Most cyber security tools work reactively. Something suspicious happens, the system spots it, and…
Implement Secure Configuration Control for Cyber Essentials.
The secure configuration control focuses on setting up your devices and software securely. By properly configuring your devices and applications, you protect them from vulnerabilities and cyber threats that may use these devices and applications as access points to compromise your business. As many cyber incidents occur due to weak or default configurations, this is a key focus in the Cyber Essentials framework that serves as a foundation for a solid cyber security posture.
The Scope and Goals of the Secure Configuration Control
This control applies to: Desktop computers, laptop computers, tablets, mobile phones, firewalls, routers, and email, web, and application servers.
Its objectives: To reduce the level of inherent vulnerabilities that come with default configurations on devices, firewalls, software, and application servers. Additionally, to have these configured in a way that allows them to fulfil their roles, without needlessly leaving open additional vulnerabilities.
For example, you need user accounts to allow your team do their work, but if some accounts are no longer in use, they should be removed. Another example is that a software may come with a platform or device as a default standard, but if there is no plan to use it, it should be removed.
Your organisation will be required to routinely:
- Remove and disable unnecessary user accounts (such as guest accounts and administrative accounts that won’t be used).
- Change any default or guessable account passwords to ones that are more complex and secure.
- Remove or disable unnecessary software (including applications, system utilities, and network services).
- Disable any auto-run feature that allows file execution without user authorisation (such as when they are downloaded from the internet).
- Authenticate users before allowing internet-based access to commercially or personally sensitive data, or data that is critical to the running of the organisation.
So, how do you practically implement this control? It’s not as hard as it may sound!

Your Practical Guide to Implementing Secure Configuration
By taking action in each of these key areas, you will be able to meet the criteria for the secure configuration control.
Each organisation uses different technology and uses them in different ways. While our guide cannot cover all of the specifics for your organisation, you can follow these core steps to implement secure configuration:
- Map out how: For each device and application, ask how each of the areas below can be applied. For common solutions such as Microsoft 365, applying these steps can be easier. For more niche devices and applications, there will likely be guidance online; falling short of this, you can enquire with an IT support provider who can provide clear guidance and implement them for you.
- Implement: What it says on the tin, implement the secure control measures in each of these areas. With implementation, you can document how you meet the key controls.
- Document: As the measures are implemented, document them so that they can be easily referenced and demonstrated for your Cyber Essentials application.
Inventory of Devices, Software & Users
Start by creating an inventory of all the devices, software and users that are present in your organisation. This includes computers, laptops, servers, smartphones, routers, switches, and all installed applications. Without a map, navigating the territory to getting certified will be harder to achieve. This inventory should be documented and will serve as a very helpful guide for getting the documentation together for your application.
Patch Management
Now that you have an inventory, you can be empowered to ensure that all of your software and applications are up-to-date with the latest security patches. Enable automatic updates whenever possible to ensure you are protected against known vulnerabilities.
Secure Passwords & Multi Factor Authentication
Set strong passwords for all devices, applications, and user accounts. Use a combination of upper and lower-case letters, numbers, and special characters. Avoid common passwords and enforce policies to change them regularly.
Implementing Multi-Factor Authentication (MFA) also ensures more security when your users are accessing your network and its data. Some platforms automatically apply MFA, but it is best to ensure that it is applied across your applications and devices.
Disable Unnecessary Features
Review the settings of your devices and software to disable any unnecessary features or services that are not in use. Turn off remote access features if they are not required, as they can be exploited by cybercriminals.
Network Security
Configure your network devices (routers, firewalls, switches) with secure settings that prevent access from unnecessary external traffic into your network. Change default credentials, enable firewalls, and implement encryption to protect data in transit.
Role-Based Access
Grant access to devices and applications on a ‘need to know’ basis, that are based on user roles and responsibilities. Avoid providing unnecessary administrative privileges, which will minimise the impact of potential security breaches.
Antivirus and Anti-malware
We recommend installing reputable antivirus and anti-malware software on all organisational devices. Like your other applications, keep them updated to ensure that they can detect and thwart the latest cyber threats.
Secure Browser Configurations
Configure web browsers to block pop-ups and enable phishing protection. These aspects can be configured via the browser’s security and privacy settings. Additionally, restrict the use of plugins or extensions, which create further potential access points for cyber threats.
Mobile Devices
Implement security configurations on mobile devices, such as by enabling passcodes, biometric authentication and the encrypting of data. Implement both a policy and a practical solution, such as a mobile device management system, to ensure that users do not install unauthorised apps.
Regular Audits
Conduct regular audits of your configurations to ensure compliance with your security policies and Cyber Essentials requirements. Additionally, incorporate regular audits into your security policy documentation.
Get your FREE cyber risk traffic light report
Our Cyber Risk Traffic Light Report is designed to help businesses audit their cyber security posture, enabling them to find risks areas and security gaps and to address them with actionable insights. Get started with your cyber security journey by getting your own Cyber Risk Traffic Light Report today.
