How we chose
We began with the Telford-area firms offering cyber or security services found through local listings. Certification claims were checked against the IASME certificate search and the CREST marketplace, each firm's own site and reputable platforms [3] [4]. Every business first meets our basic checks: it is who it says it is, it is trading today and can be reached, and anything it must hold by law is in place. A dozen firms were assessed and ten make the table. What customers say counts most toward the score, then proven competence, then trading history, stated cover, pricing clarity and website detail. All evidence is dated early September 2026.
How to hire
Start by matching the person to the job. A cybersecurity consultant advises, tests and helps you certify; a managed IT firm looks after your computers day to day with security included; a penetration tester probes your website and network for flaws a criminal would use. A repair shop that clears viruses is none of those. When you enquire, say what you hold, whether customer records, card payments or a contract that demands certification, and what you want at the end: a report, a certificate or ongoing cover.
Check competence against the registers that matter for this trade. For certification, search the business name or certificate number on the IASME certificate search and confirm the entry yourself rather than trusting a logo [3]. For testing, look the firm up on the CREST marketplace, which lists only independently assessed providers [4]. The NCSC Cyber Essentials pages also point to a network of advisers for hands-on help [1]. Ask for any membership number in writing and check it before you agree anything.
Confirm the business is real and covered. Search the company name on the Companies House register and check the record is active [10]. Ask for professional indemnity and public liability details in writing: one pays out if advice is wrong, the other if something is damaged on site, and check both documents are current. If the work touches personal data, ask how they handle it and who answers for it when something goes wrong.
Get two or three itemised quotes on the same written scope. Each quote should name the systems and users covered, the days on site or remote, what you receive at the end, and the price split between labour, licences and VAT. For testing, insist the scope names the targets, the report includes remediation, and a retest of fixes is included or priced. Treat an outlier far above or below the rest as a question, and ask what is included or left out.
Plan for the bad day before it comes. Read the NCSC response and recovery guide for small businesses so someone in your firm knows the first steps [5]. A cyber attack is a crime: report it to the police through Report Fraud on 0300 123 2040, and check whether the incident must also go to the Information Commissioner's Office, whatever your IT arrangements [6]. Tell affected staff and customers promptly through the clearest channel you have.
Close the job with paperwork, not a handshake. You should finish with a written report of findings and fixes, confirmation that fixes were retested, and any certificate earned, then check the certificate yourself on the IASME search [3]. File everything with your business records; you will need it for insurers, clients and the next assessment. If a dispute follows, Citizens Advice sets out your options for faulty services and traders who will not put things right [7].
Pricing
As of autumn 2026, the commonest fixed price in this trade is certification itself. IASME sets Cyber Essentials assessment fees by organisation size, running from £320 plus VAT for a micro organisation to £600 plus VAT for a large one [2]. Cyber Essentials Plus costs more and is quoted by size and network complexity, since it adds independent technical testing [1]. Testing has no fixed tariff: market guides put a standard website test at £5,000 to £15,000 with infrastructure tests from around £4,000, rising with scope [8].
Scope moves the price most. More systems, users and applications mean more tester days; an on-site audit costs more than a remote self-assessment; and remediation help plus a retest of fixes may be included or charged extra, so ask. Urgency adds cost too: a certificate needed for next week's tender will not be priced like one booked for next quarter.
Ask whether every figure includes VAT, since published fees are quoted plus VAT [2]. Firms in this round publish almost no example rates: only the top firm shows its monthly support price and yearly certification price on its site, so treat testing as quote-only by default. A single fixed price for a large programme with no breakdown of days, deliverables and VAT is a question, not an answer.
Get the scope in writing before work starts: exactly which systems are covered, how many days, what the report contains, whether a retest and the certificate fee are included, and what changes the price if the test finds worse problems than expected. Agree payment stages, since a deposit is normal while full payment before delivery is not, and keep every quote, invoice, report and certificate together.
Red flags
Quotes a penetration test without asking which systems, websites and addresses are in scope.
Cannot give a Cyber Essentials certificate number you can check yourself on the IASME search [3].
Promises you will pass certification before assessing anything.
Prices the job as a single figure with no written scope, deliverables or retest terms.
Asks for full payment in cash before starting, with no written quote or terms [7].
Will not say who will run the test, show a sample report, or name what they hold.
Finishes the work with no written report and no mention of retesting the fixes.
The bottom line
For most small Telford businesses, start with Amery IT Support: managed IT with security included, credentials stated on its site and prices visible before you call. Its company record is shorter than most rivals here and it states no insurance detail, so ask for proof of cover alongside your quote.
Match the firm to the job where you have a fixed need: Round Cyber for testing and fast certification, Round Software when security must ship inside new software, Midland Computers where a walk-in shop matters, and Lockdown Cyber Security for board-level governance.
Then get two or three itemised quotes on the same written scope, check any certification claim on the official search, and keep every quote, report and certificate together.
Corrections and business responses
Tell us what needs checking, or ask to claim a listing and reply to an assessment.