Max Cloud Services
The 5 controls of Cyber Essentials, explained
Cyber Security11 July 20266 min read

The 5 controls of Cyber Essentials, explained

Cyber Essentials boils good security down to five practical controls. Get these right and you’ll block the overwhelming majority of common attacks — here’s what each one actually means.

Cyber Essentials can sound intimidating, but the scheme is refreshingly practical. It’s built on five core technical controls — the security basics that, done properly, stop the vast majority of internet-based attacks. Here’s each one in plain English, and what you’ll need to demonstrate.

1. Firewalls

Firewalls create a buffer between your devices and the internet, only allowing through the traffic that should be there. In practice this means having a properly configured firewall at your network boundary and on individual devices — with default passwords changed and no unnecessary services exposed to the internet.

2. Secure configuration

Devices and software often ship with insecure defaults — extra accounts, sample settings, unnecessary features switched on. Secure configuration means removing what you don’t need, changing default passwords, and setting things up deliberately rather than accepting whatever comes out of the box.

The theme running through all five

Attackers overwhelmingly rely on the basics being wrong — default passwords, missing updates, over-shared access. Cyber Essentials simply forces the basics to be right.

3. User access control

Not everyone needs access to everything. This control is about giving each person only the access they need to do their job, removing accounts promptly when people leave, and — crucially — not letting people run day-to-day as administrators. Admin rights should be the exception, granted only when needed.

4. Malware protection

You need a reliable, active defence against malicious software on your devices. That can be well-configured anti-malware software kept automatically up to date, or an approach that only allows approved applications to run. The key is that it’s always on and always current.

5. Security update management

Unpatched software is one of the most common ways in for attackers. This control requires that operating systems and applications are kept up to date, with high-risk and critical updates applied promptly — typically within 14 days — and that anything no longer supported by the vendor is removed.

We assess your setup against all five controls, close the gaps, and guide you through certification. Want a readiness check before you start?

Book a readiness check

A note on Microsoft 365

For most businesses, several of these controls come down to how Microsoft 365 and your devices are configured — multi-factor authentication, access control and secure defaults especially. This is where self-assessments most often come unstuck, and where a bit of preparation makes all the difference.

The bottom line

The five controls aren’t abstract security theory — they’re the practical basics every business should have anyway. Cyber Essentials just gives you a recognised badge for getting them right, and a clear checklist to work through.

Got a question about your IT?

Book a free, no-obligation audit or call 0800 994 9028. Straight answers, no jargon, no hard sell.