Cyber Essentials 101: Secure Configuration February 27, 2025 – Posted in: Cyber Security – Tags: , , , , , , ,

This is the next article in our Cyber Essentials 101 series, if you haven’t yet read the first part covering why you should consider Cyber Essentials and how to answer the initial questions about your organisation you can find it here.

Computers and cloud services often aren’t secure on default installation or setup. An out-of-the-box set-up can often include an administrative account with a standard, publicly known, default password, one or more unnecessary user accounts enabled (sometimes with special access privileges) and pre-installed but unnecessary applications or services. All of these present security risks.

Questions in this section apply to: servers, desktop computers, laptops, thin clients, tablets, mobile phones, and cloud based software services.

Further guidance can be found here.

A5.1 – Where you are able to do so, have you removed or disabled all the software and services that you do not use on your laptops, desktop computers, thin clients, servers, tablets, mobile phones and cloud services?

Why are they asking you this?

Every piece of software on your devices is an additional risk. If the software is required for your staff to do their jobs – it is a risk worth taking. If it is a program that is never opened or used, it is not.

What’s the detail?

All businesses should have an approved software list that includes the tools you have reviewed and made sure are regularly updated and you are comfortable with the support and security. Only approved software should be installed on business devices.

This can prove a challenge with pre-installed bloatware coming from the manufacturer and, if permitted, staff downloading freeware solutions they would use at home.

The solution is to rebuild all new devices, or clear down bloatware, and ensure end users don’t have admin access to install software unless they have access too, and understand the importance of, the approved software list.

Ideally the approved software list should include indicators as to whether specific job titles or job title groups need access to each item – for example marketing might need the adobe creative cloud suite, but sales likely won’t.

Example answer:

All new devices are cleared of bloatware and set up with approved software by our IT team. We keep a regularly reviewed approved software list and only software from that list – that is also required by the specific user who will be using the device, is installed. Users do not have admin access to install software on their own devices unless they have been trained on what the approved software list includes and why it is vital that no other software is installed.

A5.2 – Have you ensured that all your laptops, computers, servers, tablets, mobile devices and cloud services only contain necessary user accounts that are regularly used in the course of your business?

Why are they asking you this?

Every user account on your devices is an additional risk. If the account is required for the user to access the device – it is a risk worth taking. If it is no longer used, it is not.

What’s the detail?

It is important to remove user accounts that are not needed in day to day use on all devices and cloud services. This is why it is important to remove users from systems and devices once a staff member has left the business, started using a new device, or moved to a new position that no longer requires access to a specific system or software.

Example answer:

Whenever a staff member leaves the business or is moved from one device to another our IT team are informed immediately and they then remove the no longer required account from the device.

A5.3 – Have you changed the default password for all user and administrator accounts on all your desktop computers, laptops, thin clients, servers, tablets and mobile phones that follow the Password-based authentication requirements of Cyber Essentials?

Why are they asking you this?

Default passwords are often short and lack complexity leaving them easily guessed with brute force attacks. Many are also published online so only a short search away. Default passwords are incredibly risky to keep on any devices.

Example answer:

The answer to this question should always be yes.

A5.4 – Do you run external services that provides access to data (that shouldn’t be made public) to users across the internet?

Why are they asking you this?

Any door between the wider internet and privileged information is a risk factor – you need to show how you protect yours.

What’s the detail?

Your business might run software that allows staff or customers to access information across the internet to an external service hosted on the internal network, cloud data centre or IaaS cloud service. This could be a VPN server, a mail server, or an internally hosted internet application (SaaS or PaaS) that you provide to your customers as a product. In all cases, these applications provide information that is confidential to your business and your customers and that you would not want to be publicly accessible.

Example answer:

Yes or no

A5.5 – If yes to question A5.4, which option of password-based authentication do you use?

Why are they asking you this?

You only need to answer this one if you said Yes to A5.4. This is where they check if your password policies are up to scratch for your external services.

Example answer:
  1. Multi-factor authentication, with a minimum password length 8 characters and no maximum length
  2. Automatic blocking of common passwords, with a minimum password length 8 characters and no maximum length
  3. A password minimum length of 12 characters and no maximum length
  4. None of the above, please describe

A5.6 – Describe the process in place for changing passwords on your external services when you believe they have been compromised.

Why are they asking you this?

You only need to answer this one if you said yes to A5.4. As with any password you need to make sure you can change them when required.

What’s the detail?

Passwords may be compromised if there has been a virus on your system or if the manufacturer notifies you of a security weakness in their product. You should know how to change the password if this occurs.

Example answer:

If we suspect a password has been compromised we will contact our IT team and they will immediately change the password.

A5.7 – When not using multi-factor authentication, which option are you using to protect your external service from brute force attacks?

Why are they asking you this?

You only need to answer this one if you said yes to A5.4 AND you do not use MFA to protect the external service login.

External logins are particularly at risk so if you’re not using MFA you’ll need some other mechanism to protect your logins from being guessed simply by throwing multiple possible combinations of words and letters at them until one works.

Example answer:
  1. Throttling the rate of attempts
  2. Locking accounts after 10 unsuccessful attempts
  3. None of the above, please describe

A5.8 – Is “auto-run” or “auto-play” disabled on all of your systems?

Why are they asking you this?

Auto-run and Auto-play are features that will automatically run and software on CDs or flash drives inserted into your computer, or even downloaded programs. This prevents you from viewing and assessing files before they run and allows malicious downloads that you may never have wanted to download at all to run before you realise it.

Example answer:

Yes or no.

Next Time…

Next week we will cover the Device Locking section of Cyber Essentials.

If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .