How to Prepare for Cyber Essentials in Two Weeks
You can get ready for Cyber Essentials in just two weeks by focusing on five core controls: secure configuration, user access, patch management, malware protection and firewalls. In the first week you establish a secure baseline and tighten settings, and in the second week you test, document and polish the evidence needed for certification via an accredited body. Follow this step‑by‑step guide to hit the deadline without scrambling at the last minute.
Week 1 – Baseline and Secure Configuration
Start by creating a clear picture of what you own and how it is configured. This week is about eliminating unnecessary services and locking down defaults.
1. Inventory every device and service
- Use a simple spreadsheet or a free asset‑management tool to list servers, workstations, laptops, printers and cloud services.
- Record OS version, installed applications and network location (e.g., internal LAN, DMZ, remote).
- Mark anything that is no longer required – these should be decommissioned or isolated.
2. Harden operating systems
- Apply the Microsoft Security Baseline for Windows 10/11 or the Ubuntu CIS Benchmark for Linux.
- Disable unused ports and services (e.g., SMB v1, Telnet, FTP).
- Enable built‑in firewalls (Windows Defender Firewall, ufw) and set a default deny rule for inbound traffic.
3. Secure default accounts
- Rename or disable the default "Administrator" and "root" accounts where possible.
- Enforce strong, unique passwords – at least 12 characters with mixed case, numbers and symbols.
- Implement multi‑factor authentication (MFA) for any privileged access.
4. Configure user access
- Adopt the principle of least privilege – give staff only the rights they need for their role.
- Remove local admin rights from standard workstations; use a standard user account for daily work.
- Set up role‑based groups in Active Directory or your cloud directory service.
Week 2 – Patch Management, Malware Protection and Documentation
The second week is about keeping everything up to date, ensuring anti‑malware is active and gathering the evidence required for the Cyber Essentials questionnaire.
1. Patch all software
- Enable automatic updates for Windows, macOS and supported Linux distributions.
- Use a patch‑management tool (e.g., WSUS, ManageEngine Patch Manager Plus, or a free open‑source solution) to deploy updates to third‑party applications such as Adobe Reader, Java and browsers.
- Schedule a one‑off “catch‑up” patch window on a weekend to minimise disruption.
2. Deploy anti‑malware
- Choose a solution that provides real‑time scanning, web protection and email attachment scanning – many vendors offer small‑business licences.
- Configure daily full scans on servers and weekly scans on workstations.
- Ensure definitions are updated at least once a day.
3. Verify firewall rules
- Review inbound and outbound rules; block any traffic that is not explicitly required.
- For remote access, use a VPN with strong encryption and MFA rather than exposing RDP or SSH directly to the internet.
- Document the rule set – a simple diagram of the network zones and allowed ports is sufficient for the certification questionnaire.
4. Gather evidence for the Cyber Essentials questionnaire
- Take screenshots of firewall rule tables, anti‑malware console status, patch‑management reports and secure configuration settings.
- Export logs that show successful updates and malware scans over the past 30 days.
- Compile a short policy document that outlines your password policy, MFA usage and user‑access controls.
Tools to Speed Up the Two‑Week Sprint
While you can do everything manually, a handful of free or low‑cost tools can shave hours off the process.
- Solvbeat – a web‑based scanner that checks your public‑facing assets for common misconfigurations and missing patches. It produces a concise report you can attach to your Cyber Essentials evidence pack.
nmap– quick network discovery to verify which ports are open.- Microsoft
SecEdit– generate a security baseline report for Windows machines. - Open‑source
ClamAV– lightweight anti‑malware for Linux servers where a commercial product would be overkill. - Free cloud‑based patch‑management services such as ManageEngine Patch Manager Plus Free for up to 25 devices.
Common Pitfalls and How to Avoid Them
Even with a tight schedule, certain mistakes can set you back.
- Skipping documentation – the certification body will request proof. Keep screenshots and policy drafts organised in a single folder from day one.
- Relying on “default” security – many devices ship with insecure defaults. Double‑check each new piece of hardware before it goes live.
- Leaving legacy software – old versions of Adobe Reader or Java are frequent attack vectors. Replace or isolate them.
- Inconsistent patching – automatic updates can be disabled by users. Enforce a group policy that prevents users from turning them off.
- Weak passwords on service accounts – these are often overlooked. Treat them like any other privileged account and apply MFA where possible.
Next Steps After the Two‑Week Sprint
Once you have the evidence ready, submit the Cyber Essentials questionnaire through an accredited certification body. Remember, the certification itself is issued via an accredited body, not directly by Solvbeat.
After you achieve certification, embed the five controls into your regular IT routine: schedule monthly patch reviews, run quarterly vulnerability scans, and conduct annual user‑access audits. Continuous improvement will keep you compliant and reduce the risk of the kinds of incidents highlighted in the UK Government Cyber Security Breaches Survey.
Ready to see where your current security posture stands? Run a free scan →