Cyber Essentials is built on five technical controls. The NCSC’s own analysis shows that applying these five controls correctly prevents approximately 80% of the most common cyber attacks. It’s the basis on which the certification scheme was designed, and it shapes exactly which controls are required and why.


Why five controls and not fifty?

Most successful cyber attacks are not sophisticated. They succeed because of unpatched software, weak or reused passwords, overpermissioned accounts, or misconfigured devices. The five controls address exactly these failure modes.

They are not a guarantee against every possible threat. They are a baseline that closes the gaps attackers most commonly exploit. Understanding what each one actually does in practice is more useful than knowing it exists.


The five controls

Firewalls

A firewall controls what network traffic is allowed to pass through a boundary. Under Cyber Essentials, every device connecting to the internet, including laptops, phones, and tablets used for work, must be protected by one. The boundary firewall manages traffic entering and leaving your office network. A personal firewall on each device handles the same function when staff are working remotely or from a coffee shop.

The principle is: allow what you need, block everything else. Default configurations that permit all inbound connections are not acceptable. The firewall must be configured explicitly, not left on factory settings.

Secure configuration

Devices and software arrive with default settings that are not always secure. Accounts enabled but unused, ports open by default, administrative privileges granted automatically: these are standard starting conditions, not secure ones.

Secure configuration means reviewing those defaults and changing what needs to change. Under CE, that means disabling software and services that are not actively used, replacing default credentials, and ensuring devices are configured with the minimum permissions required to function. The principle is the same as the firewall: permitted by exception, not by default.

User access control

Access control is about limiting who can reach what. Staff accounts should only have access to the systems, files, and applications they need for their specific role. An account manager does not need the same access as your finance lead. Under CE, that principle is documented and enforced.

It also applies to administrator accounts. Admin access carries elevated permissions. Under CE, those accounts are used only for administrative tasks, not for everyday activities like email or browsing. If someone with admin rights clicks a malicious link in their inbox, the consequences are significantly worse than if a standard account does.

Malware protection

Malware protection covers the tools and practices that prevent, detect, and remove malicious software. Under CE, this means anti-malware software is installed, kept up to date, and actively running on every device that handles work data.

CE v3.3, introduced in April 2026, extended this requirement to cloud services and mobile devices in scope. For agencies where staff use personal phones for work email or messaging apps, or where work data passes through cloud storage, this is the area most likely to surface a gap.

Patch management

Software vulnerabilities are discovered regularly. Vendors release patches to address them. Organisations that apply patches quickly are substantially less exposed than those that let them accumulate.

Under CE, all software on in-scope devices must be kept up to date, including the operating system, browsers, productivity tools, and any plugin or extension. High-severity patches must be applied within 14 days of release. Software that is no longer receiving security updates must be removed or replaced.


What a 30-person agency typically looks like against these controls

The most common gaps in agency environments are not in malware protection or firewalls. Those are usually in place. The gaps are in access control and patch management.

Access control: shared logins that were never individualised, accounts that remain active after someone left, or staff with administrator rights because no one changed the default when they were onboarded. Patch management: personal laptops running software the user never updated because it did not feel urgent, or browser extensions that have not received a security update in months.

Secure configuration is the least visible issue. Most agencies have never audited the default settings on their staff devices. Some of those devices are running with open ports, active services, and permissions that no one consciously granted.

A CE assessment does not require perfect security. It requires documented, evidenced compliance with the five controls. In most 30-person agencies, two or three gaps need addressing before the assessment. Finding and fixing those gaps is more useful than the certificate itself.

The starting point is knowing where you stand. Most agencies assume they are closer to compliant than they are, not because they have been careless, but because the gaps are in areas that are rarely audited.

Our Cyber Check tool gives you a baseline against the five controls in under 10 minutes. Or if you would rather talk to a human that knows a thing or two about businesses like yours, contact Ralph today.