Cyber Essentials question · Secure configuration
Where a password is the only thing protecting access, is it suitably strong (and is brute-force protection in place)?
Why assessors ask this
E.g. a minimum length plus throttling/lockout, or MFA on top.
What “good” looks like for Secure configuration
- Remove unused user accounts, software and services from your devices.
- Change or remove every default/vendor password.
- Set a strong-password baseline (length + lockout) or add MFA where a password is the only control.
See where you stand in 5 minutes
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →Part of the Secure configuration control.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.