CYBER ESSENTIALS
The Five Cyber Essentials Controls Explained

Five controls. One objective: reduce your exposure to the most common cyber attacks.
Cyber Essentials is built around five fundamental technical controls:
- Firewalls
- Secure Configuration
- Security Update Management
- User Access Control
- Malware Protection
The principles are deliberately straightforward. The challenge is making sure they are applied consistently across every device, application and service within your Cyber Essentials scope, so you’re going to need help and SX7 is ready to go!
This guide explains what each control requires, the common weaknesses to look for and the practical steps you can take to prepare for certification.
SecureX7 helps turn those requirements into measurable technical checks — discovering your assets, identifying configuration and vulnerability gaps, prioritising remediation and helping you verify that improvements have actually been made.
Understand the five controls. Find the gaps. Fix what matters.
Cyber Essentials Firewall Requirements
Control the connections between your devices and the outside world
Cyber Essentials requires appropriate firewall protection between devices and untrusted networks such as the internet. This may be provided by a network firewall, router or the software firewall built into individual devices.
The principle is straightforward: block unnecessary inbound connections, control administrative access and ensure firewall configurations cannot be changed by users who do not have permission to do so.
The challenge is consistency. A firewall being installed does not necessarily mean it is enabled, correctly configured or operating consistently across every endpoint.
Why SecureX7?
SecureX7 automates the assessment of supported endpoint firewall configurations, helping identify devices where protection is disabled or settings differ from the required security baseline.
Rather than simply reporting a failed control, SecureX7's AI-powered actionable guidance explains what is wrong, why it matters and what should be done to remediate it.
This transforms firewall compliance from a manual device-by-device check into a repeatable assessment that can identify configuration drift as your environment changes.
Find firewall configuration gaps before your Cyber Essentials assessment.
Cyber Essentials Secure Configuration
Secure by design, not simply by default
Cyber Essentials requires devices and software to be configured securely. Unnecessary accounts, applications and services should be removed or disabled, insecure default settings changed and security features configured appropriately.
The difficulty is scale. A Windows PC alone can contain hundreds of configurable security settings, applications and services. Multiply that across an organisation and manually checking every device against an approved baseline quickly becomes impractical.
Why SecureX7?
SecureX7 automates secure configuration assessment by examining supported devices against established hardening requirements and security guidance.
It identifies deviations from the required baseline and produces a measurable compliance position across the environment.
More importantly, SecureX7 doesn't stop at identifying a failed setting. Its AI-powered actionable remediation guidance provides context around the weakness, explains its significance and helps determine the appropriate corrective action.
Continuous assessment can also identify configuration drift after remediation—helping prevent a compliant device gradually moving away from its approved security baseline.
Automatically assess. Understand the weakness. Remediate with confidence.
Cyber Essentials Security Update Management
Finding a vulnerability is only useful if you know what to do next
Cyber Essentials requires in-scope software to be licensed and supported, with applicable high-risk or critical security fixes applied within 14 days of release.
That means understanding much more than whether Windows Update has run. Organisations need visibility of operating systems, applications and other software across their environment, whether those products remain supported and which vulnerabilities require action.
Why SecureX7?
SecureX7 automatically discovers installed software and combines asset, vulnerability and configuration information to identify where security updates or other remediation may be required.
Instead of presenting security teams with another long list of vulnerabilities, SecureX7 uses AI-powered analysis to add context, establish which weaknesses matter and provide actionable guidance on how they can be remediated.
This helps teams focus on the vulnerabilities that represent genuine Cyber Essentials exposure, track remediation and identify systems that remain vulnerable as the 14-day deadline approaches.
Automation also makes the process continuous: new vulnerabilities can be identified against the estate without waiting for the next annual compliance review.
Know what's vulnerable. Know what matters. Know what to fix.
Cyber Essentials User Access Control
Give people the access they need — and no more
Cyber Essentials requires organisations to control access to systems and data, manage user accounts appropriately and restrict administrative privileges.
Users should normally operate with standard accounts. Administrative access should only be provided where necessary and used for tasks that genuinely require elevated privileges. Appropriate authentication controls, including MFA where required, provide additional protection.
The challenge is that access changes over time. Accounts are created, privileges are granted and temporary exceptions have a habit of becoming permanent.
Why SecureX7?
SecureX7 can help identify relevant endpoint accounts, privileges and security configurations, providing visibility of conditions that could undermine your Cyber Essentials position.
Its automated assessment highlights deviations from the expected baseline, while AI-powered actionable guidance explains the issue and provides practical remediation recommendations rather than simply generating another alert.
SecureX7 complements identity and organisational processes rather than replacing them. Cloud MFA, account approval and joiner/mover/leaver processes may still require identity-system integration or human verification.
Find excessive privilege. Understand the risk. Take appropriate action.
Cyber Essentials Malware Protection
Protection needs to be present, active and correctly configured
Cyber Essentials requires organisations to protect devices against malicious software. Depending on the device and environment, this can involve anti-malware software, application allowlisting or application sandboxing.
For many Windows environments, Microsoft Defender or another endpoint security product provides the underlying protection. But having security software installed is not the same as knowing that protection is enabled and correctly configured across every device.
A single overlooked or incorrectly configured endpoint can create unnecessary exposure.
Why SecureX7?
SecureX7 provides centralised assessment of supported endpoint security configurations, helping identify devices where expected protection or security settings differ from the required baseline.
Automated assessment removes much of the need to manually inspect individual endpoints and makes it easier to identify exceptions across a changing estate.
Where weaknesses are discovered, SecureX7's AI-powered actionable guidance provides context around the finding and practical guidance on the corrective action required.
Continuous assessment also helps detect configuration drift, providing visibility when endpoint security moves away from the approved state after the initial Cyber Essentials preparation has been completed.
Verify protection across your estate — not just on the device in front of you.


