Cyber Essentials: Secure Configuration
The Cyber Essentials Secure Configuration control requires that devices and software are set up as securely as reasonably possible. This means removing unnecessary software, changing insecure default settings, and ensuring only the services you actually need are running. These guides cover every Secure Configuration task for home users.
Last reviewed: July 2026
Cyber Nova AI helps you prepare for Cyber Essentials. It doesn't award or certify it. Follow the steps here to get ready, then apply for certification through an accredited Cyber Essentials body when you're set.
What this control covers
- ✓Enable full-disk encryption on laptops (BitLocker on Windows, FileVault on Mac)
- ✓Remove unused apps and software that don't receive security updates
- ✓Review and restrict app permissions on phones and tablets
- ✓Disable Remote Desktop Protocol (RDP) if not needed: a common ransomware entry point
- ✓Set a strong screen lock, and have your phone and laptop lock automatically when idle
Secure Configuration Guides (20)
- Set a strong screen lock on your phoneSet a PIN, password, or biometric lock on your phone so that no one can access it if it is lost or stolen. A screen lock is the single most important protection on a mobile device.
- Remove unused apps and softwareUninstall applications you no longer use from your devices. Every extra app is a potential vulnerability.
- Review app permissions on your phoneCheck which apps have access to your camera, microphone, location, and contacts. Remove permissions that aren't needed.
- Back up your most important filesSet up automatic backup to the cloud for your photos, documents, and important files. If your device is lost, stolen, or infected with ransomware, a backup means you don't lose everything.
- Enable full-disk encryption on your laptopTurn on BitLocker (Windows) or FileVault (Mac) to encrypt everything on your laptop's hard drive.
- Disable remote desktop access if not neededIf you do not use Remote Desktop Protocol (RDP) or similar remote access tools, disable them on your computers.
- Apply the 3-2-1 backup ruleKeep 3 copies of important data, stored on 2 different types of media, with 1 copy held offsite or in the cloud. This approach protects against ransomware, hardware failure, fire, and theft simultaneously.
- Turn off software and features your business does not useRemove or switch off software, apps, and services on your business devices that nobody uses. Every extra program is one more thing that can be attacked.
- Use a VPN when connecting to public Wi-FiA VPN is a free or cheap app that scrambles your connection when you use public Wi-Fi in coffee shops, hotels, and airports. Without one, anyone else on the same network could potentially read your emails or login details.
- Set your phone up to erase itself if it's ever lost or stolenSet your phone up so that if it is ever lost or stolen, you can erase everything on it from any other device. This takes a few minutes and could prevent serious data exposure.
- Test that your backup actually worksRestore a single file from your backup to confirm it is working correctly. Many people discover their backup has been failing silently only when they need it most.
- Review your social media privacy settingsCheck who can see your posts, your location, and your personal information on each social media account. Fully public profiles give scammers and identity thieves easy access to information they can use against you.
- Review what data Google holds about youVisit your Google account's privacy settings, review what activity and personal data is stored, and turn off any collection you are not comfortable with. Includes location history, search history, and ad personalisation.
- Remove personal contact details from your social media profilesReview every social media profile and remove any personal information you do not need to share publicly: phone number, home address, birthday, and workplace. This information is routinely harvested for use in targeted scams and identity theft.
- Set your phone to lock automatically after 30 secondsConfigure your phone to lock itself automatically after 30 seconds of inactivity. If you put your phone down and walk away, it will lock before anyone else can pick it up and access it.
- Turn on Find My MacSwitch on Find My so you can locate, lock, or erase your Mac from another device if it is ever lost or stolen.
- Review your Mac's privacy permissionsCheck which apps can reach your camera, microphone, files, and screen, and turn off any access an app doesn't need.
- Turn on Find My iPhoneSwitch on Find My so you can locate, lock, or erase your iPhone from another device if it goes missing.
- Review and turn off services you don't useCheck which background services and remote-access tools are running, and switch off any you don't need, such as SSH on a home desktop.
- Set up every new business device the same secure wayCreate one standard, secure setup and apply it to every business computer and phone before it is used, so nothing goes out with weak default settings.
Test yourself
A few quick questions to check what you have learned. Pick an answer to see whether it is right and why. Nothing is saved or scored.
Track your Secure Configuration progress. Free.
Create a free account to tick off tasks as you complete them and see your overall Cyber Essentials readiness score.
Start your free security checkCommon questions
What is secure configuration?
Secure configuration means setting up devices and software as securely as possible, rather than leaving them on default settings. Default settings are designed for ease of setup, not security. They often have services enabled that you do not need, and passwords that are publicly known. Changing them reduces the attack surface available to an attacker.
What default settings should I change?
The most important defaults to change are: your router's admin password (change from the printed default), your Wi-Fi password (if it was pre-set), and any admin or management passwords on software or services. You should also disable services you do not use, for example Remote Desktop on Windows if no one needs remote access.
What does Cyber Essentials require for secure configuration?
Cyber Essentials requires that all in-scope devices are configured securely. This means default passwords changed, unnecessary software and services removed or disabled, and devices set up with the minimum access required. Admin accounts should not be used for everyday tasks.
Do I need to encrypt my laptop?
Full-disk encryption is required under Cyber Essentials for laptops and other portable devices. On Windows, this is BitLocker; on Mac, it's FileVault. Both are built in and free. Encryption means that if your laptop is lost or stolen, the data on it cannot be read without your password.