Buy the GCP R3 course & get a FREE eBook— your complete ICH-GCP R3 reference guide. Book Now →

  • Preclinical & Laboratory Foundations Learning Path
  • Phase I – First-in-Human Trials Learning Path
  • Phase II & III – Efficacy & Pivotal Trials Learning Path
  • Clinical Trials Foundation PathNew
  • Regulatory Submission & Approval

About

Cyber Essentials v3.3 provides a practical baseline for protecting organisations against common internet-based cyber threats. For life sciences organisations and small and medium-sized enterprises (SMEs), implementing the scheme's five technical controls can strengthen cybersecurity while supporting the protection of sensitive business, research, personal, and regulated information.
This Cyber Essentials v3.3 (Life Sciences and SMEs) Training Course & Certification provides comprehensive knowledge of the Cyber Essentials v3.3 requirements, certification scope, firewalls and internet gateways, secure configuration, security update management, user access control, passwords and multi-factor authentication, malware protection, assessment preparation, evidence requirements, remediation, and ongoing compliance. The course also addresses practical considerations for life sciences organisations and SMEs operating regulated environments and handling sensitive information. Upon successful completion, learners receive a certification demonstrating their understanding of Cyber Essentials v3.3 requirements and practical cybersecurity readiness principles.

Who Should Enrol?

  • IT and Cybersecurity Professionals in SMEs
  • Life Sciences IT, Digital, and Information Security Teams
  • Quality Assurance and Compliance Professionals
  • System Administrators and IT Support Personnel
  • Data Protection, Risk, and Governance Professionals
  • Business Owners, Directors, and Senior Managers
  • Cyber Essentials Certification and Assessment Teams
  • Anyone responsible for preparing an organisation for Cyber Essentials v3.3 certification
📢 Every purchase also includes our FREE companion Cyber Essentials v3.3 (Life Sciences and SMEs) Training eBook, designed to help you apply principles in real-world inspection readiness settings.

What you will learn

Understand the Cyber Essentials v3.3 scheme, its five technical controls, certification requirements, and how the framework applies to life sciences organisations and small and medium-sized enterprises.

Learn how to define certification scope, secure firewalls and internet gateways, maintain secure configurations, and manage software and security updates across organisational systems.

Develop knowledge of user access control, strong authentication, passwords, multi-factor authentication, malware protection, and practical measures for reducing common cyber risks.

Gain practical understanding of assessment preparation, evidence requirements, common certification issues, scope management, remediation planning, and maintaining Cyber Essentials compliance.

Course Syllabus

  1. What Cyber Essentials is
  2. The history and evolution of Cyber Essentials
  3. Purpose 1 — baseline protection against commodity threats
  4. Purpose 2 — the common threats CE addresses
  5. Purpose 3 — assurance, confidence and supply-chain expectation
  6. The five technical controls — overview
  7. Controls 1 and 2 — firewalls and secure configuration
  8. Controls 3 and 4 — updates and user access
  9. Control 5 and how the five work together
  10. Cyber Essentials versus Cyber Essentials Plus — what each is
  11. CE versus CE Plus — the verification method
  12. Choosing between CE and CE Plus
  13. The roles in the scheme — overview
  14. NCSC — the scheme owner
  15. IASME — the official Delivery Partner
  16. Certification Bodies and Assessors
  17. Cyber Advisors, the applicant and the main contact
  18. The board signatory and Whitehall’s role
  19. The learning-versus-certification boundary
  20. What the Whitehall certificate is — and is not
  21. The assessment lifecycle — overview
  22. Lifecycle steps 1–4 — prepare, route, purchase, account
  23. Lifecycle steps 5–8 — version, scope, completion, verification
  24. Lifecycle steps 9–12 — declaration, submission, marking, clarification
  25. Lifecycle steps 13–16 — remediate, certify, issue, maintain
  26. Who signs the verified self-assessment
  27. What verified self-assessment means
  28. Certification is point-in-time
  29. The ongoing-compliance declaration
  30. Annual renewal
  31. The scheme version you must use — v3.3
  32. The Danzell question set replaces Willow
  33. Reading the v3.3 changes — change-type labels
  34. v3.3 change — 12-character minimum passwords
  35. v3.3 change — mandatory cloud MFA and auto-fail
  36. v3.3 change — phishing-resistant admin MFA
  37. v3.3 change — passwordless authentication and passkeys
  38. v3.3 change — firmware patching is explicit
  39. v3.3 change — tighter scope and cloud wording
  40. v3.3 change — application development and other updates
  41. What certification does not prove — overview
  42. Cyber Essentials does not replace GxP
  43. Cyber Essentials does not prove GDPR compliance

  1. What 'certification scope' means
  2. Why scope matters: the certificate reflects only what is declared
  3. Whole-organisation versus partial scope
  4. The whole-infrastructure default and why it is preferred
  5. Documenting and justifying exclusions
  6. The golden rule: do not manipulate scope to pass
  7. Three ways to draw a boundary
  8. The business-unit boundary
  9. The physical-location boundary
  10. The network boundary and segregation
  11. Scope agreement and certificate wording
  12. In-scope internet connections and data flows
  13. In-scope internet-connected devices
  14. End-user devices: the nine types
  15. End-user devices cannot be excluded
  16. Servers and network devices
  17. In-scope software
  18. Bespoke and custom applications
  19. In-scope cloud services
  20. SaaS, PaaS and IaaS defined
  21. The shared-responsibility model
  22. Applicable cloud services cannot be excluded
  23. Life-science cloud examples
  24. Provider assurance does not remove your responsibility
  25. Home and remote-working devices
  26. Home-working devices cannot be excluded
  27. Bring-your-own-device (BYOD)
  28. BYOD: native voice/text and MFA-only exceptions
  29. A BYOD scoping decision tree
  30. Third-party and contractor access
  31. The MSP relationship and accountability
  32. Partial scope: the requirements
  33. Segregation: firewall and identity boundary
  34. Exclusion description and transparent wording
  35. Commercial limitations of partial certification
  36. Why an accurate asset inventory matters
  37. The eleven inventories to maintain
  38. The role of ongoing asset management
  39. Building a scope diagram
  40. Common scoping failures to avoid
  41. Scope and the five controls
  42. Separately-managed subsets
  43. Outbound connections and data-flow control
  44. Wireless networks and access points
  45. Laboratory instruments and connected devices
  46. Cloud email and file storage
  47. Evaluating cloud-provider evidence
  48. Secure remote access and VPNs
  49. Managing BYOD in practice
  50. Contractor devices: in or out of scope?
  51. Getting device and user counts right
  52. Users and administrators in the inventory
  53. Managing scope change and avoiding drift
  54. Legal-entity and certificate options
  55. Validated and GxP systems remain in scope

  1. Why firewalls are the first Cyber Essentials control
  2. What a firewall and internet gateway actually does
  3. The boundary as attack surface
  4. Three kinds of firewall you must consider
  5. Boundary firewall versus host-based firewall
  6. Where firewalls sit for a modern SME
  7. Which devices need firewall protection
  8. Why home and mobile devices change the picture
  9. Change default administrative credentials
  10. Unique credentials, ownership and documentation
  11. Disable remote administration from the internet
  12. If remote administration is genuinely needed
  13. Default-deny inbound: the baseline principle
  14. Controlling inbound services
  15. Documenting business-justified rules
  16. Rule attributes: least exposure by design
  17. Temporary rules and rule expiry
  18. Logging and monitoring firewall activity
  19. Reviewing firewall rules regularly
  20. Identifying and removing stale rules
  21. Internet-accessible services: the risk overview
  22. Remote desktop exposure and safer alternatives
  23. Vendor support and laboratory remote maintenance
  24. Risk-based restriction and secure authentication
  25. Software firewalls on end-user devices
  26. Protecting devices on public and home networks
  27. VPNs and their relationship to firewalls
  28. Users should not be able to disable protection
  29. Home-working configuration expectations
  30. Cloud and virtual firewalls
  31. The shared-responsibility model applied to firewalls
  32. Who configures what: a practical split
  33. Remote administration of cloud consoles
  34. Evaluate provider assurance — do not assume it
  35. Firewall evidence: what an assessor expects
  36. Evidence quality: current, complete, traceable, scope-linked
  37. The firewall inventory and rule-review record
  38. Firewalls and secure configuration: how they connect
  39. How firewall controls appear in the self-assessment
  40. Common firewall assessment failures to avoid
  41. A defensible firewall posture: bringing it together

  1. Why secure configuration matters
  2. What secure configuration means in v3.3
  3. The problem with out-of-the-box defaults
  4. Attack surface: the idea to shrink
  5. What a secure-configuration baseline is
  6. Building a baseline: what to include
  7. Consistency across the estate
  8. Secure configuration within the five controls
  9. Who configures what: roles
  10. Removing unnecessary user accounts
  11. Types of default and unnecessary accounts
  12. Remove or disable? Making the choice
  13. Changing default passwords
  14. Default passwords on devices and services
  15. Removing unnecessary software
  16. Disabling unnecessary services and ports
  17. Pre-installed apps, extensions and remote tools
  18. Changing insecure default settings
  19. Standard versus administrator accounts
  20. Renaming and protecting built-in admin accounts
  21. Building a software and services inventory
  22. Ports and protocols: a quick reference
  23. Auto-run and auto-play risks
  24. Disabling auto-run and controlling media
  25. Device locking: purpose
  26. Locking parameters and auto-lock
  27. Locking mobile devices
  28. Browser and application settings
  29. Removable media and USB policy
  30. Locking shared and kiosk devices
  31. Cloud configuration and shared responsibility
  32. Cloud tenant settings to secure
  33. External sharing, guest and anonymous access
  34. Cloud admin, logging and supplier responsibility
  35. Cloud example: Microsoft 365 security defaults
  36. Cloud example: file-storage sharing
  37. Hardening workstations and laptops
  38. Hardening servers
  39. Hardening mobile devices
  40. Life-science configuration examples
  41. Validated systems: controlled change, not neglect
  42. eQMS and LIMS access configuration
  43. Warehouse terminals and kiosk devices
  44. Maintaining configuration over time
  45. BYOD configuration boundaries
  46. Documentation as evidence
  47. Secure-configuration evidence exemplars
  48. Common secure-configuration failures

  1. Why security update management is a Cyber Essentials control
  2. What unmanaged vulnerabilities cost
  3. Where update management sits among the five controls
  4. How the assessment tests this control
  5. What the control covers — the full technology picture
  6. Operating systems and applications
  7. Browsers, extensions and plugins
  8. Third-party libraries and software dependencies
  9. Firmware, routers and firewalls — explicit in v3.3
  10. Patching firmware in practice
  11. Mobile devices, appliances and other endpoints
  12. Supported versus unsupported software
  13. End of life and end of support explained
  14. Licensing and vendor support status
  15. Extended support and long-term support (LTS)
  16. Custom and bespoke applications
  17. Deciding whether a product is supported
  18. Update timescales — the 14-day rule
  19. What 'critical' and 'high-risk' mean
  20. Not every routine update must be within 14 days
  21. Worked timeline — a critical update within 14 days
  22. Enabling automatic updates where appropriate
  23. When automatic updates are not appropriate
  24. Identifying the security updates you need
  25. Judging severity — vendor ratings and CVSS
  26. Known exploitation and release-note review
  27. Prioritising updates by severity and exposure
  28. A repeatable update-management process
  29. Monitoring for new updates
  30. Testing and change control for updates
  31. Deploying and verifying installation
  32. Handling failed, missed or rolled-back updates
  33. Coordinating updates with your MSP
  34. Mapping updates to the asset inventory
  35. Updates in the cloud — shared responsibility
  36. SaaS, PaaS and IaaS — who patches what
  37. Version selection and provider evidence
  38. Managing unsupported technology — the options
  39. Remove, replace, decommission or isolate
  40. No automatic compensating-control substitution
  41. Genuine isolation versus the 'risk-accepted' myth
  42. Validated systems still need security updates
  43. Patch assessment under change control
  44. The CE and GxP boundary for updates
  45. The update-management register
  46. The end-of-support register
  47. The 14-day compliance tracker in practice
  48. Evidence that satisfies an assessor
  49. Evidence versus assertion for updates
  50. Common security-update assessment failures
  51. Prioritising updates in a resource-limited SME
  52. Building the registers into business as usual

  1. Why user access control is a Cyber Essentials control
  2. What the access-control requirement expects
  3. Key terms: identity, authentication, authorisation, privilege
  4. The user-account lifecycle
  5. Account request and approval
  6. Provision with least privilege from day one
  7. Unique user identities and individual accountability
  8. The problem with shared and generic accounts
  9. Shared accounts on lab systems and shared terminals
  10. What administrative privilege means — and why it is risky
  11. Restrict administrative privileges (least privilege)
  12. Separate administrative and standard-user activities
  13. No web browsing or email on administrative accounts
  14. Just-in-time and time-limited administration
  15. Local, domain, cloud and SaaS administrators
  16. Managed service provider and vendor administrative access
  17. Reviewing privileged access
  18. Authentication factors: know, have, are
  19. The range of authentication methods
  20. Strength of authentication methods
  21. Password controls in v3.3 — the 12-character minimum
  22. The Cyber Essentials password options
  23. Brute-force protection
  24. Blocking common and breached passwords
  25. Password managers and avoiding needless complexity
  26. What multi-factor authentication is
  27. MFA is mandatory for cloud services where available
  28. Free, included or chargeable — no excuse to leave MFA off
  29. MFA must cover users and administrators
  30. Phishing-resistant MFA for administrators
  31. Genuine constraints and assessor guidance on MFA
  32. Passwordless authentication
  33. Passkeys and FIDO2 explained
  34. Benefits of passkeys and passwordless
  35. Adopting passwordless in an SME
  36. Joiners, movers and leavers (JML)
  37. Joiners and movers in detail
  38. Leavers — timely account removal
  39. Dormant and inactive accounts
  40. Temporary, agency and clinical-contractor accounts
  41. Third-party and vendor access principles
  42. Remote maintenance and equipment-engineer access
  43. Evidence for the access-control requirement
  44. The registers: user, privileged and MFA coverage
  45. Common access-control assessment failures
  46. Access control in life-science environments
  47. Authentication versus authorisation in practice
  48. Removing standing local administrator rights
  49. Cloud identity and single sign-on
  50. Conditional and risk-based access
  51. Session controls and re-authentication
  52. Emergency and break-glass administrator accounts
  53. Never share or store credentials insecurely
  54. Authenticator apps versus text-message codes
  55. Monitoring sign-ins and account activity
  56. Documenting account approvals and the request workflow
  57. Bringing it together — access-control readiness

  1. Why malware protection is a Cyber Essentials control
  2. The kinds of malware you are defending against
  3. How malware reaches a device
  4. The requirement in plain terms
  5. The three accepted approaches
  6. At least one approach — active — on every device
  7. Anti-malware software — what Cyber Essentials expects
  8. Using and keeping anti-malware updated
  9. Real-time scanning, web protection and alerts
  10. Built-in protection: Windows and macOS options
  11. Application allow-listing — what it is
  12. Implementing application allow-listing
  13. When application allow-listing fits best
  14. Application sandboxing — the concept
  15. Where sandboxing applies
  16. Matching the approach to the device type
  17. Windows devices — meeting the requirement
  18. macOS devices — meeting the requirement
  19. Managing mobile-device application installation
  20. Approved stores and mobile device management (MDM)
  21. Rooted, jailbroken and unsupported mobile devices
  22. Servers — meeting the requirement
  23. Specialised and hard-to-protect devices
  24. Cloud and SaaS considerations
  25. Life-science examples across the fleet
  26. Cyber Essentials does not replace GxP or validation
  27. Evidencing malware protection
  28. The malware-protection coverage report (Toolkit 26)
  29. Common malware-protection assessment failures
  30. Bringing it together — HelixBridge malware remediation
  31. Central management of malware protection
  32. Removable media, macros and auto-run
  33. Ransomware, detection response and recovery
  34. Application allow-listing — evidence and pitfalls
  35. Sandboxing — strengths and limits
  36. Evaluating a SaaS provider's malware assurances
  37. Windows and macOS servers versus endpoints

  1. What assessment readiness means
  2. The readiness review: an ordered walk-through
  3. Who does what in the readiness phase
  4. Readiness areas: scope, assets and cloud
  5. Readiness areas: firewalls, configuration, software and updates
  6. Readiness areas: accounts, privileges, MFA and malware
  7. Readiness areas: outsourced services, evidence and remediation
  8. The self-assessment questionnaire
  9. Response principle: answer the exact question asked
  10. Response principle: current information and defined scope
  11. Response principle: no generic policy copy, no unsupported 'yes'
  12. Response principle: consistency of numbers and terminology
  13. Response principle: verify technically before answering
  14. Response principle: record the evidence source as you answer
  15. Evidence versus unsupported assertion
  16. Nine characteristics of good evidence — part 1
  17. Nine characteristics of good evidence — part 2
  18. Evidence types and worked examples
  19. Policy without implementation — the classic failure
  20. The evidence register: purpose
  21. What to record in the evidence register
  22. Why applications fail — overview
  23. Common failures 1 — scope, cloud and device counts
  24. Common failures 2 — unsupported software, MFA, admin and defaults
  25. Common failures 3 — firewalls, updates and malware
  26. Common failures 4 — MSP, evidence and contradictions
  27. Correcting gaps before submission
  28. The internal pre-submission review
  29. Working with an MSP — accountability stays with you
  30. The MSP responsibilities matrix
  31. What to obtain from your MSP — part 1
  32. What to obtain from your MSP — part 2
  33. Evaluating cloud-provider control evidence
  34. Shared responsibility and provider assurance
  35. The verified self-assessment declaration
  36. The signatory's responsibility
  37. Briefing the board signatory
  38. The assessor review and clarification stage
  39. Responding to assessor queries well
  40. Tracking assessor queries and responses
  41. Certification and certificate scope
  42. The point-in-time nature of assessment
  43. The ongoing-compliance declaration
  44. Maintaining the five controls through the period
  45. The ongoing-compliance calendar
  46. Change triggers that affect compliance
  47. Preparing for annual renewal
  48. The annual-renewal checklist
  49. High-level Cyber Essentials Plus readiness — what it adds
  50. Cyber Essentials Plus testing components
  51. Getting ready for Cyber Essentials Plus
  52. Applying the controls in life-science environments
  53. Cyber Essentials does not replace GxP or regulatory controls
  54. Cyber Essentials does not prove GDPR or other standards
  55. Integrating Cyber Essentials into life-science governance
  56. Building an organisational remediation plan
  57. Prioritising and tracking remediation

  1. 📘 Bonus: Cyber Essentials v3.3 (Life Sciences and SMEs) Training eBook (Free with purchase)

Our Certified Customers

novartis
NHS
takeda
roche
baxter

Learner Rating & Reviews

4.7
Average Rating
536 global ratings
87.0%
5.0%
3.0%
3.0%
2.0%
RC

Working with Whitehall training for the last two years of partnership has been a very successful experience – I have fast access to all the GCP course...

SM

I have finalised the demo for the ICH-GCP E6 R3 refresher course. Overall, I liked the content and the interface. I also want to thank Whitehall Train...