What are the cyber essentials secure configuration requirements?
What are the Cyber Essentials secure configuration requirements?
Cyber Essentials secure configuration requirements are designed to help organisations reduce avoidable weaknesses in devices, software, accounts, and cloud services. In simple terms, secure configuration means setting up technology in a safe, controlled, and business-appropriate way, rather than relying on factory defaults or leaving unnecessary features switched on.
For many UK businesses, secure configuration is one of the most practical parts of Cyber Essentials. It focuses on everyday security hygiene: removing unused accounts, changing default passwords, disabling unnecessary software, requiring authentication, locking devices properly, and reducing the opportunities attackers have to gain unauthorised access.
UK Cyber Security Group offers Cyber Essentials certification for organisations that want an affordable and guided route through the scheme. Its Cyber Essentials service is built around helping businesses understand the five core controls, prepare for assessment, and deal with gaps before submission.
Secure configuration matters because many cyber attacks do not start with highly advanced techniques. They often begin with simple weaknesses: a default password, an old guest account, an exposed admin function, an unnecessary service, a device with poor lock settings, or a cloud account that was never reviewed. Cyber Essentials helps businesses close these easy routes in.
Why secure configuration matters
Cyber Essentials is the UK Government-backed scheme designed to help organisations protect themselves against common online threats. It is based on five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection.
Secure configuration sits near the centre of the scheme because it reduces the number of weak points an attacker can use. A device or cloud service may be fully patched and protected by a firewall, but if it still has default accounts, unused services, weak login controls, or unnecessary applications, it can still create risk.
The National Cyber Security Centre’s Cyber Essentials requirements explain that default configurations are not always secure. Out-of-the-box settings can include publicly known default passwords, unnecessary accounts, unnecessary applications, or services that are switched on by default. These settings can give attackers easier access to sensitive information.
The aim is not to make IT difficult. The aim is to keep only what is needed, protect what remains, and make sure staff and suppliers access business systems through controlled routes.
The plain-English meaning of secure configuration
Secure configuration means making sure each in-scope device, application, account, and service is set up safely for business use.
That includes removing or disabling unnecessary user accounts, changing default or guessable passwords, removing unnecessary software, disabling automatic file execution where it creates risk, requiring users to authenticate before accessing business data, and applying device locking controls where people physically access devices.
It also includes cloud services. Many businesses now rely on Microsoft 365, Google Workspace, hosted finance platforms, CRM systems, cloud file storage, security dashboards, and online project tools. Cyber Essentials v3.3 makes clear that cloud services used to store or process organisational data are in scope and cannot simply be ignored.
For a small business, secure configuration may sound technical at first. In reality, it is mostly about control. Know what you use, remove what you do not need, protect accounts, restrict risky settings, and check that devices and services remain suitable for business use.
What are the key requirements for achieving Cyber Essentials certification?
The key requirements for achieving Cyber Essentials certification are based on five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection.
From a secure configuration perspective, the business must proactively manage computers and network devices. This means unnecessary accounts should be removed or disabled. Default or guessable account passwords should be changed. Unnecessary software, applications, system utilities, and network services should be removed or disabled. Auto-run features that allow files to execute without user authorisation should be disabled where applicable.
The business must also ensure users are authenticated before they can access organisational data or services. Devices that require a person to be physically present, such as laptops and mobile phones, should have suitable unlocking credentials such as a password, PIN, or biometric control.
These requirements are closely linked to other Cyber Essentials areas. For example, user access control handles account approval and privilege management. Firewalls restrict unnecessary network exposure. Security update management keeps software supported and updated. Malware protection helps reduce harmful activity. Secure configuration supports all of these by making sure technology is not left in an unsafe default state.
Default settings are not always safe
Many devices and services are designed to be easy to start using. That does not always mean they are secure enough for business use. A router, laptop, phone, cloud account, application, or online portal may come with default settings intended for convenience rather than protection.
Default accounts and passwords are a major example. If a device or system is supplied with a known administrator password, attackers may already know it. If a guest account is active by default, it may provide a route into a system that nobody intended to leave open.
Default software can also create risk. Devices often come with applications or utilities that a business never uses. If they remain present, they may need updates, permissions, or monitoring. Removing unnecessary software reduces the attack surface and makes management easier.
Secure configuration is therefore about moving from default settings to business-approved settings. The business should know what is active, why it is active, and who is responsible for managing it.
Removing unnecessary accounts
Unnecessary accounts are a common problem. They may include guest accounts, old administrator accounts, test accounts, shared accounts, temporary supplier accounts, accounts for former staff, or accounts created during setup and never removed.
Cyber Essentials expects businesses to remove or disable accounts that are not needed. This reduces risk because every active account can become a route into business systems.
A good account review should check whether each account is linked to an authorised person or legitimate business function. If the account has no clear purpose, it should be removed or disabled. If it has high privileges, it should receive even closer attention.
This is especially important for administrator accounts. These accounts can make significant changes to systems and security settings. If an old admin account remains active, it can create serious risk.
Changing default and guessable passwords
Secure configuration requires organisations to change default or guessable passwords. This applies to devices, applications, admin portals, routers, firewalls, cloud services, and other in-scope systems.
A default password is dangerous because it may be publicly known. A guessable password is dangerous because it may be easy for attackers to work out through common password lists, company names, dates, simple patterns, or personal information.
Changing default passwords should be part of every new device or service setup process. It should also be part of regular review. A business should never assume that an IT supplier has already changed every default credential unless it has evidence.
Strong password practice also links to the user access control requirement. Passwords should be protected against brute force guessing, and cloud services should use multi-factor authentication where available. Authentication needs to be suitable for the sensitivity of the system and the access being granted.
Removing unnecessary software and services
Unnecessary software creates extra work and extra risk. If software is not needed, it may still contain vulnerabilities, require updates, request permissions, or create background services. The same applies to unnecessary network services and system utilities.
Cyber Essentials expects businesses to remove or disable unnecessary software, including applications, system utilities, and network services. This helps reduce the number of possible weaknesses an attacker can target.
For example, a business laptop should not be full of unused trial software, old remote access tools, unknown browser extensions, or applications that staff do not need. A server or cloud service should not expose services that are not required for the business function.
This is not about stripping devices so far that staff cannot work. It is about keeping the build clean, purposeful, and easier to manage.
Auto-run and file execution
Cyber Essentials secure configuration also includes disabling any auto-run feature that allows file execution without user authorisation. Auto-run can create risk because files may launch automatically when downloaded or accessed through removable media or connected services.
The business aim is simple: files should not execute without the user or system having appropriate control. Automatic execution can help malware spread or make accidental activation more likely.
This does not mean staff cannot open files as part of normal work. It means the business should avoid settings that allow untrusted content to run without clear user action or suitable protection.
For businesses with staff who receive attachments, use shared folders, or work with external documents, this control supports safer day-to-day working.
Authentication before access
Cyber Essentials expects users to authenticate before accessing organisational data or services. This means business information should not be freely accessible without checking who the user is.
Authentication may involve passwords, PINs, biometrics, passkeys, security keys, one-time codes, or multi-factor authentication, depending on the system and business need.
For secure configuration, the key point is that devices and services should not allow unauthorised access by default. Laptops should require unlock credentials. Mobile devices should require secure access. Cloud services should require proper sign-in. Shared business systems should identify users.
This protects the business if a device is lost, stolen, left unattended, or accessed by someone who should not have access.
Device locking controls
Device locking controls protect laptops, desktops, tablets, and mobile phones when a person is physically present. Cyber Essentials expects devices that require physical access to services to have a credential such as a biometric, password, or PIN before access is granted.
The chosen unlocking method should also be protected against brute force attacks. Where possible, Cyber Essentials expects throttling or locking after repeated failed attempts. The requirement points to no more than 10 guesses in 5 minutes, or device locking after no more than 10 unsuccessful attempts, where the vendor allows this to be configured.
For businesses, this is important because devices are often used outside the office. A laptop left in a vehicle, a phone misplaced in a café, or a tablet used at home can all contain business data or provide access to cloud services.
A device lock is a simple control, but it is a powerful one.
How can I prepare my small business for Cyber Essentials assessment?
A small business can prepare by starting with a clear view of its devices, software, cloud services, and accounts. You do not need an overly complicated system, but you do need enough visibility to know what is in scope.
Begin by listing business laptops, desktops, mobiles, tablets, servers, routers, firewalls, cloud platforms, and key applications. Include services such as business email, cloud storage, finance systems, CRM tools, website administration, remote support tools, and any service that stores or processes organisational data.
Next, review accounts. Remove old staff accounts, guest accounts, unused admin accounts, test accounts, and any supplier accounts that are no longer required. Confirm that all active accounts have a valid business reason.
Then review passwords and authentication. Check whether default passwords have been changed, whether administrator access is controlled, whether cloud services use multi-factor authentication where available, and whether users must sign in before reaching business data.
Review devices for unnecessary software and services. Remove what is not needed. Check that devices lock properly, require credentials, and cannot be accessed freely when unattended.
UK Cyber Security Group can help businesses work through these areas before assessment, making the process clearer and reducing the chance of avoidable delays.
Secure configuration and cloud services
Cloud services are now central to most businesses. Email, documents, accounts, customer records, HR platforms, phone systems, security tools, and project systems may all be cloud-based.
Cyber Essentials v3.3 states that cloud services which store or process organisational data are in scope. This means secure configuration should not only focus on laptops and office networks. It should also include cloud settings, user access, admin portals, authentication, data sharing, and supplier responsibilities.
A cloud provider may manage some controls on your behalf, but the organisation still needs to understand its own responsibilities. In many cloud services, the provider secures the platform while the customer controls accounts, permissions, sharing, authentication, and configuration choices.
This is known as shared responsibility. Your business should know what the provider handles and what you must manage.
Third-party accounts and managed services
Many small businesses use external IT providers, managed service providers, contractors, or support companies. These third parties may have accounts that access business systems.
Cyber Essentials makes clear that accounts owned by the organisation are in scope, even if used by a third party. If a supplier uses an account to support your infrastructure, your business still needs to confirm that the Cyber Essentials controls are being met.
This matters for secure configuration because suppliers may create administrator accounts, remote support accounts, service accounts, or temporary access. These should be controlled, reviewed, and disabled when no longer required.
Outsourcing IT does not remove business responsibility. It means the organisation needs clear assurance that its provider is managing systems securely.
What software solutions support compliance with Cyber Essentials standards?
Software solutions that support Cyber Essentials standards include endpoint management platforms, mobile device management, identity and access management, password managers, vulnerability management tools, anti-malware platforms, cloud security dashboards, asset management systems, and compliance management platforms.
For secure configuration, useful software should help the business understand which devices exist, which applications are present, which accounts are active, which devices meet lock requirements, whether cloud security settings are aligned, and whether unnecessary software has been removed.
Endpoint management can help maintain consistent settings across laptops and desktops. Mobile device management can help protect phones and tablets. Identity tools can help manage accounts, access, and authentication. Compliance platforms can help track evidence, responsibilities, and assessment readiness.
The best solution is one the business will actually use. A tool that is too complex, ignored, or badly maintained will not improve compliance. The goal is practical visibility and control.
Common secure configuration mistakes
A common mistake is assuming that new devices are secure because they are new. New devices may still contain unnecessary applications, default settings, inactive security features, or trial software.
Another mistake is leaving guest accounts or test accounts active. These may seem harmless, but they can become hidden access routes.
A third mistake is allowing users to install whatever they want. This can lead to unsupported applications, risky browser extensions, or tools that the business cannot manage.
A fourth mistake is forgetting cloud services. A company may configure laptops properly but leave cloud sharing, administrator access, or MFA settings unmanaged.
A fifth mistake is failing to review supplier accounts. If a former supplier still has access, the business may not know who can reach its systems.
Secure configuration reduces these risks by making technology controlled, reviewed, and purposeful.
Secure configuration and remote working
Remote working makes secure configuration even more important. Staff may access business data from home, customer sites, hotels, shared offices, trains, and public networks.
Devices used remotely should have firewalls enabled, device locking in place, unnecessary software removed, and authentication required before access to business services. Cloud accounts should use suitable authentication, and remote access tools should be controlled.
Personal devices used for business may also be in scope if they access organisational data or services. A business should understand whether bring-your-own-device arrangements exist and how they are managed.
A simple remote working review can identify where controls are strong and where changes are needed.
Secure configuration and user behaviour
Technology settings matter, but staff behaviour matters too. Staff should understand why they cannot keep old software, share admin passwords, bypass device locks, or use unapproved applications.
Clear guidance helps. People are more likely to follow rules when the reason is explained plainly. Secure configuration should not feel like an arbitrary restriction. It is there to protect customer data, business information, and the organisation’s ability to operate.
Staff should also know how to report problems. If a device behaves strangely, an unauthorised application appears, or an account seems wrong, early reporting helps the business respond quickly.
Can I renew my Cyber Essentials certification through an online service?
Yes, Cyber Essentials can be renewed through an online assessment process. Renewal is a good time to review secure configuration because business technology often changes during the year.
Since the last assessment, your business may have added new laptops, changed cloud providers, adopted new software, taken on new staff, changed suppliers, or introduced remote working changes. Each change can affect secure configuration.
Before renewing, review whether unnecessary accounts have been removed, default passwords have been changed, unnecessary software has been removed or disabled, users must authenticate before accessing data, and device locking remains in place.
UK Cyber Security Group provides Cyber Essentials certification support and can help organisations renew with a clearer understanding of current requirements. This is useful because Cyber Essentials requirements are updated over time, and old assessment answers may no longer reflect the current scheme.
Why secure configuration supports wider cyber resilience
Secure configuration is not only about passing Cyber Essentials. It supports wider resilience by reducing avoidable weaknesses.
A well-configured device is easier to manage. A clean software set is easier to update. A controlled account list is easier to review. A locked device is harder to misuse. A cloud service with proper authentication is harder to compromise.
These controls also support incident response. When a business knows what should be installed, who should have access, and how devices should behave, unusual activity is easier to spot.
Secure configuration therefore supports prevention, detection, and recovery.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification services in the UK are provided through approved certification bodies and specialist cyber security providers. Businesses should choose a provider that explains the requirements clearly and can help with practical areas such as secure configuration, firewalls, access control, malware protection, and security updates.
UK Cyber Security Group offers Cyber Essentials certification and support for organisations that want a straightforward route through the assessment. Its Cyber Essentials service highlights the five core controls, including secure configuration, and can help businesses prepare more confidently.
When comparing providers, look for clear guidance, current scheme knowledge, practical support, and a process that helps your business understand what needs to be done. The certificate matters, but the support before submission can be just as important.
A good provider should help your business identify gaps without making the process feel overwhelming.
Which UK-based firms offer Cyber Essentials consultancy services?
UK-based firms offering Cyber Essentials consultancy services include cyber security consultancies, certification bodies, compliance providers, managed IT companies, and specialist advisory firms.
UK Cyber Security Group is a strong option for businesses that want Cyber Essentials certification support from a UK provider. The company can help organisations understand the scheme, prepare for assessment, and deal with areas such as secure configuration, user access control, patching, passwords, and firewalls.
Good consultancy should be clear and proportionate. A small business does not need unnecessary complexity. It needs practical help to understand what is in scope, what needs changing, and how to maintain good cyber hygiene after certification.
For secure configuration, consultancy support can help identify default settings, old accounts, unnecessary software, weak device locking, and unmanaged cloud configuration.
Secure configuration readiness checklist
Before starting Cyber Essentials, ask these questions:
Do we know which devices, cloud services, and applications are in scope?
Have guest accounts and unused accounts been removed or disabled?
Have default and guessable passwords been changed?
Do users authenticate before accessing business data or services?
Are administrator accounts controlled and limited?
Has unnecessary software been removed or disabled?
Have unnecessary network services been removed or disabled?
Are auto-run features controlled where they could allow file execution without user authorisation?
Do laptops, phones, and tablets lock properly?
Are unlocking credentials protected against repeated guessing?
Are supplier accounts reviewed?
Are cloud services configured securely?
Are remote working devices managed appropriately?
Is evidence available to support assessment answers?
If any answer is unclear, it should be reviewed before submission. These checks will make assessment smoother and improve real security.
Keeping secure configuration alive after certification
Cyber Essentials should not be treated as a one-day task. Secure configuration needs to be maintained as the business changes.
Every new device, account, cloud service, or supplier can create new configuration risk. Every staff leaver, role change, or retired application can leave something behind if not managed properly.
A simple review process helps. Check accounts regularly. Review admin access. Remove unused applications. Confirm device lock settings. Review cloud sharing and authentication. Keep records short but useful.
The goal is not to make security heavy. The goal is to make secure choices part of normal business management.
Why UK Cyber Security Group is a practical place to start
UK Cyber Security Group offers Cyber Essentials certification for businesses that want an affordable route with expert support. Secure configuration is one of the areas where guidance can make a real difference because the requirement touches devices, software, accounts, cloud services, remote working, and supplier access.
For many small businesses, the challenge is not unwillingness. It is knowing what Cyber Essentials expects and how to evidence it. A guided process helps reduce uncertainty and makes the assessment easier to approach.
The result should be more than a certificate. The business should end the process with better control over its technology, clearer access management, fewer unnecessary weak points, and stronger confidence in its day-to-day cyber hygiene.
Final guidance for UK businesses
Cyber Essentials secure configuration requirements are built around common sense. Remove what is not needed. Disable what should not be active. Change default passwords. Protect accounts. Require authentication. Lock devices. Keep cloud services under control. Review supplier access.
These actions reduce the easy routes attackers often rely on. They also make business systems easier to manage and easier to explain during assessment.
For UK organisations that want support, UK Cyber Security Group provides Cyber Essentials certification and practical guidance. With the right help, secure configuration becomes a manageable part of certification and a useful step towards stronger cyber resilience.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










