack of effort, but from misreading the questions.
Independent assessment and testing can strengthen the support you already have. Agree who provides evidence, who makes changes and how findings are handed back.
From frontline testing to strategic advice. Focused capabilities that meet real obligations.
Simulated attacks across web apps, cloud infrastructure, and internal networks. Delivered by Cyber Scheme Certified Testers.
Read moreContinuous or one-off scanning across your websites and infrastructure. Know what's exposed, week after week.
Read moreAs a licensed Certification Body, we deliver Cyber Essentials and Cyber Essentials Plus directly. Assessment, audit and certification under one roof.
Read moreTrust, but verify. A vendor-neutral audit of your security posture, whether managed in-house or by a third-party provider.
Read moreTenant configuration review, Conditional Access hardening, multi-factor authentication enforcement, Entra ID audit. The cloud most UK businesses live in, properly secured.
Read moreRisk assessments, security architecture, incident response planning, M&A due diligence. Senior advice without the senior consultancy fees.
Read moreImplementation support to get you certified, or independent internal audit to keep you there. Gap analysis first, always.
Read moreSenior security leadership and hands-on programme management, a few days a month, without the full-time salary.
Read moreGovernance, risk and data protection assessed across fourteen themes. Level One is a verified assessment, Level Two adds an independent audit. Certified by us directly.
Read moreEvery engagement follows the same arc: understand, test, report, fix, verify.
Free 30-minute call. We understand your business, your risks, your obligations.
Fixed-price proposal. Methodology, timeline, deliverables. No hidden extras.
Named delivery responsibilities, appropriate methods and clear communication throughout.
Executive summary. Technical detail. A remediation plan your team can actually act on.
Reporting, debrief and any included retest are defined in your proposal.
Penetration testing costs vary because no two assessments are quite the same. The time required depends on what is being tested, the …
A supplier receives a Ministry of Defence (MoD) contract, finds a clause called DEFCON 658, and asks whether Cyber Essentials covers it. No. …
Both levels certify against the same five technical controls. The difference is who checks that the controls are actually in place. Cyber …
Search for the cost of a Cyber Security audit and you will find almost nothing useful. Page after page explains why audits matter, then asks …
Nobody asks this question casually. It is asked quietly, usually by someone who has read the question set properly for the first time and …
Ask an organisation how many administrator accounts it has and you will usually get a number. Ask it to list them and the number changes. …