Skip to main content

Cyber Essentials Does Not Cover Everything

Media Cyber Essentials Does Not Cover Everything

 

Cyber Essentials is one of the most useful cyber-security certifications available to UK businesses.

It provides a clear baseline.

It forces organisations to address weaknesses that commonly lead to compromise.

And increasingly, customers and supply chains expect businesses to have it.

But there is an important distinction:

Cyber Essentials is a strong foundation. It is not a complete cyber-security strategy.

The National Cyber Security Centre describes Cyber Essentials as the minimum standard of cyber security recommended by government, built around five technical controls intended to prevent common internet-based attacks.

Those five controls matter enormously.

But a business can pass Cyber Essentials and still have important risks elsewhere.

Understanding that distinction is the key to getting real security value from the certification.

What Does Cyber Essentials Actually Cover?

The current Cyber Essentials Requirements for IT Infrastructure v3.3 organise certification around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

In practical terms, that means checking whether your organisation has controls around:

internet-facing network protection

secure device and software configuration

supported and patched software

appropriate user and administrator access

malware protection


These are not arbitrary controls.

The NCSC says they are designed specifically to reduce exposure to the most common online attacks.

That makes Cyber Essentials an excellent starting point for an SME.

Cyber Essentials Got Stricter in 2026

The April 2026 update is worth understanding because some businesses may still think of Cyber Essentials as the scheme they completed several years ago.

It has evolved.

Under v3.3, cloud services used by the organisation cannot simply be excluded from scope, and the requirements now include an explicit cloud-service definition.

That matters because modern businesses increasingly depend on services such as:

Microsoft 365

cloud CRM

cloud accounting

cloud storage

hosted applications


Cyber Essentials increasingly reflects that reality rather than assuming that every important system is sitting in your office.

MFA Is Now Much Harder to Ignore

One of the most significant 2026 changes concerns multi-factor authentication.

IASME states that MFA is mandatory for cloud services where it is available, whether the capability is free, included with the service or requires payment. Failure to implement it in those circumstances now results in automatic assessment failure.

That is a substantial improvement.

But it still does not mean:

“Cyber Essentials passed = our identity security is fully mature.”

A more advanced identity strategy may still include:

phishing-resistant MFA

Conditional Access

privileged identity management

risky sign-in monitoring

separate administrator accounts

stronger controls for finance and executives


Cyber Essentials gives you the baseline.

Risk-based identity security goes further.

Critical Security Updates Need to Be Timely

The 2026 scheme has also become stricter around patching.

IASME says two update-management questions now carry automatic failure where high-risk or critical security updates and vulnerability fixes for operating systems, router/firewall firmware and applications are not installed within 14 days of release.

That is exactly the sort of requirement that materially reduces everyday attack exposure.

But again, it is a minimum requirement.

A mature vulnerability-management programme might also consider:

actively exploited vulnerabilities

asset criticality

exposure to the internet

zero-day mitigations

emergency patching

vulnerability scanning


Some flaws should be addressed much faster than fourteen days.

So What Doesn’t Cyber Essentials Fully Cover?

This is where the distinction matters most.

Cyber Essentials is intentionally focused on its five technical controls. It does not attempt to assess every component of a mature security programme.

Areas that generally need additional attention include:

security awareness and human behaviour

incident response

business continuity

backup resilience and restore testing

continuous security monitoring

vulnerability management beyond baseline patch compliance

penetration testing

supplier and supply-chain risk

data classification

advanced detection and response


Your existing article already identifies many of these gaps, and that central argument is worth keeping.

1. Security Awareness Training

Cyber Essentials includes technical controls that make attacks harder.

It does not replace the need to teach staff how attackers operate.

Employees still encounter:

phishing emails

fake Microsoft 365 login pages

payment diversion fraud

malicious attachments

QR-code phishing

telephone social engineering

MFA fatigue attacks


A secure configuration cannot stop every employee from willingly handing credentials to a convincing fake website.

Businesses therefore still need:

regular awareness training

simulated phishing where appropriate

clear reporting routes

role-specific education


Technical controls and human controls work together.

2. Incident Response

Cyber Essentials helps reduce the likelihood of common attacks succeeding.

It does not give you a complete incident-response plan for the day one does.

Every organisation should still know:

Who leads the response?

Who isolates affected systems?

How do we contact people if Microsoft 365 is unavailable?

Who contacts our insurer?

Who decides whether customers or regulators need notification?

Where are our recovery credentials?

These questions need answers before the incident.

Not while ransomware is spreading.

3. Backup and Disaster Recovery

The v3.3 Cyber Essentials requirements now explicitly emphasise the importance of backing up data, but backup and disaster-recovery maturity is not one of the five technical control categories being certified.

A proper backup strategy still needs to consider:

off-site copies

immutability

isolation

retention

separate backup credentials

restore testing

ransomware recovery

recovery time objectives


A company may satisfy Cyber Essentials and still discover during a disaster that nobody has ever successfully restored the accounting database.

That is a different problem.

4. Continuous Security Monitoring

Cyber Essentials checks whether baseline controls are in place.

That is different from continuously detecting suspicious activity.

Modern businesses may also need capabilities such as:

endpoint detection and response

identity monitoring

Microsoft Defender

centralised alerting

security event monitoring

suspicious sign-in detection

managed detection and response


The difference is:

Cyber Essentials helps make compromise harder.

Monitoring helps tell you when something is happening anyway.

You need both as security maturity increases.

5. Vulnerability Management

Cyber Essentials strongly addresses patching.

But full vulnerability management is broader than:

“Install critical updates within fourteen days.”

A mature programme may need to know:

which vulnerabilities exist

where they exist

whether they are exposed externally

whether attackers are actively exploiting them

which systems are business-critical

which mitigations exist before a patch is available


That often requires:

vulnerability scanning

prioritisation

remediation tracking

verification


Patch compliance is crucial.

It is not the whole vulnerability-management process.

6. Penetration Testing

Cyber Essentials does not mean an ethical hacker has attempted to compromise your complete environment.

Cyber Essentials Plus gives greater assurance by technically auditing whether the Cyber Essentials controls have been implemented, but it remains an assessment against those same core Cyber Essentials requirements rather than a full penetration test of the organisation. IASME describes CE+ as a higher-assurance technical audit of the organisation’s cyber-security measures against the scheme.

A penetration test asks different questions:

Can we exploit this application?

Can we move laterally?

Can permissions be abused?

Can this custom system be compromised?

Some organisations need both.

7. Supplier Risk

Your security does not stop at your firewall.

Businesses increasingly depend on:

accountants

software providers

MSPs

cloud platforms

payroll services

contractors

outsourced support


A supplier with privileged access can create risk even when your own Cyber Essentials controls are correctly implemented.

The NCSC itself encourages organisations to use Cyber Essentials within supply chains as part of a wider strategic approach to cyber risk.

That phrase matters:

part of a wider approach.

Supplier risk still needs active management.

8. Data Classification and Governance

Cyber Essentials helps control access.

But it does not answer questions such as:

Which information is genuinely sensitive?

Which Teams sites contain financial information?

Which SharePoint folders can guests access?

Which information should never leave the organisation?

Those questions belong to broader information governance.

Without it, you can have technically secure systems containing badly organised and excessively shared data.

Cyber Essentials Is Still Extremely Valuable

None of this is an argument against Cyber Essentials.

Quite the opposite.

The NCSC describes the scheme as the minimum security standard it recommends, and the five controls are specifically designed to stop many common attacks.

It also brings commercial benefits.

The NCSC says a growing number of organisations require suppliers to hold Cyber Essentials before they can bid for work, and certification can help demonstrate that a business takes cyber security seriously.

For SMEs in particular, the scheme gives a very practical starting point.

Cyber Essentials Is a Point-in-Time Assessment

This is another 2026 point I would strengthen substantially.

IASME clarified that Cyber Essentials remains a point-in-time assessment, with the relevant point being the date the certificate is issued. The 2026 process also requires the board-level declaration to acknowledge the organisation’s responsibility to maintain compliance during the certification period.

That means:

Passing in May does not protect you from configuration drift in November.

During the year:

employees join

employees leave

devices are purchased

software goes out of support

cloud applications are added

permissions change

firewall rules accumulate


Cyber Essentials needs to be maintained, not merely renewed.

Cyber Essentials Plus Does Not Make You Invincible Either

Cyber Essentials Plus is the more rigorous version.

It provides greater confidence because an assessor performs technical verification rather than relying only on the verified self-assessment. The 2026 CE+ process has also been tightened so organisations cannot simply fix only the sampled devices and leave the wider estate non-compliant.

That is a meaningful improvement.

But CE+ still does not mean:

“No attacker can breach us.”

It means there is stronger independent evidence that the Cyber Essentials technical controls are operating as required.

That distinction matters.

A Better Security Model for SMEs

I would think of security in layers.

Layer 1 — Cyber Essentials

Get the baseline right:

firewalls

secure configuration

security updates

access control

malware protection


Layer 2 — Identity and Email

Add:

strong MFA

Conditional Access where appropriate

email protection

phishing controls

privileged-account protection


Layer 3 — Detection

Add:

EDR

identity monitoring

central security alerts


Layer 4 — Recovery

Build:

immutable/off-site backups

restore testing

disaster recovery

business continuity


Layer 5 — People and Process

Develop:

staff training

incident response

supplier management

security policies


Layer 6 — Assurance

Use as appropriate:

vulnerability scanning

Cyber Essentials Plus

penetration testing

external security reviews


That creates something much stronger than treating certification as the finish line.

The Questions to Ask After You Pass

Once you have Cyber Essentials, ask:

1. Are all important cloud services included in our security model?


2. Is MFA enabled wherever it is available?


3. Can we reliably deploy critical updates within the required timescale?


4. Are administrator privileges reviewed regularly?


5. Can we detect suspicious activity?


6. Could we recover from ransomware?


7. When did we last test a backup restore?


8. Do employees know how to recognise and report phishing?


9. Do we understand supplier access?


10. Have we tested the environment beyond the Cyber Essentials baseline?

 

If several answers are:

“No”

then that tells you exactly where to go next.

How Hamilton Group Can Help

Hamilton Group can help businesses achieve Cyber Essentials without treating the certificate as the end of the security journey.

We can assist with:

Cyber Essentials readiness

Cyber Essentials Plus preparation

Microsoft 365 security

MFA

patch management

firewall configuration

endpoint protection

vulnerability scanning

security awareness training

backup and disaster recovery

ongoing cyber-security management


The objective should be:

achieve Cyber Essentials, maintain it throughout the year and then build additional protection around the risks the scheme was never designed to assess in full.

Visit hgmssp.com or call 0330 043 0069 to discuss Cyber Essentials and cyber security.