Cyber Essentials When You Have No IT Team, the Ops-Lead Work Map

Net Sec Group is an IASME and NCSC certification body. A substantial share of the microbusinesses we assess have no internal IT team. The work still gets done; it gets done by an ops lead, an office manager, or the founder, with light-touch technical help where the controls require specialist input. This article is the work map, the two columns of preparation tasks split into "I can do this myself" and "I need help with this", drawn from our 800-plus engagement history.

This article sits on the scope-decisions hub. For the related question of "should I do this myself or pay for help across the whole engagement", see the self-cert vs assisted spoke. For the broader microbusiness scope playbook, see Cyber Essentials for a 1 to 9 person business.

What "no IT team" actually means

Most microbusinesses without an IT team still have someone who handles practical IT: setting up laptops, resetting passwords, helping with printer trouble. That person is an ops lead, an office manager, a founder, or an external IT support contractor on a part-time arrangement. The CE preparation work runs on top of whatever that person already does.

Cyber Essentials with no IT team is a routine assessment shape for us, not a special case. What changes when there is no IT team is not the nature of the work but the depth of technical specialism available. An ops lead can complete the majority of the SAQ preparation; specific tasks (firewall configuration evidence, default-deny application allow-listing, vulnerability scanning at CE Plus tier) need someone with system administration access and skill. The work map below identifies which is which.

Column A, what you can do yourself

These tasks need no specialist technical knowledge. They need attention to detail, access to the cloud admin consoles your firm already has, and the willingness to capture screenshots methodically. An ops lead with no IT background can complete every task in this column.

A1, the asset list (2 to 3 hours)

What it is: a complete inventory of every device, server, virtual machine, mobile device, and cloud service in scope.

How to do it: log into your MDM or device-management console (Microsoft Intune, Google Endpoint Management, Jamf, Mosyle, or whatever your firm uses), export the device list. Log into your identity provider (Microsoft 365 admin centre, Google Workspace admin console), export the user list. Pull the cloud-services list from finance. Reconcile the three into one master inventory in a spreadsheet.

Evidence captured: the master inventory spreadsheet plus the three source exports.

When to ask for help: only if you cannot find the device-management console or do not have admin access to it. The fix is to ask the founder or whoever holds the admin credentials to grant you the access.

A2, MFA enable on cloud admin (1 to 2 hours)

What it is: every administrator account on Microsoft 365, Google Workspace, AWS, Azure, or any other cloud service has multi-factor authentication enforced.

How to do it: in Microsoft 365, the simplest path is to enable Security Defaults (Microsoft 365 admin centre → Show all → Azure Active Directory or Entra → Properties → Manage Security Defaults → On). Security Defaults enforces MFA on every administrator and is included on every paid Microsoft 365 plan. For tenants with Entra ID P1 or higher, Conditional Access is the more flexible path. The legacy per-user MFA portal still works but is being retired by Microsoft and should not be the default. For Google Workspace, the path is Admin console → Security → Authentication → 2-step verification → Allow users to turn on 2-Step Verification → Enforcement: On. For other services, follow the vendor's MFA enforcement documentation.

Evidence captured: a screenshot of the MFA report (Microsoft 365 admin centre → Reports → Multi-factor authentication, or the Entra ID sign-in logs filtered to admin accounts; Google Workspace → Security → Authentication → 2-step verification report).

When to ask for help: if the cloud service is AWS, Azure, or another IaaS platform that you do not normally administer; the MFA enable path is similar but the IAM model is more complex and the screenshot needs interpretation.

A3, leaver process documentation (1 hour)

What it is: a written process describing how a leaver's accounts are disabled, hardware returned, and access revoked, with a worked example from the last 90 days.

How to do it: write 5 to 10 lines describing the process: the trigger (notification from HR or the leaver themselves), the steps (disable account in Microsoft 365, transfer mailbox if needed, retire device in MDM, retrieve hardware), the timing (the same working day for account disable), the evidence retained (audit log entry, account-disable timestamp). Pick one leaver from the last 90 days, run through the process retrospectively, capture the evidence as a worked example.

Evidence captured: the written process plus the worked example.

When to ask for help: only if your firm has had no leavers in 90 days; in that case, run the process forward as a tabletop exercise on a hypothetical leaver and document the steps you would take. The IASME assessor accepts a written process plus tabletop documentation if no real leaver has occurred.

A4, password manager and password policy (2 hours)

What it is: a password manager rolled out to every user, plus a written password policy meeting the IASME minimum requirements.

How to do it: pick a password manager (1Password, Bitwarden, Dashlane, or Microsoft Edge's built-in password manager with Entra sync for Microsoft 365 tenants). Roll it out to every user. Capture the screenshot showing every user enrolled. Write the password policy in 10 to 15 lines covering minimum length, complexity, manager-vs-personal use, and rotation rules.

Evidence captured: the password-manager enrolment screenshot plus the written password policy.

When to ask for help: only if you need to migrate existing browser-saved passwords to the password manager; this is straightforward but takes a 30-minute walkthrough with an IT-fluent helper.

A5, evidence collection in screenshots (3 to 4 hours)

What it is: per-control evidence captured as screenshots, configuration exports, and policy documents, organised in folders matching the SAQ structure.

How to do it: create five folders, one per Cyber Essentials control. For each control, capture the evidence the SAQ asks for. The bulk of the evidence is screenshots from cloud admin consoles you already use. The Cyber Essentials Five Controls Technical Guide on netsecgroup.io is the per-control technical reference; print it and use it as your evidence-capture checklist.

Evidence captured: 30 to 50 screenshots and documents organised in five folders.

When to ask for help: when the SAQ asks for evidence of something you have not configured (a default-deny application policy, an internal vulnerability scan, a CIS-aligned standard build); these go to column B.

A6, basic policy documentation (1 to 2 hours)

What it is: short written documents covering the security policies the SAQ asks about (acceptable use, password, joiner-mover-leaver, BYOD if applicable).

How to do it: each policy is 5 to 15 lines. The IASME assessor does not require corporate-style policy documents; they require written evidence that the firm has thought through the topic. Use the netsec Cyber Essentials Checklist 2026 (Danzell) as a starting structure.

Evidence captured: 4 to 5 short policy documents.

When to ask for help: only if the policy needs to reference technical configuration you do not understand; in that case, ask the helper to fill in the technical paragraph and you write the rest.

Column A total

If your firm has MFA broadly in place and a basic password manager rolled out, column A is 10 to 14 hours of ops work. The work compresses easily into 3 to 5 working days alongside the day job. None of it needs technical specialism.

Column B, where you will need technical help

These tasks need someone with administrative access to the systems and the technical skill to interpret what they see. The "someone" can be an internal employee with relevant skills, an external IT support contractor, an assisted-path engagement with Net Sec Group, or a managed service provider you already pay for IT.

B1, boundary firewall evidence for cloud-only firms (1 to 2 hours of helper time)

What it is: the host-based firewall configuration on each in-scope laptop plus the cloud-platform security-group configuration for any IaaS workload in scope.

Why it needs help: the host-based firewall screenshots are straightforward, but the IaaS security-group configuration requires reading and interpreting the rules, which is technical work. The cloud-only spoke covers this; see cloud-only business scope for the per-control evidence formats.

Question to put to the helper: "can you produce a screenshot of every laptop's host-based firewall and the security-group configuration for every in-scope IaaS workload, with default-deny on inbound documented?"

B2, default-deny application configuration (2 to 3 hours of helper time)

What it is: an application-control policy in MDM (AppLocker via Intune, Jamf Restricted Software, Chrome Browser Cloud Management for Google Workspace) preventing users from running unauthorised software, plus the screenshot evidence.

Why it needs help: configuring an application-control policy in Intune or Jamf needs an admin who knows the policy structure and the side-effects of common rules. Misconfiguring breaks user productivity in subtle ways.

Question to put to the helper: "please configure an application-control policy in our MDM that prevents users running unauthorised software while leaving the apps on our approved list functional, and capture the screenshot."

B3, internal vulnerability scanning at CE Plus tier (3 to 4 hours of helper time)

What it is: at CE Plus, a vulnerability scan run against in-scope devices, with the assessor reviewing the findings on the day. CE Basic does not require vulnerability scanning; this only applies if you are pursuing CE Plus alongside CE Basic.

Why it needs help: the vulnerability scan tooling and remediation cycle need technical skill to interpret. An ops lead without prior CVE-triage experience cannot work through a scan report on their own.

Question to put to the helper: "can you run a vulnerability scan against every in-scope device, triage the findings, and produce the post-remediation evidence pack?"

B4, complex access reviews (1 to 2 hours of helper time)

What it is: where the firm has a complex Active Directory or non-trivial cloud IAM model, the SAQ asks for evidence that administrative privilege is appropriately separated and reviewed.

Why it needs help: access reviews require understanding the access model. An ops lead can review the user list; only an admin-fluent helper can review the role assignments behind it.

Question to put to the helper: "can you produce evidence that administrative roles are reviewed quarterly and that no user holds permissions they no longer need?"

Column B total

Column B is typically 4 to 8 hours of helper time, scattered across 1 to 2 weeks. The cost depends on the helper: an internal employee is no additional cost; an external IT support contractor is at their standard rate; the Net Sec Group assisted path consolidates all of column B into a single engagement at the published assisted-path pricing.

Common questions

Can a non-technical ops lead complete the SAQ entirely alone?

Not quite. Column A above is genuinely DIY-able, but column B has 4 tasks that need technical input. The cleanest path is to do column A yourself and ask one helper for the 4 column B tasks; total helper time is 4 to 8 hours.

What if I have no helper available, internal or external?

The Net Sec Group assisted path covers column B and the SAQ review in one engagement. The pricing is published on the pricing page.

What if I get stuck on a column A task?

Each column A task above lists the specific stuck point and how to unstick it. The recurring stuck point we see is access: the ops lead does not have the cloud admin credentials needed to capture an MFA report. Asking the founder or the credential holder for read-only admin access for the engagement window is usually the fix.

Can I use the CE Self-Assessment Tool to check my readiness before booking?

Yes. The self-assessment tool is designed for exactly this audience; it walks through every SAQ question and tells you which controls are ready and which need work. Run it before booking.

Where do we book?

Book a Cyber Essentials assessment with Net Sec Group. The booking form lets you describe whether you have an IT team or not; the assessor returns a confirmed scope statement and engagement timeline, and recommends the right tier (self-led vs assisted) for your starting point.

Reference material

Where this fits on this site

This article is the no-IT-team spoke under the scope-decisions hub. The other scope-decision spokes are the microbusiness scope playbook, the cloud-only business scope, and the self-cert vs assisted decision. Once the scope and the work-split are settled, the timelines hub indexes the three engagement-speed paths.