Skip to main content

Cyber Essentials Explained for Small Businesses

A plain-English guide to the Cyber Essentials certification for UK SMEs: what it is, the five controls, why firms pursue it, and what getting ready involves.

6 min read By Adnan R.
Computer security technology concept

Cyber Essentials is the UK government-backed certification that shows your business has the basic security controls in place to fend off the most common attacks. This guide explains what it covers, why smaller firms bother with it, and what a typical run-up to certification actually looks like.

Share this article:

Table of Contents

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered through IASME. In plain terms, it’s a way for a business to demonstrate that it has the basic technical controls in place to defend against the overwhelming majority of everyday cyber attacks — the opportunistic, automated stuff that sweeps the internet looking for soft targets, rather than a determined attack aimed specifically at you.

There are two levels. The standard Cyber Essentials is a self-assessment questionnaire that your organisation completes and a certification body reviews. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit, where an assessor actually tests your systems rather than taking your word for it. Most small firms start with the standard certification and step up to Plus only if a client or contract requires it.

The five controls

The whole scheme is built around five technical control areas. None of them is exotic — they are simply the fundamentals done properly and consistently.

  • Firewalls. Every device that connects to the internet should sit behind a properly configured firewall or a router with the firewall enabled. Default administrator passwords on that hardware must be changed.
  • Secure configuration. Devices and software should be set up to reduce unnecessary risk — removing or disabling accounts and features you don’t use, and not shipping systems with weak default settings.
  • User access control. People should only have the access they genuinely need. Administrator accounts are reserved for admin tasks, everyone has their own login, and accounts are removed promptly when someone leaves.
  • Malware protection. Machines need a defence against malicious software — anti-malware software, an approved-applications list, or sandboxing — kept up to date and switched on.
  • Security update management (patching). Operating systems and applications must be supported by the vendor and kept patched. High-risk and critical updates should be applied within 14 days of release.

That last point catches a lot of businesses out. If you’re still running an operating system that no longer receives security updates, you cannot pass — the software has to be within its supported life.

Why smaller firms pursue it

Plenty of owners assume a certification like this is for large corporations. In practice it’s often the smaller business that gains the most, and there are three common reasons firms come to us about it.

The first is winning work. Cyber Essentials is mandatory for many UK government contracts and increasingly appears as a requirement in tenders and supplier questionnaires from larger private clients. If a bigger customer is doing due diligence on you, the certificate is a quick, credible answer.

The second is genuine risk reduction. The controls exist precisely because they block the attacks that actually happen to small businesses — phishing that harvests a login, ransomware that walks in through an unpatched machine, an old account nobody closed. Getting certified forces a tidy-up that materially lowers your exposure.

The third is insurance and reassurance. Some cyber insurance policies look more favourably on certified businesses, and for many owners the exercise is simply a way to sleep better knowing the basics are covered rather than assumed.

What getting ready involves

The certification itself is a questionnaire, but the useful work is everything you do to be able to answer it honestly. In our experience preparing a small business, the run-up usually covers a few recurring areas.

You’ll want an accurate picture of what’s in scope: every device, laptop, mobile, server and cloud service that touches your business data. Firms are often surprised how much has quietly accumulated. From there it’s a matter of closing the obvious gaps — enabling firewalls, turning on multi-factor authentication, tightening admin rights, confirming anti-malware is active on every machine, and getting patching under control so updates aren’t left for months.

Cloud and email are a big part of modern scope, which is why a properly configured Microsoft 365 setup — MFA switched on, admin roles restricted, sensible sharing defaults — does a lot of the heavy lifting towards several controls at once. It’s also the right moment to confirm your backup solutions genuinely work: Cyber Essentials doesn’t formally require backups, but recovering from an incident is impossible without them, and a certification tidy-up is the natural time to check yours restore rather than just run.

A realistic timeline for a small firm is a few weeks: a short assessment, the remediation work, then the self-assessment submission. Certification lasts twelve months, so it’s best treated as an annual rhythm rather than a one-off.

Getting a hand with it

If you’d like an honest view of where your business stands before committing to certification, we’re happy to run through the five controls with you and flag what would need fixing first. Call the workshop on 020 7610 0500, drop into our Putney base, or use the contact form — and if you want ongoing help hardening your systems, that’s exactly what our cybersecurity support is for.

Helpful Internal Links

Need Help With This Issue?

Speak with our support team for practical help and next steps.

Author

Adnan R.

Principal IT & Security Consultant

CISSP-certified IT and security consultant with an MSc in Information Security from Royal Holloway, University of London, and 20+ years across systems administration, networking and cybersecurity. Professional member of the British Computer Society (BCS).

Explore more

Related Posts

View all

How to Secure Your Home Wi-Fi Network

A practical guide to securing your home Wi-Fi: strong passwords, WPA3 encryption, a guest network, router firmware updates and keeping smart devices apart.