Cyber Essentials: What It Covers, What It Does Not, and Whether You Need More

Cyber Essentials is the UK government-backed certification scheme designed to help organisations defend against the most common cyber attacks. It is required for organisations seeking certain government contracts and is increasingly referenced by insurers and procurement teams across the private sector. Understanding what it actually covers helps organisations make informed decisions about where it fits in a broader security programme.

The scheme has two levels: Cyber Essentials, which involves a self-assessed questionnaire verified by a certifying body, and Cyber Essentials Plus, which adds a technical assessment that includes vulnerability scanning and basic verification of the controls.

The Five Controls

Cyber Essentials focuses on five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. These controls address the mechanisms behind the majority of commodity cyber attacks and represent a genuine improvement for organisations starting from a low baseline.

Firewalls and boundary controls limit exposure of services to the internet. Secure configuration addresses default credentials and unnecessary services. Access control requires appropriate use of administrator privileges. Malware protection covers endpoint security. Patch management requires software to be updated within defined timeframes.

Expert Commentary
William Fieldhouse, Director of Aardwolf Security Ltd
“Cyber Essentials is a solid baseline and worth having, particularly for organisations seeking government contracts or looking to reduce cyber insurance premiums. But clients sometimes treat it as a comprehensive security assurance rather than a starting point. The scheme covers five controls. A mature attacker works around all five.”

What Cyber Essentials Does Not Cover

The scheme does not address social engineering, phishing, or business email compromise. It does not cover cloud security configuration beyond basic requirements. It does not assess the security of web applications or APIs. It does not test internal network security, Active Directory configuration, or the resilience of access controls against an authenticated attacker.

Advanced persistent threats, insider risks, and targeted attacks from skilled adversaries are outside the scope of what Cyber Essentials is designed to address. The scheme explicitly targets commodity, opportunistic attacks rather than determined, targeted ones.

When Cyber Essentials Plus Is Worth Considering

Cyber Essentials Plus includes a technical assessment element that verifies the five controls are in place through testing rather than self-attestation. This provides a more reliable assurance than the standard scheme and is typically required for government contracts involving sensitive data.

The Plus assessment involves vulnerability scanning of internet-facing systems and internal hosts, and verification that patching and configuration requirements are met. It is more rigorous than the base certification but remains narrower in scope than a penetration test.

Building Beyond the Baseline

Best penetration testing company for your organisation will view Cyber Essentials as a baseline to build from, not a ceiling. For organisations in regulated sectors, those handling sensitive data, or those that have become more visible targets, additional testing against a broader set of attack scenarios is appropriate.

If you hold Cyber Essentials but have not conducted a broader security assessment, getting a penetration test quote will give you a view of the risk that the scheme does not cover. The two are complementary rather than alternatives.

Leave a Reply

Your email address will not be published. Required fields are marked *