Why Businesses Fail Cyber Essentials (And How to Avoid It)

Many businesses assume Cyber Essentials is simply a questionnaire. In reality, most failures occur because organisations believe they are secure but have overlooked a few key areas.

The good news is that most failures can be fixed quickly if identified before submission.


1. Unsupported Software and Operating Systems

One of the most common reasons for failure is running software that is no longer supported by the vendor.

Examples include:

  • Windows 10 after support ends
  • Windows Server 2012
  • Outdated firewall firmware
  • Legacy networking equipment

Cyber Essentials requires security updates to be available and installed.


2. Missing Multi-Factor Authentication (MFA)

Many organisations have MFA enabled for administrators but forget:

  • Shared mailboxes
  • VPN access
  • Microsoft 365 users
  • Remote desktop access

This is one of the easiest issues to fix and one of the most common reasons businesses fail.


3. Excessive User Permissions

Staff often have local administrator rights because it is convenient.

Cyber Essentials requires privileged accounts to be tightly controlled and only used where genuinely necessary.


4. Devices Missing Security Updates

A single laptop that hasn’t been patched for months can put certification at risk.

Common issues include:

  • Remote workers not connecting to company systems
  • Unmanaged laptops
  • Forgotten test devices
  • Old PCs kept “just in case”

5. Weak Password Policies

Cyber Essentials now places significant emphasis on account security.

Problems include:

  • Shared passwords
  • Predictable passwords
  • No MFA
  • Poor password management practices

6. Unknown Devices on the Network

Many businesses don’t have an accurate asset register.

During assessments we regularly discover:

  • Old PCs
  • Retired servers
  • Legacy Wi-Fi equipment
  • Test machines

that nobody realised were still connected.


7. Incomplete Scope

Businesses sometimes accidentally exclude systems that should be included.

This can lead to failed assessments, delays, or having to restart the process.


How Orb IT Helps

At Orb IT, we don’t simply submit the questionnaire and hope for the best.

We help businesses:

✅ Identify compliance gaps before submission

✅ Review Microsoft 365 security settings

✅ Implement Multi-Factor Authentication

✅ Check devices for missing updates

✅ Remove unnecessary administrator permissions

✅ Review firewall and network security

✅ Prepare for Cyber Essentials and Cyber Essentials Plus

✅ Maintain compliance throughout the year

Our managed Cyber Essentials service includes guidance, remediation assistance, support throughout the assessment process, and ongoing advice to help keep your business secure.


Don’t Wait Until You Fail

Most Cyber Essentials failures are preventable.

A short pre-assessment review can identify the issues that commonly cause businesses to fail, saving time, frustration, and additional certification costs.

Need Help with Cyber Essentials?

Whether you’re applying for the first time, renewing an existing certification, or preparing for Cyber Essentials Plus, Orb IT can help.

Contact us today for a free Cyber Essentials readiness review and find out exactly where your business stands before you submit your assessment.

Call: 01625 704 838
Email: info@orbitserv.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *

Most Recent Posts

  • All Post
  • case studies
  • Cloud
  • Creative
  • Digital
  • Disaster Recovery
  • Marketing
  • Security
  • Support
  • Website Design