Cyber Essentials in a fortnight: an honest timeline
What actually takes the time, and the one control that blocks nearly everyone on their first attempt.
A fortnight to Cyber Essentials is realistic for a lot of small firms, but only if you know where the days actually go. The self-assessment questions are not the hard part and can be answered in an afternoon. What eats the time is discovering that the honest answer to a question is “no”, and then having to change something in the real world before you can truthfully say “yes”.
The first few days are an inventory, and people underestimate this. You need to know every device that touches your work data - laptops, phones, the tablet in the van, the old machine in the back office everyone forgot - and every account with access. You cannot certify what you have not listed, and the list is almost always longer than the owner expects. Budget real time here; it is the foundation for everything after.
The control that blocks nearly everyone is multi-factor authentication, the code-on-your-phone step, on every cloud service that offers it. Not because it is hard to switch on, but because turning it on across email, file storage and every app, for every member of staff, surfaces the accounts nobody wanted to touch and the one person who resists. Start this on day one, because it needs everybody, and people are the slow part.
The rest is a steady clearing of small things: devices that were never set to update automatically, a firewall setting, default passwords still in place on a router, admin rights handed out years ago and never taken back. None of it is difficult in isolation. It is the accumulation, and the chasing of colleagues to do their bit, that fills the second week.
So the honest timeline is: a couple of days to list everything, most of the fortnight to fix what the list reveals, and the assessment itself near the end almost as a formality. Firms that fail their first go nearly always tried it the other way round - answering the questions first and meeting reality too late.
- ✓List every device and every account that touches your work data before answering anything.
- ✓Turn on multi-factor authentication for every cloud service and every member of staff first.
- ✓Set operating systems, browsers and apps to update automatically on all devices.
- ✓Remove admin rights and old accounts nobody needs, and change any default passwords.
- Cyber Essentials: requirements for IT infrastructure NATIONAL CYBER SECURITY CENTRE ↗
- Multi-factor authentication for online services NATIONAL CYBER SECURITY CENTRE ↗
- Cyber Essentials and funding for small firms GOV.UK ↗
Links open each publisher’s live coverage of this topic.