5. Putting it into practice
Workplace scenarios
Scenario 1: The leaver who never left
While preparing the self-assessment questionnaire, an office manager notices that a colleague who resigned three months ago still has an active email account and a login for the company's cloud file storage. Nobody deliberately kept the access; it simply never occurred to anyone to remove it.
What good looks like: the accounts are disabled the same day the problem is found, and the organisation writes a simple leaver process so that account removal is a standard step whenever someone departs. Dormant accounts are one of the most common findings in Cyber Essentials assessments, and an attacker who compromises one gets access nobody is watching.
Scenario 2: The server that time forgot
An IT review ahead of certification finds a server running an operating system that stopped receiving security updates from its vendor over a year ago. It still works perfectly well, and it quietly runs a system the warehouse team uses every day.
What good looks like: the organisation accepts that "it still works" is not the test; "it still receives security updates" is. A plan is made to upgrade or replace the server before applying, because software past end of life cannot meet the requirements, and every newly discovered vulnerability in it will remain unpatched forever.
Scenario 3: The everyday admin account
A director insists on having administrator rights on their laptop "to avoid being slowed down", and uses that same account all day for email, browsing, and video calls. They see no problem, since they're careful about what they click.
What good looks like: the director gets two accounts: a standard one for daily work and a separate administrative one used only when a task genuinely needs it. If a phishing email or malicious download is opened from a standard account, the damage is contained; from an admin account, the attacker inherits the keys to the whole machine. Being careful is not a control.
Scenario 4: The firewall rule nobody remembers
While reviewing the firewall before the assessment, IT finds an inbound rule opening a port for a remote support contractor whose project finished over a year ago. Nobody can remember exactly why it's there, and nobody wants to be the one who breaks something by removing it.
What good looks like: the rule is investigated, confirmed as no longer needed, and removed, and the firewall's rules are given an owner and a review date. Every open port without a current, documented business justification is an unwatched door, and "we might need it again someday" is not a justification an assessor will accept.
› Course contents
What Cyber Essentials is
Firewalls and secure configuration
Security updates and malware protection
User access control and certification
Putting it into practice