What Does Cyber Essentials Cover for UK Businesses?
What Does Cyber Essentials Cover for UK Businesses?
A supplier asks for Cyber Essentials before renewing a contract. A customer wants proof that their data is protected. Or you have had a near miss with a phishing email and want to tighten the basics. In each case, the practical question is the same: what does Cyber Essentials cover, and will it address the risks your organisation actually faces?
Cyber Essentials is a UK Government-backed certification scheme designed to help organisations defend against the most common, internet-based cyber attacks. It is deliberately focused on foundations rather than expensive or highly specialised security technology. For many SMEs, getting these foundations right prevents a large proportion of avoidable incidents.
What does Cyber Essentials cover?
Cyber Essentials covers five technical control areas: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together, they reduce the chances that an attacker can find an easy route into your systems, misuse an account, or exploit known weaknesses.
The scheme applies to the agreed scope of your certification. That may be the entire organisation, or a clearly defined part of it. Scope matters. If staff use business laptops at home, access Microsoft 365, or connect to cloud-based line-of-business systems, those services and devices may need to be considered within the assessment.
Certification is available at two levels. Cyber Essentials is a self-assessment questionnaire that is reviewed by an authorised certification body. Cyber Essentials Plus includes the same requirements but adds independent technical testing, such as checking a sample of devices and attempting controlled external vulnerability scans.
Firewalls and internet gateways
This control is about managing the boundary between your systems and the internet. A firewall can be a dedicated appliance, a properly configured router, or a software firewall on individual devices. The aim is simple: block unnecessary connections and allow only the services that have a genuine business purpose.
For a small office, that often means changing default router passwords, disabling remote administration unless it is needed, and reviewing which ports are open to the internet. For organisations with several sites, remote workers or hosted systems, the setup may be more involved. The principle remains the same – do not leave a door open merely because it is convenient.
Secure configuration
New computers, servers, cloud platforms and mobile devices are built to work for a wide range of users. Their default settings are not always right for your organisation. Cyber Essentials requires systems to be configured securely, with unnecessary accounts, applications and features removed or disabled.
This includes changing default passwords, setting screen locks, controlling auto-run features, and ensuring users do not have administrator rights when they only need standard access. It also means knowing what equipment and software you have. An accurate asset list is not paperwork for its own sake; it is how you spot an old laptop, forgotten user account or unsupported application before it becomes a security gap.
Secure configuration needs sensible judgement. A design team may need specialist software, while a finance user may need access to banking portals. The goal is not to restrict people until they cannot work. It is to give them the minimum access and functionality needed to do their job safely.
User access control
Stolen passwords remain one of the most common ways criminals gain access to business systems. Cyber Essentials addresses this by requiring organisations to control who can access systems and data, use separate administrator accounts for administrative tasks, and remove access when it is no longer required.
Strong password practices are part of the picture, but multi-factor authentication is increasingly central. A password plus an authenticator app, security key or other second factor makes a compromised password far less useful to an attacker. This is particularly valuable for email, cloud storage, remote access and administrator accounts.
Access control should also be joined up with your joiner, mover and leaver process. When somebody changes role, their permissions should change with them. When they leave, accounts and access should be removed promptly. A former employee’s active mailbox or shared password is an unnecessary risk that is easily missed in a busy business.
Malware protection
Cyber Essentials requires protection against malicious software, including viruses, ransomware and spyware. In practice, this commonly involves reputable anti-malware software, endpoint protection or a managed security service, kept active and up to date across relevant devices.
Technology alone is not enough. Staff also need a clear route to report suspicious emails, unexpected login prompts and unusual pop-ups without worrying that they are wasting anyone’s time. Fast reporting can turn a phishing attempt into a non-event rather than a costly outage.
This control does not mean every malicious email will be blocked. Criminals continually change their methods, and convincing social-engineering attacks can bypass technical filters. It does mean you have sensible defences in place and can respond more quickly when something looks wrong.
Security update management
Software updates often fix vulnerabilities that criminals already know how to exploit. Cyber Essentials therefore requires supported operating systems, applications and firmware to be kept up to date, with critical and high-risk security updates applied within the scheme’s required timeframe.
This can be challenging where a business relies on older software, legacy machinery or an application that has not been tested with the latest version of Windows. Delaying updates may feel safer operationally, but it leaves a known weakness in place. The right answer may be testing updates first, isolating a legacy system, replacing the software, or agreeing a planned upgrade path. Ignoring the issue is rarely a viable long-term option.
What Cyber Essentials does not cover
Cyber Essentials is a valuable baseline, not a promise that your organisation can never suffer a cyber incident. It does not replace backups, disaster recovery planning, staff awareness training, incident response procedures, cyber insurance or regular review of suppliers.
It also does not automatically prove that every device, account and process across a large organisation is secure. The certificate reflects the scope submitted and the point in time at which the assessment took place. If you add a new cloud platform, open a new site or take on remote staff, your controls need to keep pace between renewals.
Businesses handling highly sensitive information, operating critical services, or facing targeted threats will usually need additional safeguards. These could include advanced email protection, 24/7 monitoring, security testing, network segmentation, encrypted backups and formal incident exercises. The appropriate level depends on the data you hold, the consequences of downtime and the expectations of your customers or regulators.
Preparing for Cyber Essentials without disrupting work
The fastest route to certification is usually a clear view of your current environment. Start by listing your users, computers, servers, mobile devices, internet connections, cloud services and key software. Then check which systems are unsupported, which accounts have administrator rights, whether multi-factor authentication is enabled, and how updates are being managed.
Do not treat the questionnaire as a box-ticking exercise. If the answer reveals that a device is out of date or a user has more access than they need, resolve the underlying issue. That improves both your assessment outcome and your day-to-day resilience.
It is also worth deciding your scope early. Including every system may give customers more confidence, but it can take longer to prepare. A narrower scope may be legitimate where it accurately reflects a separate part of the organisation, but it should never be used to exclude systems that handle the work, data or services you are claiming to protect.
For businesses without an in-house IT team, an experienced support partner can help identify gaps, apply the required settings and keep the controls working after certification. Andromeda Solutions supports UK organisations with practical security improvements alongside day-to-day IT support, so security does not become another task left on an already full desk.
Cyber Essentials works best when it becomes part of normal IT housekeeping: prompt updates, controlled access, secure new-device setup and staff who know when to ask for help. Start with the systems your team relies on most, fix the obvious gaps, and build from there.