Cyber Essentials: What Actually Trips Businesses Up
Cyber Essentials: What Actually Trips Businesses Up
Most guides to Cyber Essentials list the five controls and leave it there. That part isn’t difficult, the requirements are published and anyone can read them.
What’s harder is the gap between reading the requirements and passing the assessment. Businesses rarely fail because they didn’t know firewalls were on the list. They fail because of a laptop nobody remembered, an unsupported phone, or a shared login that seemed harmless until someone asked about it.
This is a practical look at where that gap usually opens up.
What Cyber Essentials Actually Is
Cyber Essentials is a UK government-backed certification scheme, delivered by IASME, covering five basic technical controls. It’s designed to protect against the large majority of common, untargeted cyberattacks, the opportunistic kind that make up most of what a small business will realistically face.
There are two levels:
Cyber Essentials is a self-assessment questionnaire, reviewed and verified by a certification body.
Cyber Essentials Plus covers the same controls, but adds a hands-on technical audit where an assessor tests your systems directly rather than taking your word for it.
Certification lasts twelve months and needs renewing annually.
Requirements are updated periodically, so check the current version on the IASME or NCSC website before you start, rather than working from an older guide.
Why Businesses Actually Pursue It
In our experience, it’s usually one of three reasons:
A contract requires it. Central government contracts involving certain types of data require Cyber Essentials, and increasingly larger private-sector clients ask for it during supplier due diligence. This is the most common driver.
Insurance. Some cyber insurance policies offer better terms, or require certification outright.
A genuine desire to check the basics are covered. Less common as the initial trigger, but often what businesses value most afterwards. The assessment forces an honest audit of things that have quietly drifted.
The Five Controls, and Where They Get Awkward
1. Firewalls
The requirement: every device must be protected by a properly configured firewall at the boundary of your network, and on the device itself.
Where it gets awkward: home and hybrid working. If staff work from home, their home router isn’t under your control. You’ll generally need device-level firewalls properly configured on the laptops themselves, and you need to be able to demonstrate that.
The other common issue is default router passwords. If the internet-facing router still has the credentials it shipped with, that alone can sink an assessment.
2. Secure Configuration
The requirement: remove or disable what you don’t need. Default passwords, unnecessary user accounts, unused software, and features nobody uses.
Where it gets awkward: old accounts. Almost every business we assess has active accounts belonging to people who left, sometimes years ago. It’s nobody’s fault in particular. Offboarding is one of those tasks that gets done in a hurry, and disabling an email account isn’t the same as removing every system access that person had.
This is worth auditing before you start the questionnaire rather than discovering it midway through.
3. Security Update Management
The requirement: software and operating systems must be supported by the vendor and patched, with critical and high-severity updates applied within fourteen days of release.
Where it gets awkward: this is the single most common failure point, and usually for one of two reasons.
Unsupported devices. An old Android phone that no longer receives security updates, or a Windows machine on a version past end-of-life, will fail the assessment. Any device that accesses organisational data counts, including personal phones used for work email. Businesses are frequently surprised by how many devices that turns out to include.
Patching that isn’t actually happening. Automatic updates enabled isn’t the same as updates being installed. Machines that are rarely rebooted, or laptops that sit unused for weeks, quietly fall behind.
4. User Access Control
The requirement: users get the minimum access they need. Administrator accounts are used only for administrative tasks. Accounts are properly managed when people join and leave.
Where it gets awkward: everyone being an administrator. It’s convenient, particularly in smaller businesses where people install their own software, and it’s a very common finding.
Shared accounts are the other issue. A single login used by several people, often for a specific system or a shared mailbox, fails the requirement that accounts are assigned to individuals.
5. Malware Protection
The requirement: protection against malware, through antivirus software, application allow-listing, or sandboxing.
Where it gets awkward: this is usually the most straightforward control, provided the protection is actually active and updating on every device. The failures tend to be devices that were missed rather than a lack of protection in principle.
The Scoping Decision That Causes Most Problems
Before anything else, you have to define what’s in scope. That means identifying every device and system that accesses your organisational data.
This is where businesses most often go wrong, because scope is easy to underestimate:
- Personal phones with work email on them
- Laptops used occasionally by contractors
- A machine in the corner running one specific piece of software
- Cloud services holding company data
- Devices belonging to staff who work from home
You can scope to a subset of your organisation rather than the whole thing, which is sometimes the sensible route, but the scope has to be a genuine, defensible boundary rather than a convenient exclusion of the awkward parts.
Getting scope wrong is the most common reason an assessment goes badly. Getting it right early makes everything after it more straightforward.
How Long It Realistically Takes
For a business already in reasonable shape, the questionnaire itself is not a long job. The preparation is the variable part.
If you’ve a clean device inventory, current operating systems, proper account management and no unsupported hardware, you may be close to compliant already.
If you’re not sure how many devices access your data, or you suspect there are dormant accounts and older machines in circulation, budget time for that audit before starting. It’s the work that determines whether the assessment is smooth or painful.
Cyber Essentials Plus needs more lead time, because the technical audit requires scheduling and any issues found have to be fixed before certification is issued.
Is It Worth Doing Without a Contract Requiring It?
If a client or contract demands it, the decision is made for you.
If not, it’s worth being honest about what it is and isn’t. Cyber Essentials covers basics well and protects against common opportunistic attacks. It is not a comprehensive security programme, and certification doesn’t make you immune to a determined or targeted attacker.
What it does reliably do is force an audit that most businesses never quite get round to. The dormant accounts, unsupported devices, and unpatched machines it surfaces are genuine risks, and finding them is valuable regardless of whether you complete the certification.
For most small businesses, that’s the real argument for it.
Where to Start
- Build a device inventory. Everything that accesses company data, including personal phones with work email.
- Check operating system support status on every device. Anything past end-of-life needs replacing or removing from scope.
- Audit your user accounts. Look specifically for leavers, shared logins, and unnecessary administrator rights.
- Read the current requirements on the IASME website, since they change periodically.
- Then start the questionnaire, not before.
Getting Help
CCSW is Cyber Essentials certified, and we support businesses across Cardiff and South Wales through both Cyber Essentials and Cyber Essentials Plus certification. If you’d like to talk through what’s involved for your business, get in touch or call us on 0333 014 4544.
You can also read more about our cyber security services.
