Five Controls of Cyber Essentials

Book Free Consultation ›

Cyber security doesn’t have to be complicated. The Cyber Essentials scheme highlights five practical steps that any organisation can take to reduce its risk of falling victim to common cyber attacks. These controls are designed to be straightforward, even for those without specialist knowledge, and can be implemented with minimal disruption.

Arrange a FREE consultation 01748 905 002

Why Five Controls?

Cyber Essentials is built around five key security controls that help protect your business from the most common online threats. These controls are not overly technical or difficult to understand; they focus on simple, practical steps that make a big difference in keeping your systems and data safe.

Each control is designed to tackle a specific type of risk, such as preventing viruses, stopping unauthorised access, or making sure your software is up to date. Together, they create a strong foundation for cyber security. By following these five controls, you are showing your customers and partners that you take security seriously and are committed to protecting their information.

Certification is not just a badge. It gives you confidence that your business is doing the right things to stay secure and helps build trust with those you work with.

The Five Controls

Boundary Firewalls and Internet Gateways
Secure Configuration
Access Control
Malware Protection
Security Update Management

1. Boundary Firewalls and Internet Gateways

Boundary firewalls and internet gateways are your first line of defence; they protect the devices on your network, such as your computer, phone, printer and anything else connected. By examining the incoming traffic, firewalls decide whether or not to give external bodies access to your network. Most ISPs provide a router with a firewall built in, this is suitable for homes and smaller organisations. You’ll need to make some configuration changes to your router, such as configuring the firewall to meet your needs and changing any default passwords.

2. Secure Configuration

When you buy a new computer, smartphone or other such device, the settings of that device will vary from manufacturer to manufacturer. Computer manufacturers often have agreements with software vendors to preload devices with software. In the past this preloaded software has come with its own security flaws. That’s why it’s always important to securely configure your devices.

Secure configuration can be achieved by:

  • Removing unused software
  • Removing and disabling unnecessary user accounts
  • Removing any default passwords and setting strong, unique passwords which are not easily guessable
  • Disabling auto-run or auto-play features that allow execution of files on removal devices without user interaction

3. Access Control

Access control is the practice of ensuring users can access only the data they need to be able to do their jobs. For larger organisations, this can be achieved through role-based access control (RBAC) software, but for smaller organisations this is perfectly achievable on a user-by-user basis.

For each user accessing an organisation’s IT data, the organisation is responsible for determining what data that user should be able to access and ensuring that the user cannot access anything else. In the case of privileged users (such as IT administrators) this is particularly important. This usually means IT admins are given two accounts: a user account, used for reading emails and accessing the internet; and an administrator account, used for admin tasks only.

Further access controls may include:

  • Enabling two-factor authentication (2FA) where possible
  • Tracking and auditing user privileges
  • Disabling and deleting accounts which are no longer used

4. Malware Protection

Malware is any kind of malicious software, including viruses, adware, ransomware and more. Organisations hoping to achieve Cyber Essentials certification should be protecting themselves against a variety of malware.

There are a number of things your organisation can do to protect itself against malware:

  • Install anti-malware software – in the case of Windows, Windows Defender, which usually comes pre-enabled, is a perfectly acceptable solution. You must ensure that automatic updates are enabled. There are many alternatives to defender which support Windows and other operating systems.
  • Limit installation of applications to an approved set – in the case of tablets and smartphones, Google Play Store or the App Store both serve as an application whitelist, although you could go further and implement controls to select only the specific applications you want users to install. For desktops and laptops, you can restrict non-administrators from installing applications, or you can even deploy an application catalogue to allow users to install approved applications themselves.
  • Application sandboxing – application sandboxing restricts applications from accessing or controlling other applications or data on your device. Many smart phones come with some form of application sandboxing built in.

5. Security Update Management

Security Update Management is all about keeping your software and operating systems up to date. Most devices include automatic updating, especially smartphones and tablets, organisations should ensure that automatic updating is enabled where possible. In the case of desktops and laptops, you can usually switch automatic updating on. Larger organisations may implement more formal patch management solutions.

Organisations should ensure that updates are performed within 14 days of release.

need more information? Visit our Cyber Essentials home page – Call 01748 905 002

CLICK HERE

Arrange a FREE Consultation

Evolve North provides a simple and streamlined system to achieving Cyber Essentials with a focus on small to medium sized organisations. Our personal approach ensures you are informed and guided throughout the process.