- Cloud Email
How to Manage Microsoft 365 Licences Cost-Effectively
9 Jul, 2025
Certified cyber security that protects your patients' most sensitive personal information
We understand the specific cybersecurity challenges and compliance requirements facing mental health businesses in London.
Bespoke Cyber Essentials certification packages designed specifically for the mental health sector, aligned with your compliance needs.
Centrally located in the City of London, providing hands-on certification support and on-site remediation for mental health firms.
A complete Cyber Essentials certification service — from initial gap analysis through to successful certification and ongoing annual recertification.
Self-assessment certification covering the 5 core security controls. Suitable for most businesses and a requirement for many government contracts. We guide you through every question and ensure you pass first time.
Advanced certification with hands-on technical auditing, vulnerability scanning and penetration testing by certified assessors. The highest level of Cyber Essentials assurance for your organisation and supply chain.
A thorough pre-assessment review of your current security posture against all five Cyber Essentials controls. We identify exactly what needs fixing before you apply — eliminating surprises and failed attempts.
Hands-on technical work to fix firewalls, patching gaps, access controls and insecure configurations. We don't just tell you what's wrong — we fix it, ensuring every control meets the certification standard.
Cybersecurity awareness training for your employees covering phishing, password hygiene, social engineering and safe working practices. Reducing human-error risks is essential for both certification and real-world security.
Cyber Essentials certification must be renewed every 12 months. We manage the entire recertification process, adapting to evolving requirements and ensuring continuous compliance year after year.
Mental health records are among the most sensitive data any organisation holds. A data breach could cause profound harm to vulnerable patients and destroy the trust your practice depends on. Cyber Essentials certification provides verified protection against the most common threats.
Cloudswitched guides therapy practices through Cyber Essentials certification with a focus on patient data protection. We understand the unique technology landscape of mental health services and ensure certification strengthens your security without disrupting clinical workflows.
For Mental Health businesses, Sussex offers a well-established county with strong commercial foundations. Sussex encompasses the vibrant city of Brighton and Hove alongside the historic towns of Chichester, Lewes, and Eastbourne. The county has a growing technology and creative sector, particularly in Brighton, alongside established tourism and education industries. Key sectors including technology, creative industries, tourism, education, retail, professional services, hospitality ensure a steady flow of opportunities for Mental Health firms operating in the area.
For Mental Health organisations, Sussex combines practical business benefits with excellent transport links. Connections include Brighton connects to London Victoria and London Bridge in approximately one hour, Gatwick Airport provides international connections. The county's commercial ecosystem and quality of environment make it a natural choice for Mental Health & Therapy businesses.
With an economy built around technology, creative industries, tourism, education, retail, professional services, hospitality, Sussex provides fertile ground for Mental Health businesses. The county's economic diversity creates resilience and ensures a consistent demand for the technology and professional services that Mental Health & Therapy organisations provide.
Certification demonstrates to patients that their deeply personal therapeutic information is protected by government-recognised security standards.
Meet the cyber security requirements of NHS commissioners and local authority contracts, opening doors to funded mental health service provision.
Support your compliance with BACP, UKCP, and BPS data protection guidance through independently verified security controls.
Implementation of five essential security controls that prevent the vast majority of cyber attacks targeting healthcare organisations.
A proven four-stage process that takes you from initial assessment to certified status — with zero failed attempts.
We audit your current IT environment against all five Cyber Essentials controls — firewalls, secure configuration, access control, malware protection and patch management — identifying every gap that needs addressing.
Our engineers fix every issue identified in the gap analysis. From firewall rules and patching schedules to user access policies and endpoint protection — we bring your entire environment up to certification standard.
Before you submit, we run a full internal pre-assessment to verify every control passes. For Cyber Essentials Plus, this includes vulnerability scanning and testing to mirror the actual audit process.
We guide you through the IASME assessment submission, handle assessor queries, and support you through the entire certification process. Our 100% pass rate speaks for itself.
Cyber Essentials is built around five fundamental technical controls. We ensure your organisation meets every one of them.
Your first line of defence. Boundary firewalls and internet gateways must be properly configured to control inbound and outbound traffic, with default passwords changed and unnecessary services disabled.
All devices must be configured securely — removing unnecessary software, changing default settings, disabling unused accounts and ensuring only essential services are running on each system.
User accounts must follow the principle of least privilege — only granting the access needed for each role, with admin rights tightly restricted and multi-factor authentication enforced where possible.
Anti-malware software must be installed on all in-scope devices, kept up to date and configured for real-time scanning. This protects against viruses, ransomware, spyware and other malicious software.
All software and firmware must be kept up to date with security patches applied within 14 days of release. Unsupported software that no longer receives updates must be removed or isolated.
Sensitive handling of certification processes within mental health practice environments
Understanding of the specific cyber threats facing therapy practices and telehealth services
Experience certifying practices that use a mix of clinical platforms and personal devices
Minimal disruption to patient sessions and therapeutic work during the certification process
Ongoing guidance to maintain certification as your practice technology evolves

Two levels of certification to match your requirements. Both cover the same 5 core controls — the difference is how they're verified.
Self-assessment certification for most businesses
Hands-on audit for higher assurance
We combine deep technical expertise with a proven certification process to deliver Cyber Essentials with a 100% pass rate.
Every single business we've guided through Cyber Essentials has achieved certification first time. Our methodical approach and internal pre-assessment process eliminates failed attempts entirely.
We don't just advise — we implement. As a full-service IT company, we fix the technical gaps ourselves: configuring firewalls, hardening systems, patching software and setting up access controls.
We deliver both Cyber Essentials Basic and the more rigorous Cyber Essentials Plus certification. For Plus, our engineers prepare your systems for hands-on vulnerability scanning and technical testing.
Before any certification attempt, we run a comprehensive gap analysis against all five controls. You'll know exactly what needs fixing, how long it will take and what it will cost — no surprises.
No hourly rates or unexpected invoices. Our Cyber Essentials packages are fixed-price, covering gap analysis, remediation, certification submission and assessor fees — everything included.
We don't disappear after certification. We manage your annual renewal, adapting to evolving requirements and ensuring continuous compliance — so you never lose your certified status.
Cybersecurity awareness training for your team — covering phishing, passwords, social engineering and safe working practices. Because the biggest vulnerability in any organisation is human error.
A single point of contact who knows your business, your systems and your certification status. No ticket queues, no call centres — just direct access to someone who understands your needs.
We understand the specific requirements for MOD, NHS and local council contracts. Our certification process ensures you meet every criterion needed to bid on and win government work.
Mental Health & Therapy firms in Sussex rely on technology for client management, compliance, and communication. The county's growing digital infrastructure supports the systems these businesses need. Partnering with a managed IT provider helps Mental Health businesses maintain uptime and data security.
Sussex encompasses both East and West Sussex, with Brighton recognised as one of the UK's leading digital and creative hubs. The city's thriving tech scene centres around the North Laine and New England Quarter, while Crawley and Gatwick Airport form a major logistics and aviation economy. The county combines a vibrant south coast business culture with direct Thameslink and Southern rail services to central London.
Key industries: technology, creative industries, aviation, tourism, hospitality, education
Getting here: 55 minutes by Thameslink from City Thameslink to Brighton station
County
Near Brighton digital hub, Gatwick Airport
Cyber Essentials for Mental Health
Achieve Cyber Essentials certification tailored for mental health businesses. We understand the unique cyber threats facing the Mental Health sector and guide you to compliance.
Cyber Essentials audit Sussex
Independent Cyber Essentials audit services in Sussex to verify your security controls are properly implemented. Prepare confidently for formal assessment.
Got questions about Cyber Essentials certification for mental health businesses? We've answered the most common ones below.
Absolutely. Mental health records are among the most sensitive personal data that exists. We implement the highest levels of encryption, access control, and audit logging. We understand that a breach doesn't just violate regulations — it can cause real harm to vulnerable individuals.
We deploy and manage clinical-grade video consultation platforms with end-to-end encryption, waiting room functionality, session recording controls, and integration with your practice management system. We ensure the platform is reliable, private, and meets professional body standards.
We implement role-based access controls ensuring therapists only see their own clients' records. We manage joiner/leaver processes to revoke access immediately when staff leave. Screen privacy filters, automatic session locks, and audit logging provide additional layers of protection.
We guide you through the NHS Data Security and Protection Toolkit assessment, implementing the technical controls and policies required. This includes staff training, access management, encryption, backup, and incident response procedures that satisfy NHS data security standards.
Our 100% pass rate means you can trust us to get your mental health business certified first time. We handle the complexity so you don't have to.
Whether you need Cyber Essentials Basic, Cyber Essentials Plus or help with annual recertification, our team is ready to guide your mental health business through every step of the process.
Submit your details and one of our friendly team members will be in touch with you shortly
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.