Cyber Security
Frequently Asked Questions

Frequently Asked Questions

Straight answers about who we work with, how engagements run, and the government assurance obligations that most often bring people to us.

About E2E Security Consulting

Who we are, who we work with, and how we operate.

What does E2E Security Consulting do?
We are a specialist cyber security and assurance consultancy working with UK government, critical national infrastructure and regulated organisations. Our work spans risk management, security architecture, assurance against government frameworks, supply chain assurance, testing and data protection. See all services →
Which sectors do you work in?
We focus on UK government and the regulated sectors — central government departments and their arm’s-length bodies, critical national infrastructure operators, and organisations subject to regulatory cyber obligations. These are environments where assurance has to stand up to external scrutiny rather than simply satisfy an internal audit.
Are you independent of technology vendors?
Yes. We provide objective, vendor-neutral guidance and are not a reseller for security products. Recommendations are based on what the risk warrants, not on commercial relationships with vendors.
Are your consultants security cleared?
We use security-cleared consultants for work that requires it. The level of clearance needed depends on the engagement and the environment, so it is agreed with you before work begins.
What certifications does E2E Security Consulting hold?
We hold Cyber Essentials and Cyber Essentials Plus. Both certificates are independently verifiable — the badges in our footer link directly to the certificate registry entries rather than to an image we host ourselves. What is Cyber Essentials? →

Services and engagements

How work starts, how it is scoped, and what to expect.

How does an engagement usually start?
It starts with a conversation about the problem rather than a fixed package. We establish what is driving the requirement — a regulatory obligation, an assurance deadline, a procurement question or an incident — then scope the smallest piece of work that answers it credibly. Get in touch →
Do you offer one-off assessments or ongoing support?
Both. Some organisations need a defined assessment against a framework; others need continuing capability they do not have in-house, which is where our virtual consultancy model applies. Assurance obligations such as GovAssure and supplier assurance are recurring, so a single assessment rarely resolves them permanently. Virtual cyber security consultancy →
How do you quantify cyber risk?
We use both qualitative and quantitative methods. Where a decision needs financial framing — comparing control investments, testing insurance adequacy, or presenting to a board — we apply quantitative approaches including FAIR and Monte Carlo simulation to express exposure in financial terms rather than as a colour on a heat map. Cyber risk management →
Which frameworks and regulations do you work with?
Our work covers the NCSC Cyber Assessment Framework, UK Government Secure by Design, ISO 27001, GDPR and UK data protection law, DORA, NIS2 and PCI DSS, among others. Which apply depends on your sector and where you operate. Browse the glossary →
Can you help suppliers responding to government security requirements?
Yes. Suppliers are increasingly asked for evidence mapped to specific framework outcomes rather than general security statements, because the department needs that evidence for its own assurance. We help suppliers understand what is actually being asked and produce evidence that answers it. Supply chain assurance →

Government assurance

The obligations that most often prompt organisations to contact us.

Do you support GovAssure submissions?
Yes. We support departments and arm’s-length bodies through scoping, CAF self-assessment and the independent assurance review, and we help suppliers answer the CAF-aligned questions that GovAssure pushes down the supply chain. What is GovAssure? →
Can you help us adopt Secure by Design?
Yes. Secure by Design is mandatory for central government departments and their arm’s-length bodies, and it is a way of working rather than a certificate to obtain. We help establish ownership, make risk-driven decisions, and build evidence that stays current as the service changes. What is Secure by Design? →
Is Cyber Essentials enough for a government contract?
It is mandatory for many UK central government contracts, and some require Cyber Essentials Plus. Whether it is sufficient depends on the contract and the information involved — it is a baseline against common untargeted attacks, not a substitute for wider assurance where the consequence of failure is high. What is Cyber Essentials? →
Does NIS2 apply to us as a UK organisation?
Not directly. The UK is not bound by NIS2 and retains its own NIS Regulations 2018. UK organisations are usually affected indirectly, either through EU operations or because an in-scope EU customer passes obligations down through contracts and assurance questions. What is the NIS2 Directive? →

The E2ERisk platform

How our software relates to the consultancy.

What is E2ERisk?
E2ERisk is our platform for managing cyber assurance work — supplier assurance, risk registers, control mapping, evidence and reporting in one place. It exists because the work we do for clients was otherwise being run on spreadsheets that could not keep evidence current or defensible.
Do I have to use the platform to work with you?
No. The consultancy and the platform are separate. Many engagements involve no platform at all, and the platform is used where continuing assurance needs to be maintained rather than captured once.
Does the platform replace the frameworks?
No. It does not introduce an alternative set of principles or a competing scoring method. It helps you operate the official frameworks more consistently, with better traceability between decisions, evidence and outcomes.

Still have a question?

If your question is about a specific obligation, a deadline or a procurement requirement, it is usually quicker to talk it through than to read around it.