Cyber Essentials Audits: What We Check & Why It Matters
ยท 5 min read

Running a business in Petersfield means juggling clients, staff, suppliers and, of course, your IT. Your laptops, servers and cloud accounts may seem to be ticking along nicely, but most successful cyber attacks on small businesses don't rely on anything clever. They exploit the basics: an unpatched laptop, a default password, an old admin account nobody remembered to remove.
That's exactly what Cyber Essentials is designed to stop. And the best way to get there is a structured audit of your IT against the scheme's requirements. Think of it as an MOT for your cyber security: a regular check that the fundamentals are in place before something goes wrong.

What Is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, developed by the National Cyber Security Centre (NCSC). It sets out a minimum standard of security that protects organisations against the most common internet-based threats, such as phishing, malware and password guessing.
There are two levels:
Cyber Essentials: a self-assessment questionnaire, independently verified by a certification body.
Cyber Essentials Plus: everything in the basic level, plus a hands-on technical audit where an assessor tests your devices and systems to confirm the controls actually work.
Certification lasts 12 months, so it needs renewing every year. That annual cycle is a big part of its value: it makes reviewing your security a habit, not a one-off project.
What a Cyber Essentials Audit Checks: The 5 Controls
When we carry out a Cyber Essentials readiness audit for a Petersfield business, we review your whole IT environment against the scheme's five technical controls.
1. Firewalls
Every device that connects to the internet must sit behind a properly configured firewall. We check your router and boundary firewalls, the software firewalls on laptops, and that default admin passwords have been changed and unnecessary ports are closed.
2. Secure Configuration
Devices and software often ship with settings that favour convenience over security. We look for unused accounts and software, default passwords, auto-run features and weak screen-lock settings, and help you harden each device.
3. Security Update Management
Cyber Essentials requires critical and high-risk security updates to be installed within 14 days of release, and any software that is no longer supported by its vendor to be removed or isolated. We check operating systems, browsers, plugins and business applications, and set up patching so it happens automatically.
4. User Access Control
Staff should have only the access they need. We review user permissions, remove or disable old accounts, separate admin accounts from day-to-day accounts, and check that multi-factor authentication (MFA) is switched on for cloud services such as Microsoft 365.
5. Malware Protection
We confirm that every in-scope device is protected by up-to-date anti-malware software or application allow-listing, and that it is set to scan files and web pages automatically.
Why Cyber Essentials Matters for Your Business
Stops the most common attacks. The five controls close the doors most attackers try first.
Wins contracts. Cyber Essentials is required for many UK government contracts, and more private-sector customers and supply chains now ask for it too.
Builds trust. The certificate shows clients and partners that you take protecting their data seriously.
Supports insurance. Eligible small organisations that certify their whole business can receive cyber liability insurance with their certification, and insurers increasingly expect these controls.
Helps with GDPR. The controls demonstrate "appropriate technical measures" for protecting personal data.
Cyber Essentials Plus vs Penetration Testing
The technical audit in Cyber Essentials Plus checks that the five basic controls are working on a sample of your devices. It's an important step, but it isn't designed to find every weakness.
Penetration testing goes further. A penetration tester acts like a real attacker, probing your network, websites and cloud services to find vulnerabilities that a checklist won't catch, such as misconfigured remote access, weak web applications or chains of small issues that together lead to a breach.
For most small businesses, the right order is:
Get the basics right with Cyber Essentials.
Prove they work with Cyber Essentials Plus.
Add regular penetration testing if you hold sensitive data, run customer-facing systems or need to meet stricter client requirements.
How Often Should You Audit?
At minimum, once a year, in time for your Cyber Essentials renewal. We also recommend a review whenever your business changes: new offices, new staff, a move to the cloud or new key systems. Each change can quietly break a control that was working before.
Get Cyber Essentials Ready with Petersfield IT Support
Our team takes the stress out of certification. We audit your IT against all five controls, fix the gaps, guide you through the questionnaire and support you through the Cyber Essentials Plus assessment. If you need to go further, we can arrange penetration testing to find the weaknesses attackers would look for.
๐ Book your Cyber Essentials audit today and take the first step towards certification.
Need help with your IT or telecoms?
Contact Us