Fast Cyber Essentials › Remote and hybrid teams
The scheme was updated some years ago to deal properly with home and hybrid working, and the current position is clearer than most people expect. The difficulty is not that the rules are complicated, it is that the intuitions are wrong.
The home router is out of scope. The device is not.
This surprises people, and it is the single most useful thing to know. A router supplied by an internet service provider to a home worker is out of scope. You are not required to configure, audit or replace it.
What is in scope is the software firewall on the device itself, and it has to be enabled and configured. In practice this means every home-working laptop needs its host firewall on, which is the default on current Windows and macOS but is routinely disabled by somebody troubleshooting a printer three years ago.
The exception: a router or firewall that you supplied to the home worker is in scope and must meet the firewall requirements, including a changed default password.
Personal devices are in scope if they touch work data
If a member of staff reads work email on their own phone, that phone is in scope for Cyber Essentials. This is the requirement that causes the most difficulty, because you now have to assert things about a device you do not own.
The device has to be running a supported operating system, receiving security updates, have a screen lock, and have malware protection appropriate to the platform. On a modern iPhone or Android phone that is mostly true by default, which is why this is less painful than it sounds. On a five-year-old phone that stopped receiving OS updates two years ago, it is not.
Two workable approaches. Restrict work data to managed devices only, so personal phones fall out of scope entirely, which is cleaner but unpopular. Or permit personal devices and enforce the baseline through conditional access, which permits access only from devices meeting your policy.
What does not work is asserting that personal devices comply because you asked people nicely.
Multi-factor authentication, everywhere, for everyone
Required on all cloud services, for all users, not only administrators. Remote working makes this both more important and more visible, because remote access to everything now runs through cloud identity.
The failure is almost never the main tenant. It is the forgotten service: an old file-sharing account, a marketing tool, a legacy mailbox, a supplier portal somebody set up for one project. Inventory every cloud service in use before you answer the question, not after.
Worth noting that a shared account used by several people cannot meaningfully have multi-factor authentication tied to an individual, which is one of several reasons shared accounts cause problems in assessment.
Separate administrative accounts
Users must not do day-to-day work in an account holding administrative privileges. On a remote estate this is harder to enforce and easier to let slide, because the person who set up a home worker's laptop over a screen share made them a local administrator to save a callback.
Audit it rather than assume it. The gap between policy and reality on local administrator rights is usually larger than anyone expects, and it is one of the four most common causes of a failed submission.
Practical positions that work
| Setup | What Cyber Essentials needs from you |
|---|---|
| Company laptops, centrally managed, cloud identity | The easiest position. Host firewall on, patching enforced, standard user accounts, MFA across every service. Mostly configuration you already have. |
| Company laptops, unmanaged | Same requirements, but you have to evidence them per device rather than by policy. Achievable at ten devices, painful at eighty. This is the case for management tooling. |
| Bring your own device | Every personal device is in scope. Either restrict work data to managed devices, or enforce a baseline through conditional access. Asserting compliance you cannot evidence is how submissions fail. |
The question to answer honestly before applying
Can you say, with evidence, what every device that touches your data is running and how it is configured? If yes, remote working adds very little difficulty. If no, that is the work, and it is worth doing before you submit rather than discovering it in feedback.
Evidencing a remote estate
The requirements for home working are not harder than for an office. Evidencing them is, because you cannot walk to a desk and look.
The practical question an assessor is asking, behind every control, is the same: how do you know? For an unmanaged remote estate the honest answer is often that you do not, and that is the gap to close before submitting rather than during.
| Control | Weak evidence | What actually demonstrates it |
|---|---|---|
| Host firewall enabled | A policy saying it must be | A report from management tooling listing every device and its firewall state |
| Patching within 14 days | Automatic updates are on | A patch compliance report covering every device, with the ones that have not checked in flagged |
| No everyday admin rights | Staff are told not to | Actual local administrator group membership pulled across the estate |
| Malware protection active | The product is deployed | Console output showing enabled, updating, per device |
| Personal devices compliant | Staff have confirmed | Conditional access permitting only devices meeting policy, so non-compliant ones cannot connect |
That last row is the important one, and it is why conditional access solves the bring-your-own-device problem rather than merely documenting it. If a non-compliant device cannot reach the data, you no longer need to assert anything about devices you do not control: the control enforces itself and the evidence is the policy plus the sign-in logs.
The policy that makes this manageable
A short, actually-enforced acceptable use position covering four things does most of the work: which devices may access organisational data, that a device must be running a supported and updated operating system, that work accounts are not shared with family members, and that a lost or stolen device is reported immediately.
One page, signed, and referenced in induction. Longer documents get less compliance rather than more, and an assessor is more interested in whether it is followed than in how comprehensive it is.
Do we have to audit our staff\u2019s home broadband routers?
No. A router supplied by an internet provider to a home worker is out of scope. The software firewall on the device itself is in scope and must be enabled. A router you supplied is in scope and needs its default password changed.
Can staff use their own phones for work email?
Yes, but the phone is then in scope: supported operating system, security updates, screen lock and appropriate malware protection. Most current phones meet this by default. Older ones that no longer receive OS updates do not.
What about staff working from abroad?
Location does not change scope. The device is in scope wherever it is. What can change is whether your conditional access policies permit access from that country, which is a separate decision from certification.
Is a VPN required for home working?
No. Cyber Essentials does not require a VPN. It requires the controls to be met on the device and on the services. A VPN can be part of how you achieve that, but it is not itself a requirement, and having one does not excuse an unpatched laptop.
Mostly remote and not sure where you stand?
The gap analysis goes through your actual setup against the five controls and tells you what needs fixing before you answer anything.