grc-scan

Malware protection

Protecting devices from malicious software, via anti-malware and/or only allowing approved applications to run.

๐Ÿ” What a scan can verify

Endpoint anti-malware is essentially invisible to an external website scan โ€” we can verify almost nothing here.

๐Ÿ“ What stays self-declared

Whether anti-malware is active on every device, and whether app allow-listing or sandboxing is used, is entirely self-declared โ€” a CE Plus assessor checks this on your actual devices.

What Cyber Essentials asks for this control

How to get ready

  • Make sure reputable, auto-updating anti-malware is running on every device โ€” or use application allow-listing instead.
  • Prevent unapproved software from running, and don't auto-open downloads or attachments.

Check your malware protection โ€” and the other four controls

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict โ€” free, no login needed, and we don't store your answers.

Start the free readiness check โ†’

โ† Back to all five Cyber Essentials controls.

This is a free readiness / gap report to help you prepare โ€” it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.