Published 11/04/2023 – est. 5 minutes to read.
Cybersecurity is an essential aspect of any business.
With the rise of digital technologies and the widespread use of the internet, businesses are exposed to various cyber threats that can harm their operations, reputation, and customers. Cyber Essentials is a program designed to help businesses protect themselves against cyber-attacks. In this blog, we will explore Cyber Essentials and how it can benefit your business.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification program that helps businesses protect themselves against cyber threats. The program provides a set of security standards that businesses can follow to secure their IT systems and data. By implementing these standards, businesses can reduce their risk of cyber-attacks, data breaches, and other security incidents.
The arrival of Montpellier!
The NCSC announced an update to the 2023 set of Cyber Essentials requirements on 24th April 2023. Version 3.1 (Montpellier) replaced version 3.0 Evendine. Some of the key changes in the Montpellier release are listed below.
We’ll start with changes that have been implemented with immediate effect and have involved a change in the assessment of the following questions currently active on the portal:
- A2.4 Please list the quantities of laptops, desktops and virtual desktops within the scope of this assessment.
- A2.6 Please list the quantities of tablets and mobile devices within the scope of this assessment.
The model is no longer required to answer the above questions; the make and operating system will suffice. Also, Thin clients must now also be listed with their make and operating system.
This will benefit larger companies using device management solutions that do not record device models. However, for question A2.8, it is still required to list the make and model for network equipment.
One of the most surprising changes is the easing of Multi-Factor Authentication requirements: applicants can no longer fail for not applying MFA unless they have also submitted additional non-compliant responses.
For BYOD, personal devices used by employees, volunteers, trustees, and university research assistants are in scope if they are used to access company information or services. Devices owned by students, MSP administrators, third-party contractors, and customers are not in scope, even if they access company information or services.
The definition of ‘software’ has been updated to include firmware. Following on from this, for firewalls and routers, the applicant will only need to list the make and model; the specific firmware version is not required.
Asset management will now be included in Cyber Essentials. The requirements clarify that asset management doesn’t mean creating lists or databases that go unused; it means creating, establishing, and maintaining authoritative, accurate information about your assets that supports both day-to-day operations and efficient decision-making when you need it.
Clarification on including third-party devices:
The device unlocking section has been updated to reflect that some configurations cannot be changed due to vendor restrictions. Sometimes, an applicant might be using a device that lacks options to change its configuration to meet the Cyber Essentials requirements. One example of this is locking the device after 10 failed sign-in attempts. Samsung, possibly the largest provider of smartphones in the world, have set its minimum sign-in attempts at 15, with no option to alter this number. So, in this instance, Cyber Essentials would require that the applicant use the minimum number of sign-in attempts allowed by the device before it locks.
The malware protection section has changed; applicants must ensure that the malware protection mechanism is active on all in-scope devices. For each device, you must use at least one of the options below:
- Be updated in line with vendor recommendations
- Prevent malware from running
- Prevent the execution of malicious code
- Prevent connections to malicious websites over the internet
- Actively approve such applications before deploying them to devices
- Maintain a current list of approved applications; users must not be able to install any application that is unsigned or has an invalid signature
All in all, the release of Montpellier conveys that Cyber Essentials is evolving with the ever-changing cyberspace, and hopefully continues to be a valuable scheme for businesses looking to improve their cybersecurity. By implementing the controls required for certification, businesses can reduce their risk of a cyber-attack, enhance their reputation, and gain a competitive advantage.
Let us help you to get certified!
We are an accredited Cyber Essentials Certification Body with a 100% success rate in certifying organisations for Cyber Essentials & Cyber Essentials Plus, or to discuss our other services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
