Skip to main content
    NixInfinity-AI
    Five Controls

    Cyber Essentials Secure Configuration: A Practical Guide

    Published 5 June 2026

    The control in plain English

    Devices and software arrive from the vendor configured for ease of use, not security. Default passwords. Sample accounts. Unused services running. Auto-fill enabled. The Cyber Essentials secure configuration control says: tighten the defaults before you put a device into production, and keep them tight.

    What you must do

    1. Change every default password

    Routers, firewalls, switches, printers, NAS devices, on-premise applications. Default credentials are the first thing scanned for on the open internet.

    2. Remove or disable unused services and accounts

    That includes the "Guest" account on Windows, sample databases on a fresh SQL server, the vendor demo user on a SaaS app. If you're not using it, turn it off.

    3. Enforce screen lock and login

    Auto-lock after a period of inactivity (10 minutes is the common standard – but the scheme accepts your reasoned policy). Every user must log in with their own account; shared logins are a fail.

    4. Disable auto-run for removable media

    Plugged-in USB sticks should not silently execute anything. This is default on modern Windows but worth confirming via group policy or Intune.

    5. Require user authentication for software install

    Standard users shouldn't be able to install arbitrary software. Either UAC prompts admin credentials, or the user is a managed standard user with software installs gated.

    Application allowlisting – when it applies

    The IASME question set offers allowlisting as one valid approach to malware protection. If you choose it, the configuration of the allowlist itself becomes a secure configuration item: who can change it, how new software is added, how exceptions are reviewed.

    For most UK SMEs, signature-based anti-malware is the simpler route. Allowlisting fits regulated environments and locked-down kiosk setups.

    Where teams slip

    • One legacy printer with the default web admin password.
    • Auto-lock policy in M365, but the Mac fleet not actually pulling it (no MDM enforcement).
    • A "build" or "test" Windows machine running as local admin permanently.
    • A NAS device exposed via the router's UPnP because the box shipped with it on.
    • Conditional Access policies in M365 set up but not applied to the Microsoft-365-internal apps the staff actually use.

    How to evidence it

    Two things satisfy most assessor questions:

    • A short configuration baseline document – one page per device class (Windows laptop, Mac laptop, mobile, server) listing the settings you've enforced.
    • Sample screenshots from MDM (Intune compliance, Jamf configuration profile) showing the policy applied across the fleet.

    The wider evidence kit is covered in our evidence pack guide.

    Where this fits with the other controls

    Secure configuration sits next to firewalls, access control, malware protection and the 14-day patching rule. None of them on their own is sufficient; together they are the five technical controls that earn the certificate.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions