ipfour

Toolkit · Compliance · about 4 minutes

Cyber Essentials Readiness Check

Twenty questions across the five Cyber Essentials controls. It takes about four minutes and tells you honestly whether you would pass today — including when the answer is that you do not need help.

20 questions. Nothing is sent anywhere as you answer — the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.

0 of 20 answered0%

Firewalls

Every device is protected by a correctly configured firewall at the boundary or on the device itself.

Have the default administrative passwords on your firewalls and routers been changed?

Including any device supplied by your ISP.

Are inbound firewall rules limited to those with a documented business need?

Is the firewall administration interface blocked from the internet, or protected by MFA and an IP allow-list?

Do laptops used outside the office have a software firewall enabled?

Home and public networks are untrusted, so the device firewall is what applies.

Secure configuration

Devices and software are set up to reduce what an attacker can reach, and default settings are not left as shipped.

Have default passwords been changed on all devices and software?

Has unnecessary software and have unused user accounts been removed or disabled?

Do devices lock automatically after a period of inactivity and require a PIN, password or biometric?

Where passwords protect accounts, is there either MFA, a minimum length of 12 characters, or automatic blocking of common passwords?

Security update management

All software is supported by its vendor and patched promptly.

Is all software on your devices still supported by its vendor and receiving security updates?

End-of-life operating systems, unsupported phones, or old server software fail this outright.

Are critical and high-severity updates applied within 14 days of release?

Is automatic updating enabled where the vendor offers it?

Do you have an inventory of the software and devices in use, so you would notice something unsupported?

User access control

People have their own accounts, with only the privileges their role requires.

Is multi-factor authentication enabled on all cloud services, including email?

Mandatory under the scheme. Email without MFA is the most common route into a small business.

Does each person have their own named account, with no shared logins?

Are administrator accounts separate from day-to-day accounts, and used only for administrative tasks?

Is there a process to remove access promptly when someone leaves or changes role?

Is there an approval step before a new account or elevated privilege is granted?

Malware protection

Devices are defended against malicious software.

Is anti-malware software active on all in-scope devices, or is application allow-listing in place?

Is it kept up to date automatically?

Are staff prevented from installing unapproved applications on work devices?

More in the toolkit