---
title: Why Cyber Essentials is a good starting point
description: Cyber Essentials is helps organisations protect themselves against the most common cyber threats, giving them a solid security baseline.
image: https://blog.fordway.com/hubfs/Llhama%20security.jpg
---

T. 01483 528 200 [How can we help?](https://www.fordway.com/contact-us) [Contact us](https://www.fordway.com/contact-us)

[![fordway-logo](https://www.fordway.com/wp-content/uploads/2019/07/fordway-logo.png "fordway-logo")](https://www.fordway.com/)

- [Home](https://www.fordway.com)
- [Insights](https://www.fordway.com/insights/blog)
- [Cloud Services](https://www.fordway.com/services/cloud)

# Fordway Blog

## [Why Cyber Essentials is a good starting point](https://blog.fordway.com/why-cyber-essentials-is-a-good-starting-point)

 \[fa icon="calendar"\] Nov 7, 2019 3:09:44 PM / by [Neville Armstrong](https://blog.fordway.com/author/neville-armstrong)

- [Tweet](https://twitter.com/share)

 

![Many organisations don't take cyber security seriously!](https://blog.fordway.com/hs-fs/hubfs/Llhama%20security.jpg?width=1590&name=Llhama%20security.jpg)

This week the Government launched a [review](https://www.scmagazineuk.com/tell-government-whats-needed-cyber-security-incentives-regulation-review-2020/article/1664611) to find out what’s needed to make UK business leaders take cyber security seriously. In our view, a good place to start is the government’s Cyber Essentials scheme, which is based on advice from the UK’s National Cyber Security Centre (NCSC), part of GCHQ.

[Cyber Essentials](https://info.fordway.com/everything-cyber-essentials) is designed to help organisations protect themselves against the most common cyber threats, give them a solid security baseline which will mitigate the majority of these threats, and demonstrate to their customers that they take cyber security seriously. Having certified cyber security measures in place may also help to attract new customers, and it’s becoming an essential requirement for pitching for public sector contracts, so any business bidding for public sector contracts should be implementing it as a matter of priority.

Having become certified ourselves to the advanced level, Cyber Essentials Plus, we believe the scheme gives organisations a solid security baseline which will mitigate the majority of cyber attacks. The controls it recommends are those which should most directly and measurably mitigate the risk of attack: those which will make a tangible difference to an organisation’s cyber security, and would, for example, minimise the damage if something does go wrong, e.g. someone accidentally opens a malicious attachment. This can happen all too easily, even with the best security training.

Cyber Essentials also includes mobile device protection and basic security policies, and will help with GDPR compliance by demonstrating that the organisation has clearly defined security processes in place, so can be used as a bridge to a more comprehensive standard such as ISO 27001.

##### The five basic controls recommended by Cyber Essentials are to:

- implement firewalls
- configure equipment securely, including setting effective passwords and, where appropriate, using two-factor authentication
- control who has access to your organisation’s data and service
- implement malware protection, such as antivirus software
- keep devices and systems up to date with patching.

These may seem like obvious security measures, and many organisations will have at least some of them already in place, making the step to Cyber Essentials accreditation relatively straightforward. However, all too often we find that organisations let one or more of these slip as they focus on other priorities. For example, administrator access is given out all too easily to those who do not need it. Instead, we recommend that organisations implement least privilege and default deny policies for each user and each system, with clear processes to elevate rights on approval.

We also find that many organisations have let patching slip down their ‘to-do’ list. It can then quickly become too onerous to tackle! One option is to automate it, using tools such as SCCM, which many organisations will have within their existing software licences. For those with limited time or expertise, patching can be provided via a [third party managed service](https://www.fordway.com/it-services-and-consultancy/cloud-management-and-monitoring/) and is even available through the cloud.

Achieving Cyber Essentials certification gives an organisation confidence that it has put the core measures in place to protect its business and its staff against the majority of common cyber attacks. Going through the certification process also reminds users of their own security responsibilities – and no security policy will be successful unless employees adhere to it. Education is key, as users are much more likely to comply if they understand the risks rather than seeing security as a set of annoying rules which prevent them working as they wish. Everyone should be clear on exactly what is and is not allowed, as well as the penalties for policy violations.

However, even the best cyber security cannot be 100 percent effective. Every organisation should have an appropriate level of security monitoring, so it knows if it has been breached and to what extent. As a minimum, this means monitoring and analysing internet traffic flowing out of the organisation to help identify any potential compromises on internal systems. It should also adopt the mentality that one day it will be breached and as a minimum ensure it has a cyber security incident response procedure in place, a backup of all business critical systems and a disaster recovery plan.

If you’d like to discuss your security requirements please contact us for a no-obligation chat with one of our consultants. You can also read a longer discussion of this topic in my recent article in [Data Protection magazine](https://dataprotectionmagazine.com/?p=523).

 

[![New call-to-action](https://no-cache.hubspot.com/cta/default/2198812/ab270c39-0ddc-4464-9432-97b42014d5b1.png)](https://cta-redirect.hubspot.com/cta/redirect/2198812/ab270c39-0ddc-4464-9432-97b42014d5b1)

 Topics: [Security](https://blog.fordway.com/topic/security), [Ransomeware, incident response, CISO, Security](https://blog.fordway.com/topic/ransomeware-incident-response-ciso-security)

![Neville Armstrong](https://blog.fordway.com/hs-fs/hubfs/Blog%20images/bloggers/86_NevilleA.jpg?width=100&height=100&name=86_NevilleA.jpg)

#### Written by [Neville Armstrong](https://blog.fordway.com/author/neville-armstrong)

### Get updates directly to your inbox

 

Read more about [Fordway Cloud Services](http://www.fordway.com/cloud-services)

- Recent
- Popular
- Categories

### Lists by Topic

- [Cloud (16)](https://blog.fordway.com/topic/cloud)
- [IT Strategy (13)](https://blog.fordway.com/topic/it-strategy)
- [Security (13)](https://blog.fordway.com/topic/security)
- [IT Transformation (10)](https://blog.fordway.com/topic/it-transformation)
- [Technology (10)](https://blog.fordway.com/topic/technology)
- [cloud intermediation (10)](https://blog.fordway.com/topic/cloud-intermediation)
- [Cloud migration (9)](https://blog.fordway.com/topic/cloud-migration)
- [Cloud Security (8)](https://blog.fordway.com/topic/cloud-security)
- [enterprise cloud (8)](https://blog.fordway.com/topic/enterprise-cloud)
- [Insider (7)](https://blog.fordway.com/topic/insider)
- [Strategy (7)](https://blog.fordway.com/topic/strategy)
- [Cloud Shock (6)](https://blog.fordway.com/topic/cloud-shock)
- [Fordway Managed Services (6)](https://blog.fordway.com/topic/fordway-managed-services)
- [GDPR (6)](https://blog.fordway.com/topic/gdpr)
- [managed cloud (6)](https://blog.fordway.com/topic/managed-cloud)
- [Azure (5)](https://blog.fordway.com/topic/azure)
- [Disaster Recovery (5)](https://blog.fordway.com/topic/disaster-recovery)
- [New Technology (5)](https://blog.fordway.com/topic/new-technology)
- [legacy (4)](https://blog.fordway.com/topic/legacy)
- [tactical (4)](https://blog.fordway.com/topic/tactical)
- [#ChooseToChallenge (3)](https://blog.fordway.com/topic/choosetochallenge)
- [#IWD2021 (3)](https://blog.fordway.com/topic/iwd2021)
- [Cloud Monitoring (3)](https://blog.fordway.com/topic/cloud-monitoring)
- [Data Protection (3)](https://blog.fordway.com/topic/data-protection)
- [Fordway (3)](https://blog.fordway.com/topic/fordway)
- [Governance (3)](https://blog.fordway.com/topic/governance)
- [ITIL (3)](https://blog.fordway.com/topic/itil)
- [Risk Management (3)](https://blog.fordway.com/topic/risk-management)
- [cloud first (3)](https://blog.fordway.com/topic/cloud-first)
- [remote working (3)](https://blog.fordway.com/topic/remote-working)
- [trends (3)](https://blog.fordway.com/topic/trends)
- [Cyber Security (2)](https://blog.fordway.com/topic/cyber-security)
- [Meet the team (2)](https://blog.fordway.com/topic/meet-the-team)
- [Ransomeware, incident response, CISO, Security (2)](https://blog.fordway.com/topic/ransomeware-incident-response-ciso-security)
- [Ransomware (2)](https://blog.fordway.com/topic/ransomware)
- [case study (2)](https://blog.fordway.com/topic/case-study)
- [compliance (2)](https://blog.fordway.com/topic/compliance)
- [technical debt (2)](https://blog.fordway.com/topic/technical-debt)
- [Cloud Paging (1)](https://blog.fordway.com/topic/cloud-paging)
- [Connectivity (1)](https://blog.fordway.com/topic/connectivity)
- [DaaS (1)](https://blog.fordway.com/topic/daas)
- [DraaS (1)](https://blog.fordway.com/topic/draas)
- [Incident Response (1)](https://blog.fordway.com/topic/incident-response)
- [Managed Services (1)](https://blog.fordway.com/topic/managed-services)
- [Microsoft Sentinel (1)](https://blog.fordway.com/topic/microsoft-sentinel)
- [Networking (1)](https://blog.fordway.com/topic/networking)
- [Optimised Infrastructure (1)](https://blog.fordway.com/topic/optimised-infrastructure)
- [Patch Management (1)](https://blog.fordway.com/topic/patch-management)
- [Patching (1)](https://blog.fordway.com/topic/patching)
- [Project Management (1)](https://blog.fordway.com/topic/project-management)
- [Technology Services 2 (1)](https://blog.fordway.com/topic/technology-services-2)
- [Web hosting (1)](https://blog.fordway.com/topic/web-hosting)
- [hyperconvergence (1)](https://blog.fordway.com/topic/hyperconvergence)
- [information security (1)](https://blog.fordway.com/topic/information-security)
- [shared services (1)](https://blog.fordway.com/topic/shared-services)
- [vdi (1)](https://blog.fordway.com/topic/vdi)
- [virtual desktop (1)](https://blog.fordway.com/topic/virtual-desktop)

see all

## [Older Fordway Posts](http://www.fordway.com/blog/archive)

 

[Tweets by @Fordway](https://twitter.com/Fordway)

### CONTACT

01483 528 200

[Privacy Policy](https://www.fordway.com/privacy-policy)  
[Anti-Slavery Policy](https://www.fordway.com/anti-slavery-policy)

 

### This is Ermincloud the Fordway cow

[Find out why she matters to us!](https://www.fordway.com/ermincloud)

[![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/twitter-footer-icon.png)](https://twitter.com/Fordway) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/facebook-footer-icon.png)](https://www.facebook.com/Fordway-358130410947628/) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/youtube-footer-icon.png)](https://youtube.com) [![](https://fw-dev-neu-webasp-001.azurewebsites.net/wp-content/uploads/2019/07/linkedin-footer-icon.png)](https://www.linkedin.com/company/fordway-solutions)

Copyright © 2020 Fordway Solutions

\[fa icon="chevron-up"\]Back to top

![](https://dc.ads.linkedin.com/collect/?pid=94312&fmt=gif)