
Jamie Levers
Security Consultant at URM Consulting and a Cyber Essentials / Cyber Essentials Plus certified assessor, with a background in penetration testing and offensive security.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Aug 20, 2026
Cyber Essentials 2026 – Lessons Learned From Actual Assessments
14:00
14:18
14:30
14:52
32:52

Lauren GottingGUEST
So as we've conducted a number of assessments, what lessons have we learned as an assessment body that we can sort of pass over to applicants?

Jamie LeversGUEST
We've had a number of organisations that maybe thought something could be out of scope when it couldn't.

Jamie LeversGUEST
If the assessment isn't scoped correctly and you move on to CE+, when we come to conduct the technical scope verification, if we see something that doesn't add up, you'll have to go back and redo the cyber essentials questionnaire so that it does match up.

Jamie LeversGUEST
And again, like you said, many people finding this out with excluding test and development networks maybe they're part of a group and they've previously done whole organization but now they can't because of the statements for designating who can and who can't be whole organization that ties in quite nicely with the next point so if you're not doing whole organization segregation has to be network based and that is VLAN or firewall, so layer two or layer three of the OSI model.
17 MINS LATER

Lauren GottingGUEST
Jamie, so from your perspective, from a certification body's perspective, what obviously we said a lot about what, you know, what to do, right? How How to do this and what are the steps? What steps should people be taking, whether it's research or fresh certification?