CyberEssentials 101: Security Update Management April 16, 2025 – Posted in: Cyber Security, IT Support
This is the next article in our Cyber Essentials 101 series, if you haven’t yet read the first part covering why you should consider Cyber Essentials and how to answer the initial questions about your organisation you can find it here.
Patching your devices is one of the most important things you can do to secure your data. For more on why take a look at our infographic about patching computers and our article on what you need to patch.
Questions in this section apply to: servers, desktop computers, laptops, thin clients, tablets, mobile phones, and cloud based software services.
Further guidance from IASME can be found here.
A6.1 – Are all operating systems on your devices supported by a vendor that produces regular security updates?
Why are they asking you this?
It is really important that your operating systems are kept up to date. Out of support hardware – hardware that no longer gets security updates – is at huge risk from malicious actors.
What’s the detail?
If you have included firewall or router devices in your scope, the firmware of these devices is considered to be an operating system and needs to meet this requirement. It’s important you keep track of your operating systems and understand when they have gone end of life. Most major vendors will have published EOL dates for their operating systems and firmware.
Example answer:
In order to pass the answer to this question should always be yes.
A6.2 – Is all the software on your devices supported by a supplier that produces regular fixes for any security problems?
Why are they asking you this?
Unsupported software is always at risk from malicious actors. You should never have any unsupported software on your devices.
What’s the detail?
The most commonly unsupported software solutions are bespoke or niche solutions that may have been developed especially for you. If the company or developer is no longer available to update the software it will soon become incompatible with latest operating systems and will not receive security updates and protocols develop and hacks are invented.
Example answer:
In order to pass the answer to this question should always be yes.
A6.2.1 – Please list your internet browser(s)
Why are they asking you this?
Internet browsers are the gateway to the wider internet on your PC. They should always be kept up to date.
What’s the detail?
The version is required – and this makes this question often one of the most problematic ones. It is unfortunately common for users to have multiple browsers on their devices. Browsers only update when they are open and in use. If a user only uses one of the browsers on their PC, the others will always be out of date. The easiest solution to this is to remove all browsers that are not used regularly.
Example answer:
Microsoft Edge – 131.0.2903.63
A6.2.2 – Please list your malware Protection software
Why are they asking you this?
Malware protection software (Anti-Virus) is one of the key pillars of any company’s security setup.
What’s the detail?
List all protection software and versions. The assessor will check if it is in support and up to date.
Example answer:
Vipre Endpoint Server – Version 13.0.8352
A6.2.3 – Please list your email applications installed on end user devices and server.
Why are they asking you this?
Like web browsers, email clients are another piece of software that is always open to the wider internet. This puts them at greater risk so the assessor needs to check yours is up to date.
What’s the detail?
List all email software and versions. The assessor will check if it is in support and up to date.
Example answer:
Office 365 Outlook Classic and Outlook New
A6.2.4 – Please list all office applications that are used to create organisational data.
Why are they asking you this?
These are the tools that have the most interaction with your company data so the assessor needs to check yours is up to date.
What’s the detail?
List all office application software and versions. The assessor will check if it is in support and up to date.
Example answer:
Office 365 including Access
A6.3 – Is all software licensed in accordance with the publisher’s recommendations?
Why are they asking you this?
Unlicensed or illegal versions of software will often be unable to update and may even have malware built in.
What’s the detail?
All software must be licensed. It is acceptable to use free and open source software as long as you comply with any licensing requirements.
Example answer:
In order to pass the answer to this question should always be yes.
A6.4 – Are all high-risk or critical security updates for operating systems and router and firewall firmware installed within 14 days of release?
Why are they asking you this?
As mentioned previously, updates are vital to make sure you aren’t left vulnerable to known bugs or exploitable features.
Example answer:
In order to pass the answer to this question should always be yes.
A6.4.1 – Are all updates applied for operating systems by enabling auto updates?
Why are they asking you this?
Another one making sure you keep your devices up to date.
Example answer:
Yes or no.
A6.4.2 – Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all operating systems and firmware on firewalls and routers are applied within 14 days of release?
Why are they asking you this?
Some operating systems and firmware don’t offer automatic updates, and on some more delicate ecosystems you might not want to apply them without testing first to make sure they don’t cause any problems. In those cases you need to show your working and prove you make sure important updates are applied in a timely fashion.
Example answer:
Our IT team monitor updates for all operating systems and firmware and apply them within 7 days of release. The OS on the devices connected to our manufacturing plant are not set to automatically update to ensure no problems are created by unplanned updates so our IT team test all updates in a sandbox environment before rolling them out to these devices.
A6.5 – Are all high-risk or critical security updates for applications (including any associated files and any plugins such as Java, Adobe Reader and .Net.) installed within 14 days of release?
Why are they asking you this?
Similarly to 6.4.2 this is another one making sure you’ve thought about how to make sure manual updates are applied.
Example answer:
In order to pass the answer to this question should always be yes.
A6.5.1 – Are all updates applied on your applications by enabling auto updates?
Why are they asking you this?
Updates are important! There are a lot of questions relating to them because a massive proportion of breaches are enabled by out of support operating systems, firmware or software.
Example answer:
Yes or no.
A6.5.2 – Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all applications are applied within 14 days of release?
Why are they asking you this?
Some software doesn’t offer automatic updates, and on some more delicate ecosystems you might not want to apply them without testing first to make sure they don’t cause any problems. In those cases you need to show your working and prove you make sure important updates are applied in a timely fashion.
Example answer:
Our IT team monitor updates for all software and apply them within 14 days of release. Access is not set to automatically update to protect a bespoke database so our IT team test all updates in a sandbox environment before rolling them out to users.
A6.6 – Have you removed any software installed on your devices that is no longer supported and no longer receives regular updates for security problems?
Why are they asking you this?
Unsupported software is one of the biggest risk factors for a cyber security breach.
Example answer:
In order to pass the answer to this question should always be yes.
A6.7 – Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment? Please explain how you achieve this.
Why are they asking you this?
On rare occasions it may be required for a device to keep running an out of date operating system or unsupported piece of software in order to perform a critical business function. You need to make sure you protect the rest of your network and protect this device.
What’s the detail?
When they say move the devices and software out of scope of this assessment they mean that you have isolated the machine or program in such a way that the questions at the beginning no longer apply to it. Namely: Your whole organisation includes all divisions, people and devices which access your organisations data and services. The simplest way to remove a device from this category would be to remove the network connection. A non-networked device cannot be accessed from the internet or pass on any malware to the rest of the devices and servers in the business. If a device needs to ‘talk’ to other services it will need its own VLAN and a separate firewall to protect the network from it.
Example answer:
A Windows XP device that is required in order to run the large format scanner is not connected to the network and is connected to the scanner via a USB cable. Any file transfer from the XP device to a networked device is done by our IT team using a USB storage device and is scanned for malware in an isolated sandbox environment before transfer.
Next Time…
Next week we will cover the Administrative Accounts section of Cyber Essentials.
If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .