Cyber Essentials Plus

To meet the Cyber Essentials criteria the University must meet strict requirements for:  

The criteria that must be met include: 

  • Secure Configuration
  • Secure Firewall and Internet Gateways
  • Control Access to Data
  • Malware Protection
  • Patch Management

For more detailed information on the requirements listed above, please visit the Cyber Essentials website

There are two levels to Cyber Essentials. There is the standard Cyber Essentials accreditation and then there is Cyber Essentials Plus. Cyber Essentials Plus brings the evaluation process one step further as it requires an audit from a qualified third-party assessor in addition to the self-assessment survey required for the standard Cyber Essentials certification. 

You can search for organisations that hold Cyber Essentials and Cyber Essentials Plus certification on the IASME Consortium website.

Having this accreditation assures current and potential business partners that we hold our cyber security to the highest standard and have proven that we meet the requirements outlined in this Government supported scheme. By having this certification, the University is equipped to deal with government data opening doors to potential new research opportunities for staff and students. 

For more detailed information about Cyber Essentials, please visit the National Cybersecurity Centre website,

Serious about cybersecurity

Anthony Cotton, from Digital Services & Solutions, responsible for much of the work that involves achieving Cyber Essentials Plus explains: 

“The University of Derby was the first University to achieve Cyber Essentials when the scheme came out in 2014. It’s a constant game of cat and mouse with the hackers, so the assessment gets tougher every year. Our auditors are Jisc, who understand the complexities of a large educational institution. It’s a team effort across the departments, with work going on all the time to ensure the University is secure.” 

The University of Derby is Cyber Essentials Plus Certified

Cyber Essentials is an assessment scheme, sponsored by the UK Government, which requires the assessed institution to prove annually that they adhere to the government criteria for cyber security. The University of Derby has been Cyber Essentials Plus accredited since 2019.


Cyber Essentials Plus Logo