Resource Library
Solution BriefsComplianceVisibilitySegmentationFebruary 15, 2024

Cyber Essentials Solution Brief

SOLUTION BRIEF

Overview

Cyber Essentials was created by the National Cyber Security Centre (NCSC) in 2014 to help commercial organisations establish a minimum standard for their cybersecurity operations. According to the NCSC, Cyber Essentials help "protect your organisation, whatever its size, against a whole range of the most common cyber attacks."

Cyber Essentials Pillars

  • Firewalls and Gateways
  • Secure Network Configuration
  • Access Control
  • Malware Protection
  • Patch Management

The NCSC says that Cyber Essentials benefits those organisations that choose to follow its guidelines through the increased customer retention and new business development that comes from earning a reputation as a trusted steward of data. And while participation is voluntary, many organisations that collect and maintain certain types of sensitive consumer data, like personally identifiable information (PII), protected health information (PHI), and financial data must comply with Cyber Essentials before doing business with government agencies.

About ORDR

ORDR makes it easy to secure every connected device including traditional IT, IoT, IoMT, and OT devices. ORDR uses advanced machine learning to automatically discover and classify every device, identify risk, map all communications, baseline behavior, and provide protection with automated policies.

SEE

KNOW

SECURE

Every asset and connection

Device risks and behaviors

Every thing

  • Discover and profile every device
  • Map every network connection
  • Understand device utilization
  • Identify devices with vulnerabilities
  • Understand risks and potential exploits
  • Identify anomalous behavior
  • Proactive Zero Trust policies for segmentation and NAC
  • Reactive policies for incident response
  • Retrospective analysis for new IoCs

How ORDR Helps with Cyber Essentials

ORDR's step-by-step guide, How to Meet Cyber Essential Requirements for IT Infrastructure, walks IT and security leaders through the NCSC's requirements and how to ensure compliance in accordance with the five pillars of Cyber Essentials.

Guidance covered includes details on:

  • Home working and BYOD
  • Wireless devices
  • Cloud services
  • Firewalls
  • Secure configuration
  • Access control
  • Password-based authentication
  • Malware protection

Key ORDR Capabilities

Asset Visibility – Automatically discover, accurately classify, and collect high fidelity details of every device on the network including newly connected devices.

Asset Inventory – Integrate with CMMS and CMDB products to ensure device inventories are always up to date with accurate details.

Vulnerabilities and Risk – Identify devices with vulnerabilities and risk such as outdated operating systems, unpatched or unauthorized software, PHI, recalls, risky communications, and anomalous behaviour.

Device Risk Rating – Automatically calculate real-time risk ratings per device by combining vulnerabilities, risk, and customizable parameters to help prioritize remediation and mitigation efforts.

Vulnerability Management – Robust vulnerability management and mitigation capabilities including integration with existing IT tools, workflows, and network and security infrastructure to help teams efficiently manage risk.

Behavioural Profiling – Establish a baseline of normal communications for every device to identify active threats including zero-day attacks.

Threat Response – Improve threat response and with dynamically created policy enforced with existing security and network infrastructure.

Accelerate Zero Trust – Automate the creation of Zero Trust policy such as NAC or segmentation to reduce the attack surface and improve security.

Ecosystem Integrations – 80+ integrations with security, network, and IT products to enrich device insights, enable existing workflows, improve security efforts, and accelerate Zero Trust initiatives.

Compliance – Generate custom reports for evidence and a solution that is SOC 2 Type 2 certified, encrypts data at rest and in motion, does not collect PHI or PII data, and meets GDPR data privacy requirements by ensuring that all data collected remains in the United Kingdom.

Frequently asked questions
How can healthcare organizations meet NCSC Cyber Essentials requirements for connected medical devices?
ORDR's automated device discovery and behavioral profiling automatically identifies and classifies all connected medical devices across your healthcare environment, then maps device behavior directly to Cyber Essentials controls. This eliminates manual asset inventory work while providing the visibility and documentation needed to demonstrate ongoing compliance.
What is the fastest way to implement Zero Trust policies on medical devices and clinical networks?
ORDR enables Zero Trust policy enforcement on IoT and OT assets by first establishing complete device visibility and behavioral baselines, then automatically segmenting the network based on actual device communications and risk profiles. This approach reduces your healthcare breach attack surface without disrupting clinical operations.
How does automated device discovery reduce compliance audit burden for healthcare?
Rather than manually maintaining asset inventories that quickly become outdated, ORDR continuously discovers and profiles devices in real-time, automatically mapping their behavior to compliance requirements. This ensures audit teams have current, accurate device intelligence that directly addresses Cyber Essentials control evidence requirements.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →