Cyber Essentials gets mentioned a lot, often as a box to tick for winning contracts. But it is genuinely one of the most cost-effective things a small business can do to lower its risk. Here is the plain-English version.
What it is
Cyber Essentials is a UK government-backed certification scheme, supported by the National Cyber Security Centre. It sets out a baseline of five technical controls that, between them, stop the large majority of common, opportunistic cyber attacks.
There are two levels: Cyber Essentials, which is a self-assessment verified by a certifying body, and Cyber Essentials Plus, which adds a hands-on technical audit.
The five controls
- Firewalls. Properly configured boundaries between your network and the internet.
- Secure configuration. Devices and software set up safely, with default passwords and unnecessary features removed.
- Security update management. Operating systems and applications kept patched and up to date.
- User access control. People only have the access they need, and admin rights are tightly controlled.
- Malware protection. Endpoint protection in place and kept current.
Why bother?
Three reasons. First, it works: the controls block most everyday attacks. Second, it is increasingly required to win public-sector work and to satisfy larger clients. Third, it often reduces your cyber insurance premium and can come with included cover.
How to get certified
For most small businesses the self-assessment route is very achievable, especially if your IT is already well managed. The common stumbling blocks are unpatched software, leftover admin accounts and devices that have drifted from a secure baseline, all of which proactive managed security keeps on top of anyway.
We help businesses get their house in order and guide them towards certification. If you want to know how close you already are, get in touch for a quick readiness chat.


