Skip to main content
    NixInfinity-AI
    NCSC Technical Controls

    The 5 Cyber Essentials Controls Explained

    A practical, NCSC-aligned breakdown of every Cyber Essentials control, what auditors look for, and the common pitfalls that cause first-time failures. Updated for the 2026 IASME requirements.

    Cyber Essentials is the UK government-backed scheme set by the National Cyber Security Centre (NCSC) and delivered by IASME. Implementing the five controls below correctly stops around 80% of common internet-based attacks.

    1. Firewalls

    Boundary firewalls and software firewalls that protect every device connecting to the internet.

    What auditors check

    • Block all unauthenticated inbound connections by default.
    • Change the default administrative password on every firewall.
    • Disable remote administrative access from the internet (or protect with MFA).
    • Document and approve all open inbound ports through a documented business case.

    Common pitfall: Forgetting that home routers used by remote workers are in scope. Software firewalls on each device are usually the cleanest solution.

    2. Secure Configuration

    Build devices and software to a known-secure baseline, removing unnecessary functionality.

    What auditors check

    • Remove or disable unused user accounts.
    • Change all default passwords and apply strong password policy or MFA.
    • Disable auto-run/auto-play for removable media.
    • Lock screens after no more than 10 minutes of inactivity.

    Common pitfall: Inherited builds with old default accounts. Use a hardened build image or MDM baseline policy.

    3. User Access Control

    Grant users only the access they need to do their job – no more.

    What auditors check

    • Unique account for every user – no shared logins.
    • Multi-factor authentication on all cloud services and admin accounts.
    • Standard users cannot install software or change system settings.
    • Documented joiner / mover / leaver process with prompt access revocation.

    Common pitfall: Users running with local admin rights for convenience. Use a separate admin account that is only used when needed.

    4. Malware Protection

    Prevent malicious software from running on your devices using one of three approved approaches.

    What auditors check

    • Anti-malware software with daily updates and real-time scanning, OR
    • Application allow-listing limiting execution to approved software, OR
    • Sandboxing / containerisation that isolates untrusted code.
    • Block access to malicious websites at the network layer where possible.

    Common pitfall: Choosing allow-listing without the operational maturity to maintain it. For most SMEs, modern anti-malware (e.g. Microsoft Defender for Endpoint) is the practical choice.

    5. Security Update Management

    Keep all software and firmware patched against known vulnerabilities.

    What auditors check

    • Use only software that is licensed and supported by the vendor.
    • Enable automatic updates where the vendor provides them.
    • Apply high and critical severity patches within 14 days of release.
    • Remove unsupported / end-of-life software from in-scope devices.

    Common pitfall: Lingering Windows 10 devices after end-of-support, or unmanaged firmware on routers. Maintain a live software inventory.

    Frequently Asked Questions

    Need help implementing the 5 controls?

    As an IASME accredited certification body, our qualified assessors walk you through every control from start to finish. 100% first-time pass rate.

    Start your certification

    Related Cyber Essentials Guides