Cyber Essentials

Simplify Cyber Essentials compliance – protect, manage, and secure every endpoint with NinjaOne.
NinjaOne dashboard

Differences between Cyber Essentials and Cyber Essentials Plus

Cyber Essentials is a self-assessed certification that provides foundational security measures to protect against common cyber threats. It consists of five technical control themes:

The aim of firewalls is to make sure that only secure and necessary network services can be accessed from the internet.
The aim of secure configurations is to ensure that computers and network devices are properly configured to reduce vulnerabilities and provide only the services required to fulfill their role.
The aim of security update management is to ensure that devices and software are not vulnerable to known security issues for which fixes are available.
The aim of user access control is to ensure that user accounts are assigned to authorized individuals only and provide access to only those applications, computers and networks the user needs to carry out their role.
The aim of malware protection is to restrict execution of known malware and untrusted software from causing damage or accessing data.

Cyber Essentials Plus encompasses all Cyber Essentials requirements and is designed to provide greater assurance that security controls are effectively implemented through external audits.

Firewalls, secure configuration, security update management, user access control, and malware protection.
Technical security testing including external pen testing and dark web audits.

See how NinjaOne helps organizations meet Cyber Essentials requirements

Scope overview

Cyber Essentials certification applies to an organization’s entire IT infrastructure or a defined, separately managed subset. End-user devices cannot be excluded, and all in-scope systems must be secured against cyber threats. The scope must include all internet-facing devices and software, covering business units, networks, and locations, and must be pre-agreed upon with the certification body.

A comprehensive scope maximizes protection and builds customer trust. 

How NinjaOne helps to fulfill Cyber Essentials requirements by technical control

Firewalls

NinjaOne network monitoring alerts administrators of anomalies and disabled firewalls. Additionally, NinjaOne’s comprehensive automation library provides ready-to-use script templates to audit firewall profiles, status, configure exceptions, and enable or disable Windows Firewalls with ease.

Secure configuration

NinjaOne comes equipped with security-focused scripts that can detect disabled BitLocker profiles and securely store recovery keys. These scripts also identify outdated protocols, such as SMB v1 or weak TLS versions, ensuring your systems stay secure and up to date. Other useful NinjaOne automations include the removal of unnecessary user accounts, removal of unwanted software, or lock devices after too many failed logon attempts.

Security update management

Update Management is available for Windows, Mac, and Linux operating systems as well as for iPadOS and iPadOS for mobile devices. With NinjaOne you can patch over 6,000 third-party applications with ease. It can enforce the deployment of critical updates within a timeline of two weeks as required by Cyber Essentials. NinjaOne can also proactively alert when risk scores (CVSS) exceed a pre-defined threshold.

User access control

NinjaOne enforces multi-factor authentication (MFA) across its entire platform, covering administrators, technicians, and end users. Its integration with Microsoft SCIM ensures seamless synchronization with Active Directory, simplifying identity management and enhancing security. NinjaOne can also execute scripts to remove old user profiles and rotate admin passwords.

Malware protection

NinjaOne also actively monitors endpoints to ensure AV protection and/or endpoint detection and response (EDR) is installed, operational, and always up to date. NinjaOne is integrated with leading EPP and EDR solutions such as SentinelOne, Crowdstrike, and Bitdefender Gravity Zone.
Ready to simplify the hardest parts of IT?