Insights

Does Cyber Essentials Protect Against Ransomware?

Discover how the five Cyber Essentials controls reduce common ransomware risks and where additional security measures are still needed.

Business using the five Cyber Essentials controls to reduce common routes used by ransomware attacks.

Ransomware remains one of the most disruptive cyber threats facing businesses. It can prevent employees from accessing systems, interrupt customer services and bring day-to-day operations to a standstill.

So, does Cyber Essentials protect against ransomware?

The short answer is that Cyber Essentials can significantly reduce the risk of many common ransomware attacks. Its five technical controls address several of the weaknesses attackers regularly exploit to gain access to businesses.

However, certification does not guarantee that ransomware will never get in. It should form part of a wider approach that includes secure backups, staff awareness, monitoring and incident response planning.

Ransomware is a business problem

Ransomware is sometimes treated as an IT issue, but its effects can quickly reach every part of an organisation.

A successful attack may result in:

  • Business interruption
  • Loss of access to important information
  • Missed customer deadlines
  • Recovery and investigation costs
  • Reputational damage
  • Regulatory consequences
  • Contractual disputes
  • Theft and publication of sensitive information

Modern ransomware attacks do not necessarily stop at encrypting files. Attackers may steal confidential information before deploying the ransomware and then threaten to publish it unless the organisation pays.

This means that even a business with recoverable backups could still face extortion, reputational harm and difficult conversations with customers, regulators and insurers.

The objective should therefore be to prevent attackers from gaining access in the first place, limit what they can do if they get in, and prepare the business to respond if an incident still occurs.

How do ransomware attackers get in?

Ransomware incidents rarely begin with someone dramatically “hacking the mainframe”. They usually begin with a much more familiar weakness.

Common entry points include:

  • Phishing emails and stolen credentials
  • Internet-facing systems with known vulnerabilities
  • Unsupported operating systems and applications
  • Poorly configured remote-access services
  • Weak or reused passwords
  • Excessive administrator privileges
  • Malicious email attachments or downloads
  • Unnecessary services exposed to the internet
  • Accounts belonging to former employees
  • Devices that have not received important security updates

Attackers do not always need a highly sophisticated technique. If a business has an exposed remote-access service, an unpatched vulnerability or a poorly protected user account, the attacker may simply take the easiest available route.

Cyber Essentials focuses on several of these common weaknesses.

How the five Cyber Essentials controls reduce ransomware risk

Cyber Essentials is built around five technical control areas. Each provides a different layer of protection against the routes ransomware attackers commonly use.

Firewalls and internet gateways

Firewalls help control which connections can reach the organisation’s systems from the internet.

Without appropriate firewall controls, systems and administrative services may be unnecessarily exposed. Attackers can scan the internet for these services and attempt to exploit vulnerabilities, guess passwords or use stolen credentials.

The Cyber Essentials requirements help reduce this risk by encouraging organisations to:

  • Block unnecessary incoming connections
  • Restrict exposed administrative services
  • Remove insecure firewall rules
  • Change default administrative passwords
  • Limit access to management interfaces
  • Review services that are accessible from the internet

This does not mean that every internet-accessible service is automatically dangerous. Many businesses need to provide remote access or host online services. The important point is that access should exist because it is required, not because an old or temporary firewall rule has been forgotten.

Reducing unnecessary exposure gives attackers fewer opportunities to enter the network.

Secure configuration

New devices and applications are often configured for convenience and compatibility rather than maximum security.

They may include default accounts, unnecessary services, unwanted software and features that the organisation never uses. Each of these can create an additional opportunity for an attacker.

Secure configuration helps reduce the available attack surface by requiring organisations to:

  • Remove unused accounts
  • Disable unnecessary services
  • Remove unwanted software
  • Change default passwords
  • Reduce unnecessary functionality
  • Apply suitable security settings

This is particularly important because ransomware attacks often involve several stages. An attacker may compromise one account, discover an unnecessarily exposed service and then use excessive permissions to move further into the environment.

Removing what the business does not need makes that process more difficult.

Security update management

Ransomware groups frequently exploit known vulnerabilities for which security updates are already available.

Once a vulnerability becomes public, attackers may quickly begin scanning for organisations that have not applied the relevant fix. In some cases, automated tools make it possible to identify and compromise vulnerable systems at scale.

Cyber Essentials requires organisations to:

  • Use supported operating systems and applications
  • Enable automatic updates where appropriate
  • Apply important security updates promptly
  • Remove software that no longer receives security fixes
  • Ensure firmware is supported and updated where required

Patching closes known routes that attackers might otherwise use to gain access or expand their control.

The 14-day requirement for relevant high-risk security updates should be treated as a maximum, not a target to aim for. If a serious vulnerability is being actively exploited, waiting two weeks could leave the organisation unnecessarily exposed.

Updates should be applied as quickly as can be done safely. Vulnerabilities known to be under active attack may require a much faster response.

User access control

The damage an attacker can cause often depends on the privileges attached to the account or device they compromise.

If every employee has administrator privileges, an attacker who steals an ordinary user’s credentials may immediately gain the ability to install software, disable protection or make significant system changes.

Cyber Essentials helps limit this risk by requiring organisations to:

  • Give users only the access they need
  • Restrict administrator privileges
  • Use separate accounts for administrative work
  • Remove accounts that are no longer required
  • Protect internet-accessible accounts with multi-factor authentication
  • Review access when roles or responsibilities change

Multi-factor authentication makes a stolen password less useful because the attacker also needs to satisfy an additional authentication step.

It is not completely foolproof. Attackers may use fake login pages, session theft or repeated authentication requests to trick users. However, properly implemented multi-factor authentication creates a valuable additional barrier.

Restricting administrator privileges also helps contain an incident. Compromising a standard user account should not automatically give an attacker unrestricted control over the device or wider network.

Malware protection

Malware protection provides another barrier against ransomware entering or running within the organisation.

Depending on the device and operating system, this may include:

  • Anti-malware software
  • Application allow-listing
  • Restrictions on where applications can be installed
  • Browser security controls
  • Built-in operating system protections

Traditional anti-malware products look for known malicious files and suspicious behaviour. Application allow-listing takes a different approach by allowing only approved software to run.

Both approaches can make it more difficult for ransomware to execute successfully.

However, no security product can identify every new or modified ransomware payload. Attackers continually adapt their software and techniques to avoid detection. Malware protection is important, but it should not be the organisation’s only defence.

Making common ransomware attacks more difficult

The real value of Cyber Essentials comes from combining its five controls.

A ransomware attacker may need:

  1. A route into the organisation
  2. A vulnerable or poorly configured system
  3. A compromised user account
  4. Permission to run malicious software
  5. Sufficient privileges to spread or disable security controls

Cyber Essentials places barriers at each of these stages.

Firewalls reduce unnecessary routes into the business. Secure configuration removes avoidable weaknesses. Security updates close known vulnerabilities. User access controls restrict what compromised accounts can do. Malware protection attempts to stop malicious software from running.

The objective is not to make the organisation magically invulnerable. It is to remove the easy options and make a successful attack considerably more difficult.

Attackers often look for the quickest and least expensive route to a return. Improving these fundamental controls may encourage an opportunistic attacker to move on to an easier target.

What Cyber Essentials does not guarantee

It is important to be realistic about what certification means.

Cyber Essentials does not guarantee that:

  • Ransomware can never enter the organisation
  • Employees will never be deceived by phishing
  • Every malicious file will be detected
  • All cloud services are securely configured beyond the scheme’s requirements
  • Attackers cannot exploit a previously unknown vulnerability
  • Information cannot be stolen
  • The business can recover quickly from an incident
  • Suppliers and connected organisations are secure

Cyber Essentials confirms that a defined set of foundational controls has been assessed. It does not certify every aspect of the organisation’s cybersecurity arrangements.

A business could meet the Cyber Essentials requirements but still have weaknesses in its backup arrangements, cloud configuration, security monitoring or incident response plan.

Certification is therefore a strong baseline rather than a promise that no cyber incident can occur.

Secure backups remain essential

Backups are not one of the five Cyber Essentials control areas, but they remain critical to ransomware resilience.

Without reliable backups, an organisation may have no practical way to recover encrypted files and systems. Simply having a backup product or copying files to another folder is not enough.

Effective backups should be:

  • Performed regularly
  • Monitored for failures
  • Protected from alteration or deletion
  • Separate from normal user access
  • Retained for an appropriate period
  • Tested through restoration exercises

The separation point is particularly important.

If ransomware can access the backups using the same compromised account that can access the live systems, it may encrypt or delete those backups too. Attackers may deliberately target backup systems before deploying ransomware because they know this increases pressure on the victim to pay.

Restoration testing is also essential. A backup has limited value if the organisation discovers during an emergency that it is incomplete, corrupted or cannot be restored within an acceptable timeframe.

Backups can help recover from encryption, but they do not undo the theft of information. If an attacker has copied sensitive client data, restoring the affected systems will not remove the threat of publication.

Staff awareness still matters

Cyber Essentials provides important technical protections, but people remain a frequent target.

Attackers may impersonate suppliers, senior employees, Microsoft support teams or IT providers. They may create fake login pages, send convincing password-reset messages or persuade someone to install remote-access software.

Employees should know how to recognise and report:

  • Unexpected attachments
  • Links to fake login pages
  • Urgent payment requests
  • Multi-factor authentication fatigue attacks
  • Suspicious password-reset messages
  • Unusual requests from senior colleagues
  • Requests to install remote-access tools
  • Messages designed to bypass normal procedures

Training should not be based on blaming employees for making mistakes. People should feel comfortable questioning unusual requests and reporting possible incidents quickly.

An employee who reports a suspicious login immediately may give the organisation time to disable an account before an attacker can move further into the environment.

Detection and response are also important

Preventive controls reduce risk, but they cannot stop every possible attack.

Businesses also need to consider how they would detect and respond to an incident.

Questions worth asking include:

  • How would we identify unusual account activity?
  • Who can isolate an affected device?
  • How quickly can we disable a compromised account?
  • Who should employees contact if they suspect an attack?
  • How will we preserve evidence for investigation?
  • When should we contact our IT provider or security specialist?
  • How would we inform customers, insurers or regulators?
  • Can essential business services continue during recovery?
  • How will we confirm that systems are safe before restoring them?

An incident response plan is most valuable when it has been written, discussed and tested before an incident occurs.

Trying to decide who has authority to disconnect systems, contact clients or engage an external specialist during an active ransomware attack wastes valuable time.

Even a short tabletop exercise can identify missing contact details, unclear responsibilities and unrealistic assumptions about recovery.

Does Cyber Essentials Plus provide greater protection?

Cyber Essentials is a verified self-assessment. The organisation confirms that the required controls are in place, and an assessor reviews the answers.

Cyber Essentials Plus uses the same five control areas but includes independent technical testing of a sample of systems. This provides greater confidence that the controls have been implemented correctly and are operating as expected.

Cyber Essentials Plus may be particularly valuable for organisations that:

  • Handle sensitive client information
  • Depend heavily on digital services
  • Face security requirements in contracts or tenders
  • Need to provide stronger assurance to customers
  • Want independent verification of their controls

It still cannot guarantee immunity from ransomware. However, the technical assessment can identify implementation problems that may not be obvious from policies, system settings or self-assessment answers alone.

Cyber Essentials should form part of layered security

Cyber Essentials provides a valuable foundation, but the strongest ransomware defence uses multiple layers.

Depending on the organisation’s size, systems and risk exposure, additional measures might include:

  • Protected and regularly tested backups
  • Email security controls
  • Security awareness training
  • Endpoint detection and response
  • Microsoft 365 security reviews
  • Vulnerability management
  • Network and account monitoring
  • Penetration testing
  • Incident response planning
  • Cyber insurance
  • Supplier security reviews

Not every organisation needs the same combination of security products and services. A small consultancy will have a different risk profile from a large legal practice or managed service provider.

The important point is to understand what information and services the business depends on, how attackers might reach them and what would happen if those protections failed.

A practical step towards ransomware resilience

Cyber Essentials cannot promise that a business will never experience ransomware.

What it can do is close many of the common routes attackers use, improve the security of accounts and devices, and reduce the opportunities available to them.

For many organisations, this makes Cyber Essentials an important and practical first step towards ransomware resilience.

The strongest protection comes from combining its five technical controls with secure backups, staff awareness, effective monitoring and a response plan that has been prepared and tested in advance.

Plainsight Security helps organisations prepare for and achieve Cyber Essentials and Cyber Essentials Plus certification. We can identify potential gaps, work alongside your existing IT provider and help strengthen the controls that reduce exposure to ransomware and other common cyberattacks.

Contact us to discuss your certification requirements.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights