• Introduction

Keeping devices secure with vendor-provided updates is key for cyber security best practice. It helps prevent unauthorised access and helps keep devices safe from harm. Whether pursuing Cyber Essentials, Cyber Essentials Plus, or just looking to be secure, applying security updates is a crucial step. In this article, we explain why security updates are so important, present tips and recommendations, as well as an example scenario to show how to implement the requirements of the Cyber Essentials scheme.

 

Why Security Updates Are Important

Devices that run software can contain security flaws, known as vulnerabilities. Vulnerabilities are discovered regularly. Once discovered, malicious individuals can misuse (or exploit) the vulnerabilities and find ways to attack computers / networks. Vendors therefore provide regular updates and guidance to fix these weaknesses. The vendors can rely on other entities to ensure fixes are applied in a timely manner.

 

Security Updates in Cyber Essentials

To meet Cyber Essentials certification requirements, organisations must ensure:

  • Software is licenced and supported, to have access to the security updates
  • Remove devices when not in support or move to a sub-set, to reduce risks 
  • Have automatic updates enabled where possible, to help automate and ensure updates are applied 
  • Be updated or have manual configuration changes applied within 14 days, to address critical/high risk vulnerabilities or when no details of the risk are provided by the vendor, to ensure weaknesses that are most risky are addressed within a reasonable amount of time


Considerations and Key Notes

When reviewing security updates for your organisation, please consider:

  • Enabling automatic updates on operating systems and applications – reduce manual activity, speed up activity, but not fully remove the need for manual processes
  • Applications, malware protection software, email clients and browsers, are important to update – keep devices and data secure
  • 14 days is the maximum time to apply updates for Cyber Essentials – sooner is better, as devices are exposed to the vulnerabilities in the meantime

 

Key Notes

  • Cyber Essentials uses Common Vulnerability Scoring System (CVSS) version 3 and considers vulnerabilities with a base score of 7 or above as being high/critical risk

 

Example Scenario

Organisation ABC uses software that is supported by the vendor:

  • For Organisation ABC, no out-of-support software is in use and the focus is on security updates
  • Security updates are applied within 14 days – operating systems, applications, email server/client, browsers, firmware on network equipment, malware protection
  • Automatic updates are enabled (where possible) and a manual check is carried out to ensure all updates have taken effect
  • A mobile device management solution (MDM) and vulnerability assessment tool are considered to automate and speed up processes – this requires investment and is put on the roadmap. In the meantime, manual processes are introduced to ensure security updates are applied and checked by all users, with an information security policy being introduced (with focus on the timely application of security updates)
  • Software lifecycle is monitored to ensure continuity of support from the vendor – plans are put in place to address and upgrade operating systems/applications before support ends

 

Tips and Recommendations

  1. Having a way to monitor the lifecycle of operating systems and applications should help avoid end-of-support issues
  2. Removing or retiring operating systems and software that are out of support helps reduce risk
  3. If there’s a business need to use out-of-support software, document the risk and take action to reduce risk through use of a sub-set
  4. Consider guidance and support from an NCSC Cyber Advisor for implementation of the technical controls 

For more detailed guidance, review the IT Requirement for Infrastructure document and/or visit the IASME knowledge hub for Cyber Essentials.

 

How We Help

At RB Consultancy Ltd, we support organisations in their desire to improve cyber security and also to meet Cyber Essentials and Cyber Essentials Plus requirements:

  • We explain the importance of security updates
  • We help ensure security updates are being applied in a timely manner
  • We explain why the Cyber Essentials questions are being asked and how they intend to protect organisations in different ways
  • We ensure security update settings and processes align with Cyber Essentials guidelines
  • We assess and issue organisations with Cyber Essentials and Cyber Essentials Plus certifications

 

Conclusion

Security updates are a critical component of cyber security and Cyber Essentials certification. Out-of-date software can leave your organisation vulnerable. By implementing best practices and ensuring compliance with Cyber Essentials technical controls, organisations can significantly reduce cyber risk. If you would like assistance with security update configuration, or Cyber Essentials / Cyber Essentials Plus certification, please contact us for support.

 

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.

Cyber Essentials: Security Updates

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP