IT cyber security checklist
The essential controls every organisation should review.
Your organisation might have firewalls, access policies, anti-malware software and patching processes in place. But are those controls applied consistently across every device, user, cloud service and location? Can you demonstrate that they are working? And have they kept pace with changes to your technology environment?
You may not have all the answers yet, but working through the five areas will help you focus your thinking, spot where there may be gaps and decide what to look at next.
It can also help you begin preparing for Cyber Essentials or Cyber Essentials Plus certification.
For smaller and growing organisations, answering these questions can be particularly difficult when internal security expertise and resources are limited. Cyber Essentials provides a practical, recognised framework for establishing strong security fundamentals without the complexity of an enterprise-scale security programme.
Developed with the support of the UK National Cyber Security Centre (NCSC), Cyber Essentials focuses on five technical control areas that help protect organisations against the most common internet-based cyber threats:
Talk to our Cyber Essentials specialists to understand your current position, identify possible certification gaps, and plan your next steps.
Cyber Essentials uses a verified self-assessment to establish whether the organisation has implemented the required baseline controls. It offers a practical and achievable route for organisations looking to protect themselves against common attacks and demonstrate their commitment to cyber security.
Cyber Essentials Plus includes an independent technical assessment of whether the controls are operating effectively in practice. This additional assurance can be valuable where customers, procurement frameworks or contractual requirements require stronger evidence of cyber security capability. It demonstrates that controls are not only documented but have been independently tested.
Cyber Essentials certification is also required for suppliers bidding for certain government and NHS contracts involving specific cyber risks. Current government procurement guidance asks applicable organisations to ensure proportionate cyber security controls are used to reduce supply-chain risk.
Certification may therefore support organisations looking to:
The appropriate level will depend on the assurance your organisation needs to provide, and the requirements placed on it by customers, contracts and procurement frameworks.
Cyber Essentials provides a valuable security baseline. It helps organisations focus on essential controls that protect against the most common cyber threats and gives customers, partners, and procurement teams a recognised form of assurance.
However, it should be viewed as the foundation of a wider security approach rather than the final destination.
Certification does not remove the need for ongoing monitoring, vulnerability management, incident response, supplier assurance, and recovery planning. These capabilities help organisations maintain visibility, respond to change, and continue operating when an incident occurs.
Your first priority should be to confirm that essential controls are in place and working. From there, you can build a wider programme shaped by your critical services, customer commitments, and business risks.
As a Cyber Essentials and Cyber Essentials Plus Certification Body, Redcentric helps organisations understand their readiness, address gaps, and approach certification with confidence.