Is Your IT Support Cyber Essentials Certified?

Cyber Essentials 2023
Cyber Essentials is the minimum security baseline that all companies should aim to achieve. It checks to ensure that the very basics are covered, such as MFA on all Cloud service accounts, no admin rights for day-to-day use, and that security updates are installed promptly. If you are seeking to certify your own organisation, you should definitely ensure that your IT Support – who likely have far more access and control over your company data than you do – has at least this basic benchmark certification.

What is Cyber Essentials>

In a nutshell, Cyber Essentials is a certification that verifies your company meets the most basic requirements of security as defined by the NCSC (National Cyber Security Centre) which ultimately overseas the standard. If you don’t meet these requirements you are more vulnerable. The scheme is delivered by IASME via an army of IT Professionals who act as assessors of the standard.

Cyber Essentials comes in two tiers.

  • Self Assessment
  • Assessed

The self-assessment is a question set that you fill in yourself, and the answers assessed for compliance with the standard. Nevertheless it is fairly rigorous and covers some technical areas, such as what versions of operating systems, browsers, and security software are in use, as well as policies such as how you mange admin rights. As such, you will likely need some help and guidance from your IT department or external support.

The assessed version comes later, if you want it, and involves the assessor taking your answers from the self-assessment and checking them directly. This includes a random sampling of your machines for update status and vulnerabilities, a basic external scan of your firewalls, checking that security software is working as expected, and verifying that MFA is enabled on all your Cloud services.

Not Just Technical, But Educational

While the Cyber Essentials baseline does check that technical controls are in place, that’s not it’s only purpose. It’s other significant benefit is to raise awareness within the organisation about what controls are in place, and what procedures there are for managing changes such as new software or staff access and admin rights.

Some 98% of cyber attacks in 2023 came in some form of social engineering – i.e. phishing, CEO fraud, and similar. Training and Awareness is therefore a vital component of any security solution in any company. The more staff are aware of the need for security and what the threats actually look like, the more savvy they will be in spotting them early.

Whose Fault Is It Anyway?

There is an old saying in the Cyber Security world that ‘you cannot outsource responsibility’. You may have an IT Support provider in place, but that doesn’t mean you are secure.

As IASME says:

“If your organisation outsources its IT, a third-party provider will manage your network for you, however, the responsibility for your network security is still yours… some IT providers may have good technical knowledge, but they do not always have good understanding about cyber security.”

In short, you cannot assume that your IT Support is taking care of your security. And even if they are, the responsibility is still yours, not theirs, regardless of whatever contractual requirements you may have in place for service delivery. If a staff member gives away their password, while technical controls may be in place, the breach is human error, not the fault of IT Support.

Let’s say IT implements MFA on all your Microsoft 365 accounts. They’re not responsible for any other cloud services you may use, so you cannot rely on them to do the same there, and some services have no centralised way of enforcing it on all accounts, leaving it up to individual staff to apply it themselves. Or, what if you decide you don’t want MFA on M365 and they disable it, because after all, you are the client and that’s what you want?

How do you know that your IT Support is protecting their own accounts? Do you know how they access your systems? It may surprise you. Do they have MFA themselves on those accounts? Does anyone share access to admin accounts?

What To Ask Your IT Support About Cyber Essentials

IASME have put together a list of questions, which mirrors the Cyber Essentials question set and your IT support should be able to answer them, or provide their own certificate for CE. If they can’t, you really need to question whether they are suitable for supporting you for IT, let alone whether you can rely on them for your security.

See here for the IASME guidance and the questions you should be asking: Cyber Essentials guide to working with a third party IT Provider

Macnamara’s Certifications

Macnamara holds both Cyber Essentials and Cyber Essentials Plus and are a certification body for the standard, as well as holding a suite of other certifications around security and information management (up to and including, as of October 2024, ISO27001). This is not just because we take security seriously, but as assessors ourselves we are required to meet if not exceed the standards that we are assessing against.

Our Certifications – Macnamara ICT

Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance Level 1 & 2, ISO27001
Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance Level 1 & 2, ISO27001
Cyber EssentialsCyber Essentials Plus
Cyber Essentials Certification BodyISO27001

Ready to Talk?

If you’re looking for certification on Cyber Essentials and your IT Support doesn’t have it themselves or cannot assess you or help you through it, then get in touch and we can help you out.

Further reading

Dangers of CEO Fraud

CEO Fraud: Don’t Let It Be You

CEO fraud is a highly targeted scam where criminals impersonate senior leaders to pressure staff into making payments or sharing sensitive information. This article explains how these attacks work, the warning signs to look out for, and the practical steps organisations can take to reduce the risk through awareness training, strong approval processes, MFA and regular security reviews.

Read More »
Copilot Studio

Getting Started with Copilot Studio

Artificial Intelligence is becoming a major part of modern business, and more organisations are starting to look at AI not only as a trend, but as a real productivity tool. One of Microsoft’s most powerful platforms in this space is Copilot Studio.

Read More »