Skip to main content

Hamilton Group’s IT Security Baseline: Proactive Cyber Security for Managed Devices in 2026

Media

 

Cyber security should not depend on someone remembering to check whether a laptop is secure.

It should be monitored.

Continuously.

A computer can gradually fall away from an organisation’s expected security standard for many reasons. Updates fail. A firewall gets disabled. Endpoint protection stops running. An old application becomes unsupported. A user ends up with unnecessary administrative privileges. A laptop that was secure six months ago may no longer meet the same standard today.

That is why Hamilton Group introduced our IT Security Baseline.

Rather than treating cyber security as something we inspect once a year, our objective is to continually assess important configuration and security indicators across the devices we manage and identify when something moves outside the expected baseline.

When one of those checks identifies a problem, it can generate an alert or support ticket for our technical team to investigate and remediate.

It is a simple principle:

Don't wait for a security problem to become an incident before doing something about it.

Hamilton Group holds Cyber Essentials and Cyber Essentials Plus certification and supports customers working towards their own certification. Our IT Security Baseline is influenced by the same cyber-hygiene principles, but it is important to make a distinction: our monitoring baseline is not itself Cyber Essentials Plus certification. Cyber Essentials Plus requires independent technical testing through the official certification scheme.

Why Do Businesses Need a Security Baseline?

Think about the number of settings and components involved in securing just one business laptop.

The operating system needs updating.

The firewall needs to remain active.

Malware protection needs to work.

Unnecessary or insecure services should not be enabled.

User privileges need controlling.

Applications need to remain supported.

Backups may need monitoring.

Encryption may need to remain enabled.

Now multiply that across 20, 50 or 200 computers.

Checking everything manually once every few months is not a particularly scalable security strategy.

A baseline gives us an expected state against which managed devices can be monitored.

If something changes, we can investigate.

That moves IT support from:

“Tell us when something goes wrong.”

towards:

“Let's identify problems before they cause disruption or increase risk.”

Cyber Essentials in 2026

Cyber Essentials remains the UK Government-recommended minimum cyber-security standard for organisations of all sizes.

Its five technical control areas are:

Firewalls

Secure configuration

Security update management

User access control

Malware protection

The current Cyber Essentials Requirements for IT Infrastructure v3.3 came into effect on 27 April 2026. Among its changes are clearer treatment of cloud services, updated passwordless-authentication terminology covering FIDO2 and increased emphasis on the importance of backups.

Cyber Essentials Plus uses the same underlying protections but adds more rigorous independent technical testing.

That distinction matters.

Hamilton Group's baseline can help us identify conditions relevant to good security hygiene and help customers prepare for certification, but certification itself remains a formal independent process.

What Does the Hamilton Group IT Security Baseline Check?

Our baseline includes checks across areas relevant to security, reliability and device health.

The exact checks can evolve as technology, operating systems and Cyber Essentials requirements change.

Examples include the following.

Security Updates

Keeping software supported and patched is one of the most important security fundamentals.

Our monitoring can help identify devices where expected updates are missing or where patching has not completed correctly.

This supports one of the five core Cyber Essentials controls: security update management.

A laptop that quietly stops installing updates shouldn't remain unnoticed indefinitely.

Firewall Status

The device firewall is an important defensive layer.

If the Windows or macOS firewall is unexpectedly disabled or incorrectly configured, that warrants investigation.

Cyber Essentials explicitly identifies firewalls as one of its five fundamental controls.

Endpoint Protection and Microsoft Defender

Security software needs to do more than simply exist.

It needs to be running and functioning correctly.

Our baseline can monitor indicators relating to endpoint security and services so that unexpected failures can be investigated.

For customers using more advanced protection, this can form part of a wider security strategy involving EDR — Endpoint Detection and Response — rather than relying exclusively on traditional antivirus.

Disk Encryption

For appropriate managed devices, we can check technologies such as BitLocker on Windows.

Full-disk encryption is particularly valuable if a laptop is lost or stolen because it helps protect information stored on the device from unauthorised access.

Although disk encryption should not be confused with one of the five named Cyber Essentials technical controls, it is a sensible additional security measure for many businesses.

That is an important theme of our baseline:

Cyber Essentials should be a starting point, not necessarily the limit of your security strategy.

Secure Configuration

Default or unnecessary settings can increase attack surface.

Cyber Essentials v3.3 specifically requires organisations to proactively manage computers and network devices and remove or disable unnecessary accounts, applications and services.

Our baseline can therefore include checks around configuration items such as:

Unnecessary or insecure services

Legacy protocols such as SMBv1

Security services that have unexpectedly stopped

Local security configuration

The precise requirement depends on the device and environment, but the objective is the same:

Only enable what the business actually needs.

User Account Control and Privilege

Administrator rights deserve particular attention.

An employee who spends the whole day working with unnecessary administrator privileges creates additional risk because malicious software or a compromised account may gain greater capability.

Cyber Essentials includes user access control as one of its fundamental technical controls.

A mature security baseline should therefore consider not only whether the laptop itself is healthy, but whether access and privilege remain appropriate.

Backup Health

Backups deserve special mention.

Backup is not one of the five named Cyber Essentials controls, but the 2026 v3.3 requirements explicitly strengthen the emphasis on the importance of backing up organisational data.

Where Hamilton Group manages backup systems, checking whether backup jobs are actually succeeding is an important operational control.

A backup system showing failures for three weeks isn't much of a backup strategy.

And even a successful backup job doesn't prove recovery works.

Businesses should also test restores.

Windows and Mac Devices

Business technology is increasingly mixed.

Many organisations use Windows laptops alongside Macs, mobile devices, cloud applications and SaaS platforms.

Our approach therefore isn't built around assuming every employee uses the same type of computer.

Appropriate baseline and management checks can be applied across Windows and macOS environments, while recognising that the underlying controls and tools may be different.

Security Isn't the Only Thing We Monitor

The original version of our baseline article included items such as Outlook indexing and Outlook search problems alongside security checks.

Those are useful things to monitor, but they are better described as device-health and service-quality checks, not Cyber Essentials controls.

That distinction is worth making.

Hamilton Group's wider proactive monitoring can cover both:

Security posture

and

Operational health

because both matter to the customer.

A broken Outlook index isn't normally a cyber-security incident.

But identifying and fixing it before an employee spends half a day unable to search their mailbox is still good managed IT support.

What Happens When a Device Fails the Baseline?

This is where monitoring becomes useful.

It is easy to build dashboards covered in green and red indicators.

The important part is what happens next.

When one of our monitored checks identifies a condition requiring attention, the objective is to create an actionable support process.

Depending on the issue, Hamilton Group may be able to remediate it remotely.

Other situations may require us to contact the customer or gain access to the affected computer.

The important difference is that we have identified the condition proactively rather than relying on an employee to notice it.

For example:

A security service unexpectedly stops.

An alert is generated.

Our technical team investigates.

The problem is corrected.

The employee may never even have known anything went wrong.

That is exactly how proactive IT support should work.

Does Passing the Baseline Mean You Are Secure?

No.

And any security provider promising otherwise should make you cautious.

There is no single product, certification or checklist that makes an organisation impossible to compromise.

Cyber Essentials itself is designed as a baseline protecting organisations against common internet-based attacks, not as a guarantee against every possible threat.

Hamilton Group's IT Security Baseline should therefore be seen as one layer within a broader security strategy.

That strategy may also include:

EDR

Microsoft 365 security

MFA and passkeys

Microsoft Entra Conditional Access

DNS and web filtering

Email security

Vulnerability management

Ransomware-resistant backups

Security awareness training

Incident response

Network security

Cyber Essentials or Cyber Essentials Plus

Security works best in layers.

If one control fails, another should ideally reduce the damage.

Cloud Services Matter Too

Another important change in the 2026 Cyber Essentials requirements is the treatment of cloud services.

Version 3.3 makes clear that cloud services within the organisation's scope cannot simply be excluded. The requirements recognise the shared-responsibility model: in some areas the cloud provider implements the technical control, while in others the customer still has responsibility for configuration and access.

That matters enormously for modern businesses.

Your laptop security could be excellent while your Microsoft 365 tenant is badly configured.

A proper business-security strategy therefore needs to look beyond physical endpoints and consider:

Microsoft 365.

Google Workspace.

Cloud administrator accounts.

SaaS services.

Identity.

MFA.

Access controls.

Managed mobile devices.

The modern security perimeter increasingly follows the user, identity and device, not merely the walls of the office.

Making Cyber Essentials Easier to Prepare For

One of the benefits of maintaining sensible security controls throughout the year is that certification preparation becomes less painful.

Trying to fix dozens of security issues immediately before a Cyber Essentials assessment can mean:

Discovering unsupported software.

Finding forgotten user accounts.

Chasing unpatched laptops.

Removing outdated applications.

Correcting firewall settings.

Investigating devices nobody knew existed.

A security baseline encourages those issues to be addressed as part of normal IT management.

That does not guarantee certification.

But maintaining good cyber hygiene should make the journey considerably more straightforward.

Cyber Essentials Plus then adds the independent technical assessment that provides greater assurance that the controls are actually operating as intended.

Why Hamilton Group Introduced the IT Security Baseline

Hamilton Group has always taken the view that managed IT support should involve more than repairing broken technology.

If we are responsible for managing a customer's IT environment, we should also be looking for opportunities to make that environment more secure, reliable and manageable.

Our IT Security Baseline helps us do that systematically.

It gives our technical team another way to identify:

Configuration drift.

Security failures.

Missing controls.

Device-health issues.

Potential certification problems.

And opportunities for remediation.

One line from the original launch article still captures the philosophy particularly well:

> “Hope is not a cyber security strategy.”

 

We would rather identify a problem because a monitoring check failed than discover it after an attacker took advantage of it.

Want to Improve Your IT Security Baseline?

Hamilton Group can help businesses assess their existing IT security, improve managed-device configuration and prepare for Cyber Essentials and Cyber Essentials Plus.

Our wider services include managed IT support, Microsoft 365 security, EDR, vulnerability management, backup and disaster recovery, patch management, security awareness and proactive monitoring.

And when our customers do need support, our aim is to make first contact on IT support requests within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with our IT and cyber-security team.