Introduction

Technical debt and out of support software can be a challenge when considering Cyber Essentials certification. This summary demystifies the topic, with advice, explanation and an example – aimed to help and inform. In this article, we consider why technology may be a challenge to replace, urge organisations to plan for the replacement of technology, explain how Cyber Essentials provides some flexibility for out of support technology (to be applied if necessary), and provide an example scenario to help explain the requirements of the Cyber Essentials scheme.

 

Out of support software and technical debt

There are plenty of examples of organisations needing to retain end of support software (including operating systems), such as:

  • Financial constraints
  • Resource constraints
  • Operational needs
  • Lack of expertise to replace / retire
  • Poor documentation leading to migration challenges
  • Replacement systems haven’t been designed, or simply can’t replace

 

A sub-set could help

  • A sub-set is described as “a part of the organisation whose network is segregated from the rest of the organisation by a firewall or VLAN”
  • Out of support (technical debt) systems can be located in sub-set in order to support certification and reduce risk
  • The Cyber Essentials Requirements for IT document states “Your assessment and certification should cover the whole of the IT infrastructure used to carry out your organisation’s business, or if necessary, a well-defined and separately managed sub-set

Note – deploying a firewall on the boundary of that VLAN will help control traffic going in and out and further reduce risk 

 

Cyber Essentials, out of support software and technical debt

So, if necessary, it is possible to achieve and maintain Cyber Essentials certification with technical debt and network segregation – detail to further assist:

  • Technical debt is located in a Virtual LAN (VLAN), so it’s at least ‘one hop’ away from the network being assessed for Cyber Essentials, and is de-scoped from the assessment
  • Once segregated, a couple of options may then exist:
    1. Internet connectivity remains between out of support software devices and the internet
    2. Internet connectivity is blocked at the boundary of the segregated network, so there’s no inbound / outbound internet communication – this lowers the risk of internet based threats and the out of support software devices
  • Depending upon whether internet connectivity remains for the sub-set or not, leads onto how the organisation can then apply scope for Cyber Essentials:
    1. If internet connectivity is blocked at the boundary of the sub-set – the whole of the organisation can be in scope for the assessment (as there is no internet connectivity to the out of support devices, which means they are out of scope)
    2. If internet connectivity remains in place for the sub-set – then the whole organisation cannot be in scope and there needs to be an ‘exclusion of network’ statement in the scope description – it also means higher risk and that an organisation would not qualify for free cyber liability insurance

 

Considerations and Key Notes

When a ‘network is excluded’ for Cyber Essentials:

  • A boundary firewall or VLAN is in place between ‘network1’ (main network in scope and ‘network2’ (network being de-scoped)
  • End of support devices located on ‘network2’ can communicate with the internet
  • Devices on ‘network1’ and ‘network2’ can communicate with each other
  • The description of the scope could be “whole organisation excluding network2’

When the whole organisation can still be considered for scope:

  • A boundary firewall or VLAN is in place between ‘network1’ (main network in scope) and ‘network2’ (network being de-scoped)
  • End of support devices on ‘network2’ can not communicate with the internet
  • Devices on ‘network1’ and ‘network2’ can communicate with each other
  • The description of the scope could be “whole organisation”

Key Notes

  • See the Cyber Essentials Knowledge Hub for a number of excellent scenario descriptions to support the use of sub-sets
  • Reference to cloud and student networks in the Cyber Essentials Knowledge Hub too

 

Example Scenario

Organisation ABC uses an out of support server and application to support operations and can’t replace it within the timescales proposed for Cyber Essentials certification

  • For this environment, focus is on the end of support server and application
  • The server and application is deployed into a VLANX, with a firewall controlling traffic in / out of VLANX
  • Firewall rules are applied at the boundary of VLANX that prevents internet connectivity to / from VLANX
  • Firewall rules also allow traffic from VLANX to the rest of the environment, in order to support ongoing organisational operations
  • Organisation ABC submits a scope of “Whole organisation” as there is no internet connectivity for the out of support server / application in VLANX

 

Tips and Recommendations

  1. Aim for the ‘whole organisation’ to be certified for Cyber Essentials wherever possible – only use a subset if necessary.  
  2. Plan ahead and replace software / hardware ahead of time – check vendor notifications and ensure a suitable timeline and budget can agreed to avoid issues
  3. Consider the risks associated with technical debt and apply additional technical controls wherever possible – to protect the device, prevent exploitation of weakness and alert should exploitation occur
  4. Seek guidance and support from a NCSC Cyber Advisor – such as RB Consultancy Ltd

For more detailed guidance, review the IT Requirement for Infrastructure document and/or visit the IASME knowledge hub for Cyber Essentials

 

How We Help

At RB Consultancy Ltd we support organisations by securing environments and assisting with Cyber Essentials and Cyber Essentials Plus requirements:

  • We explain the importance of security updates and risks of technical debt
  • We help ensure sub-sets are applied in the event technical debt remains
  • We explain why the Cyber Essentials questions are being asked and how they intend to protect organisations in different ways
  • We ensure the use of sub-sets align with Cyber Essentials guidelines
  • We assess and issue organisations with Cyber Essentials and Cyber Essentials Plus certifications

 

Conclusion

  • It is possible for organisations to achieve Cyber Essentials certification with out of support software and technical debt – deployment of a sub-set is required
  • The risk is higher for end of support equipment with internet connectivity – rather than this being blocked
  • If internet connectivity is blocked at the boundary of the sub-set that’s being de-scoped, then the risk is lower and the Cyber Essentials certification can cover the ‘whole of the organisation’
  • By ensuring compliance with Cyber Essentials technical controls, organisations can significantly reduce their cyber risk

If you need any assistance with sub-setting, or Cyber Essentials / Cyber Essentials Plus certification, please contact us for support.

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.

Cyber Essentials: Using Out of Support Software

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
Cyber Security Consultancy: Asset Management Guide

Cyber Security Consultancy: Asset Management Guide

  Introduction Imagine the business is thriving. Clients are happy, services delivered, and systems working well. There’s trust in the underlying software. But some things aren’t documented or very well known. Then it happens…. One day, you learn that a flaw in a forgotten piece of software has exposed data – millions of records, stolen […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP