Cyber Essentials planning

Use cyber security training to turn Cyber Essentials controls into a practical 90-day plan.

Cyber Essentials gives businesses a useful control framework, but the real value comes from understanding what those controls mean in the organisation’s own accounts, devices, software, firewalls and day-to-day processes.

A training day should not pretend to be a Cyber Essentials assessment or certification. What it can do is help owners and managers understand the five control themes, identify obvious gaps and decide which improvements should happen first.

Start with the five control themes

Cyber Essentials focuses on firewalls, secure configuration, security update management, user access control and malware protection. Training should translate those headings into practical questions about the equipment and cloud services the business actually uses.

Secure configuration means making deliberate choices

Default settings are not always appropriate for a business. Unused software, unnecessary administrator rights, exposed services and poorly controlled sharing can all increase risk. A practical review asks what is enabled, who needs it and whether the configuration still matches the way the business works.

Updates and device lifecycle belong in the same conversation

Security updates are essential, but older devices can eventually fall outside supported operating-system or firmware lifecycles. Businesses need a process for patching current devices and replacing equipment that can no longer be maintained securely.

User access should follow the employee lifecycle

New starters need the right access, role changes should trigger a review and leavers should lose access promptly. Training helps managers understand why shared accounts, excess privileges and forgotten users create avoidable exposure.

Malware protection is more than installing antivirus

Modern endpoint protection combines prevention, monitoring, investigation and response. Staff also need to recognise suspicious behaviour and know how to report it quickly so the technical controls can be used effectively.

Build a 30, 60 and 90-day improvement plan

The first 30 days should address urgent gaps such as missing MFA or unsupported devices. The next phase can standardise configuration, backups and access. By 90 days, the business should be able to evidence its core controls and decide whether it is ready to progress towards formal Cyber Essentials certification.

Frequently asked questions

Does attending training give us Cyber Essentials certification?

No. Training can help you understand and prepare for the control requirements, but certification is a separate assessment process.

What are the five Cyber Essentials control themes?

They cover firewalls, secure configuration, security update management, user access control and malware protection.

Can training help before a Cyber Essentials assessment?

Yes. A practical course can help decision-makers understand the controls, identify gaps and prioritise work before entering a formal assessment process.

Practical cyber security training

Take the next step with a 39Security training day.

Work through phishing, payment fraud, Microsoft 365, device security, backups, incident response and a prioritised 90-day action plan.

View and book