IT cyber security checklist

The essential controls every organisation should review.

Are your IT security controls working in practice?

Your organisation might have firewalls, access policies, anti-malware software and patching processes in place. But are those controls applied consistently across every device, user, cloud service and location? Can you demonstrate that they are working? And have they kept pace with changes to your technology environment?

Use the checklist below to start reviewing your current position

You may not have all the answers yet, but working through the five areas will help you focus your thinking, spot where there may be gaps and decide what to look at next.

It can also help you begin preparing for Cyber Essentials or Cyber Essentials Plus certification.

For smaller and growing organisations, answering these questions can be particularly difficult when internal security expertise and resources are limited. Cyber Essentials provides a practical, recognised framework for establishing strong security fundamentals without the complexity of an enterprise-scale security programme.

Developed with the support of the UK National Cyber Security Centre (NCSC), Cyber Essentials focuses on five technical control areas that help protect organisations against the most common internet-based cyber threats:

  1. Firewalls
  2. Secure configuration
  3. User access control
  4. Malware protection
  5. Security update management

Are your IT security controls ready for assessment?

Talk to our Cyber Essentials specialists to understand your current position, identify possible certification gaps, and plan your next steps.

Chat to a Cyber Essentials specialist

Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials

Cyber Essentials uses a verified self-assessment to establish whether the organisation has implemented the required baseline controls. It offers a practical and achievable route for organisations looking to protect themselves against common attacks and demonstrate their commitment to cyber security.

Cyber Essentials Plus

Cyber Essentials Plus includes an independent technical assessment of whether the controls are operating effectively in practice. This additional assurance can be valuable where customers, procurement frameworks or contractual requirements require stronger evidence of cyber security capability. It demonstrates that controls are not only documented but have been independently tested.

Cyber Essentials certification is also required for suppliers bidding for certain government and NHS contracts involving specific cyber risks. Current government procurement guidance asks applicable organisations to ensure proportionate cyber security controls are used to reduce supply-chain risk.

Certification may therefore support organisations looking to:

  • Meet customer and supplier requirements.
  • Participate in relevant procurement opportunities.
  • Demonstrate credibility to prospective customers.
  • Provide evidence of good security practices to stakeholders.
  • Establish a structured baseline for further security improvement.

The appropriate level will depend on the assurance your organisation needs to provide, and the requirements placed on it by customers, contracts and procurement frameworks.

From an IT security checklist to stronger cyber resilience

Cyber Essentials provides a valuable security baseline. It helps organisations focus on essential controls that protect against the most common cyber threats and gives customers, partners, and procurement teams a recognised form of assurance.

However, it should be viewed as the foundation of a wider security approach rather than the final destination.

Certification does not remove the need for ongoing monitoring, vulnerability management, incident response, supplier assurance, and recovery planning. These capabilities help organisations maintain visibility, respond to change, and continue operating when an incident occurs.
Your first priority should be to confirm that essential controls are in place and working. From there, you can build a wider programme shaped by your critical services, customer commitments, and business risks.

How Redcentric can help

As a Cyber Essentials and Cyber Essentials Plus Certification Body, Redcentric helps organisations understand their readiness, address gaps, and approach certification with confidence.

Start the conversation

Our specialists can support you with:

redcentric

Redcentric

0800 983 2522 [email protected]