Unizen Blog

What Is a Cyber Essentials Gap Analysis for Healthcare

Written by Shaun Randhawa | Jul 30, 2026, 6:03:16 PM

Healthcare organisations tend to be very good at managing visible risk.

Clinical governance, safeguarding, medicines management, infection control, data protection policies: these are familiar parts of regulated healthcare life. They may not be glamorous, but they are understood. They sit in committees, dashboards, audits, staff training, and those quietly terrifying spreadsheets that somehow hold entire departments together.

Cybersecurity risk is different. It often hides in ordinary-looking places.

A shared mailbox.
An old laptop still used by a part-time clinician.
A firewall rule nobody remembers approving.
A cloud system that stores patient information but was never formally added to the asset list.
A critical update that “will be done next week” and then quietly becomes part of the furniture.

This is where a Cyber Essentials gap analysis earns its keep.

It is not the certificate itself. It is the sensible bit before the certificate: the health check, the dry run, the “let’s find the problems while there is still time to fix them” stage.

For UK healthcare organisations with compliance needs, that can be the difference between a calm certification process and a last-minute scramble involving IT, operations, governance, suppliers, and someone muttering darkly about old printers.

Cyber Essentials is simple, but not casual

Cyber Essentials is the UK Government-backed baseline standard for cybersecurity. The National Cyber Security Centre describes it as a minimum standard built around five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection.

That sounds straightforward. In principle, it is.

But “straightforward” does not mean “easy to evidence”. Especially in healthcare, where IT environments often include a mixture of clinical systems, Microsoft 365, remote access, mobile devices, third-party platforms, legacy software, outsourced suppliers, and people working across multiple sites.

Cyber Essentials certification is based on a verified self-assessment. The organisation answers a structured questionnaire, a senior person signs off the accuracy of the answers, and an assessor reviews the submission. Cyber Essentials Plus then adds independent technical testing.

A gap analysis sits before that process. It asks a practical question:

Are we actually ready to answer these questions confidently?

Not optimistically. Not “we think so”. Not “that was probably set up by the previous provider”.

Confidently.

What a Cyber Essentials gap analysis actually does

A Cyber Essentials gap analysis compares your current IT environment against the requirements of the Cyber Essentials scheme. It identifies where your controls already meet the standard, where evidence is missing, and where changes are needed before assessment.

In a healthcare setting, this usually means looking at several layers of risk.

First, there is the technical control layer. Are devices supported and updated? Is multi-factor authentication enabled where required? Are admin accounts tightly controlled? Are firewalls configured appropriately? Are unsupported systems still connected to patient or business data?

Second, there is the scope layer. This is often where healthcare organisations get caught out. The question is not just “what systems do we own?” It is “what systems store, process, or provide access to organisational data?” That may include cloud services, user-owned devices used for business access, remote working tools, clinical portals, finance platforms, and third-party applications.

Third, there is the evidence layer. A control may exist, but can you prove it? Can you show the asset list, access controls, update status, configuration baselines, MFA coverage, malware protection, and process ownership?

A good gap analysis turns all of this from a foggy concern into a clear list of actions.

That is its real value. It converts “cybersecurity feels complicated” into “these seven things need fixing, these three need evidence, and these two need a decision from leadership.”

Why healthcare organisations need to be especially careful with scope

Scope is the part people often underestimate.

In healthcare, data does not sit politely in one place. It moves through appointment systems, diagnostics portals, email, document storage, patient communications, billing systems, HR files, referral pathways, remote consultations, and supplier platforms.

Some of that data is obviously sensitive. Some of it looks mundane until you remember it can identify a patient, reveal a condition, expose a staff issue, or create a regulatory headache.

A Cyber Essentials gap analysis helps define what is in scope before the formal assessment begins. That matters because poor scoping can create two kinds of problem.

The first is certification risk. If important systems are missed, the assessment may be inaccurate or challenged. If exclusions are not justified properly, the organisation may struggle to demonstrate that its certification reflects reality.

The second is operational risk. If a system is excluded because nobody remembered it existed, that does not make it safe. It just makes it invisible. Invisible systems are rarely well-managed systems.

For regulated healthcare organisations, this is where Cyber Essentials becomes more than a badge. It becomes a useful discipline for understanding how data, devices, users, and suppliers actually fit together.

The common certification blockers

Most Cyber Essentials blockers are not exotic. They are the cybersecurity equivalent of failing an MOT because of tyres, lights, and brakes. Not dramatic, perhaps, but rather important if you want the vehicle to stay on the road.

Common blockers include:

  • Multi-factor authentication not enabled across all relevant cloud services
  • Unsupported operating systems or applications still in use
  • Critical security updates not applied quickly enough
  • Weak or inconsistent admin account controls
  • Incomplete asset records
  • Unclear ownership of third-party systems
  • Staff using personal devices without suitable controls
  • Old user accounts that should have been removed
  • Firewall or remote access settings that have not been reviewed
  • Malware protection that is installed but not consistently monitored

The April 2026 Cyber Essentials updates make some of these areas even more important. IASME has confirmed stricter marking criteria, including automatic failure where MFA is not implemented for cloud services where available, and where high-risk or critical security updates are not applied within the required timeframe.

That is a useful shift, because it reinforces what good IT security assessment should already be doing: not treating baseline controls as paperwork, but as operational hygiene.

Cyber insurance is asking similar questions

Cyber insurance has changed. A few years ago, some organisations treated it like a financial backstop: buy the policy, hope never to use it, carry on.

Now insurers often want more evidence of basic controls. They may ask about MFA, backups, endpoint protection, patching, privileged access, incident response, remote access, staff awareness, and whether the organisation holds Cyber Essentials certification.

This does not mean Cyber Essentials and cyber insurance are the same thing. They are not. Certification is not a guarantee of cover, and insurance requirements vary by provider, sector, revenue, claims history, and risk profile.

But the overlap is obvious.

A Cyber Essentials gap analysis can help healthcare organisations prepare for cyber insurance conversations because it provides a structured view of baseline control maturity. It shows whether the organisation can answer common insurer questions with confidence, and where remediation is needed before renewal or application.

That is particularly useful in healthcare because the stakes are not purely technical. A cyber incident can affect appointment delivery, patient communications, clinical records access, finance operations, supplier trust, and regulatory confidence. Insurance may help with financial recovery, but it does not make downtime pleasant. It does not magically restore patient trust. It does not make a disrupted Monday clinic less chaotic.

Cyber insurance is part of resilience. It is not resilience by itself.

The data protection angle

For healthcare organisations, data protection is never far from the conversation.

Cyber Essentials is not a full data protection framework, and it should not be treated as one. It does not replace UK GDPR obligations, clinical governance, records management, supplier due diligence, or sector-specific requirements.

What it does provide is a practical baseline for reducing common technical risks that can lead to data exposure.

For example, user access control supports the principle that people should only access what they need. Security update management reduces the chance of known vulnerabilities being used to compromise systems. Malware protection helps reduce the risk of malicious software affecting devices or data. Secure configuration helps remove unnecessary weaknesses.

A gap analysis helps connect those technical controls to real data protection outcomes.

Where is patient data stored?
Who can access it?
How are accounts protected?
Are leavers removed promptly?
Are shared devices configured safely?
Are cloud services covered by MFA?
Can backups be restored if ransomware lands at the worst possible moment?

These are not abstract IT questions. They are governance questions wearing an IT jacket.

What good looks like after the gap analysis

The best outcome of a Cyber Essentials gap analysis is not a long report that gets admired once and then quietly buried.

The best outcome is clarity.

A useful gap analysis should leave the organisation with:

  • A defined certification scope
  • A list of blockers and near-misses
  • A prioritised remediation plan
  • Evidence requirements for the assessment
  • Clear owners for each action
  • A view of cyber insurance readiness
  • Practical improvements to day-to-day healthcare cybersecurity

That final point matters. The certificate is valuable, but the improved control environment is more valuable.

A healthcare organisation that has tightened MFA, removed old accounts, patched critical systems, documented assets, clarified supplier responsibilities, and improved device controls is not just closer to Cyber Essentials certification. It is harder to compromise, easier to govern, and better prepared for awkward questions from insurers, auditors, partners, and regulators.

The leadership value: fewer surprises

Good compliance work reduces surprises.

A Cyber Essentials gap analysis gives leaders an earlier view of risk. It helps avoid discovering, during the actual assessment, that a key clinical system is unsupported, a cloud platform has no MFA, or nobody can say with certainty which devices are in scope.

There is a calmness that comes from knowing.

Not because everything is perfect. It rarely is. Healthcare environments are busy, practical, and full of exceptions created for understandable reasons. But once the gaps are visible, they can be managed.

That is the real thought-leadership lesson here: cybersecurity maturity is not about pretending there are no gaps. It is about finding them before someone else does.

Final thought

A Cyber Essentials gap analysis is best understood as preparation with a purpose.

For UK healthcare organisations, it helps identify certification blockers, strengthen IT security controls, support data protection expectations, and prepare for increasingly detailed cyber insurance questions. It is practical, evidence-led, and refreshingly honest.

And in cybersecurity, honest is useful.

Because the systems that protect patient data do not improve because someone hopes they are secure. They improve when an organisation looks carefully, finds the weak points, fixes what matters, and builds a habit of doing that again before the next certificate, renewal, audit, or incident forces the issue.

Sources used: NCSC Cyber Essentials overview: https://www.ncsc.gov.uk/cyberessentials/overview; IASME April 2026 Cyber Essentials update: https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/; IASME self-assessment guidance: https://iasme.co.uk/cyber-essentials/preview-the-self-assessment-questions-for-cyber-essentials/