Cheap Cyber Essentials › Free readiness routine
There is a version of buying Cyber Essentials where you pay someone to walk you through the questions, and for some organisations that is the right purchase. There is another version where you spend a week looking at your own estate properly, find the handful of things that would have failed, fix them, and answer the questionnaire yourself. This article is the second version.
It costs nothing but attention. It does not need a specialist. It does need one person who can get answers out of other people, and it works considerably better if that person has about an hour a day for a week rather than one long afternoon.
Before you start: one decision and one download
The decision is who owns this. It should be one named person, and preferably not the busiest person in the organisation, because the work is mostly chasing rather than thinking. The download is the current self-assessment question set, which IASME publishes. Read it before you look at anything else. An hour spent reading the actual questions saves you from spending the week preparing for questions that are not asked.
Day one: write down everything in scope
Scope covers anything organisational data passes through. In practice that means every laptop, desktop, tablet and phone used for work, every server, every router and firewall, every wireless access point, and each cloud service holding your data.
Write it in one place, with four columns: what it is, who has it, what operating system or firmware version it runs, and whether it is owned by the organisation or by an individual. That fourth column matters more than people expect, because a personally owned phone used to read work email is in scope and the person who owns it may not know that yet.
The list will be wrong on day one. That is fine. The point of writing it down is that it becomes visibly wrong, which is how the missing items surface.
Day two: check what has gone out of support
Take the list and check each operating system and firmware version against the vendor's published support dates. Free, and it is the check that catches the most failures.
Look hardest at the things that are not obviously computers. The internet router, the firewall, the network storage box in the cupboard, the wireless access points, the old phone somebody still uses for two-factor codes. Desktops and laptops usually get updated because people notice them. Infrastructure does not, and it is usually the oldest thing you own.
Anything out of support has three honest outcomes: update it to a supported version, retire it, or remove it from scope by properly segregating it so it genuinely cannot reach organisational data. Note which applies to each item. The first two are often free.
Day three: patching, and proving it
High risk and critical updates need to be applied within fourteen days of release, across operating systems, applications, browsers and firmware. Two questions to answer honestly.
First, is automatic updating actually turned on, on every device on your list, including the ones that belong to individuals? Check a sample rather than assuming, because the default has often been changed on exactly the devices that matter. Second, can you show it? A screenshot of the update policy, or a report from whatever manages your devices, is enough. This is free and it takes an hour.
Firmware is the part people skip. Router and firewall updates are usually manual, frequently years behind, and take ten minutes each.
Day four: multi-factor authentication, service by service
Not "do we have multi-factor authentication" but "is it on, for every user, on every cloud service in the list from day one".
Go through the list one service at a time and check the actual user roster rather than the policy. The pattern that fails is a policy that applies to most people with three exceptions: a shared mailbox, a senior person who found it inconvenient, and a service account nobody wants to touch. Each of those is a conversation rather than a technical problem, which is why this belongs mid-week rather than on the last day.
Where a service does not offer multi-factor authentication on your current plan, note it. That one may cost money, and knowing about it on day four rather than the morning you submit is the entire point of this exercise.
Day five: administrator accounts
Two things to establish. Nobody should be doing ordinary work from an account with administrative rights, and administrative accounts should be separate, listed, and only used for administration.
List every account with administrator rights on every device and in every cloud service. The list is almost always longer than expected, and it usually contains at least one person who left. Remove what is not needed, split what remains so that administrators have a normal account for daily use, and write down who holds what and why.
Do this on a Friday if you can, so that anything which breaks surfaces over a quiet period rather than during month end.
Day six: the boundary and the defaults
Three free checks at the edge of the network. Is the firewall's administrative interface reachable from the internet, and if so, can it be turned off? Have the default passwords been changed on every network device, including the ones installed by a supplier years ago? Is there anything published to the internet that does not need to be, such as a remote desktop service or an old test site nobody has looked at?
Then the devices themselves. Default accounts disabled or renamed, unnecessary software removed, and a screen lock with a sensible timeout. None of this costs anything and all of it is asked about.
Day seven: answer the questions and have someone else read it
Now go through the question set properly, with the list from day one and the notes from the rest of the week beside you. Answers should be specific. "We use Microsoft 365 with security defaults enabled and multi-factor authentication enforced for all 23 users" is an answer. "Yes" is not, and vague answers are a reliable way to turn a pass into a request for clarification.
Then have a second person read it who was not involved. They are looking for one thing: any answer that describes what you intend to do rather than what is true today. Those are the answers that fail, and the person who wrote them is the last person who will spot them.
How to tell whether the week worked
You are ready if you can answer all five of these without having to check.
- You can name each device organisational data passes through, and say who holds it.
- Nothing on that list is running software or firmware that the vendor no longer supports.
- Every cloud service has multi-factor authentication on for every user, with no exceptions you are hoping nobody asks about.
- No one does everyday work from an account with administrative rights.
- Every answer in the questionnaire describes the present tense.
If all five are true, buy the assessment and nothing else. You do not need a gap analysis, a consultant or a readiness package, and anyone selling you one at that point is selling you reassurance rather than work.
If one or two are not true, fix them and run the check again. If four or five are not true, the week has done its job anyway: you now know exactly what the problem is, which is a much better position from which to decide whether to buy help.
Does this really need a full week?
It needs about six or seven hours of work, but spread over several days rather than done in one sitting. The reason is that half the tasks involve waiting on somebody else: a supplier confirming a version, a colleague enabling multi-factor authentication, an update installing. Compressing it into a day mostly produces a list of things you are still waiting for.
Can we do this if our IT is outsourced?
Yes, and it is arguably more valuable. You will need your provider for several of the checks, so send them the day one list and the specific questions early in the week rather than asking for general help. Specific questions get answered faster and are less likely to be treated as chargeable project work.
What if we find something that costs money to fix?
Then the week has paid for itself, because you found it before you submitted rather than after. The usual candidates are an out-of-support router or firewall and a cloud service whose plan does not include multi-factor authentication. Both are cheaper to deal with on a schedule than under a deadline.
Is a gap analysis pointless if we do this?
For an organisation that can answer all five readiness questions honestly, yes, and we will say so. A gap analysis earns its place where the estate is genuinely unclear, where it was inherited recently, or where the person responsible has no way of verifying what they are being told. It is not a substitute for the week; it is what you buy when the week is not possible.
Ready, or nearly?
If the five checks come out clean, buy the assessment on its own. If one of them does not, send us the detail and we will tell you whether it is a ten minute fix or a real problem before you pay for anything.