Most SMEs that fail Cyber Essentials fail for the same handful of reasons. None of them are exotic — they're the boring fundamentals that quietly drift over time.
1. MFA missing on cloud admin accounts
The single biggest fail. Microsoft 365 and Google Workspace global admin accounts must have MFA enforced — including legacy accounts, ex-staff and break-glass accounts. Fix: enable a Conditional Access policy that requires MFA for all admins, with one documented break-glass exception.
2. Patching slipping past 14 days
Operating systems, browsers and applications must receive high/critical security updates within 14 days. Manual patching almost never hits this. Fix: automate via Intune, RMM or equivalent, and report on compliance monthly.
3. Standing admin rights on user laptops
Day-to-day accounts shouldn't be local admins. Fix: separate admin accounts, used only when needed. Tools like LAPS (or its Intune equivalent) handle the rest.
4. Unsupported software still in use
Windows versions out of support, ancient line-of-business apps, abandoned plugins. Fix: build an inventory, set end-of-life dates, and budget replacements before they bite.
5. BYOD with no controls
Personal phones and laptops accessing corporate email without management. Fix: enforce app protection policies or require enrolment for any device touching company data.
6. Firewall and router defaults
Default admin passwords, unnecessary services exposed, remote admin enabled on the WAN. Fix: a 30-minute hardening review of every boundary device.
7. No clear scope
Half-defined scope leads to half-passed assessments. Fix: write a one-page scope document covering locations, device types, cloud services and exclusions — then test it against reality.
The shortcut: pre-assessment
A two-hour pre-assessment will find every one of these before you spend the certification fee. That's exactly what our free 30-minute review covers — book it below.

