Acceleration for ZTNA - background

Why Cyber Essentials Matters, and How ZTNA Can Help You Get There


Cyber attacks affect nearly half of UK businesses every year. Yet many of the most damaging incidents exploit basic, preventable weaknesses: unpatched software, weak access controls, misconfigured systems. The UK government’s Cyber Essentials scheme exists precisely to address this: a structured, independently verified certification that sets a baseline every organisation should be able to meet.

What is Cyber Essentials?

Overseen by the National Cyber Security Centre (NCSC) and administered by IASME, Cyber Essentials defines five technical controls that protect against the most common internet-based attacks. Certification starts at £320 + VAT for the baseline self-assessment, or Cyber Essentials Plus for organisations that want independent hands-on verification that the controls are genuinely working.

The commercial case is straightforward. Government contracts involving personal or financial data require it. NHS procurement frameworks list it as a minimum baseline. It’s a recognised way to demonstrate compliance with the “appropriate technical measures” required under UK GDPR. And cyber insurers are increasingly treating it as a prerequisite for favourable terms.

The Five Controls

Firewalls: Every internet-connected device must sit behind a properly configured firewall. The 2025 “Willow” update (v3.2) clarified that home routers used by remote workers fall within scope, which catches more organisations than expected.

Secure Configuration: Devices and software should be stripped of unnecessary features and services, with default credentials changed. Every unnecessary opening is unnecessary risk.

Security Update Management: Critical patches must be applied within 14 days. Software that is no longer supported by its vendor must be removed from scope.

User Access Control: Users should have access only to what they need. Administrator privileges must be tightly controlled, with separate standard accounts used for routine tasks like email and browsing.

Malware Protection: Active, up-to-date endpoint protection must be in place across the device estate.

Why VPNs Create Problems Here

Many organisations rely on VPNs for remote access, but VPNs have a structural weakness: once authenticated, a user is placed on the corporate network, and so is anyone who steals their credentials. Enforcing least-privilege access across a flat network is difficult, and demonstrating that remote devices meet patching and configuration requirements requires additional tooling. For Cyber Essentials assessments, this creates real complexity.

How Replify Secure Access Helps

Replify Secure Access is a self-hosted Zero Trust Network Access (ZTNA) solution. Rather than placing users on the network, it brokers access to specific applications only, after verifying the identity of the user and the security posture of the device on every session. Here’s how that maps to the five controls:

Firewalls. With no flat network exposed, the attack surface shrinks dramatically. Users can only reach the applications they’re explicitly authorised to access, and nothing beyond that.

Secure Configuration. Internal applications that previously required open firewall ports or VPN tunnels can sit behind the ZTNA broker with no internet-facing exposure, reducing the overall configuration surface.

Security Update Management. Replify Secure Access evaluates device posture in real time, including patch status. A device running out-of-date software can be denied access until it’s remediated, turning a policy requirement into a technical enforcement mechanism.

User Access Control. Policies are defined around users, groups, and applications rather than IP addresses and subnets. Each user accesses exactly what they need, with entitlements reassessed on every connection.

Malware Protection. Device posture checks extend to endpoint protection status. If antivirus is disabled, access is blocked until it’s restored, enforcing the control at the network layer rather than relying on guidelines alone.

It’s worth being clear: Replify Secure Access doesn’t replace antivirus software or a patch management tool. What it adds is enforcement: making the active, compliant state of those tools a hard dependency for access rather than a matter of trust. For Cyber Essentials Plus in particular, that distinction matters: technical testing looks for evidence that controls are working, not just documented.

Because Replify Secure Access is self-hosted, it’s also well suited to organisations with data sovereignty requirements. The entire control plane runs on your own infrastructure, with no vendor cloud dependency.

The Cyber Insurance Connection

Cyber Essentials has a direct and growing relationship with cyber insurance that’s worth understanding separately. IASME data shows that organisations with the Cyber Essentials controls in place make 92% fewer insurance claims — a statistic that insurers have taken notice of.

Major UK underwriters including Hiscox, CFC, Aviva, Zurich, and Beazley now factor Cyber Essentials into their underwriting. Some offer premium discounts of 10-25% for certified organisations. Others are moving toward requiring it as a condition of coverage, and some will reduce or reject claims if basic controls were found to be absent at the time of an incident.

There is also a practical immediate benefit: UK organisations with a turnover under £20 million that achieve certification covering their whole organisation are automatically entitled to £25,000 of cyber liability insurance arranged by IASME, at no additional cost.

The controls that insurers scrutinise most closely — access management, patch status, endpoint protection — are exactly the controls that a ZTNA solution with posture enforcement addresses. Being able to demonstrate that non-compliant devices are technically blocked from accessing systems, rather than simply required by policy to be compliant, is the kind of evidence that strengthens both a certification submission and an insurance application.

In Summary

Cyber Essentials is designed to be achievable, and the five controls reflect hygiene that any organisation should be practising regardless of certification. For organisations modernising their access infrastructure, a ZTNA solution like Replify Secure Access can address all five controls in a single deployment, reducing complexity rather than adding to it.

Get in touch with the Replify team to find out more.


For official guidance on Cyber Essentials, visit the NCSC website or the IASME Consortium.

Categories: