Top Cyber Essentials Controls for Small Businesses

Top Cyber Essentials Controls for Small Businesses

A cyber attack rarely starts with a Hollywood-style hack. More often, it starts with an unpatched laptop, a reused password, an overly generous user account or a staff member clicking a convincing email. The top Cyber Essentials controls focus on closing those everyday gaps before they turn into lost data, downtime or a difficult conversation with customers.

For a small business, this matters because technology is woven into almost every task. From sending invoices and accessing cloud files to running specialist garage systems or managing charity donor information, a security incident can stop work quickly. Cyber Essentials gives businesses a practical baseline, not a pile of unnecessary technical theory.

What are the top Cyber Essentials controls?

Cyber Essentials is a UK Government-backed certification scheme designed to help organisations protect themselves against the most common cyber threats. Its requirements are built around five technical control areas: firewalls and internet gateways, secure configuration, access control, malware protection and security update management.

The certification process assesses the systems that fall within your chosen scope. That could mean your whole organisation, or a defined part of it. The right choice depends on how your business operates, what customers or tenders require, and whether every device and service is managed to the same standard. A narrow scope can be appropriate in some cases, but it should never be used to leave a major business risk unchecked.

Top Cyber Essentials controls explained

1. Firewalls and secure internet connections

A firewall is the first line of defence between your network and the internet. It controls what traffic is allowed in and out, helping to block unwanted access attempts before they reach business devices.

For many small firms, the practical question is not whether a firewall exists. Most routers have one. The question is whether it is properly configured, updated and monitored. Default passwords, unnecessary open ports and old office routers can all create risk.

This control also applies to home working. If staff access company systems from home, they need a safe method for doing so. That may include a managed device, secure remote access and clear rules on using public Wi-Fi. Convenience matters, but it should not mean exposing sensitive systems directly to the internet.

2. Secure configuration

New laptops, phones, cloud services and software often arrive with settings designed for general use. Secure configuration means changing those defaults so they suit your business and reduce opportunities for attack.

In practice, this includes removing unused accounts and applications, changing default passwords, disabling services you do not need and setting devices to lock automatically when unattended. It also means setting up cloud platforms carefully. Shared files should not be available to everyone simply because it is easier than managing permissions.

Secure configuration is where businesses often discover hidden inconsistency. One person may have a well-managed work laptop while another uses an old personal computer with no encryption or screen lock. A simple, documented device setup standard makes these differences easier to identify and fix.

3. Access control

People should only be able to access the systems and information they genuinely need for their job. This principle sounds obvious, but it is commonly overlooked when staff change roles, leave the business or need temporary access to help with a project.

Strong, unique passwords remain essential, but passwords alone are no longer enough for many important services. Multi-factor authentication adds another check, such as an approval through an authenticator app. It is particularly valuable for email, cloud storage, finance systems and administrator accounts because these are frequent targets.

Access control should also include regular checks. Ask who has administrator rights, who can view payroll or customer records, and whether former staff accounts have been removed. Giving everyone admin access may seem to reduce support requests, but it also makes accidental changes and malicious software far more damaging.

4. Malware protection

Malware is software created to disrupt, damage or gain unauthorised access to systems. It includes ransomware, which can lock files and demand payment, as well as spyware that quietly collects information.

Malware protection is not just about installing antivirus software and forgetting it. Your protection needs to be active, up to date and centrally managed where possible. It should also work alongside sensible controls that prevent suspicious files and unsafe applications from running.

Staff awareness plays a real part here. People do not need to become security experts, but they should know how to spot a suspicious attachment, unexpected login request or unusual payment instruction. A culture where staff can pause and ask for help is safer than one where people feel pressured to act quickly.

5. Security update management

Cyber criminals actively look for known weaknesses in operating systems, browsers, apps, firewalls and other business software. Security updates fix those weaknesses. Delaying them for months gives attackers more time to exploit a problem that already has a published solution.

A good update process identifies every device and application your business relies on, applies important updates promptly and checks that updates have completed successfully. This includes mobile phones, cloud-connected software and specialist equipment, not only office PCs.

There can be exceptions. A garage diagnostic system, line-of-business application or older device may depend on a specific software version. In those situations, do not simply ignore updates. Document the reason, speak to the supplier and put compensating measures in place, such as restricting access, segmenting the device from the wider network or planning a replacement.

Making Cyber Essentials part of normal operations

The controls work best when they become part of how your business runs, rather than a one-off task completed before a tender deadline. Keep an accurate list of devices, software and user accounts. Make security checks part of staff onboarding and leaver processes. Review administrator access regularly, and make sure backups are protected and tested.

Backups are not one of the five Cyber Essentials control areas, but they are vital for business continuity. If ransomware, hardware failure or human error affects your files, a tested backup can be the difference between a short disruption and days of lost work. Keep backup access separate from everyday user accounts so an attacker cannot easily delete it too.

Small businesses also benefit from deciding who owns each security task. Without clear responsibility, updates are assumed to be someone else’s job and old accounts remain active. An internal office manager may coordinate the process, while a managed IT provider handles monitoring, patching, device configuration and technical evidence. The arrangement should fit the business, but the accountability must be clear.

Preparing for certification without the scramble

Certification should confirm good practice, not force a last-minute clean-up. Start by understanding your scope and mapping the devices, users, cloud services and internet connections involved. Then review each of the top Cyber Essentials controls against what is actually happening day to day, rather than what your policy says should happen.

Be honest about gaps. An unsupported computer, shared administrator password or unmanaged personal phone is easier to deal with before an assessment than after an incident. Keep records of your processes too. Clear evidence of how accounts are managed, updates are applied and devices are configured makes ongoing oversight much simpler.

My Tech Team helps Sussex businesses turn these requirements into practical actions that support daily work rather than getting in the way of it. The aim is straightforward: your technology should be secure, manageable and ready when your team needs it.

Cyber Essentials is not a guarantee that an attack will never happen. It is a sensible foundation that makes the common attacks much harder to succeed with. Start with the control that presents the biggest immediate risk, make improvement a regular habit, and give your business a stronger footing for whatever comes next.

More to read

Related Topics

AI cyber security is entering a genuinely interesting new phase. Most security tools work reactively: something suspicious occurs, the system detects it, and then attempts

Garage network upgrade case study: see how a practical Wi-Fi and network refresh can protect diagnostics, improve uptime and support a busy workshop daily.
Choose a password manager for teams with clear access controls, safer sharing and support that reduces risk without slowing staff down across your business.