What is Cyber Essentials?

Get reliable IT support and cyber security for your London business.

Contact us today to find out how we can help.

Cyber Essentials is a UK Government-backed cyber security certification scheme designed to help organisations protect themselves against the most common internet-based cyber attacks. Developed by the National Cyber Security Centre, the scheme is based on five technical controls that establish a practical minimum standard of cyber security for organisations of all sizes.

Cyber Essentials focuses on the fundamental security measures that make it more difficult for attackers to access systems, exploit known software vulnerabilities, compromise user accounts, or introduce malicious software. It does not guarantee that an organisation will never experience a cyber incident, but it can significantly reduce exposure to common and widely used attack methods.

For businesses under scrutiny from clients, insurers, regulators, or auditors, Cyber Essentials also provides recognised evidence that essential cyber security controls have been assessed. Certification can help an organisation demonstrate that basic security is being managed rather than simply assumed.

Why Cyber Essentials Is Important for Businesses

For businesses, particularly SMEs in London, Cyber Essentials is important because many cyber attacks exploit basic security weaknesses. Unsupported software, excessive access rights, missing updates, insecure configurations, and poorly protected devices can all create opportunities for attackers.

Cyber Essentials gives organisations a defined baseline against which these areas can be reviewed. It can also support commercial relationships, as a growing number of organisations expect suppliers to hold certification before they can bid for contracts or handle sensitive information.

Key benefits of Cyber Essentials include:

  • Stronger protection against common internet-based cyber attacks
  • Better visibility of devices, software, users, and security configurations
  • Improved management of software updates and access rights
  • Greater confidence for customers, partners, and leadership teams
  • Better readiness for client security questionnaires and supplier reviews
  • Recognised evidence that essential cyber security controls are in place
  • A clearer foundation for wider cyber security improvement

These benefits help businesses move away from informal or inconsistent security practices and towards a more structured, measurable, and defensible position.

How Cyber Essentials Works

Cyber Essentials works through an independently verified self-assessment. The organisation reviews its IT environment, defines the scope of certification, and answers questions about how the five technical controls are implemented.

A board member or equivalent senior representative confirms that the submitted information is accurate. A qualified external assessor then reviews the answers and determines whether the organisation meets the scheme’s requirements.

A typical Cyber Essentials certification process includes:

  • Identifying the systems, devices, software, and cloud services within scope
  • Reviewing the current Cyber Essentials technical requirements
  • Checking security controls across the organisation
  • Correcting weaknesses before submitting the assessment
  • Completing the online self-assessment questionnaire
  • Obtaining senior management approval of the answers
  • Submitting the assessment for independent review
  • Addressing any clarification requests from the assessor

Cyber Essentials certification is valid for 12 months and must be renewed annually. This renewal process encourages organisations to review their security as technology, users, systems, and cyber risks change.

Cyber Essentials Plus uses the same underlying requirements but adds independent technical testing of the organisation’s IT systems. It therefore provides a higher level of assurance that the controls described in the assessment have been implemented in practice.

The Five Cyber Essentials Technical Controls

Cyber Essentials is built around five technical controls. Together, they are designed to reduce the likelihood that common cyber attacks will successfully compromise an organisation.

The five Cyber Essentials controls are:

Firewalls

Firewalls create a protective boundary between devices or networks and the internet. They help block unauthorised connections while allowing legitimate business traffic to pass through.

Secure Configuration

Secure configuration involves removing unnecessary accounts, services, applications, and default settings that could create security weaknesses. Systems should be configured according to business needs rather than left with insecure default options.

Security Update Management

Security update management ensures that operating systems, applications, firmware, and other software are kept up to date. Applying security updates helps prevent attackers from exploiting known vulnerabilities.

User Access Control

User access control limits who can access systems, applications, and data. Users should receive only the permissions needed for their roles, while administrative access should be restricted and carefully managed.

Malware Protection

Malware protection helps prevent, detect, and contain malicious software. This may involve anti-malware tools, application controls, secure configurations, and restrictions on untrusted software.

These controls provide a practical security foundation. However, they should form part of a wider approach that also includes backups, incident response, security monitoring, staff awareness, risk management, and business continuity.

Common Cyber Essentials Readiness Challenges

Businesses often discover that obtaining Cyber Essentials certification requires more preparation than expected. The organisation may already have security tools in place but lack an accurate view of its systems or consistent control across all devices and users.

Common Cyber Essentials readiness challenges include:

  • An incomplete inventory of devices, software, and cloud services
  • Unclear boundaries for the certification scope
  • Unsupported operating systems or applications
  • Delayed or inconsistent installation of security updates
  • Users having unnecessary administrative permissions
  • Default accounts or insecure settings remaining active
  • Personal or remote-working devices not being managed consistently
  • Weak control over cloud accounts and external access
  • Firewall rules that have not been reviewed
  • Security practices that are not documented or evidenced
  • Unclear responsibility for completing and maintaining the assessment

These gaps can lead to unsuccessful assessments, but they can also reveal wider security risks that should be addressed regardless of certification.

Best Practices for Cyber Essentials Certification

Preparing for Cyber Essentials should be treated as a security improvement project rather than only a form-filling exercise. The answers in the assessment need to reflect the organisation’s actual IT environment and current security practices.

Best practices for Cyber Essentials certification include:

  • Creating an accurate inventory of devices, software, and cloud services
  • Defining the certification scope before beginning the assessment
  • Reviewing the latest Cyber Essentials requirements
  • Removing or replacing unsupported software and systems
  • Applying security updates within appropriate timescales
  • Restricting administrator accounts and unnecessary permissions
  • Strengthening authentication and access controls
  • Reviewing firewall configurations and exposed services
  • Checking how remote workers and personal devices are managed
  • Testing controls before submitting the assessment
  • Keeping evidence of configurations, reviews, and remediation actions
  • Assigning clear ownership for maintaining certification
  • Reviewing security throughout the year rather than only at renewal

Following these practices helps make the assessment more accurate and reduces the risk of discovering avoidable problems during certification. It also helps ensure that the controls remain effective after the certificate has been issued.

Conclusion: Why Cyber Essentials Matters

Cyber Essentials is an important starting point for organisations that want to improve cyber security and demonstrate that fundamental technical controls are in place. It provides a recognised baseline covering firewalls, secure configuration, security updates, access control, and malware protection.

For London SMEs and regulated firms, Cyber Essentials can support stronger cyber resilience, supplier assurance, client trust, insurance discussions, and readiness for external scrutiny. When maintained as part of a wider security and governance programme, it helps businesses move from assumed protection to a clearer and independently assessed security position.