Cyber Security Fundamentals
The cyber security fundamentals most businesses rely on are well established:
Supported systems
Controlled access
Multi-factor authentication
Secure, tested backups
An incident response plan
The harder question is whether those controls are complete, current and capable of working together when something goes wrong.
A business can invest heavily in security and still carry unnecessary risk through an old administrator account, an untested backup or a supplier connection nobody has reviewed for years.
Cyber resilience depends less on the presence of individual controls than on the quality of the decisions around them.
Start with an accurate view of the business
Cyber attack prevention begins with knowing which systems, devices, services and online accounts the organisation uses. That picture is often less complete than expected, particularly where cloud platforms, older devices and temporary environments have been added over time.
Patching only works reliably when ownership is clear. Automatic updates help, but they do not remove the need to identify unsupported software, confirm that critical fixes have been applied and decide what to do when a system cannot be updated promptly.
The same applies to endpoint protection and firewalls. Installing security tools is not the same as knowing they are active on every relevant device, configured correctly and producing alerts that somebody reviews. Temporary firewall rules and remote-access permissions are particularly easy to overlook once the original task has ended.
Businesses should be able to answer some basic questions:
- Which systems, applications and devices are currently in use?
- Who is responsible for patching and maintaining them?
- Is any software unsupported or approaching end of life?
- Are endpoint protection and firewalls active and correctly configured?
- Who reviews security alerts?
- Are temporary access permissions and firewall rules removed when they are no longer required?
Senior leaders do not need to manage these controls themselves, but they should expect clarity from internal IT teams and external providers. Cyber risk management weakens when ownership falls between departments or suppliers.
Protecting access and spotting third-party risk
Many incidents begin with legitimate credentials being misused. Access management therefore deserves the same attention as the network perimeter, particularly where external parties connect to the business.
Strong access controls should include:
- Permissions based on an employee’s current role
- Separate administrator accounts for privileged activity
- Prompt removal of leaver, contractor and dormant accounts
- Unique credentials supported by a reputable password manager
- Multi-factor authentication for email, cloud platforms, remote access and privileged accounts
- Regular reviews of third-party and supplier access
Employees should have the permissions needed for their role, rather than access retained from previous responsibilities. Administrator accounts should be limited, reviewed and kept separate from everyday email and web browsing. Leaver, contractor and dormant accounts should be removed promptly.
Password policy should also be practical. Unique credentials and a reputable password manager are more useful than frequent, arbitrary password changes that encourage predictable variations. The NCSC supports password managers and advises against routine password expiry without evidence of compromise.
Multi-factor authentication should cover email, cloud platforms, remote access and privileged accounts. Simply saying that MFA is enabled is not enough. Exceptions, weak recovery methods and older systems can provide routes around it, while different forms of MFA offer different levels of resistance to phishing.
Third-party access requires the same level of scrutiny. IT providers, software companies and contractors may hold extensive permissions across systems and data. Businesses should understand what access exists, how it is secured and when it will be removed. Named accounts are generally preferable to shared credentials, and permissions should be limited to the work being carried out.
Contracts and working arrangements should also make responsibilities clear. This includes how access is granted, how it is monitored and how quickly it can be withdrawn. Responsibility for the associated risk remains with the organisation, regardless of who provides the service.
Detection and response need equal weight
Preventative controls cannot be expected to stop every incident. Businesses also need enough visibility to recognise suspicious activity and enough preparation to act without losing critical time.
Logging is useful only when the right information is retained, and somebody is responsible for reviewing it. Records of unusual sign-ins, administrator changes or malware alerts have limited value if they are never assessed. NCSC guidance describes logging as the foundation of security monitoring and links detection directly to incident management.
Where monitoring is outsourced, the business should understand what is being watched, which alerts trigger action and what happens outside normal working hours. “Managed security” can describe very different levels of support.
A practical incident response plan should make clear:
- Who leads the response
- Who can authorise urgent action
- Which internal and external contacts need to be involved
- When technical, legal, regulatory and insurance support should be brought in
- What happens if an incident occurs outside normal working hours
Where personal data is affected, the response may also need to account for regulatory obligations and any relevant data protection insurance arrangements.
Backups should be judged by the recovery they enable
Most businesses have backups. Fewer can say with confidence how long a meaningful recovery would take.
A successful backup notification confirms that a process ran; it does not prove that the information is complete, protected from the same attack or usable in the order the business needs it.
Restoration testing is what turns a backup strategy from an assumption into evidence.
At a minimum, businesses should be able to answer three questions:
- Is there a suitable backup copy isolated from the live environment?
- Has restoration actually been tested?
- How quickly can critical systems and services be recovered?
At least one suitable copy should be isolated from the live environment, with access to backup systems and credentials tightly controlled. This reduces the chance of an attacker altering or deleting every recovery copy.
Recovery planning also needs a commercial perspective. Restoring a database achieves little if the related application, credentials or supplier connection remains unavailable. The business should know which services must return first, what they depend on and how much disruption it can tolerate.
That recovery planning should also be considered alongside business interruption insurance and any cover arranged for the reinstatement of computer data.
Restoration testing is what turns a backup strategy from an assumption into evidence.
Cyber Essentials provides a useful baseline
Cyber Essentials brings several of these controls into a recognised framework covering firewalls, secure configuration, security updates, user access and malware protection.
Certification is not a guarantee that an organisation cannot be attacked. Its value lies in creating a consistent baseline and requiring evidence for controls that might otherwise be assumed.
The process can expose gaps around unsupported software, administrator access and unmanaged devices.
Read more about how the Cyber Essentials scheme works.
Where cyber insurance fits
Even well-managed businesses retain cyber risk. Cyber insurance can help manage the financial and operational impact of an incident, but it should sit alongside effective controls rather than replace them.
Businesses may encounter terms such as cyber and data insurance, data breach insurance and cyber risk liability insurance when researching cover. These terms are not always used consistently, so the important point is what the individual policy actually covers.
Related technology risks may also be addressed through separate products, including computer insurance, depending on how the organisation’s protection is arranged.
The relevant question is not simply whether a business has a policy, but whether the cover reflects its systems, data, suppliers and exposure to disruption. Policy wording, limits, conditions and exclusions vary, and should be considered in the context of how the organisation operates.
Sutcliffe & Co can advise businesses on the cyber insurance options available to them and help them consider cover as part of their wider risk management arrangements, subject to insurer terms, conditions and eligibility criteria. Get in touch today.
Last updated: October 2026
