As we approach our seventh consecutive Cyber Essentials Plus independent technical audit this July, we want to share some more of the work that goes on behind the scenes to keep your systems current, patched, and protected.
Cyber Essentials Plus
Achieving certification year after year isn’t just about passing an audit, it requires continuous investment in keeping every layer of the platform up to date. Here’s a snapshot of what that looks like in practice:
Python 3.13 upgrades across the estate
With Python 3.9 reaching end of life, we’ve been rolling out upgrades to Python 3.13 across all customer Windows servers. This work has already been completed for many customers, with further rollouts continuing. Each upgrade is tested to ensure your services continue to run smoothly on the newer version.
Automated PostgreSQL point-version patching
We’ve built a new automated capability to keep PostgreSQL on the latest point version across customer servers. This means security patches and performance improvements can be applied faster and more consistently, without manual intervention on each server. It’s a good example of how we invest in tooling to make ongoing maintenance more reliable.
Estate-wide software patching
Alongside the headline upgrades, we’ve completed a sweep of supporting software across all servers — updating QGIS, Notepad++, Firefox, Chrome, PGAdmin and WinSCP. We’ve also disabled any legacy PowerShell versions. Individually these are small changes, but collectively they close off potential vulnerabilities and keep the platform aligned with current security standards.
Why this matters
Cyber threats evolve constantly, and so does the software landscape. By treating patching and upgrades as continuous activities rather than annual projects, we ensure your platform stays ahead of known vulnerabilities throughout the year, not just at audit time. When confirmed, our seventh consecutive CE+ certification will be further evidence of that commitment.
