Kuulo
← Trust Centre
Cyber Essentials mark

Information security

Cyber Essentials technical security baseline

Baseline controls are the starting point for a system that has to be trusted by customers, procurement teams or public-sector partners. They make avoidable exposure visible before it becomes an incident or a blocked review.

Evidence included in health deliveryNCSC overview

The framework

What Cyber Essentials is for.

Cyber Essentials is a government-backed baseline for protecting organisations against common internet-borne threats. It focuses on practical controls such as secure configuration, access control, malware protection, software updates and firewalls.

How we work with it

Make the obligation usable.

  • Review the system boundary, devices, accounts and software that need protection.
  • Apply the baseline controls to the service and the way it is operated.
  • Keep the configuration, review and remediation evidence ready for assurance conversations.

What we can leave behind

Evidence a reviewer can follow.

  • Technical-control checklist
  • Security review responses
  • Remediation and handover record
Request documentation →

Concrete delivery evidence

How this showed up in client work.

For the regulated health platform, Cyber Essentials work was delivered alongside the patient and clinician service. The related case study explains how baseline security evidence sat with the data-protection and clinical-safety work, rather than being postponed until after the build.

Keep the map connected

Need this mapped to your system?

Start with the evidence your review needs.

Talk to us →