Cyber Essentials is no longer a tick-box exercise – businesses need to act now
The latest Cyber Essentials overhaul is raising the bar for businesses of all sizes.
The Cyber Essentials framework, designed to provide basic security controls for businesses, has undergone significant changes. Recent reviews indicate that businesses of all sizes are at risk from cyber breaches, with 40% of companies affected in the past year alone. The new framework, dubbed 'Denzel,' aims to raise the bar and implement continuous cyber resilience.
Key changes include stricter patch management and vulnerability management, requiring a 14-day window for critical patch deployment. MFA must be enabled on all cloud services and user accounts, with non-compliance resulting in certification failure. Additionally, businesses must replace legacy hardware and update operating systems, as vendors discontinue support for older systems.
The framework emphasizes continuous improvement, shifting from a one-time compliance exercise to an ongoing commitment to security. Businesses are advised to review their current patching and MFA practices, assess their cloud service usage, and plan for hardware and software updates to remain compliant and minimize breach risks.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.