Skip to content
Call 03333 20 97 97
bristol.digital: empowering ideas
Legacy PHP rescue and modernisation
On this page

"We failed Cyber Essentials, or our insurer's security questionnaire"

Turn the findings into a fix list. Answer honestly. Don't certify what isn't true.

Cyber Essentials assessments, cyber insurance renewals and customer security questionnaires keep asking about the same things: supported software, patching, access controls and backups. An old PHP application tends to fail several at once.

This page explains what's usually behind the failure and how to put it right. I can fix the technical problems. I can't certify you, and I can't tell you what to say to an insurer. The honest answer is the only safe one.

Book a free conversationLegacy System Assessment, from £2,500


What they're actually checking

Different bodies word it differently, but the questions come down to this:

  • Is all your software still supported by its maker? (PHP, operating system, database, framework, CMS, plugins)
  • Are security updates applied promptly? Cyber Essentials expects critical and high-risk fixes to be applied within a short window. (Check the current scheme requirements for the exact rule.)
  • Who can get in, and how? Multi-factor authentication, strong passwords, admin accounts kept to a minimum
  • Is the network and server locked down? Firewalls, unused services turned off, default settings changed
  • Can you recover? Backups that exist, are stored safely and have been tested
  • Do you know what you have? An accurate list of systems, software and who has access

An application nobody has documented, running on unsupported PHP on an unpatched server, fails most of those at once.


Common findings, and the fix

Finding What fixes it
Unsupported PHP version Upgrade to a supported version. PHP upgrades
Unsupported framework, CMS or plugin Upgrade or replace it. Laravel upgrades
End-of-life server operating system Move to a supported server. Hosting migration
Old database version Upgrade the database, with the application tested against it
Known vulnerabilities in dependencies Update or replace the vulnerable packages
No multi-factor authentication on admin access Add it to admin areas, hosting, email and server access
Weak or shared logins Named accounts, strong passwords, least privilege
No tested backups Verified backups, stored separately, with restore tests
No patching process A regular, recorded patching routine. Ongoing care
Nobody knows what's running Inventory and documentation. Documentation
Application-level weaknesses Security review and fixes. Security audit

What I do, and what I don't

I can:

  • Find the technical problems behind the failure, and prioritise them
  • Fix them: upgrades, patching, configuration, access controls, backups
  • Produce clear written evidence of what was found and changed, which you can give to your assessor, insurer or customer
  • Keep the system maintained afterwards, so it doesn't drift back

I can't:

  • Certify you for Cyber Essentials, ISO 27001, PCI DSS or anything else. Only the certification body can
  • Give legal or insurance advice
  • Guarantee a pass. The assessor decides

About insurers' questionnaires

If an insurer's questions are hard to answer truthfully, don't be tempted to answer the way you wish things were. An inaccurate answer can give the insurer grounds to reduce or refuse a claim when you need it most.

A better route:

  1. Answer accurately.
  2. Ask what remediation would change the answer, and by when.
  3. Fix the underlying problem, then update the answer with evidence.
  4. Talk to your broker. They deal with this every renewal and may be able to give you time.

A sensible route

  1. Get the failure in writing, with the exact findings and any deadline for re-assessment.
  2. Assessment. I investigate the application and server against those findings, and give you a prioritised plan. Legacy System Assessment, from £2,500
  3. Fix, in order of importance and deadline. Upgrades are done in stages, with tests.
  4. Evidence. A written record for your assessor or insurer.
  5. Keep it current, with maintenance and a yearly review. Ongoing care

What it costs

Fixes are quoted fixed-price after the assessment where scope is clear, or at £950 per day for open-ended work. Deadline pressure may call for the urgent rate (from £1,300 per day), subject to availability. Pricing


Data protection

Security failures often sit alongside data protection obligations. Unsupported software can be hard to defend as "appropriate" security under UK GDPR, though that's a legal question for your adviser. Data protection and security


Frequently asked questions

Can unsupported PHP really cause a Cyber Essentials failure?

It can. The scheme expects software to be supported and updated, so unsupported PHP, operating systems or frameworks within scope are a common reason for failure. Check the current scheme requirements and ask your assessor how it applies to you.

Can you make us compliant?

I can fix the technical problems that cause failures, and prepare the evidence. I can't certify you. That's decided by the assessor.

Is there a quick fix?

Rarely, for unsupported software. The real fix is to upgrade or replace what's unsupported. Short-term mitigations may help some questions, but they don't change the underlying position.

We need this done before our renewal date. Can you help?

Possibly. Tell me the date and the findings, and I'll say what's realistic. Urgent work is subject to availability.

Do you need access to our live data?

Usually not. Most of the work is on code, configuration and servers. How I handle access


Tell me what you've inherited.

Send me the findings or the questionnaire. I'll tell you which ones are technical, which I can fix, and what I'd do first.

Book a free conversationLegacy System Assessment, from £2,500

Call Book a free conversation