You’ve probably formed an opinion on Windows 11 by now. It’s capable. It’s familiar.…
Implementing Access Control Key Control for Cyber Essentials
Access controls play a key role in protecting your organisation’s systems and sensitive information from unauthorised intrusion. Access controls ensure that only authorised and relevant individuals can access specific kinds of data and network resources. For example, not everyone should have access to your firewall configuration settings!
In summary, access controls help to safeguard confidential information and network settings. In the event of a network breach via a specific user account, the breach could only go as far as that user’s access controls. This is why they are a key pillar of the Cyber Essentials certification process.
The Scope and Goals of the Access Control
This control applies to: Desktop computers, laptops, tablets, mobile phones, email, web, and application servers.
Its objectives: To ensure that user accounts are 1) accessible to authorised individuals only, and 2) that these accounts only provide access to applications, computers and networks that are necessary for that user to perform their role-based duties. In short, access should be on a ‘need-to-know’ basis, and administrative privileges (such as the ability to configure apps, systems and user accounts) should be given only when they are strictly necessary.
For example, imagine a social care home that keeps sensitive service user data and detailed care plans. A care support worker should be able to fill in care records to fulfil their role and keep the rest of the team in the loop, but they should not be able to unrestrictedly edit the service user’s profile information. Not only is this appropriate for the organisation, but it also prevents cyber actors from manipulating this information if they were to get access to the care worker’s login credentials.
Your organisation will be required to routinely:
- Have and use a user account creation and approval process
- Authenticate users before granting access to applications or devices, using their unique credentials
- Remove or disable user accounts when they are no longer required (e.g when a user leaves the organisation or after a defined period of account inactivity)
- Implement two-factor authentication, wherever it is available
- Use dedicated administrative accounts (e.g admin@example.com) to perform administrative activities only, with non-essential functionality – such as email or web browsing – disabled to avoid exposing these accounts to avoidable risks.
- Remove or disable special access privileges when they are no longer required, such as when a member of your team changes role or leaves your organisation.

Your Practical Guide to Applying Access Controls for Cyber Essentials
Here’s how to apply these measures in practice. Remember to document these implementations so that you can demonstrate their application in the certification process.
Identify Sensitive Data and Resources
Start by identifying the sensitive data and resources in your organisation. This may include customer information, financial data, intellectual property, and critical systems. These can then be mapped against organisational roles and the purposes for accessing these types of data and resources.
Create User Accounts
Set up individual user accounts for each employee or team member, assigning unique usernames and passwords to each of them. A mistake some organisations make is using a single account for multiple people. Individual accounts promote accountability, allowing login attempts and other user activity to be traced back to the individuals involved.
Role-Based Access Control (RBAC)
Implement a role-based access control system. Assign different roles to users based on their job responsibilities, and grant access permissions accordingly. For example, an employee in the finance department may have access to financial data, while a marketing team member may not.
Limit Administrative Privileges
Limit administrative privileges to only those who need them for their specific job roles. Administrative access should be reserved for IT staff and key decision-makers to prevent unauthorised changes.
Use Strong Passwords & Multi-Factor Authentication (MFA)
While this is covered elsewhere, access is also about making sure that outsiders do not get into your network. Enforce the use of strong passwords for all user accounts. Passwords should be unique, complex, and changed periodically. Multi-factor authentication (MFA) should be applied wherever available.
Regular Access Reviews
Conduct regular access reviews to ensure that users have the appropriate access rights for their current job roles. Remove access for employees who no longer need it due to role changes or departures.
Monitor and Log Access Activity
Set up logging and monitoring systems to track user access and activities. This helps detect suspicious behaviour and potential security breaches. Solutions for this include network monitoring tools and SIEM (Security Information & Event Management) software.
Employee Training
Many businesses’ teams will be sharing documents internally and externally; take care to educate your employees about the importance of access controls and the best practices for protecting sensitive information. Take care to document this. This helps create a security-conscious culture within your organisation.
Get your FREE cyber risk traffic light report
Our Cyber Risk Traffic Light Report is designed to help businesses audit their cyber security posture, enabling them to find risk areas and security gaps and to address them with actionable insights. Get started with your cyber security journey by getting your own Cyber Risk Traffic Light Report today.
