Published 24/03/2020 – est. 5 minutes to read.
Cyber Essentials
It is a government-backed scheme and is an important part of the NCSC’s mission to “make the UK one of the safest places to live and do business online“. It is designed as a first step to help organisations protect themselves against 80% of the most common internet threats through the secure implementation of five key control areas, summarised below.
What are the most common internet threats?
Let’s look at who may be trying to attack you and why! Many Companies, especially SMEs, may consider themselves at low risk of cyberattacks. We need to understand that many common threats come from opportunists who can be located anywhere in the world. These include:
- Cyber criminals are motivated by money through selling information (such as personal data or intellectual property) that they have stolen or fraudulently obtained.
- Hackers & Hacktivists are people who try to access your systems for fun or a challenge.
- Employees who have legitimate access to your IT systems and could be a threat either accidentally or through deliberate misuse.
How are the most common attacks carried out?
There are readily available tools on the internet that allow you to scan for exploitable vulnerabilities. This is similar to a thief surveying a neighbourhood to identify the best opportunities: unlocked doors, open windows, empty properties, no alarm systems, etc. Most attacks start with a survey to look for weaknesses.
Other surveys could include sending phishing emails to see who bites, or looking at social media accounts such as Facebook and LinkedIn to pick up clues like easily guessed usernames and passwords.
The five areas that Cyber Essentials helps to protect:
Cyber Essentials covers the following 5 key security control areas:
These are effective ways to protect your perimeter. So, for the thief conducting his survey, there will be locked doors and closed windows, requiring more effort to get around and gain access. Boundary firewalls and internet gateways determine who is allowed to access your system from the internet and let you control where your users can go.
This reduces each computer or device’s functionality to the minimum required for the user to operate it. This will help prevent unauthorised actions. It also ensures that each device discloses only the minimum information about itself to the internet. A scan can reveal opportunities for exploitation due to insecure configurations.
It is important to restrict access to the minimum necessary. This is to prevent a hacker from encountering a series of unlocked doors that would allow him access to all the information he seeks.
Administrator rights are the Holy Grail for a hacker. Once he has possession of these, he can go anywhere and have full control. Administrator rights should be restricted to administrator-only actions. Convenience sometimes results in many users having administrator rights, creating opportunities for exploitation.
It is important to protect your business from malicious software that seeks to access files on your system. Once their software can access and steal confidential information, damage files or even lock them and prevent you from accessing them unless you pay a ransom. Malware protection helps to identify and prevent/remove any potential threats from malicious software.
Cybercriminals often exploit well-known vulnerabilities in software or operating systems to gain access. These could be due to poorly designed software with known weaknesses. Updating software and operating systems will help fix these known weaknesses. It is crucial to do this as quickly as possible to close down any opportunities which could be used to gain access.
Who is Cyber Essentials for?
The National Cyber Security Centre (NCSC) identifies Cyber Essentials as a good first step that all businesses can take to protect themselves against these common threats and help reduce cybercrime.
Cyber Essentials is for all organisations, of all sizes, and in all sectors – it is not limited to the private sector. It is also applicable to universities, charities, and public sector organisations.
We are an accredited Cyber Essentials Certification Body and have a 100% success rate in certifying Companies for Cyber Essentials & Cyber Essentials Plus.
