Cyber Essentials ReadinessLesson 6 of 9
3. Security updates and malware protection
Security update management
All software in scope, operating systems, applications, and firmware, must be licensed, supported, and kept up to date. Under the current Cyber Essentials requirements, updates that fix vulnerabilities rated critical or high severity must be applied within 14 days of release.
In practice
- Only run software that's still receiving security updates from its vendor. Once a product reaches end of life, it needs to be replaced or upgraded, not just left running.
- Turn on automatic updates wherever the vendor supports it, for operating systems, browsers, and commonly targeted applications.
- Have a process for tracking and applying updates on anything that can't update itself automatically.
- Remove software you're no longer using rather than leaving it installed and unpatched.
Fourteen days sounds generous until you consider how quickly automated scanning tools start probing for newly disclosed vulnerabilities. The requirement exists because that gap is exactly where a lot of real breaches happen.
› Course contents
What Cyber Essentials is
Firewalls and secure configuration
Security updates and malware protection
User access control and certification