I have finalised the demo for the ICH-GCP E6 R3 refresher course. Overall, I liked the content and the interface. I also want to thank Whitehall Train...
About
Cyber Essentials v3.3 provides a practical baseline for protecting organisations against common internet-based cyber threats. For life sciences organisations and small and medium-sized enterprises (SMEs), implementing the scheme's five technical controls can strengthen cybersecurity while supporting the protection of sensitive business, research, personal, and regulated information.
This Cyber Essentials v3.3 (Life Sciences and SMEs) Training Course & Certification provides comprehensive knowledge of the Cyber Essentials v3.3 requirements, certification scope, firewalls and internet gateways, secure configuration, security update management, user access control, passwords and multi-factor authentication, malware protection, assessment preparation, evidence requirements, remediation, and ongoing compliance. The course also addresses practical considerations for life sciences organisations and SMEs operating regulated environments and handling sensitive information. Upon successful completion, learners receive a certification demonstrating their understanding of Cyber Essentials v3.3 requirements and practical cybersecurity readiness principles.
- IT and Cybersecurity Professionals in SMEs
- Life Sciences IT, Digital, and Information Security Teams
- Quality Assurance and Compliance Professionals
- System Administrators and IT Support Personnel
- Data Protection, Risk, and Governance Professionals
- Business Owners, Directors, and Senior Managers
- Cyber Essentials Certification and Assessment Teams
- Anyone responsible for preparing an organisation for Cyber Essentials v3.3 certification
What you will learn
Understand the Cyber Essentials v3.3 scheme, its five technical controls, certification requirements, and how the framework applies to life sciences organisations and small and medium-sized enterprises.
Learn how to define certification scope, secure firewalls and internet gateways, maintain secure configurations, and manage software and security updates across organisational systems.
Develop knowledge of user access control, strong authentication, passwords, multi-factor authentication, malware protection, and practical measures for reducing common cyber risks.
Gain practical understanding of assessment preparation, evidence requirements, common certification issues, scope management, remediation planning, and maintaining Cyber Essentials compliance.
Course Syllabus
- What Cyber Essentials is
- The history and evolution of Cyber Essentials
- Purpose 1 — baseline protection against commodity threats
- Purpose 2 — the common threats CE addresses
- Purpose 3 — assurance, confidence and supply-chain expectation
- The five technical controls — overview
- Controls 1 and 2 — firewalls and secure configuration
- Controls 3 and 4 — updates and user access
- Control 5 and how the five work together
- Cyber Essentials versus Cyber Essentials Plus — what each is
- CE versus CE Plus — the verification method
- Choosing between CE and CE Plus
- The roles in the scheme — overview
- NCSC — the scheme owner
- IASME — the official Delivery Partner
- Certification Bodies and Assessors
- Cyber Advisors, the applicant and the main contact
- The board signatory and Whitehall’s role
- The learning-versus-certification boundary
- What the Whitehall certificate is — and is not
- The assessment lifecycle — overview
- Lifecycle steps 1–4 — prepare, route, purchase, account
- Lifecycle steps 5–8 — version, scope, completion, verification
- Lifecycle steps 9–12 — declaration, submission, marking, clarification
- Lifecycle steps 13–16 — remediate, certify, issue, maintain
- Who signs the verified self-assessment
- What verified self-assessment means
- Certification is point-in-time
- The ongoing-compliance declaration
- Annual renewal
- The scheme version you must use — v3.3
- The Danzell question set replaces Willow
- Reading the v3.3 changes — change-type labels
- v3.3 change — 12-character minimum passwords
- v3.3 change — mandatory cloud MFA and auto-fail
- v3.3 change — phishing-resistant admin MFA
- v3.3 change — passwordless authentication and passkeys
- v3.3 change — firmware patching is explicit
- v3.3 change — tighter scope and cloud wording
- v3.3 change — application development and other updates
- What certification does not prove — overview
- Cyber Essentials does not replace GxP
- Cyber Essentials does not prove GDPR compliance
- What 'certification scope' means
- Why scope matters: the certificate reflects only what is declared
- Whole-organisation versus partial scope
- The whole-infrastructure default and why it is preferred
- Documenting and justifying exclusions
- The golden rule: do not manipulate scope to pass
- Three ways to draw a boundary
- The business-unit boundary
- The physical-location boundary
- The network boundary and segregation
- Scope agreement and certificate wording
- In-scope internet connections and data flows
- In-scope internet-connected devices
- End-user devices: the nine types
- End-user devices cannot be excluded
- Servers and network devices
- In-scope software
- Bespoke and custom applications
- In-scope cloud services
- SaaS, PaaS and IaaS defined
- The shared-responsibility model
- Applicable cloud services cannot be excluded
- Life-science cloud examples
- Provider assurance does not remove your responsibility
- Home and remote-working devices
- Home-working devices cannot be excluded
- Bring-your-own-device (BYOD)
- BYOD: native voice/text and MFA-only exceptions
- A BYOD scoping decision tree
- Third-party and contractor access
- The MSP relationship and accountability
- Partial scope: the requirements
- Segregation: firewall and identity boundary
- Exclusion description and transparent wording
- Commercial limitations of partial certification
- Why an accurate asset inventory matters
- The eleven inventories to maintain
- The role of ongoing asset management
- Building a scope diagram
- Common scoping failures to avoid
- Scope and the five controls
- Separately-managed subsets
- Outbound connections and data-flow control
- Wireless networks and access points
- Laboratory instruments and connected devices
- Cloud email and file storage
- Evaluating cloud-provider evidence
- Secure remote access and VPNs
- Managing BYOD in practice
- Contractor devices: in or out of scope?
- Getting device and user counts right
- Users and administrators in the inventory
- Managing scope change and avoiding drift
- Legal-entity and certificate options
- Validated and GxP systems remain in scope
- Why firewalls are the first Cyber Essentials control
- What a firewall and internet gateway actually does
- The boundary as attack surface
- Three kinds of firewall you must consider
- Boundary firewall versus host-based firewall
- Where firewalls sit for a modern SME
- Which devices need firewall protection
- Why home and mobile devices change the picture
- Change default administrative credentials
- Unique credentials, ownership and documentation
- Disable remote administration from the internet
- If remote administration is genuinely needed
- Default-deny inbound: the baseline principle
- Controlling inbound services
- Documenting business-justified rules
- Rule attributes: least exposure by design
- Temporary rules and rule expiry
- Logging and monitoring firewall activity
- Reviewing firewall rules regularly
- Identifying and removing stale rules
- Internet-accessible services: the risk overview
- Remote desktop exposure and safer alternatives
- Vendor support and laboratory remote maintenance
- Risk-based restriction and secure authentication
- Software firewalls on end-user devices
- Protecting devices on public and home networks
- VPNs and their relationship to firewalls
- Users should not be able to disable protection
- Home-working configuration expectations
- Cloud and virtual firewalls
- The shared-responsibility model applied to firewalls
- Who configures what: a practical split
- Remote administration of cloud consoles
- Evaluate provider assurance — do not assume it
- Firewall evidence: what an assessor expects
- Evidence quality: current, complete, traceable, scope-linked
- The firewall inventory and rule-review record
- Firewalls and secure configuration: how they connect
- How firewall controls appear in the self-assessment
- Common firewall assessment failures to avoid
- A defensible firewall posture: bringing it together
- Why secure configuration matters
- What secure configuration means in v3.3
- The problem with out-of-the-box defaults
- Attack surface: the idea to shrink
- What a secure-configuration baseline is
- Building a baseline: what to include
- Consistency across the estate
- Secure configuration within the five controls
- Who configures what: roles
- Removing unnecessary user accounts
- Types of default and unnecessary accounts
- Remove or disable? Making the choice
- Changing default passwords
- Default passwords on devices and services
- Removing unnecessary software
- Disabling unnecessary services and ports
- Pre-installed apps, extensions and remote tools
- Changing insecure default settings
- Standard versus administrator accounts
- Renaming and protecting built-in admin accounts
- Building a software and services inventory
- Ports and protocols: a quick reference
- Auto-run and auto-play risks
- Disabling auto-run and controlling media
- Device locking: purpose
- Locking parameters and auto-lock
- Locking mobile devices
- Browser and application settings
- Removable media and USB policy
- Locking shared and kiosk devices
- Cloud configuration and shared responsibility
- Cloud tenant settings to secure
- External sharing, guest and anonymous access
- Cloud admin, logging and supplier responsibility
- Cloud example: Microsoft 365 security defaults
- Cloud example: file-storage sharing
- Hardening workstations and laptops
- Hardening servers
- Hardening mobile devices
- Life-science configuration examples
- Validated systems: controlled change, not neglect
- eQMS and LIMS access configuration
- Warehouse terminals and kiosk devices
- Maintaining configuration over time
- BYOD configuration boundaries
- Documentation as evidence
- Secure-configuration evidence exemplars
- Common secure-configuration failures
- Why security update management is a Cyber Essentials control
- What unmanaged vulnerabilities cost
- Where update management sits among the five controls
- How the assessment tests this control
- What the control covers — the full technology picture
- Operating systems and applications
- Browsers, extensions and plugins
- Third-party libraries and software dependencies
- Firmware, routers and firewalls — explicit in v3.3
- Patching firmware in practice
- Mobile devices, appliances and other endpoints
- Supported versus unsupported software
- End of life and end of support explained
- Licensing and vendor support status
- Extended support and long-term support (LTS)
- Custom and bespoke applications
- Deciding whether a product is supported
- Update timescales — the 14-day rule
- What 'critical' and 'high-risk' mean
- Not every routine update must be within 14 days
- Worked timeline — a critical update within 14 days
- Enabling automatic updates where appropriate
- When automatic updates are not appropriate
- Identifying the security updates you need
- Judging severity — vendor ratings and CVSS
- Known exploitation and release-note review
- Prioritising updates by severity and exposure
- A repeatable update-management process
- Monitoring for new updates
- Testing and change control for updates
- Deploying and verifying installation
- Handling failed, missed or rolled-back updates
- Coordinating updates with your MSP
- Mapping updates to the asset inventory
- Updates in the cloud — shared responsibility
- SaaS, PaaS and IaaS — who patches what
- Version selection and provider evidence
- Managing unsupported technology — the options
- Remove, replace, decommission or isolate
- No automatic compensating-control substitution
- Genuine isolation versus the 'risk-accepted' myth
- Validated systems still need security updates
- Patch assessment under change control
- The CE and GxP boundary for updates
- The update-management register
- The end-of-support register
- The 14-day compliance tracker in practice
- Evidence that satisfies an assessor
- Evidence versus assertion for updates
- Common security-update assessment failures
- Prioritising updates in a resource-limited SME
- Building the registers into business as usual
- Why user access control is a Cyber Essentials control
- What the access-control requirement expects
- Key terms: identity, authentication, authorisation, privilege
- The user-account lifecycle
- Account request and approval
- Provision with least privilege from day one
- Unique user identities and individual accountability
- The problem with shared and generic accounts
- Shared accounts on lab systems and shared terminals
- What administrative privilege means — and why it is risky
- Restrict administrative privileges (least privilege)
- Separate administrative and standard-user activities
- No web browsing or email on administrative accounts
- Just-in-time and time-limited administration
- Local, domain, cloud and SaaS administrators
- Managed service provider and vendor administrative access
- Reviewing privileged access
- Authentication factors: know, have, are
- The range of authentication methods
- Strength of authentication methods
- Password controls in v3.3 — the 12-character minimum
- The Cyber Essentials password options
- Brute-force protection
- Blocking common and breached passwords
- Password managers and avoiding needless complexity
- What multi-factor authentication is
- MFA is mandatory for cloud services where available
- Free, included or chargeable — no excuse to leave MFA off
- MFA must cover users and administrators
- Phishing-resistant MFA for administrators
- Genuine constraints and assessor guidance on MFA
- Passwordless authentication
- Passkeys and FIDO2 explained
- Benefits of passkeys and passwordless
- Adopting passwordless in an SME
- Joiners, movers and leavers (JML)
- Joiners and movers in detail
- Leavers — timely account removal
- Dormant and inactive accounts
- Temporary, agency and clinical-contractor accounts
- Third-party and vendor access principles
- Remote maintenance and equipment-engineer access
- Evidence for the access-control requirement
- The registers: user, privileged and MFA coverage
- Common access-control assessment failures
- Access control in life-science environments
- Authentication versus authorisation in practice
- Removing standing local administrator rights
- Cloud identity and single sign-on
- Conditional and risk-based access
- Session controls and re-authentication
- Emergency and break-glass administrator accounts
- Never share or store credentials insecurely
- Authenticator apps versus text-message codes
- Monitoring sign-ins and account activity
- Documenting account approvals and the request workflow
- Bringing it together — access-control readiness
- Why malware protection is a Cyber Essentials control
- The kinds of malware you are defending against
- How malware reaches a device
- The requirement in plain terms
- The three accepted approaches
- At least one approach — active — on every device
- Anti-malware software — what Cyber Essentials expects
- Using and keeping anti-malware updated
- Real-time scanning, web protection and alerts
- Built-in protection: Windows and macOS options
- Application allow-listing — what it is
- Implementing application allow-listing
- When application allow-listing fits best
- Application sandboxing — the concept
- Where sandboxing applies
- Matching the approach to the device type
- Windows devices — meeting the requirement
- macOS devices — meeting the requirement
- Managing mobile-device application installation
- Approved stores and mobile device management (MDM)
- Rooted, jailbroken and unsupported mobile devices
- Servers — meeting the requirement
- Specialised and hard-to-protect devices
- Cloud and SaaS considerations
- Life-science examples across the fleet
- Cyber Essentials does not replace GxP or validation
- Evidencing malware protection
- The malware-protection coverage report (Toolkit 26)
- Common malware-protection assessment failures
- Bringing it together — HelixBridge malware remediation
- Central management of malware protection
- Removable media, macros and auto-run
- Ransomware, detection response and recovery
- Application allow-listing — evidence and pitfalls
- Sandboxing — strengths and limits
- Evaluating a SaaS provider's malware assurances
- Windows and macOS servers versus endpoints
- What assessment readiness means
- The readiness review: an ordered walk-through
- Who does what in the readiness phase
- Readiness areas: scope, assets and cloud
- Readiness areas: firewalls, configuration, software and updates
- Readiness areas: accounts, privileges, MFA and malware
- Readiness areas: outsourced services, evidence and remediation
- The self-assessment questionnaire
- Response principle: answer the exact question asked
- Response principle: current information and defined scope
- Response principle: no generic policy copy, no unsupported 'yes'
- Response principle: consistency of numbers and terminology
- Response principle: verify technically before answering
- Response principle: record the evidence source as you answer
- Evidence versus unsupported assertion
- Nine characteristics of good evidence — part 1
- Nine characteristics of good evidence — part 2
- Evidence types and worked examples
- Policy without implementation — the classic failure
- The evidence register: purpose
- What to record in the evidence register
- Why applications fail — overview
- Common failures 1 — scope, cloud and device counts
- Common failures 2 — unsupported software, MFA, admin and defaults
- Common failures 3 — firewalls, updates and malware
- Common failures 4 — MSP, evidence and contradictions
- Correcting gaps before submission
- The internal pre-submission review
- Working with an MSP — accountability stays with you
- The MSP responsibilities matrix
- What to obtain from your MSP — part 1
- What to obtain from your MSP — part 2
- Evaluating cloud-provider control evidence
- Shared responsibility and provider assurance
- The verified self-assessment declaration
- The signatory's responsibility
- Briefing the board signatory
- The assessor review and clarification stage
- Responding to assessor queries well
- Tracking assessor queries and responses
- Certification and certificate scope
- The point-in-time nature of assessment
- The ongoing-compliance declaration
- Maintaining the five controls through the period
- The ongoing-compliance calendar
- Change triggers that affect compliance
- Preparing for annual renewal
- The annual-renewal checklist
- High-level Cyber Essentials Plus readiness — what it adds
- Cyber Essentials Plus testing components
- Getting ready for Cyber Essentials Plus
- Applying the controls in life-science environments
- Cyber Essentials does not replace GxP or regulatory controls
- Cyber Essentials does not prove GDPR or other standards
- Integrating Cyber Essentials into life-science governance
- Building an organisational remediation plan
- Prioritising and tracking remediation
- 📘 Bonus: Cyber Essentials v3.3 (Life Sciences and SMEs) Training eBook (Free with purchase)









