Introduction

Deploying malicious software (like ransomware) is just one way that cyber criminals can impact organisations and people – having suitable protection in place is key to good cyber security posture. It helps to prevent malicious software from appearing on devices and running – effectively aimed at preventing damage and impact. Here, we explore the importance of malware protection, how it relates to Cyber Essentials, share tips and provide an example scenario to help explain the Cyber Essentials requirements.

 

Why Malware Protection Is Important

Cybercriminals use malware to exploit system vulnerabilities, steal data, and disrupt operations. Effective malware protection is crucial to:

  • Prevent data breaches and financial losses
  • Ensure business continuity
  • Comply with regulatory security standards
  • Reduce the risk of ransomware and phishing attacks

A single malware infection can cause significant damage, making proactive prevention essential for any organisation.

 

Malware Protection in Cyber Essentials

To meet Cyber Essentials certification requirements, organisations must either:

  • Use anti-malware software, for devices that support the software
  • Use an application allow list, for all devices and/or those that don’t support anti-malware software

 

Considerations and Key Notes

When using anti-malware software for your organisation, it must:

  • Be up to date and maintained
  • Prevent malware from running and executing malicious code
  • Prevent connections to malicious websites over the internet

When using an application allow list for your organisation:

  • Use only approved applications, restricted by code signing – such as using ‘stores’
  • Approve apps before deploying them
  • Maintain a current list of approved apps, and not allow apps to be installed that are unsigned or have an invalid signature – such as those downloaded on alternative sites than ‘stores’

Key Notes

  • Built-in anti-malware products (Windows / MacOS) are acceptable for Cyber Essentials
  • Anti-malware products should be used for servers, desktops and laptops
  • Mobile phones can be protected using an application allow list – using ‘stores’ can help minimise risk of downloading infected files

 

Example Scenario

Organisation uses a laptop and iPhone to access organisational data

  • For this environment, focus is on malware protection for the laptop and iPhone
  • Ensuring an up to date anti-malware product is running on the laptop – such as Microsoft Defender – is fundamental
  • Ensuring malicious websites are blocked for browser can be achieved through Edge (SmartScreen) and Chrome (safe browsing) tests – browser extensions can be used for further protection
  • Ensuring apps are sourced from Apple store only – no ‘jail break’ features – can be supported through policy and training

 

Tips and Recommendations

  1. If using laptops, desktops or servers to access / store organisational data, ensure it has anti-malware software running and that the software is up to date / receiving regular updates
  2. If using mobile phones (Android or Apple) to access / store organisational data, use an application allow list to ensure only trusted and (vendor) signed applications are installed
  3. Choose to deploy and purchase anti-malware products if you wish, the in-built products for Windows and MacOs are acceptable for Cyber Essentials
  4. Seek guidance and support from a NCSC Cyber Advisor – such as RB Consultancy Ltd

For more detailed guidance, review the IT Requirement for Infrastructure document and/or visit the IASME knowledge hub for Cyber Essentials

How We Help

At RB Consultancy Ltd we support organisations in ensuring malware protections are in place to meet Cyber Essentials and Cyber Essentials Plus requirements:

  • We explain the importance of malware protection
  • We help ensure malware protections are applied and working effectively
  • We explain why the Cyber Essentials questions are being asked and how they intend to protect organisations in different ways
  • We ensure malware protection settings and processes align with Cyber Essentials guidelines
  • We assess and issue organisations with Cyber Essentials and Cyber Essentials Plus certifications

 

Conclusion

Malware protections are a critical component of cyber security and Cyber Essentials certification, helping to protect your business from cyber threats. Malicious software can impact your organisation in many ways – including ransomware and data exfiltration. By implementing best practices and ensuring compliance with Cyber Essentials technical controls, organisations can significantly reduce their cyber risk. If you need any assistance with malware protection, or Cyber Essentials / Cyber Essentials Plus certification, please contact us for support.

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.


Cyber Essentials: Malware Protection

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
Cyber Security Consultancy: Asset Management Guide

Cyber Security Consultancy: Asset Management Guide

  Introduction Imagine the business is thriving. Clients are happy, services delivered, and systems working well. There’s trust in the underlying software. But some things aren’t documented or very well known. Then it happens…. One day, you learn that a flaw in a forgotten piece of software has exposed data – millions of records, stolen […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP