Common Cyber Essentials questions
Posted on 2 October 2026 by Beaming SupportPreparing for Cyber Essentials often raises questions about who is responsible for security, which processes you need and whether your devices are being kept up to date.
These are some of the questions customers ask us, with practical advice to help you understand your next steps.
Do I need Cyber Essentials if my IT provider is ISO 27001 certified?
Your IT provider’s ISO 27001 certification can offer reassurance about how it manages information security within its certified scope. However, it does not automatically cover your organisation or replace your own Cyber Essentials certification.
If a customer, supplier or contract requires your business to hold Cyber Essentials, check exactly what they require, including whether they specify Cyber Essentials or Cyber Essentials Plus.
Your provider may manage some of the relevant security controls, but your business still needs to confirm that the requirements are met across the systems included in your assessment.
The assessment asks about processes we do not have. Where should we start?
Start by identifying what each question requires and whether the gap concerns a technical setting, a working process or documentation.
Cyber Essentials focuses on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Supporting processes help you apply these consistently.
Bring together the people responsible for IT and business decisions. For each gap, agree:
- What needs to happen.
- Who is responsible.
- How you will check it has been done.
- What needs to be recorded or explained to staff.
For example, you need a reliable way to approve new accounts and remove access when someone leaves.
Keep any written guidance specific to how your business works. A policy should describe a process people actually follow, rather than something created solely to complete an assessment.
How can I check whether our devices are receiving security updates?
Ask your IT team or provider how updates are installed and how they confirm installation has succeeded.
Check coverage across operating systems, applications and router or firewall firmware. Include remote workers’ devices, which may not always connect to the office network.
Cyber Essentials requires relevant vulnerability fixes within 14 days of release when they address critical or high-risk vulnerabilities, have a CVSS v3 base score of 7 or above, or have no severity information from the vendor.
Central management tools, such as Microsoft Intune, can help deploy updates and report on device status. Other approaches can also work. What matters is that your process covers the relevant systems and identifies missed or failed updates.
Will device management software find and fix all our vulnerabilities?
Do not assume that installing a management or security tool means every vulnerability is being addressed.
Different tools perform different roles. Microsoft Intune helps manage devices, settings and updates. Microsoft Defender Vulnerability Management can identify weaknesses on supported devices and help prioritise action. When integrated with Intune, it can support remediation tasks.
Someone still needs to review findings, arrange fixes and confirm they have worked. Coverage also depends on the products, licences and configuration you use.
Ask your provider what is monitored, what is updated automatically and what requires manual action.
Get clear answers before completing your assessment
If you are unsure how to answer a question, ask your IT provider to explain the current setup and identify any work needed. This helps you complete the assessment accurately and maintain the controls afterwards.
Speak to a Beaming business security expert