Cyber Essentials – the ultimate user guide

cyber essentials ultimate guide

Would you go to bed at night with the front door wide open and car keys clearly visible on the hall table, along with your wallet and iPad?  Of course you wouldn’t… But this scenario is an analogy of what Cyber Essentials represents to our personal and professional cyber security posture.  It’s our cyber front door and comprises controls (or counter-measures you can take to protect yourself from cyber attack) that ensure that the door is not only closed, but locked and monitored.  

The Cyber Essentials Your five controls 

There is no additional hardware or software solution that needs to be purchased; like a front door, you have everything you need already.  It’s just a matter of ensuring that the door doesn’t fall off its hinges in a moderate gust of wind.  The five ‘controls’ of Cyber Essentials are:   

Keep your devices and software up-to-date 

Ensuring that all your devices’ operating systems and applications are up-to-date is very important, because manufacturers and developers regularly release patches to address security vulnerabilities that have been discovered.  Cyber Essentials will enable you to identify if you are running unsupported software, and if your supported applications / operating systems are up-to-date

Devices and software aren’t up to date = no cyber front door at all 

Protect yourself from viruses and other malware 

Protecting your systems with anti-virus software, intrusion detection / prevention systems would be akin to having CCTV or a security guard at your entrance, alerting you to potential threats and even stopping them on your behalf.  Most popular Operating Systems include effective virus and threat protection… if all the modules are enabled.  How is your configuration?  

No anti-virus or intrusion protection = cyber front door wide open

Control who has access to your data and services 

Would you let everyone you know have a key to your home?  No way!  Cyber Essentials helps you take control of who has access to your data and services.  Often clients don’t understand the significance of administrator and standard user accounts, and yet getting this wrong could result in an intruder having access to far more than you’d like. 

No access controls = cyber security front door ajar

Use secure settings for your devices and software 

Most devices and software applications are supplied with default configurations that make getting started easy for the user.  However, as above, leaving default settings can make it easier for cyber attackers to gain access to your data.  Sharing user accounts and login credentials and having weak passwords also represents a significant risk.  

Not using secure settings on devices and software = cyber front door closed, but on the latch

Use a firewall to secure your internet connection.   

Do you have a firewall?  Of course, you do!  A larger organisation may have a bespoke firewall device, a smaller company or home worker will have a software firewall built into the hub or router provided by their ISP.  But let me ask you this:  Have you changed the default password on your firewall / router?  No?   

Misconfigured firewall = cyber front door closed, but not locked

How does Cyber Essentials work? 

The above controls are produced by the UK Government and industry to help all organisations improve their defences against the most common internet-based cyber-attacks.  You can perhaps already identify flaws in your own configurations and having Cyber Essentials certification demonstrates publicly that you have these controls in place enabling them to trust you with their data.  

 There are two certifications available in the Cyber Essentials Scheme: 

1) Cyber Essentials

This is a self-assessment questionnaire which is completed on the Cyber Essentials Portal and then submitted to us for review.   

2) Cyber Essentials Plus

After achieving the above, you can proceed to the Cyber Essentials Plus certification where we audit your organisation and verify the answers given above.    

Your organisation will be entered onto the publicly available Cyber Essentials register upon certification. 

How long does it take? 

It is not impossible to achieve Cyber Essentials [Plus] in a single day – however, it is highly unusual and realistically takes between a week to a month to complete the process.  It all depends on whether your front door is closed already… or not! 

It is also not uncommon to discover, during an audit, that despite claiming that the ‘front door’ is in order, this turns out to be more wishful thinking than fact.  Ultimately, time must be spent on taking control of your systems – whether this happens during the question-answering phase or during an audit, is up to the individual!  

Some common areas of weakness we see in the Cyber Essentials process

Admin Accounts

Many organisations will happily claim in their questionnaire that all staff are using a Standard User account and that only 1-2 people have Admin Accounts, which are used only for installing software and configuration.  We often find this is not the case.  But it’s important, because login credentials can be easily ‘sniffed’ using free tools that require little computing expertise to launch.  Once armed with Admin Credentials, an attacker can switch off your firewall, deactivate your Anti-Virus, in effect removing your front door, and gaining entry. 

Unsupported Operating Systems

Operating Systems are ever-evolving, and each has a life cycle and an ‘End of Life’ date, at which point the Operating System is no longer supported, meaning that it will no longer receive critical and high-risk security updates.  This means that it becomes increasingly more susceptible to cyber-attacks.  The Cyber Essentials questionnaire will ask for a detailed list of what versions of operating systems are being used within an organisation.  This frequently highlights that unsupported software is in use.  Although this can seem like bad news, addressing the issue and updating the systems is good news for everyone.   

AutoPlay On

This is a regular!  It is important for AutoPlay and AutoRun to be switched off.  Why?  If a virus or malware file finds its way onto your devices would you like it to automatically run and cause havoc or would you prefer to at least receive a warning that the file may not be safe?   

All of these components come together to create a strong defence against most opportunistic attacks – because let’s face it, if a front door is locked, bolted and monitored by CCTV with a security guard, an opportunistic intruder is likely to go and try an easier target.  It’s the same in cyber world.  

Learn more about cyber security accreditations and supply chain compliance in our guide

This post was written by Ann, one of our cyber security consultants

See our updated Ultimate guide on how to get Cyber Essentials