On 15 July 2026, the National Cyber Security Centre published a blog confirming that its Cyber Advisor scheme — free, hands-on cyber security consultations delivered by NCSC-assured advisors — is open to small and medium-sized businesses across the UK. More than 760 small organisations have already used the service, and over 150 have gone on to achieve Cyber Essentials certification through it. If you run a small business and have never looked into this, that’s the gap the NCSC is trying to close.
The offer itself is simple: a free 30-minute introductory consultation with a Cyber Advisor — someone accredited by the NCSC and vetted through the IASME Assured Service Provider scheme — to talk through your organisation’s cyber security and, if it’s relevant, the route to Cyber Essentials certification. As the NCSC put it, these advisors “aren’t just technical specialists; they understand how to apply the advice from the experts at the NCSC in a way that’s practical, realistic and relevant for smaller businesses.” That distinction matters. A lot of cyber security guidance is written for organisations with a dedicated IT security function; this is explicitly built for the businesses that don’t have one.
Why this is worth 30 minutes of your time
The NCSC’s own figures give some sense of the stakes: in 2025, 65% of medium-sized and 46% of small UK organisations reported experiencing a cyber breach or attack. Most small businesses aren’t lacking awareness that risk exists — they’re lacking a clear, affordable starting point for doing something about it. A free consultation removes the two most common blockers at once: cost, and not knowing where to begin.
It’s also a low-risk way to get a second opinion. If you’ve already got antivirus, backups, and a password policy in place, a Cyber Advisor session is a chance to have someone independent sanity-check whether that’s actually enough, rather than assuming it is because nothing has gone wrong yet. And if you’re starting from close to zero, the session is designed to meet you there — nobody is expected to arrive already fluent in the terminology.
How to book, and what to do with it afterwards
Sessions are booked directly through IASME’s Cyber Advisor directory at iasme.co.uk/cyber-advisor/find-a-cyber-advisor/, where you can search for an assured advisor and request a free consultation. There’s no obligation to buy anything afterwards — the introductory session is genuinely free, though advisors may of course offer paid follow-on work like full Cyber Essentials certification support if you want to take it further.
Treat the consultation as a starting point, not a finish line. Whatever gaps it surfaces — outdated software, missing multi-factor authentication, no formal incident response plan — still need acting on afterwards, and that’s where ongoing monitoring earns its keep. Services like KeepSafe exist precisely for the “what happens after the advice session” stage, giving small businesses continuous visibility into whether an incident has actually occurred, rather than a one-off health check that goes stale within months.
The takeaway
This is one of the rare pieces of cyber security advice that costs nothing and takes half an hour: book a free NCSC Cyber Advisor consultation through IASME, use it to find out honestly where your business stands, and treat whatever it uncovers as this month’s to-do list rather than something to revisit “when there’s time.” For a threat landscape where nearly half of small UK businesses were attacked last year, that’s a genuinely good trade.