Cyber Essentials for recruitment agencies
Recruiters hold large databases of candidate personal data — names, addresses, right-to-work documents and bank details — making them a high-value, GDPR-sensitive target.
Why recruitment agencies are being asked for Cyber Essentials
Enterprise and public-sector clients routinely require their suppliers, including recruitment partners on their PSL, to certify to Cyber Essentials before sharing vacancies or candidate data.
What Cyber Essentials covers — the five controls
The same five controls apply to every organisation. Here's what each one means; tap through for the detail.
- Firewalls & internet gateways →A boundary between your devices and the internet, so only the services you actually need are reachable from outside.
- Secure configuration →Devices and software set up to reduce the ways in — default passwords changed, unused features and accounts removed.
- Security update management →Keeping software supported and patched, so known vulnerabilities are closed before attackers use them.
- User access control →Making sure accounts are only used by the right people, with MFA, unique logins and separate admin accounts.
- Malware protection →Protecting devices from malicious software, via anti-malware and/or only allowing approved applications to run.
See if your recruitment agencie business is ready
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →More: Cyber Essentials explained · free readiness check
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.