A cyber health check is a structured look at how exposed your business is, covering the devices you own, who can get into them, whether they are patched, whether your backups work and what happens when something goes wrong. It is a snapshot, not a certification, and the useful version ends with a short list of things to fix first.
Most UK businesses have never had one. The government’s Cyber Security Breaches Survey found that 43% of businesses identified a breach or attack in the last 12 months, while only 30% had carried out a risk assessment covering cyber security. More businesses were attacked than checked whether they could be.
You can run the public-facing half of a cyber health check yourself, free, in about ten minutes. What you cannot do alone is judge whether what it finds actually matters to your business.
What Does a Cyber Health Check Actually Look At?
Seven areas, in roughly this order. What devices and accounts exist. Who can log into them and how. Whether updates are being applied. Whether malware protection is running. Whether backups exist and have been restored from. Whether anyone is watching for attacks. And what the plan is when one lands.
The first five map almost exactly onto the five Cyber Essentials controls, which is not an accident. That scheme exists because those five stop most opportunistic attacks. If you want the detail and the cost of going further, Transputec has written about what Cyber Essentials costs in the UK separately.
The last two are where most businesses come unstuck. Monitoring and incident response are not covered by Cyber Essentials, they cost real money, and they are the difference between finding out about a breach yourself and finding out from a customer.
Can You Run the Basics Yourself for Free?
Yes, and you should do it before paying anyone. The NCSC runs a free service called Check your cyber security which scans your public-facing systems using the same openly available information an attacker would use. No registration, no downloads, and it is built for organisations without a security team.
It covers three things: a website and IP check, an email security check, and a web browser check. Alongside it sits the NCSC’s Cyber Action Plan, which takes under five minutes and returns tailored advice. Both are part of the wider NCSC guidance for small and medium organisations.
Run those first. They are genuinely good, they are free, and any provider who does not mention them is either unaware of them or hoping you are. What they will not do is look inside your network, and that is the honest limit of a free scan.
Want a Second Opinion on What You Found?
Transputec runs six cyber security services under one accountable UK SOC: 24/7 managed SOC with human analysts on every shift in London, MDR, penetration testing and vulnerability management, with escalation under contracted MTTR and monthly reporting your auditor and board can both read. Book a free Cyber Health Check consultation and talk to our team about the security work behind what your scan turned up.
Get a Strategic ConsultationWhy Have So Few UK Businesses Checked?
Because nothing forces them to, and because the work has no obvious owner. Cyber security is the sort of thing that stays fine right up until it is not, and a business with no incidents has no feedback telling it the controls are thin. The numbers show how wide that gap has become.
From the same government survey: 30% of businesses conducted a risk assessment covering cyber security, 18% carried out a vulnerability audit, and 13% ran penetration testing. Meanwhile 43% identified a breach or attack, rising to 65% of medium businesses and 69% of large ones.
Strategy is thin in the same way. Among medium businesses 57% had a formal cyber security strategy, and 74% of large ones. Below that size it drops away quickly. And 44% of businesses sought external information or guidance, which means more than half are working it out alone.
None of that is negligence. It is what happens when a job belongs to nobody in particular. Which is also why the answer is rarely a tool, and usually a decision about who owns this.
Free Scan or Full Health Check: What Each One Covers
They answer different questions. A free scan tells you what an attacker can see from outside. A health check tells you what would happen if one got in. Both are worth having, and the order matters: run the free one first so the paid conversation starts from evidence rather than from a blank page.
| Area | Free NCSC tools | A full cyber health check |
|---|---|---|
| Public-facing systems | Yes, website, IP and email checks | Yes, plus what sits behind them |
| Internal devices and accounts | No | Yes, inventory, admin rights, MFA coverage |
| Patching and updates | Partial, only what is visible outside | Yes, across the estate |
| Backups and restore testing | No | Yes, including whether a restore has been proven |
| Monitoring and detection | No | Yes, whether anyone is actually watching |
| Incident response readiness | No | Yes, the plan and whether it has been tested |
| Judgement on what matters most | No, it returns findings | Yes, that is the point of it |
The last row is the one that earns the fee. A scan produces a list. Knowing which three items on that list would actually hurt this business, in this sector, with these customers, is a judgement call, and it is the part no tool makes for you.
What a Cyber Health Check Will Not Tell You
It will not certify you, and it will not promise you are safe. A health check is a point-in-time view. It cannot tell you that you will not be breached, because nobody can, and any provider offering that is selling something other than security. It is also not a substitute for an accredited assessment.
Three limits worth knowing before you book one.
It is a snapshot, and estates move. A check that was accurate in October describes an October estate. New starters, new suppliers and new software all change the picture, which is why the output should be a short list of fixes rather than a document to file.
It does not replace certification. Cyber Essentials and ISO 27001 are awarded by accredited bodies, and an advisor cannot award either to their own client. A health check can tell you how far off you are. It cannot pass you.
And it does not fix anything by itself. Transputec sees this often: the check happens, the list gets written, and nothing changes because no budget or owner was attached to it. Agree who is doing the work before the check, not after.
What Should Happen After the Check?
Three things, and none of them is a filing cabinet. The findings get ranked by what would hurt most, not by how many there are. Each of the top items gets an owner and a date. And somebody books the follow-up, because the only thing that proves a health check worked is the second one looking better than the first.
Rank by consequence rather than by count. Forty low findings matter less than one unpatched internet-facing server. A long list sorted by severity is useful; a long list sorted by category is paperwork.
Start with the things that cost nothing. Turning on multi-factor authentication, removing leavers’ accounts and switching on automatic updates are usually free, and they close more real attack paths than most purchases do. Spend money only on what is left after that.
Then decide what you are buying, if anything. Sometimes the answer is monitoring. Sometimes it is incident response cover. Sometimes it is nobody owning security at all, which is a different problem and one we cover in our post on what a virtual CISO does.
How Do You Get the Most From a Free Consultation?
Turn up with evidence and a question. The conversations that go somewhere start with the output of a free scan, a rough idea of how many devices and staff you have, and one thing the business is actually worried about. The ones that go nowhere start with nothing and end with a generic recommendation.
Bring four things if you can: how many staff and devices, whether multi-factor authentication is on for email, when a backup was last restored from, and what your insurer or biggest customer has asked you about security. Those four answers shape almost every recommendation worth making.
Ask what the person would do first with your budget, and why. An answer that starts with a product name before they have asked about your business is a bad sign. An answer that names something free is usually a good one.
Your Checklist Before You Book One
Work through these before you book anything.
- Run the NCSC’s free checks first. Website, IP, email and browser. Keep the output.
- Count your devices and accounts, including the ones nobody uses any more.
- Check multi-factor authentication is on for email and remote access, for everyone.
- Find out when a backup was last restored from, not when one was last taken.
- Write down who would be called first at 2am, and whether they know that.
- Note what your insurer and your largest customer have asked about security.
- Decide who owns the fixes before the check, and roughly what budget exists.
Conclusion
A cyber health check is worth having, and it is worth being clear about what it is. It is a snapshot of how exposed you are, ending in a short ranked list of things to fix. It is not a certificate, not a guarantee, and not a substitute for someone owning security the rest of the year.
Start with the free NCSC checks, because they cost nothing and they narrow the conversation. Then decide whether what they found needs a second opinion. Transputec offers a free Cyber Health Check consultation, and runs the cyber security services behind it when the answer turns out to be yes. Talk to us about the security work behind what your scan turned up.
FAQs
How Long Does a Cyber Health Check Take?
The free NCSC scans take about ten minutes. A fuller review depends on the size of the estate and how much documentation already exists, and most of the elapsed time goes on gathering information rather than on analysis. If you have a device list, an account list and a recent backup report ready, it moves considerably faster.
Is a Cyber Health Check the Same as a Penetration Test?
No. A health check is broad and shallow: it looks across devices, accounts, patching, backups, monitoring and response to find obvious gaps. A penetration test is narrow and deep: someone actively tries to break in and shows you how far they got. Only 13% of UK businesses run penetration tests, and they are usually the right next step after a health check rather than instead of one.
Does a Cyber Health Check Make Us Cyber Essentials Certified?
No. Certification is awarded by an accredited certification body, and an advisor cannot award it to their own client. What a health check can do is tell you how close you are to the five controls and what stands between you and a pass. The assessment itself has to come from outside.
How Often Should We Do One?
Annually is a reasonable default for a stable business, and after any significant change is a better trigger than a date. A merger, a new office, a move to a new cloud platform, a round of leavers or a new major customer all change your exposure more than twelve months of nothing happening does. Run the free NCSC checks more often than that, since they cost nothing.
What Does the Free Consultation Involve?
It is a conversation rather than an audit. You talk through what you have, what the free scans found and what the business is worried about, and Transputec’s team gives a view on what to deal with first. If the answer is that your basics are already sound, that is a legitimate outcome and you will be told so.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



