Vendor-neutral guide · 8 min read

Cyber Essentials and remote access: what the five controls ask for

Written by the 247connect Marketing Team

Shape of the topic

A standards clause list linked to a shield of controls and an evidence file with an audit tick.A standards clause list linked to a shield of controls and an evidence file with an audit tick.
A control, the evidence for it, and a reviewer who signs it off: that chain is what an audit actually looks at.

In short

Cyber Essentials is the UK government-backed scheme, run through NCSC-approved certification bodies, that sets out five technical controls every organisation should have in place. None of the five is written specifically about remote access, but almost all of them touch it: remote support sessions cross a firewall boundary, they run on devices that need secure configuration, they depend on access control decisions, and they are one of the routes malware protection has to cover. This guide walks through what each control implies for remote access and remote support tools, and what an assessor or a self-assessment questionnaire will actually ask about.

Key takeaways

  • Cyber Essentials has five controls: firewalls, secure configuration, security update management, user access control and malware protection.
  • Remote access and remote support tools intersect with all five, even though none names remote access directly.
  • Named user accounts with multi-factor authentication support the access control requirement far better than shared logins.
  • Session encryption and vendor patching practice matter under secure configuration and update management.
  • Cyber Essentials Plus adds independent technical verification, including checks on how remote access is actually configured.
  • Organisations should confirm their own scope and obligations with an NCSC-approved certification body rather than relying on general guidance.

What Cyber Essentials actually covers

Cyber Essentials is built around five technical control areas: boundary firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. The scheme has two levels: a self-assessment questionnaire, verified by an external assessor, and Cyber Essentials Plus, which adds hands-on technical testing of the organisation's systems. Both apply to the whole of an organisation's IT that can be reached from the internet, which includes any device or service used for remote access.

Remote access tooling is rarely the headline of a Cyber Essentials assessment, but it sits inside scope wherever it touches an internet-facing device. A remote support agent installed on a laptop, a remote desktop gateway, or a cloud-brokered access service are all part of the estate the five controls are meant to protect.

Firewalls and secure configuration

The firewall control asks whether internet-facing services, including any ports opened for remote access, are restricted to what is actually needed and protected by a properly configured boundary. A remote access product that requires inbound firewall exceptions is a different proposition, from an assessment point of view, to one that only makes outbound connections and brokers the session through a cloud relay, since the latter avoids opening inbound ports altogether.

Secure configuration asks whether default accounts, default passwords and unnecessary functionality have been removed or disabled. For remote access tools this means checking that default admin credentials on any gateway appliance have been changed, that unused remote access protocols are switched off, and that only the features actually in use are enabled.

  • Check whether the remote access tool needs inbound firewall rules or only makes outbound connections
  • Confirm any gateway or on-premise component has default credentials changed
  • Disable legacy remote access protocols that are not actively required

Security update management

This control asks whether software, including operating systems and applications, is kept up to date, with security updates applied within defined timescales and unsupported software removed from use. Remote access clients and agents are a legitimate part of that inventory: an outdated remote support agent with a known vulnerability is exactly the kind of gap Cyber Essentials is designed to close.

Organisations should be able to say how quickly the vendor releases patches for their remote access product, how those updates are delivered, and how quickly they are actually applied across the estate. A vendor with a slow or unclear patching cadence adds risk that the rest of the control set cannot compensate for.

User access control

Cyber Essentials asks that user accounts are only assigned to authorised individuals, that administrative privileges are tightly controlled, and that accounts are removed or disabled when no longer needed. For remote access and remote support tools, this translates directly into a preference for named operator accounts over shared logins, multi-factor authentication on any account that can initiate a session, and a defined process for removing access when a technician or supplier relationship ends.

A tool such as 247connect, which supports named operator accounts and session audit logs, gives an organisation the raw material to answer these questions with evidence rather than assurance. What matters for the assessment is not the brand of tool used but whether the access model and the removal process can actually be demonstrated.

  • Named accounts per operator, not shared logins
  • Multi-factor authentication enforced for anyone who can start a session
  • A documented, timely process for removing leavers' access

Malware protection and Cyber Essentials Plus

Malware protection asks that anti-malware software is installed and kept updated, or that equivalent application allow-listing controls are used. Remote access is relevant here because a compromised support session is one of the routes malware protection is meant to guard against, and file transfer features inside a remote access tool should be covered by the same scanning as any other file movement.

Cyber Essentials Plus goes further, with an independent technical assessment that actually tests configuration rather than taking a questionnaire answer on trust. Organisations preparing for Plus should expect the assessor to look at how remote access is configured in practice, not just how it is described on paper.

Best-practice checklist

  1. 1. List every remote access tool in scope

    Include remote support agents, remote desktop gateways and any cloud-brokered access services that touch internet-facing devices.

  2. 2. Confirm inbound firewall exposure

    Check whether any remote access component requires open inbound ports, and restrict them to what is strictly necessary if so.

  3. 3. Change default credentials on gateway hardware

    Any on-premise appliance or gateway used for remote access should have default admin accounts changed before go-live.

  4. 4. Move to named operator accounts

    Replace shared remote access logins with named accounts, one per technician, so activity can be attributed.

  5. 5. Enforce multi-factor authentication

    Require MFA for any account that can initiate a remote session, particularly unattended or administrative access.

  6. 6. Check the vendor's patch cadence

    Ask how quickly the remote access vendor issues security updates and how those updates reach installed agents.

  7. 7. Document the leaver process

    Write down how quickly remote access accounts are disabled when a staff member or supplier relationship ends, and test it.

  8. 8. Confirm with an approved certification body

    Because scope and interpretation can vary, check specific questions with an NCSC-approved Cyber Essentials certification body rather than general guidance.

Common pitfalls

  • Leaving remote access tooling out of the asset inventory because it feels like a service rather than a device
  • Using shared technician logins, which makes the access control questionnaire answer misleading
  • Assuming Cyber Essentials Plus testing will not look closely at remote access configuration
  • Not knowing the remote access vendor's patch release timescale when asked
  • Leaving old remote access accounts active for departed staff or ex-suppliers

What to measure

Metrics for Cyber Essentials & remote access
Remote access accounts using MFATarget 100% coverage
Time to disable a leaver's accessShould be measured in hours
Default credentials remaining on gatewaysTarget zero
Remote access agent patch lagTrack days between release and deployment

Select any column heading to sort.

Frequently asked questions

Does Cyber Essentials specifically mention remote access?
Not by name, but its five controls, firewalls, secure configuration, patch management, access control and malware protection, all apply to any remote access or remote support tooling that touches an internet-facing device, so it sits inside scope even without a dedicated clause.
Do we need Cyber Essentials Plus if we already use remote support software?
That depends on your sector, your contracts and your own risk appetite rather than on the presence of remote support software alone. Plus adds independent technical testing, which will typically include a look at how remote access is actually configured, so it is worth confirming with a certification body whether your circumstances call for it.
Is a cloud-brokered remote access tool easier to certify than one needing inbound firewall rules?
Often, because it avoids opening inbound ports on the firewall, which simplifies the boundary firewall control. It does not remove the need to address the other four controls, including access control and update management, so it is one factor among several.
What counts as an authorised user for remote access under Cyber Essentials?
Broadly, anyone who has been formally granted an account for a legitimate business reason, using a named account rather than a shared login, with access removed when no longer needed. The scheme's user access control requirement is where this is assessed.
Does using a specific remote access product guarantee Cyber Essentials certification?
No single product guarantees certification, since the scheme assesses the whole environment against its five controls. Features such as named accounts, MFA and session logging make it easier to demonstrate good practice, but the certification decision rests on the full assessment, not on the choice of tool.

Sources

Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.

Putting it into practice

This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.

More best-practice guides