Cybersecurity can quickly sound complicated.
With constant talk of sophisticated attacks, new threats and increasingly advanced security technology, it’s easy for small businesses to assume that effective cybersecurity requires a large budget, specialist knowledge and an entire IT department. In reality, some of the most important steps are much more straightforward.
Good cybersecurity starts with getting the basics right. Keeping software updated, controlling access to your systems, configuring devices securely and putting appropriate protection in place can all help build a stronger foundation for your business.
These fundamentals are also at the heart of Cyber Essentials, the Government-backed cybersecurity certification scheme.
So, how well is your business covering the basics?
Start With the Technology You Already Use
Before investing in additional cybersecurity tools, it’s worth looking at the technology your business already relies on.
Computers, laptops, mobile devices, operating systems and applications all need to be properly managed and kept up to date.
We’ve all seen an update notification appear at an inconvenient time and clicked “remind me later”. But updates aren’t only about new features. They can also include important security fixes for vulnerabilities that have been discovered.
If those updates are repeatedly postponed, known vulnerabilities can remain unaddressed.
Small businesses should have a clear approach to:
- Keeping operating systems and applications updated
- Applying important security updates promptly
- Knowing which devices are being used to access business information
- Identifying software that is approaching or has reached the end of its supported life
Once software is no longer supported by its manufacturer, security updates may no longer be available. That can create an unnecessary risk for the business.
Keeping an accurate picture of the technology you use, and making sure it’s appropriately maintained, is therefore an important place to start.
Make Sure the Right People Have the Right Access
Once you’ve considered your technology, the next question is who can access it?
Not everybody in your business needs access to every system, application or piece of information.
Employees should generally have the access they need to perform their roles without being given unnecessary additional permissions. This is particularly important when it comes to administrator accounts, which can provide much greater control over devices and systems.
Rather than giving everyone elevated access because it’s convenient, businesses should regularly ask:
- Who currently has access to our systems?
- What information and applications can they access?
- Do they genuinely need that level of access?
- Who has administrator privileges?
- When was that access last reviewed?
Access can easily accumulate as people change roles or take on new responsibilities, so this shouldn’t be a one-off exercise.
Don’t Let Old Accounts Become Forgotten Accounts
Access control isn’t only about your current employees. Think about the people who used to need access.
When an employee leaves, a contractor finishes a project or you stop working with a supplier, their accounts and permissions should be reviewed. Old accounts that remain active can create unnecessary exposure, particularly if nobody is monitoring or using them. Having a straightforward process for starters, movers and leavers can help make sure access is granted when it’s needed, adjusted when someone’s responsibilities change and removed when it’s no longer required. It’s also worth periodically reviewing your systems for accounts you don’t recognise or no longer need, you might be surprised by what’s still there.
Check How Your Systems Are Configured
Keeping software updated and controlling access are important, but you should also consider how your devices and applications are configured.
Technology isn’t always set up for your particular security requirements straight out of the box. Default settings often prioritise convenience and ease of use, which means businesses should review them rather than assuming everything is automatically configured securely.
That could mean looking for:
- Default or unnecessary user accounts
- Features and services your business doesn’t use
- Unnecessary software or applications
- Inappropriate access permissions
- Device locking and security settings
The goal isn’t to make technology difficult for employees to use. It’s to remove unnecessary functionality and access that could otherwise increase your exposure.
Put Appropriate Malware Protection in Place
Another important consideration is protecting devices against malicious software. Malware is a broad term covering software designed to perform unwanted or harmful actions on a device or network. It can reach businesses in different ways, including through malicious files, downloads and compromised websites.
Modern devices and operating systems can include built-in security features, while businesses may also use additional security tools depending on their requirements. Technology is only part of the picture, though. Businesses should also think about whether employees can install software without approval, where applications are being downloaded from and how suspicious files are handled. Combining appropriate technical protection with sensible controls can help reduce the opportunity for malware to cause problems.
Don’t Forget About Firewalls
Firewalls can sound technical, but their basic purpose is relatively straightforward. A firewall helps control network traffic between your devices or network and the outside world, creating a security barrier based on defined rules. For small businesses, firewall protection may be provided by network equipment as well as functionality built into individual devices. The important thing is not to simply assume it’s there and working correctly.
If you’re unsure whether your business has appropriate firewall protection, or when it was last reviewed, speak to whoever manages your IT.
What Does All This Have to Do With Cyber Essentials?
The areas we’ve covered aren’t a random collection of cybersecurity recommendations. They closely align with the five technical control areas at the heart of Cyber Essentials:
- Firewalls – helping protect devices and networks from unauthorised connections
- Secure configuration – making sure systems are set up appropriately and unnecessary functionality is reduced
- Security update management – keeping software appropriately updated and addressing known vulnerabilities
- User access control – managing who can access systems and the privileges they have
- Malware protection – putting measures in place to help protect against malicious software
Cyber Essentials provides businesses with a structured way to look at these fundamental areas rather than trying to tackle cybersecurity without knowing where to begin.
For a small business without an internal cybersecurity team, that can provide a useful starting point.
Cyber Essentials Is More Than a Certificate
It’s easy to think of Cyber Essentials as another badge for your website. But the real value starts with the process behind it. Working towards certification encourages you to look at how cybersecurity is actually being managed across your organisation.
For example:
Are important updates being installed?
Are old accounts being removed?
Does everyone really need administrator access?
Are devices securely configured?
Do you know what technology is connecting to your business systems?
These are valuable questions whether you’re pursuing certification or simply trying to improve your cybersecurity.
Achieving Cyber Essentials also gives your business a recognised way to demonstrate that fundamental cybersecurity controls are in place. This can be useful when customers, suppliers or prospective business partners ask about your approach to security.
You Don’t Need to Fix Everything at Once
One of the reasons cybersecurity can feel overwhelming is that businesses often try to think about every possible threat at the same time. A more practical approach is to start with the fundamentals. Take stock of where you are today. Identify the obvious gaps and work through them systematically.
That could mean:
- Reviewing the devices and software your business uses
- Checking that security updates are being managed
- Reviewing user and administrator accounts
- Removing access that’s no longer required
- Checking security configurations and firewall protection
- Making sure appropriate malware protection is in place
Once those foundations are stronger, you can build on them as your business and cybersecurity requirements develop.
Is Your Business Ready for Cyber Essentials?
Good cybersecurity doesn’t have to start with complicated technology. It starts with understanding what you have, who can access it and whether the fundamental protections are in place. That’s exactly why Cyber Essentials can be so useful for small businesses. It provides a recognised framework for addressing important cybersecurity basics while giving you a clear standard to work towards. And you don’t have to navigate the process alone.
Ashdown Solutions can help you understand where your business currently stands, identify areas that may need attention and support you through the Cyber Essentials certification process.
If you’re not sure whether your business is ready for Cyber Essentials, start with a conversation.