Skip to content
rPResiliencePilot
All resources
Cyber Essentials6 min read·31 July 2026

The five Cyber Essentials controls, explained

A practical walk through the five Cyber Essentials controls: firewalls, secure configuration, security update management, user access control and malware protection.

A dark blue printed circuit board with fine gold traces, photographed in macro

The whole of Cyber Essentials rests on five technical controls. There's no risk methodology to design and no management system to build, which is exactly why the scheme is a fast, credible baseline. But "basic" doesn't mean "vague": each control has specific expectations, and a first certification usually stumbles on the same handful of details. Here's what each one is really asking for. For the bigger picture, see what Cyber Essentials is.

1. Firewalls

Every device that connects to the internet has to sit behind a correctly configured firewall, whether that's a boundary firewall on your network or the software firewall on the device itself (important for laptops that leave the office).

In practice that means: block unauthenticated inbound connections by default, only open the ports and services you genuinely need and can justify, and change the firewall's default administrative password to something strong (or disable remote admin access altogether). The common miss is home and mobile working: a laptop on a café network needs its own host firewall doing the job the office firewall would.

2. Secure configuration

Devices and software ship in a convenient, not a secure, state. This control is about tightening that default.

Expect to: remove or disable software, user accounts and services you don't need, change every default password, and remove auto-run features that let removable media execute code. Where a device or service is protected by a password alone, that authentication has to be strong, and Cyber Essentials expects multi-factor authentication to be used where it's available (particularly on cloud services). Devices should also lock after a period of inactivity.

3. Security update management

Unpatched, out-of-date software is one of the most common routes in, so this control is blunt about it.

Everything in scope must be supported by the vendor and kept updated. Critically, high-risk and critical security updates must be applied within 14 days of release. That 14-day clock is one of the most-failed requirements, usually because a fleet of devices or a forgotten application drifts behind. Anything no longer supported (an unpatched operating system, an end-of-life application) must be removed from scope or the device replaced, because there are no more fixes coming for it.

4. User access control

Access should be the minimum each person needs, and administrative power should be rare and controlled.

That means: every user has their own account (no shared logins), accounts are created through a proper process and removed promptly when people leave, and administrative privileges are restricted to those who genuinely need them and not used for everyday work like email and browsing. Special attention goes to admin accounts and cloud services, where multi-factor authentication is expected. The frequent finding here is the long-forgotten admin account, or a leaver whose access was never revoked.

5. Malware protection

Finally, devices must be protected against malicious software, using at least one of the recognised approaches:

  • anti-malware software, kept updated and set to scan files and web pages automatically, or
  • application allow-listing, where only approved applications can run, or
  • equivalent built-in protection on managed devices.

The point is that a device shouldn't be able to silently run something malicious. On modern managed laptops and phones this is often already handled by the platform, but it still has to be configured and evidenced, not just assumed.

Why "simple" still takes work

None of these five is technically difficult in isolation. The difficulty is scope and consistency: making every control true on every device, including the laptop that never comes into the office and the cloud service someone signed up for last month, and keeping it that way for the whole 12-month certification period. That gap between "we do this" and "we do this everywhere, all the time" is exactly what a Cyber Essentials Plus audit is designed to expose.

It's also why the controls are best treated as an always-on baseline rather than an annual scramble. ResiliencePilot keeps the evidence for each control current across your estate and maps it toward broader goals like ISO 27001. See the Cyber Essentials solution, the Cyber Essentials hub, or book a demo.

See ResiliencePilot in action

See it on your own data and frameworks, with your security and data-residency questions answered.