Skip to content
All posts

August Newsletter

With the DCC Level 0 deadline now just months away, organisations across digital health and defence are moving fast.

A warm welcome to Periculo's newest cyber security consultant.

An invitation to join the team at next year's Backyard Ultra, and the latest work from the team in the field.

DCC Level 0 Deadline Closes In

We have seen a sharp rise in clients booking their DCC assessments in the past month, many moving considerably earlier than they originally planned. What's notable is the direction some of that demand is taking: rather than stopping at the Level 0 minimum, a growing number of clients are asking about Level 1 and above, treating the deadline as a reason to get ahead of the requirement rather than simply meet it.

For a scheme that many suppliers were slow to engage with earlier in the year, that shift in behaviour is a strong indicator of how seriously the defence supply chain now takes the December cut-off.

The Defence Cyber Certification Level 0 deadline actually requires a valid Cyber Essentials certificate covering business-critical systems, plus a completed Supplier Assurance Questionnaire assessed against Defence Standard 05-138. With the Ministry of Defence's 31st December 2026 deadline now closing in, the response from the defence supply chain has been unmistakable.

Contact us now to find out more about the process...

Welcome to Periculo, Casey!

Casey-Stewart-Meet-The-Team-1

Introducing Casey Stewart, the newest Cyber Security Consultant at Periculo

"After completing a degree apprenticeship in Digital and Technology Solutions, specialising as a cyber analyst, I decided to pursue a career in GRC. This let me lean into the people-focused side of cybersecurity, which is where my real passion lies.

I joined Periculo because I admired the team's innovative approach to customer security, developing new strategies and tools to maximise efficiency. The biggest appeal was the range of growth opportunities on offer, including certifications to further my career. I'm looking forward to continuing to learn and grow here at Periculo!"

We’re delighted to have Casey on board, and she has already made a strong start in meeting and introducing themself to our client base.

In the Field

August has been a busy delivery month across the team. Cyber Essentials and Cyber Essentials Plus assessments have picked up noticeably, driven in part by the DCC Level 0 deadline. 

DCC Level 0 assessments have continued, and a large number are expected to follow in the coming months.

A fully booked Penetration testing calendar has covered a mix of infrastructure and web application testing for clients across digital health and defence.

On the data protection and GRC side, the team has worked through DPIAs for Cloud migration and a separate DPIA covering CCTV, alongside supporting a client through an internal audit spanning ISO 27001 and the incoming NIS 2 requirements.

The managed services team has kept day-to-day monitoring and support running smoothly across the client base, including daily log checks and alert triage continuing without interruption throughout the month.

Periculo Returns to the Backyard Ultra in 2027! And There's Room for You to Join

Last year, a team from Periculo took on the Red On Back Yard Ultra at Cheltenham Racecourse, a punishing endurance format where runners complete a 4.167-mile loop every hour, on the hour, until only one competitor is left standing.

Periculo is confirmed to return for the 2027 edition, taking place on Friday 21 May at Cheltenham Racecourse, and this time there are a limited number of spaces open to clients who'd like to join the team on the start line.

For anyone who fancies testing their endurance alongside the Periculo team, get in touch to find out more and secure a place.

Security Tip of the Month

Multi-factor authentication on every cloud service — not just email.

Talking to clients preparing for Cyber Essentials and Cyber Essentials Plus this month, a clear gap keeps surfacing: MFA is switched on for email and core admin accounts, but nowhere else. Under Cyber Essentials v3.3, the "Danzell" update is no longer enough. From 28 April 2026, MFA becomes mandatory for all in-scope cloud services, not just the obvious ones.

In practice, this means organisations need to list every cloud service that falls within their Cyber Essentials scope and check each one individually. File storage, CRM platforms, HR systems and backup services are the ones most often missed, because they don't feel like "security" systems in the way email or a VPN does, but if they hold or process company data, they're in scope, and they need MFA enforced for every user, not just administrators.

The other change worth acting on now is the type of MFA in use. App-based authenticators or hardware keys are preferable to SMS codes, which are more easily intercepted. Where a service only supports SMS-based MFA, it's worth flagging as a risk to address before the April deadline rather than after.

For organisations with a Cyber Essentials or Cyber Essentials Plus renewal coming up, this is worth checking now; closing the gap ahead of assessment is far easier than a last-minute scramble. If it would help to review your cloud services against the new requirement, Periculo is happy to talk it through.

Jargon Buster

CSMv4 is the fourth version of the Ministry of Defence's Cyber Security Model, the framework that decides what level of cyber assurance a defence supplier needs, based on the risk of the contract they hold. It works by assigning each supplier a Cyber Risk Profile, Level 0, 1, 2 or 3, which maps to a set of controls set out in Defence Standard 05-138.

Defence Cyber Certification (DCC) is the independent scheme that lets a supplier evidence they meet those controls, but it currently sits alongside the Supplier Assurance Questionnaire rather than replacing it; suppliers with a valid DCC certificate still need to complete the SAQ in full.

Contact Us

If any of the areas covered are relevant to your organisation, we are always happy to have a conversation. Please contact us.