What changed during the programme
Investment: independent findings supported the case for remediation budget.
Operations: vulnerability management moved towards Business as Usual rather than certification-time preparation.
Lifecycle: asset lifecycle management was strengthened so unsupported technology could be identified and managed earlier.
Outcome: the organisation successfully achieved Cyber Essentials Plus with a more sustainable foundation for maintaining the controls.
