top of page
East-Coast-Controls-Distech-Controls-Panel.jpg

Cyber Essentials Plus

East Coast Controls have achieved Cyber Essentials Plus, the UK Government-backed standard for verified cyber security, giving our clients independently tested assurance that the systems behind their buildings are properly protected.

Cyber-Essentials-Plus-Logo-web.png

What Cyber Essentials Plus means

Cyber Essentials Plus is the higher of the two tiers within the UK Government's Cyber Essentials scheme, backed by the National Cyber Security Centre (NCSC). Unlike the base-level Cyber Essentials certification, which relies on self-assessment, Cyber Essentials Plus requires an independent, hands-on technical audit of our systems, devices, and processes.

A qualified external assessor tests our defences directly - checking our patching, access controls, malware protection, firewall configuration, and device security - rather than simply reviewing a questionnaire. Passing that audit means our cyber security controls have been verified to work in practice, not just on paper.

Why this matters in the Building Management industry

Building Management Systems (BMS) sit at the intersection of IT and the physical world. They control heating, cooling, lighting, access control, fire safety, and increasingly a growing web of connected IoT sensors and controllers - which makes cyber security a building safety issue, not just an IT one.

24/7

Connected building systems run continuously, expanding the attack surface

1000's

Of networked IoT sensors and controllers can exist in a single site

1

Weak link in the supply chain can compromise an entire building network

  1. BMS and IoT devices are prime targets
    Controllers, sensors, and gateways are often deployed for years without update cycles as robust as standard office IT, making them an attractive route into a wider network for attackers.

     

  2. A breach isn't just data loss - it's physical disruption
    A compromised BMS can mean lost heating, disabled access control, tampered fire and safety systems, or a shut-down plant room, with real operational and safety consequences.

     

  3. Buildings are part of a wider supply chain
    Attackers increasingly target smaller contractors and suppliers as a way into larger client networks. Certified suppliers reduce that risk for everyone in the chain.

     

  4. Regulation and procurement expectations are rising
    More public sector and enterprise contracts now require verified cyber security credentials from contractors and installers before work can even be tendered for.

Why it pays to work with a cyber-aware partner

Reduced risk exposure

Independently tested controls around access, patching, and malware protection lower the chance that your buildings become an entry point for wider attacks.

Operational continuity

Well-secured systems are less likely to suffer disruptive downtime, protecting comfort, safety, and productivity across your sites.

Compliance confidence

Working with a certified supplier helps satisfy your own procurement, insurance, and regulatory requirements around third-party cyber risk.

Long-term trust

Verified accreditation is evidence, not a promise — giving you a partner whose security claims have actually been tested by an independent assessor.

East-Coast-Controls_Accreditations-Logos.png

A controls partner you can verify

Our Cyber Essentials Plus certification is independently verifiable at any time. If you'd like to discuss how we secure the building management and IoT systems we install and support, we'd be glad to talk.

image_edited.png
bottom of page