The Hidden Risks in Your Current Cyber Essentials Scope

by Matt Scahill

When businesses start preparing for Cyber Essentials certification, it’s natural to begin by looking at what needs to be included in the assessment. Scope matters, especially now that the new question set – Danzell – asks more directly about what’s included and what’s being excluded.

The problem is that many businesses look at the big picture without considering the smaller details. 

Including something within the scope doesn’t mean that part of the business is ready to be assessed. For many, there are hidden risks sitting inside the tools, devices and security products they trust.

There are three places where these risks tend to appear:

1. Microsoft 365 and cloud storage

Microsoft 365 is a perfect example. Businesses include it in scope because it’s familiar, widely used, and has a strong reputation for built-in security. That reputation is fair, but it doesn’t remove the need for proper setup. If security settings have not been properly configured or reviewed, the platform itself may not be the problem: the setup is. The same applies to cloud storage platforms. They can be secure, but only if the right controls, settings and optimisations have been put in place.

2. Business laptops 

Business laptops are usually company-owned, so it’s easy to assume they are in good shape. Organisations often believe that this eradicates the risks of including personal devices within scope. But are updates being applied consistently? Are older devices still running unsupported software? Is antivirus installed, active, and up to date across every machine? These details are crucial, because small gaps can turn what should be strong, secure devices into weak points in your Cyber Essentials assessment.

3. Security tools 

Standard security tools can carry hidden risks. A firewall is there to protect the business. However, if rules are outdated, firmware has not been updated, or the configuration no longer reflects how the business works, that firewall may not offer the protection people think it does. Antivirus software is similar. Having it installed is not the same as knowing it’s working properly. Security tools look reassuring, but Cyber Essentials looks more closely at whether those protections are doing what they need to.

Don’t let familiar systems hide weak spots

Deciding what to include within the scope of your Cyber Essentials assessment may seem like a pretty straightforward task. And actually, it is. But businesses need to be thinking not only about what’s in scope, but how those in-scope systems will stand up to closer scrutiny. 

At PSTG, we can help you review your current Cyber Essentials scope, check the systems already included, and identify where assumptions may be hiding risk. From Microsoft 365 settings to laptops, firewalls and antivirus protection, we’ll help you understand what needs tightening up. 

The biggest risks are not always the ones you forget to include. Sometimes, they’re right there, sitting inside the very tools, systems and processes you were certain were safe, secure and trustworthy. 

Related News

Helpful updates and insights from our team.

Ready to take the pain out of IT?

Let’s make IT the least stressful part of your business.

Whether you need outsourced IT support in London or nationwide coverage, we make IT simple, secure and predictable.