CyberEssentials 101: Password-Based Authentication May 22, 2025 – Posted in: Cyber Security, IT Support – Tags: , , , , ,

All accounts with access to company data must require the user to authenticate. Where this is done using a password the following protections should be used:

  • Passwords are protected against brute-force password guessing.
  • Technical controls are used to manage the quality of passwords.
  • People are supported to choose unique passwords for their work accounts.
  • There is an established process to change passwords promptly if the applicant knows or suspects the password or account has been compromised.

A7.10 – Describe how you protect accounts from brute-force password guessing in your organisation?

Why are they asking you this?

Brute force password attacks are one of the more common ways that malicious actors use so having protections in place is important.

What’s the detail?

A brute-force attack is an attempt to discover a password by systematically trying every possible combination of letters, numbers, and symbols until you discover the one correct combination that works. There’s more information about this here.

Example answer:

Accounts lock out after 4 incorrect password attempts and we use MFA.

A7.11 – Which technical controls are used to manage the quality of your passwords within your organisation?

Why are they asking you this?

Technical controls are fixed and do not allow people to use insecure passwords. They are more reliable than policies.

What’s the detail?

Acceptable technical controls that you can use to manage the quality of your passwords are outlined in the new section about password-based authentication in the ‘Cyber Essentials Requirements for IT Infrastructure’ document.

Example answer:

Microsoft 365 Security Defaults require minimum standards of password complexity. For domain accounts group policy enforces complex passwords of minimum password length of 12 characters with no maximum length restrictions, forced complexity and standard active directory password complexity requirements. For all other accounts including cloud software policies are set wherever possible.

A7.12 – Please explain how you encourage people to use unique and strong passwords.

Why are they asking you this?

Not all software solutions allow you to set minimum standards on passwords so it is important that users understand what the minimum standards are any why they’re vital to security.

Example answer:

During onboarding all staff are required to read and sign our password policies that lay out minimum standards. Password creation is advised by our IT team and the importance of secure passwords is emphasised with each new account.

A7.13 – Do you have a documented password policy that includes a process for when you believe that passwords or accounts have been compromised?

Why are they asking you this?

Laying out clear policies is the best way to make sure all staff know what their responsibilities are if they are concerned an account has been compromised. Making it clear that everyone is encouraged to raise and concerns even if they eventually prove unfounded will make sure that a breach doesn’t pass unnoticed.

What’s the detail?

You must have an established process that details how to change passwords promptly if you believe or suspect a password or account has been compromised.

Example answer:

In order to pass the answer to this question must be yes.

A7.14 – Do all of your cloud services have multi-factor authentication (MFA) available as part of the service?

Why are they asking you this?

Cloud-based services are, by their nature, accessible via the internet. That means anyone can get at them. Even secure passwords aren’t a perfect security measure so MFA is the best way to protect your data.

Example answer:

Yes or no.

A7.15 – If you have answered ‘No’ to question A7.14, please provide a list of your cloud services that do not provide any option for MFA.

Why are they asking you this?

Only answer this question if you answered no to A7.14. Some services don’t have an option for MFA, this is the only reason not to use it. You should have a list of the services that don’t so you can use other mitigations or consider moving to a different service.

Example answer:

AcmeCloud Software is the only solution available to fil our niche business need and does not provide an option for MFA.

A7.16 – Has MFA been applied to all administrators of your cloud services?

What’s the detail?

It is required that all administrator accounts on cloud service must apply multi-factor authentication in conjunction with a password of at least 8 characters.

Example answer:

In order to pass the answer to this question must be yes, wherever possible.

A7.17 – Has MFA been applied to all users of your cloud services?

What’s the detail?

It is required that all administrator accounts on cloud service must apply multi-factor authentication in conjunction with a password of at least 8 characters.

Example answer:

In order to pass the answer to this question must be yes, wherever possible.

Next Time…

Next week we will cover the Malware Protection section of Cyber Essentials.

If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .