Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology8 min read

Cyber Essentials is no longer a tick-box exercise – businesses need to act now | TechRadar

Tougher standards mean businesses need to rethink their approach Discover insights about cyber essentials is no longer a tick-box exercise – businesses need to

TechnologyInnovationBest PracticesGuideTutorial
Cyber Essentials is no longer a tick-box exercise – businesses need to act now | TechRadar
Listen to Article
0:00
0:00
0:00

Cyber Essentials is no longer a tick-box exercise – businesses need to act now | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Cyber Essentials is no longer a tick-box exercise – businesses need to act now

Tougher standards mean businesses need to rethink their approach

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Malware kan ställa till med oreda (Image credit: Shutterstock)

When was the last time you reviewed your cyber security standards? Let’s be clear: keeping a company secure is a constant task.

Cyber breaches are on the rise; according to the latest UK Government Cyber Security Breaches Survey, 4 in 10 businesses were compromised in the last 12 months. It’s important to remember businesses of all types and sizes are at risk – where there are gaps in security, attackers will take advantage.

Against this backdrop, plus high-profile cyber-attacks on companies including M&S and JLR, the government has reviewed its Cyber Essentials framework.

Its latest overhaul is raising the bar for organizations of all sizes.

Head of cyber security at Restore Information Management.

Designed to provide the basic controls to protect businesses and their staff, if taken seriously, Cyber Essentials can make all the difference. Yet many businesses are still struggling to meet even baseline security standards.

Avoiding the auto-fail under cyber essentials’ new rules

Rethinking cyber defense in government with continuous exposure management

Common issues such as a lack of budget, limited resources and a focus on other priorities are all factors holding organizations back – and they all make a major IT breach more likely.

Historically treated as a once-a-year compliance exercise, the latest ‘Denzel’ Cyber Essentials framework signals a clear and overdue shift towards implementing continuous cyber resilience. This means tougher standards which could catch businesses out.

Here are the key changes and how to approach them, to reduce the risk of a breach.

Under the new framework, expectations have been tightened around patch management – the process of fixing a security risk or software error by installing updates – and vulnerability management.

Previously businesses could demonstrate compliance with patching requirements though documented processes and periodic updates.

The ascent of autonomous attacks and the race to contain them

AI is making cyber threats faster, but trust will define which businesses survive

In reality, teams find it hard to build in regular patching routines which work without affecting live services, due to downtime and continual testing. And that’s without taking into consideration all the third-party patches that need to be applied, as well as the critical operating system ones.

There is evidence that not addressing application issues and vulnerabilities is leading to more breaches. The 2026 Verzion Data Breach Investigations Report shows system compromise is now up to 61%, the highest it’s been over the last three years.

Timelines for applying critical patches have been made stricter, with a 14-day window to comply. Critical patches must be deployed consistently within this period, and businesses must be able to evidence their patching regime is working.

Companies will be afforded two chances to prove patches have been successfully deployed using a process called “double sampling”. If the first round of evidence has critical issues identified, a second chance will be given to fix it and prove it has worked – if it hasn’t, businesses will fail their certification.

IT teams should review systems now to determine if everything is being patched within the 14-day window. If not, they will need to work closely with operational teams to build up to the requirements in time for the next assessment.

Deploy Multi Factor Authentication (MFA) across the board

MFA remains one of the most effective controls against account compromise. The issue for many organizations is not a lack of MFA capability, but inconsistent deployment.

Businesses are likely to have MFA enabled for remote access such as Virtual Private Networks (VPNs) and Microsoft 365 services – but admin interfaces, cloud platforms and third-party services often do not follow the same practice, leaving companies exposed. Threat actors know this and use these weaknesses to try to gain access.

Under the new framework, if you have a cloud system which supports MFA then it must be enabled for all users, irrespective of whether it’s a free, included or paid-for option. Without MFA enabled, it’s an automatic certification failure.

This begs the question: do you know if MFA is enabled on all your cloud services? If not, how long will it take to turn this around?

Under previous versions of the framework, cloud services could be excluded from the assessment as it was argued they sat outside of the scope. This argument is no longer viable. Organizations need to provide a clear, well-defined document with evidence to support proper segregation of all IT Systems, otherwise they will automatically be viewed as within scope.

This means businesses must account for all services, regardless of where they are hosted. Given the flexibility of cloud solutions, this can quickly become a complex issue to gain appropriate visibility of all systems. If you are processing or storing data in a cloud service, this will be included. Typically, these are CRM platforms, HR software and financial systems, project management solutions, plus many more.

As it can take time to discover what’s in use and in scope, this is another area where organizations need to leave plenty of time to ensure all cloud services are covered.

Replace legacy hardware and update operating systems

A major change, and possibly the greatest headache, is the requirement to replace ageing hardware and software.

Recent retirement of the Windows 10 operating system is one area where businesses are under pressure to replace all their hardware to remain compliant. It doesn’t stop there – ageing IT infrastructure, along with major vendor services and solutions, all need to be replaced at some point. If organizations don’t plan ahead, they could be left with a mounting problem and not enough time to deal with it.

Once a vendor stops supporting a platform, the risk of a breach increases until this is addressed. Security patches will no longer be made available and given the time these systems have been out in the wild, it’s only a matter of time before another vulnerability is discovered and exploited.

In the short term, businesses should ensure they have a clear view of their assets in scope of Cyber Essentials and check vendor support dates (and when these run out) to avoid any hidden surprises at the last minute. In the long-term, a robust strategy for replacing all hardware as it is approaching end of life will save difficulty further down the line.

Core areas in the Cyber Essentials framework have been updated to reflect the fast-changing security landscape. It’s not all bad news, as businesses have time to turn things around. Organisations should read carefully through the new standards and consider how they apply to their own company.

Do not treat Cyber Essentials as a tick-box exercise and wait until a month before your next assessment. Do a gap analysis now and deal with the findings.

At the end of the day, it is absolutely worth the effort.

The best internet security suites for PCs, Macs and mobile devices, reviewed by the experts.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Head of cyber security at Restore Information Management.

You must confirm your public display name before commenting

Whoop launches Meridian, its jewellery-inspired fitness tracker band

I fell for the Kindle Scribe Colorsoft hype and now regret it — its monochrome sibling is the superior Amazon slate in my book

United’s new A321XLR is packed with tech, but I’m most excited about the middle seat

CPU shipments fall as consumers pay the cost for price rises — but AMD grows its share

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.