Secure configuration
Devices and software set up to reduce the ways in — default passwords changed, unused features and accounts removed.
🔍 What a scan can verify
Our scans can spot missing security headers, weak/outdated TLS, and exposed default pages, admin panels or directory listings.
📝 What stays self-declared
We can't see whether default passwords were changed on your devices, whether unnecessary software/accounts were removed, or whether auto-run and device lock are configured — you tell us those.
What Cyber Essentials asks for this control
- Have you removed or disabled software, user accounts and services that you don't use?
Every extra account or service is another way in. Remove what you don't need.
- Have all default or vendor-supplied passwords been changed or removed on your devices and software?
Default passwords are an automatic fail in Cyber Essentials.
Mandatory item — a “No” here fails this whole control.
- Where a password is the only thing protecting access, is it suitably strong (and is brute-force protection in place)?
E.g. a minimum length plus throttling/lockout, or MFA on top.
How to get ready
- Remove unused user accounts, software and services from your devices.
- Change or remove every default/vendor password.
- Set a strong-password baseline (length + lockout) or add MFA where a password is the only control.
Check your secure configuration — and the other four controls
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →← Back to all five Cyber Essentials controls.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.