<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://baigents.net/feed.xml" rel="self" type="application/atom+xml" /><link href="https://baigents.net/" rel="alternate" type="text/html" /><updated>2026-04-23T14:31:10+01:00</updated><id>https://baigents.net/feed.xml</id><title type="html">Cyber Security Services from baigent’s</title><subtitle>A boutique cyber security consultancy offering a variety of information security consultancy and compliance services designed to meet the individual needs of SME’s, public sector organisations and larger corporations, who want to protect their business and enhance the overall security of their internal and external information systems.</subtitle><author><name>BISS</name></author><entry><title type="html">14 Days Is No Longer Enough — AI Just Changed the Rules</title><link href="https://baigents.net/14-Days-Is-No-Longer-Enough/" rel="alternate" type="text/html" title="14 Days Is No Longer Enough — AI Just Changed the Rules" /><published>2026-04-18T00:00:00+01:00</published><updated>2026-04-18T00:00:00+01:00</updated><id>https://baigents.net/14-Days-Is-No-Longer-Enough</id><content type="html" xml:base="https://baigents.net/14-Days-Is-No-Longer-Enough/"><![CDATA[<h1 id="the-patching-window-just-closed-what-mythos-and-ai-powered-vulnerability-discovery-mean-for-cyber-essentials">The Patching Window Just Closed: What Mythos and AI-Powered Vulnerability Discovery Mean for Cyber Essentials</h1>

<p>Last year, <a href="https://baigents.net/is-14-days-fast-enough/">this blog asked whether 14 days</a> was fast enough. The answer then was: barely. Today, the answer is no.</p>

<p>The arrival of Anthropic’s <strong>Claude Mythos Preview</strong>, and the broader wave of AI tools now capable of finding and chaining vulnerabilities at machine speed,  has fundamentally shifted the threat calculation. If your patching process is built around a 14-day window, you’re already behind.</p>

<h2 id="what-mythos-actually-does">What Mythos Actually Does</h2>

<p>This isn’t another vulnerability scanner. Mythos operates differently:</p>

<ul>
  <li><strong>Finds what humans miss</strong>: it interacts with software dynamically, running functions, testing edge cases, and learning from each result, uncovering deeply buried weaknesses traditional methods often miss.</li>
  <li><strong>Scale that’s hard to overstate</strong>: it identified 271 zero-day vulnerabilities in Mozilla Firefox, representing the most significant single batch of security fixes in the browser’s history.</li>
  <li><strong>Speed that redefines the problem</strong>: AI is compressing vulnerability discovery timelines from months or years into hours.</li>
  <li><strong>It doesn’t just find, it acts</strong>: Mythos can launch debuggers, interact directly with systems, form hypotheses, test them, launch containers, and execute code autonomously. It does not just suggest, it acts.</li>
</ul>

<p>Mythos is currently restricted to trusted partners under <a href="https://www.anthropic.com/glasswing">Project Glasswing</a> and is positioned primarily as a defensive tool. But the capability exists. And what defenders have, adversaries will seek to replicate.</p>

<h2 id="the-wider-ai-threat-picture">The Wider AI Threat Picture</h2>

<p>Mythos is the headline, but it’s not alone. Frontier models are accelerating attack lifecycles and enabling attackers to identify and exploit vulnerabilities at scale, speed, and through novel methods that previously were the domain of advanced nation-state entities.</p>

<p>Expect the same pattern to repeat over the next several month/years: incremental progress, then a jump. Models will get more capable and cheaper with each cycle, and each jump will put more pressure on security teams still operating at human speed.</p>

<p>The old model, someone finds a vuln, writes it up, a PoC appears days later, exploitation follows, assumed human speed throughout. <strong>That assumption is gone.</strong></p>

<h2 id="so-where-does-cyber-essentials-stand">So Where Does Cyber Essentials Stand?</h2>

<p><a href="https://baigents.net/information-assurance/cyber-essentials">Cyber Essentials</a> still matters. In fact, it matters more. But the <strong>14-day patching requirement</strong> needs to be understood for what it is: a floor, not a target.</p>

<p>Here’s the reality:</p>

<ul>
  <li><strong>14 days was already tight</strong> — with nearly 30% of known exploited vulnerabilities being weaponised within 24 hours of disclosure (VulnCheck Q1 2025), the window between “published” and “exploited” has always been shorter than 14 days for the nastiest CVEs.</li>
  <li><strong>AI compresses it further</strong> — when tools can autonomously discover, chain, and exploit vulnerabilities in hours, a 14-day patch cycle is a liability, not a policy.</li>
  <li><strong>Critical vulnerabilities should now be treated as 24–72 hour problems</strong>, not 14-day ones. The Cyber Essentials 14-day rule is the compliance minimum. Your operational target should be significantly shorter.</li>
</ul>

<h2 id="what-the-cyber-essentials-controls-still-get-right">What the Cyber Essentials Controls Still Get Right</h2>

<p>The five controls remain solid, foundational hygiene, and AI doesn’t make them irrelevant, it makes them more urgent:</p>

<ul>
  <li><strong>Patching</strong>: Treat the 14-day rule as a hard ceiling for everything, and a 24–72 hour target for anything rated critical with a known exploit path.</li>
  <li><strong>Secure Configuration</strong>: AI tools are particularly effective at finding misconfigurations, locked-down, minimal attack surfaces reduce the available foothold.</li>
  <li><strong>Firewalls and Gateways</strong>: Network edge devices remain a top target. Reduce internet-facing exposure wherever possible.</li>
  <li><strong>Access Control</strong>: Lateral movement is something Mythos-class tools are explicitly designed to automate. Least privilege limits the blast radius.</li>
  <li><strong>Malware Protection</strong>: Basic, yes, but still relevant when AI-generated payloads start appearing at scale.</li>
</ul>

<h2 id="the-real-operational-challenge">The Real Operational Challenge</h2>

<p>The real problem is not discovery, it’s prioritisation and action. Security teams struggle because the operational cost of deciding what matters, what is exploitable, what can wait, and what can be fixed safely is enormous.</p>

<p>That hasn’t changed. What’s changed is the volume of findings and the speed at which the threat side moves. Your patching process needs to keep pace, triage faster, act faster, automate where you can.</p>

<h2 id="bottom-line">Bottom Line</h2>

<p><strong>14 days is the rule. Hours is the reality.</strong></p>

<p>Cyber Essentials gives the framework. AI has raised the bar on what “good enough” looks like. If you’re still treating patching as a fortnightly admin task, you’re running a risk your certification doesn’t cover.</p>

<p>Patch early. Patch often. And if you’re not sure whether your current process is fit for the AI era, <a href="https://baigents.net/contact-us/">get in touch</a>.</p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[The Patching Window Just Closed: What Mythos and AI-Powered Vulnerability Discovery Mean for Cyber Essentials]]></summary></entry><entry><title type="html">Important Update to Cyber Essentails April 2026</title><link href="https://baigents.net/Update-Cyber-Essentails-Changes-2026/" rel="alternate" type="text/html" title="Important Update to Cyber Essentails April 2026" /><published>2026-02-12T13:33:42+00:00</published><updated>2026-02-12T13:33:42+00:00</updated><id>https://baigents.net/Important-Update-Cyber-Essentails-Changes-2026</id><content type="html" xml:base="https://baigents.net/Update-Cyber-Essentails-Changes-2026/"><![CDATA[<h2 id="important-update-changes-to-cyber-essentials-for-april-2026">Important Update: Changes to Cyber Essentials for April 2026</h2>

<figure class="">
  <img src="/assets/Blog-CE-Important-Update-2026.jpg" alt="CE-Important-Update-2026" />
  
    <figcaption>
      Important Update 2026

    </figcaption>
  
</figure>

<p>This blog outlines the annual updates to the <a href="https://www.ncsc.gov.uk/cyberessentials/resources">Requirements for IT Infrastructure</a> document, which serves as the standard for achieving Cyber Essentials certification. It also contains essential new information about changes to the assessment framework.</p>

<p>The <a href="https://www.ncsc.gov.uk/">National Cyber Security Centre (NCSC)</a> has now added further adjustments to the certification process, marking scheme, and Cyber Essentials Plus assessment methodology. It is important to understand and implement these changes to ensure compliance with the updated requirements. If you’re preparing for certification or recertification, it’s vital to review these updates carefully.</p>

<p>Each year, IASME collaborates closely with the NCSC to review feedback from across the scheme, analyse findings from breach investigations, and evaluate insights gained from audits conducted by the IASME team. These inputs form the foundation of the annual review process, which informs updates to the scheme requirements, assessment question set, methodology, and marking criteria. Our goal is to complete this review and implement updates as early as possible, ensuring organisations have sufficient time to prepare for any changes. In November 2025, we published the NCSC’s updates to the Requirements for Infrastructure document, including the introduction of an ‘auto-fail’ policy for not implementing Multi-Factor Authentication (MFA) where it is available.</p>

<p>Since then, additional factors have been identified through IASME’s ongoing audit processes. While these findings have not necessitated further changes to the Requirements for Infrastructure document, they have prompted NCSC to make updates to the operation of the scheme. The details of these changes are outlined below and will take effect in April 2026.</p>

<p>The changes to the scheme will apply to all assessment accounts created after April 27, 2026. Any organisation with an active assessment account created before this date will have 6 months to attain certification using the previous version of the requirements.</p>

<p><strong>What are the upcoming changes to Cyber Essentials?</strong></p>

<p>The April 2026 updates to the Cyber Essentials scheme aim to address challenges faced by organisations and Assessors, resolve areas of ambiguity, and ensure that the scheme continues to provide robust assurance against cyber threats.</p>

<p>Many of these updates were announced in November 2025. However, newly announced changes are highlighted below with the grey background.</p>

<p>Changes to the marking criteria</p>

<p>One of the most notable updates to the scheme is the implementation of stricter marking criteria for questions that address critical practices, such as enabling multi-factor authentication and implementing timely security updates across the entire scope. Failure to meet the required standards will result in an automatic failure of the assessment. This emphasis brings the Cyber Essentials scheme into alignment with the NCSC’s recommended best practice.</p>

<p>Multi-factor authentication (MFA) will now be a mandatory requirement for all cloud services where it is available. Organisations that fail to implement MFA for cloud services whether it is free, included, or a paid option <strong>will automatically fail the assessment</strong>. This change underscores the critical role of MFA in protecting systems and highlights the importance of adopting strong authentication measures. Read more <a href="https://ce-knowledge-hub.iasme.co.uk/space/CEKH/3970007065/MFA+or+bust:+Why+skipping+multi-factor+authentication+is+a+critical+mistake">here</a>.</p>

<blockquote>
  <p>Additionally, two new questions related to <strong>security update management</strong> will be designated as <strong>‘auto-fail’</strong> questions. These questions address the timely installation of high-risk or critical security updates and vulnerability fixes for operating systems, router and firewall firmware, and applications (including associated files and extensions). Specifically:</p>

  <blockquote>
    <p><strong>A6.4:</strong> Are all high-risk or critical security updates and vulnerability fixes for operating systems and router and firewall firmware installed within 14 days of release?</p>
  </blockquote>

  <blockquote>
    <p><strong>A6.5:</strong> Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?</p>
  </blockquote>

  <p><strong>Non-compliance with either of these questions will result in an automatic failure of the assessment</strong>, regardless of performance in other areas. This change is intended to address instances where the delay of critical updates, leaves systems vulnerable to exploitation.</p>

  <p><strong>Improved scope definition and certification transparency</strong></p>

  <p>Defining and reviewing the scope of an assessment has been a persistent challenge, particularly for larger organisations with complex structures. To address this, the following changes will be introduced:</p>

  <blockquote>
    <ol>
      <li><strong>Unlimited scope descriptions:</strong> Organisations will no longer be limited to a brief scope description on their certificates. Instead, they will be able to provide a detailed scope description, which will be available to view via the digital certificate platform.</li>
      <li><strong>Out-of-scope areas:</strong> Organisations will be required to describe any areas of their infrastructure that are excluded from the scope. This information will not be made public.</li>
      <li><strong>Legal entity identification:</strong> Organisations will need to specify all legal entities included within the scope of the assessment, providing details such as the entity’s name, address, and company number. All legal entities included in scope can be viewed on the digital certificate platform.</li>
      <li><strong>New certificate types:</strong> You will be able to request an individual Cyber Essentials certificate for every legal entity certified as part of a larger scope but it will be clear that the certification is part of the wider scope. There will be a small charge for these additional certificates.</li>
    </ol>
  </blockquote>

  <p>These changes aim to improve transparency, reduce ambiguity, and ensure that the scope of an assessment is clearly defined and accurately represented.</p>

  <p><strong>Clarification of ‘point in time’</strong></p>

  <p>Cyber Essentials is a ‘point in time’ assessment, but there has been confusion about what this term refers to. To address this, the scheme will explicitly state that the ‘point in time’ is the date the certificate is issued. Organisations will need to ensure that their systems are supported at the date of certification.</p>

  <p><strong>Signed declaration and ongoing compliance</strong></p>

  <p>The declaration signed by a board member or director as part of the verified self-assessment (VSA) process will be updated to include a statement acknowledging the organisation’s responsibility to maintain compliance with all Cyber Essentials controls throughout the certification period. This change reinforces the importance of ongoing compliance and ensures that organisations remain committed to maintaining robust cyber security measures.</p>

  <p><strong>Changes to the Cyber Essentials Plus (CE+) assessment</strong></p>

  <p>The Cyber Essentials Plus (CE+) assessment provides a higher level of assurance by including a technical audit of an organisation’s cyber security measures. The April 2026 updates introduce several changes to enhance the CE+ process and align it more closely with the verified self-assessment VSA.</p>

  <p><strong>Verification of update management compliance</strong></p>

  <p>Recent audits have revealed instances of organisations ‘applying selective updates’ during the Cyber Essentials Plus (CE+) assessment process. Specifically, when updates are identified as necessary during the CE+ audit, a small number of organisations have only applied these updates to the devices included in the sample being tested, rather than implementing them across their entire CE+ scope. As a result, these organisations have passed the CE+ assessment despite failing to address vulnerabilities across their broader environment.</p>

  <p>To address this issue, the CE+ assessment process for update management will be revised. If an organisation fails the initial test of a random sample of devices, they will be required to remediate the issues and undergo a retest. During the retest, the Assessor will not only recheck the original sample, but will also test a new random sample of devices to ensure compliance across the wider environment. This change is designed to prevent organisations from selectively updating only the tested devices and to ensure that all required updates are applied consistently across the entire CE+ scope. It is important to note that a second failure will result in a revocation of the verified self-assessment certificate.</p>

  <p><strong>Prohibition of adjustments to the verified self-assessment post-CE+ testing</strong></p>

  <p>To maintain the integrity of the certification process, organisations will no longer be allowed to adjust their verified self-assessment (VSA) responses based on the results of the CE+ assessment. The scheme’s Terms and Conditions will be updated to explicitly require that the VSA must be completed, finalised, and remain unchanged prior to the commencement of CE+ testing.</p>
</blockquote>

<p>Additional updates to the Requirements Document</p>

<p>The <a href="https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf">Cyber Essentials Requirements for IT Infrastructure v3.3</a> will include several updates to improve clarity and guidance:</p>

<blockquote>
  <p>Cloud services definition: A clear definition of cloud services has been added to eliminate ambiguity about what constitutes a cloud service.</p>
</blockquote>

<p>Cloud service – A cloud service is an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials, a cloud service will be accessed via an account (which may be credentials issued by your organisation or an email address used for business purposes) and will store or process data for your organisation.</p>

<p>If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.</p>

<ul>
  <li><strong>Improved scoping requirements:</strong> The terms ‘untrusted’ and ‘user-initiated’ have been removed as qualifiers for internet connections, simplifying the scoping criteria. Organisations will also need to justify any exclusions from the scope and explain how excluded networks are segregated from in-scope systems.</li>
  <li><strong>Application development:</strong> The ‘web applications’ section has been renamed ‘application development’ and now references the UK Government’s <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">Software Security Code of Practice</a>. Publicly available commercial web applications are in scope by default, while bespoke and custom components are out of scope.</li>
  <li><strong>Guidance on Backups:</strong> Guidance on Backups: The guidance on backups has been repositioned earlier in the document to emphasise their importance in enabling organisations to recover quickly from cyber incidents.</li>
  <li><strong>User Access Control:</strong> The user access control section has been updated to highlight the importance of passwordless authentication methods, such as passkeys, which offer a more secure alternative to traditional passwords.</li>
</ul>

<p>For more details, refer to the updated <a href="https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf">Cyber Essentials Requirements for IT Infrastructure v3.3</a>, which will apply to all applications registered after April 27, 2026.</p>

<p>For more on how <a href="/information-assurance/cyber-essentials">Cyber Essentails</a> works, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Important Update: Changes to Cyber Essentials for April 2026]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://baigents.net/assets/Blog-CE-Important-Update-2026.jpg" /><media:content medium="image" url="https://baigents.net/assets/Blog-CE-Important-Update-2026.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Upcoming Cyber Essentails Changes 2026</title><link href="https://baigents.net/Upcoming-Cyber-Essentails-Changes-2026/" rel="alternate" type="text/html" title="Upcoming Cyber Essentails Changes 2026" /><published>2025-11-04T13:33:42+00:00</published><updated>2025-11-04T13:33:42+00:00</updated><id>https://baigents.net/Upcoming-Cyber-Essentails-Changes-2026</id><content type="html" xml:base="https://baigents.net/Upcoming-Cyber-Essentails-Changes-2026/"><![CDATA[<h2 id="cyber-essentials-update-whats-changing-in-2026">Cyber Essentials Update: What’s Changing in 2026</h2>

<p>The Cyber Essentials scheme is built around five core technical controls designed to protect organisations from the most common cyber threats. Each year, the National Cyber Security Centre and IASME review these requirements to ensure they remain relevant. The next update goes live in April 2026, with six months’ notice for organisations to prepare. <a href="https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf">Cyber Essentials Requirements for IT Infrastructure v3.3</a> will apply to all assessment accounts created after 27 April 2026.</p>

<h3 id="key-points">Key points</h3>
<ul>
  <li>Stronger focus on passwordless authentication and MFA.</li>
  <li>Minor changes to the requirements document.</li>
  <li>Clearer definitions, especially around cloud services.</li>
  <li>Simplified scoping rules.</li>
  <li>Updated guidance for application development.</li>
  <li>Backup guidance moved earlier for emphasis.</li>
</ul>

<h3 id="what-matters-most">What matters most</h3>
<p>The most significant update is to the marking criteria: multi-factor authentication (MFA) becomes mandatory wherever available. If a cloud service offers MFA—free or paid, and it is not enabled, the assessment will automatically fail. This change reflects the increasing importance of MFA in preventing account compromise.</p>

<p>The user access control section has been updated to place greater emphasis on passwordless authentication and multi-factor authentication (MFA). Passkeys in particular offer an easier, faster and more secure way to log in and the NCSC would like to see them become the default authentication recommendation.</p>

<p>Definitions have also been tightened. A clear definition of “cloud service” is now included, and cloud services can no longer be excluded from scope. Scoping language has been simplified so any in-scope device connected to the internet is included, regardless of connection type. Applicants excluding networks will need to justify why and explain how segregation is enforced.</p>

<p>The “web applications” section is now “application development” and aligns with the <a href="https://www.gov.uk/government/publications/software-security-code-of-practice">UK Government Software Security Code of Practice.</a> Backup guidance has been moved to highlight its importance.</p>

<p>The full v3.3 requirements will apply from 27 April 2026, with the new question set released by February 2026.</p>

<h3 id="updated-information-here"><a href="https://baigents.net/Update-Cyber-Essentails-Changes-2026/">UPDATED INFORMATION HERE</a></h3>

<p>For more on how <a href="/information-assurance/cyber-essentials">Cyber Essentails</a> works, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Cyber Essentials Update: What’s Changing in 2026]]></summary></entry><entry><title type="html">Taking Things to Bits – A Dive into IoT Security with YGHT CESH</title><link href="https://baigents.net/iot-security-course-review/" rel="alternate" type="text/html" title="Taking Things to Bits – A Dive into IoT Security with YGHT CESH" /><published>2025-06-27T14:22:42+01:00</published><updated>2025-06-27T14:22:42+01:00</updated><id>https://baigents.net/course-to-get-to-the-bits</id><content type="html" xml:base="https://baigents.net/iot-security-course-review/"><![CDATA[<h3 id="taking-things-to-bits--a-dive-into-iot-security-with-yght-cesh-10x---electronics-and-pcb-reverse-engineering">Taking Things to Bits – A Dive into IoT Security with YGHT CESH-10x - Electronics and PCB Reverse Engineering</h3>

<figure class="">
  <img src="/assets/uv-chip-board-YGHT-Course-2025.jpg" alt="Description" />
  
    <figcaption>
      UV-Chip-YGHT

    </figcaption>
  
</figure>

<p>I have just spent the week with Felix who led us through a deep dive into the world of IoT security. It wasn’t just theory – it was hands-on, practical, and exactly the kind of learning that sticks.</p>

<p>We pulled a thing to bits to get to the bits – breaking down each stage from understanding electronics to extracting and analysing firmware. We got to grips with the tools and techniques used to bypass anti-tamper protections, many of which are far less effective than manufacturers would like to believe.</p>

<p>As someone who used to take things apart as a kid just to see how they worked (and usually got told off for it), this course hit the spot. If you’re the same – curious, technical, and always asking how does this actually work? – then you’ll love it.</p>

<p>Highly recommended for anyone serious about hardware hacking, reverse engineering, or just unlocking that next level of cyber knowledge.</p>

<p>Check out the next dates <a href="https://yougottahackthat.com/courses">on YGHT Courses page</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Taking Things to Bits – A Dive into IoT Security with YGHT CESH-10x - Electronics and PCB Reverse Engineering]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://baigents.net/assets/uv-chip-board-YGHT-Course-2025.jpg" /><media:content medium="image" url="https://baigents.net/assets/uv-chip-board-YGHT-Course-2025.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Attackers move fast. Are you patching fast enough?</title><link href="https://baigents.net/is-14-days-fast-enough/" rel="alternate" type="text/html" title="Attackers move fast. Are you patching fast enough?" /><published>2025-04-24T14:01:42+01:00</published><updated>2025-04-24T14:01:42+01:00</updated><id>https://baigents.net/-Is-14-days-fast-enough</id><content type="html" xml:base="https://baigents.net/is-14-days-fast-enough/"><![CDATA[<h1 id="why-cyber-essentials-matters-more-than-ever-what-q1-2025-exploitation-trends-are-telling-us">Why Cyber Essentials Matters More Than Ever: What Q1 2025 Exploitation Trends Are Telling Us</h1>

<p>The latest <a href="https://vulncheck.com/blog/exploitation-trends-q1-2025">exploitation trends report from VulnCheck</a> is a wake-up call. Attackers aren’t hanging around — they’re jumping on newly disclosed vulnerabilities almost as soon as they’re published. If your patching process is slow, you’re basically leaving the door wide open.</p>

<p>This is exactly why the NCSC’s <strong><a href="/information-assurance/cyber-essentials">Cyber Essentails</a></strong> scheme — especially its 14-day patching rule — is more important than ever.</p>

<h2 id="what-the-vulncheck-report-says">What the VulnCheck Report Says</h2>

<ul>
  <li>159 known exploited vulnerabilities (KEVs) <a href="https://vulncheck.com/blog/exploitation-trends-q1-2025">reported in Q1 2025.</a>)</li>
  <li>Almost <strong>30% were under attack within 24 hours</strong> of being disclosed.</li>
  <li>The usual suspects are being hit hardest:
    <ul>
      <li>Content Management Systems</li>
      <li>Network Edge Devices</li>
      <li>Operating Systems</li>
    </ul>
  </li>
  <li>Top vendors affected:
    <ul>
      <li>Microsoft Windows</li>
      <li>VMware</li>
      <li>Cyber PowerPanel</li>
    </ul>
  </li>
</ul>

<p>The takeaway? Attackers aren’t targeting obscure kit — they’re going after the stuff most of us use every day.</p>

<h2 id="where-cyber-essentials-fits-in">Where Cyber Essentials Fits In</h2>

<p><a href="/information-assurance/cyber-essentials">Cyber Essentails</a> isn’t about ticking boxes — it’s about getting the basics right so you’re not the easy target. Here’s how it helps:</p>

<ul>
  <li><strong>Secure Configuration</strong>: Shut down unnecessary services, harden your systems.</li>
  <li><strong>Patching (The Big One)</strong>:
    <ul>
      <li><strong>Critical and high-risk updates must be applied within 14 days.</strong></li>
      <li>That includes OS, firmware, and any third-party apps where there’s a known exploit.</li>
      <li>With VulnCheck showing exploits popping up within a day, 14 days isn’t just a nice-to-have — it’s the minimum to stay in the game.</li>
    </ul>
  </li>
  <li><strong>Access Control</strong>: Only give people access to what they actually need.</li>
  <li><strong>Malware Protection</strong>: Basic defence against malware doing the rounds.</li>
  <li><strong>Firewalls and Gateways</strong>: Keep the bad stuff out, especially at the network edge (which, by the way, is one of the top targets right now).</li>
</ul>

<h2 id="why-you-cant-ignore-the-14-day-rule">Why You Can’t Ignore the 14-Day Rule</h2>

<p>The data’s clear: the gap between “vulnerability published” and “exploit in the wild” is getting smaller all the time. The longer you wait to patch, the higher the risk.</p>

<p>The <strong>14-day rule</strong> in Cyber Essentials isn’t about red tape — it’s about giving attackers less time to hit you.</p>

<h2 id="bottom-line">Bottom Line</h2>
<p><strong>Don’t make it easy for them. Patch early, patch often.</strong>
If you’re not patching fast enough, you’re giving attackers the upper hand. Cyber Essentials is designed to reduce that risk. It helps you cover the basics that attackers rely on you getting wrong.</p>

<p>For more on how <a href="/information-assurance/cyber-essentials">Cyber Essentails</a> works, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Why Cyber Essentials Matters More Than Ever: What Q1 2025 Exploitation Trends Are Telling Us]]></summary></entry><entry><title type="html">CE Version 3.2 for 2025-26 basics</title><link href="https://baigents.net/CE-Version-3.2-Willow-for-2025/" rel="alternate" type="text/html" title="CE Version 3.2 for 2025-26 basics" /><published>2025-03-01T13:03:42+00:00</published><updated>2025-03-01T13:03:42+00:00</updated><id>https://baigents.net/CE-Version-3.2-Willow</id><content type="html" xml:base="https://baigents.net/CE-Version-3.2-Willow-for-2025/"><![CDATA[<h1 id="cyber-essentials-32-willow-for-2025-26">Cyber Essentials 3.2 Willow for 2025-26</h1>
<p>It might be over <a href="../Cyber-Essentials-10-Years/">10 years old</a> but <a href="../information-assurance/cyber-essentials/">Cyber Essentials</a> is always being reviewed to keep pace with technology and best practice. The next update to Cyber Essentials will be version 3.2 (Willow) will take effect from 28 April 2025. This means all applications started on or after this date will use the new requirements and questions set. For more information please read <a href="https://iasme.co.uk/articles/what-will-the-changes-be-to-cyber-essentials-and-cyber-essentials-plus-in-the-april-2025-update/">IASME’s blog on their website.</a></p>

<p>This version not much has really changed, the core requirements stay the same, it is mostly some tidying of language and definitions. So for most SME’s who are all ready doing Cyber Essentials there is nothing to worry about. Those who sub-set their scope there is now an extra verification test for the plus assessment.</p>

<h3 id="key-changes">Key Changes</h3>
<ul>
  <li>Under <strong>software</strong>, the term ‘plugins’ has been changed to ‘extensions’ for improved accuracy.</li>
  <li>References to <strong>‘home working’</strong> has been changed to <strong>‘home and remote working’</strong>.</li>
  <li><strong>Passwordless</strong> technology is now included in Cyber Essentials and is defined in the same way as multi-factor authentication, “passwordless authentication is an authentication method that uses a factor other than user knowledge to establish identity“</li>
  <li>The description that used to be ‘patches and updates’. will be changed to <strong>‘vulnerability fixes’</strong> as an umbrella term for all the different methods.</li>
  <li>When the Cyber Essentials self-assessment scope is not ‘whole organisation’, it must be verified by the Assessor that any sub-sets have been segregated correctly (extra physical test)</li>
  <li>All verification evidence must be retained by the Certification Body for the lifetime of the certificate</li>
</ul>

<h3 id="ncsc-documents-are-available-from-below">NCSC documents are available from below</h3>
<ul>
  <li><a href="https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-2.pdf">https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-2.pdf</a> </li>
  <li><a href="https://www.ncsc.gov.uk/files/cyber-essentials-plus-test-specification-v3-2.pdf">https://www.ncsc.gov.uk/files/cyber-essentials-plus-test-specification-v3-2.pdf</a></li>
</ul>

<p>If your business requires <a href="../information-assurance/cyber-essentials/">Cyber Essentials</a> or you would like to know more, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Cyber Essentials 3.2 Willow for 2025-26 It might be over 10 years old but Cyber Essentials is always being reviewed to keep pace with technology and best practice. The next update to Cyber Essentials will be version 3.2 (Willow) will take effect from 28 April 2025. This means all applications started on or after this date will use the new requirements and questions set. For more information please read IASME’s blog on their website.]]></summary></entry><entry><title type="html">Winget basics</title><link href="https://baigents.net/Winget-basics/" rel="alternate" type="text/html" title="Winget basics" /><published>2025-02-04T13:01:42+00:00</published><updated>2025-02-04T13:01:42+00:00</updated><id>https://baigents.net/Winget-Basics</id><content type="html" xml:base="https://baigents.net/Winget-basics/"><![CDATA[<h2 id="winget-basics-updating-and-automating-basic-winget-tasks">Winget Basics: Updating and Automating Basic Winget Tasks</h2>

<p>Winget (Windows Package Manager) is a command-line tool that allows you to install, update, and manage applications on Windows easily. It has been around for a few years now, but many IT admins do not know it exists or how it can be intergrated into day to day admin tasks for FREE.</p>

<p>This guide covers the basics of using Winget to update applications and automate routine tasks.</p>

<h3 id="installing-winget">Installing Winget</h3>
<p>Most modern Windows 10 and 11 versions come with Winget preinstalled. To check if Winget is available, run the following command in PowerShell or Command Prompt:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nt">--version</span><span class="w">
</span></code></pre></div></div>

<p>If it’s not installed, download it from the <a href="https://apps.microsoft.com/detail/9nblggh4nns1">Microsoft Store</a> or install it via PowerShell.</p>

<p>For a list of applications that can be installed/updated by Winget check the <a href="https://github.com/microsoft/winget-pkgs/tree/master/manifests">Winget pkgs Github</a></p>

<hr />

<h3 id="updating-installed-applications">Updating Installed Applications</h3>

<p>For a list of upgradable apps:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">upgrade</span><span class="w">
</span></code></pre></div></div>

<p>To update a single application, use:</p>
<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">upgrade</span><span class="w"> </span><span class="s2">"App ID"</span><span class="w">
</span></code></pre></div></div>

<p>To update all applications at once:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">upgrade</span><span class="w"> </span><span class="nt">--all</span><span class="w">
</span></code></pre></div></div>

<p>To force update all apps without prompts:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">upgrade</span><span class="w"> </span><span class="nt">--all</span><span class="w"> </span><span class="nt">--silent</span><span class="w"> </span><span class="nt">--accept-package-agreements</span><span class="w"> </span><span class="nt">--accept-source-agreements</span><span class="w">
</span></code></pre></div></div>

<hr />

<h3 id="installing-applications">Installing Applications</h3>
<p>To install a new application:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">install</span><span class="w"> </span><span class="s2">"App Name"</span><span class="w">
</span></code></pre></div></div>

<p>For a silent installation without prompts:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">install</span><span class="w"> </span><span class="s2">"App Name"</span><span class="w"> </span><span class="nt">--silent</span><span class="w"> </span><span class="nt">--accept-package-agreements</span><span class="w">
</span></code></pre></div></div>
<hr />

<h3 id="automating-winget-tasks-with-scripts">Automating Winget Tasks with Scripts</h3>
<p>You can automate Winget tasks using PowerShell scripts. For example, to update all applications daily:</p>

<ol>
  <li>Open Notepad and enter the following script:</li>
</ol>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">upgrade</span><span class="w"> </span><span class="nt">--all</span><span class="w"> </span><span class="nt">--silent</span><span class="w"> </span><span class="nt">--accept-package-agreements</span><span class="w"> </span><span class="nt">--accept-source-agreements</span><span class="w">
</span></code></pre></div></div>

<ol>
  <li>Save it as <code class="language-plaintext highlighter-rouge">update-winget.ps1</code>.</li>
  <li>Open Task Scheduler and create a new task:
    <ul>
      <li>Set it to run daily.</li>
      <li>Choose <code class="language-plaintext highlighter-rouge">Start a Program</code> and select <code class="language-plaintext highlighter-rouge">powershell.exe</code> as the program.</li>
      <li>Add <code class="language-plaintext highlighter-rouge">-ExecutionPolicy Bypass -File "C:\path\to\update-winget.ps1"</code> as arguments.</li>
    </ul>
  </li>
</ol>

<p>This ensures applications stay up to date automatically. That <a href="https://learn.microsoft.com/en-us/mem/intune-service/apps/intune-management-extension">script could also be deployed via inTune</a></p>

<hr />

<h3 id="exporting-and-importing-installed-apps">Exporting and Importing Installed Apps</h3>
<p>To export a list of installed applications (could be used to baseline a build to make rolling out apps easy):</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">export</span><span class="w"> </span><span class="nt">-o</span><span class="w"> </span><span class="nx">apps.json</span><span class="w">
</span></code></pre></div></div>

<p>To reinstall apps from the list:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">winget</span><span class="w"> </span><span class="nx">import</span><span class="w"> </span><span class="nt">-i</span><span class="w"> </span><span class="nx">apps.json</span><span class="w">
</span></code></pre></div></div>

<hr />

<h3 id="conclusion">Conclusion</h3>
<p>Winget simplifies software management on Windows, allowing you to update, install, and automate tasks with ease. By integrating it with scripts and Task Scheduler, you can maintain your applications effortlessly and help achieve <a href="/information-assurance/cyber-essentials">Cyber Essentails</a>.</p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Winget Basics: Updating and Automating Basic Winget Tasks]]></summary></entry><entry><title type="html">Small Action, Big Security Win</title><link href="https://baigents.net/A-Reboot-is-an-Easy-Win/" rel="alternate" type="text/html" title="Small Action, Big Security Win" /><published>2024-12-12T17:02:22+00:00</published><updated>2024-12-12T17:02:22+00:00</updated><id>https://baigents.net/Reboots-are-free</id><content type="html" xml:base="https://baigents.net/A-Reboot-is-an-Easy-Win/"><![CDATA[<h3 id="the-power-of-a-reboot-small-action-big-security-win">The Power of a Reboot: Small Action, Big Security Win</h3>

<p>Rebooting. It’s one of those things we all know we should do, but it’s easy to ignore when you’re busy. However, skipping reboots is one of the most common (and risky!) issues flagged in recent Cyber Essentials assessments.</p>

<h4 id="why-rebooting-is-a-big-deal">Why Rebooting is a Big Deal</h4>
<ul>
  <li>Updates Need It: Those important security patches? Most won’t work fully until you reboot. No reboot = no protection.</li>
  <li>It Clears Out the Junk: A quick reboot refreshes your system, fixes little bugs, and keeps things running smoothly.</li>
  <li>Cyber Essentials Loves It: Rebooting isn’t just a good habit—it’s essential for meeting the Cyber Essentials standard.</li>
</ul>

<h4 id="what-happens-if-you-dont">What Happens if You Don’t</h4>
<p>Imagine installing a lock on your door but not closing it. That’s what skipping a reboot is like. You’re leaving your system vulnerable, even after you’ve done the hard work of applying updates.</p>

<h4 id="make-rebooting-easy">Make Rebooting Easy</h4>
<ul>
  <li>Set It and Forget It: Schedule automatic updates and reboots outside of work hours. Or last thing on a Friday shutdown the computer.</li>
  <li>Talk About It: Let your team know why reboots matter—it’s about staying secure, not being annoying.</li>
  <li>Track It: Use logs/reports to monitor reboots so nothing gets missed.</li>
</ul>

<p>Rebooting might feel like a small thing, but it’s one of the easiest ways to stay safe and compliant. So next time you see that “Restart” button, don’t snooze it—click it! Your security depends on it.</p>

<p>If your business requires Cyber Essentials or you would like to know more, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[The Power of a Reboot: Small Action, Big Security Win]]></summary></entry><entry><title type="html">10 Years of Cyber Essentials</title><link href="https://baigents.net/Cyber-Essentials-10-Years/" rel="alternate" type="text/html" title="10 Years of Cyber Essentials" /><published>2024-10-23T18:03:24+01:00</published><updated>2024-10-23T18:03:24+01:00</updated><id>https://baigents.net/Cyber-Essentails-10-Years</id><content type="html" xml:base="https://baigents.net/Cyber-Essentials-10-Years/"><![CDATA[<h3 id="cyber-essentials-is-10-years-old-">Cyber Essentials is 10 Years Old 🎉</h3>

<p>We were excited to celebrate the 10th anniversary of the world leading <a href="https://baigents.net/information-assurance/cyber-essentials/">Cyber Essentials</a> Scheme with the teams from <a href="https://www.ncsc.gov.uk/cyberessentials/overview">NCSC</a> and <a href="https://iasme.co.uk/">IASME</a> this afternoon at the beautiful Cholmondeley Room at the House of Lords. It was an honour to hear from Feryal Clark MP (Parliamentary Under-Secretary of State for AI and Digital Government), who shared insights into our journey and the impact we’ve had over the past decade. We also heard from Emma Philpot MBE and business CISOs on how Cyber Essentials is being used to help provide supply chain assurance.</p>

<p>Cyber Essentials has significantly impacted the Cyber resilience of businesses that implement it fully. Data from <a href="https://iasme.co.uk/articles/interview-with-duncan-sutcliffe-director-of-sutcliffe-and-co-insurance-brokers-to-the-cyber-essentials-scheme/">insurance providers</a> show that those companies that do Cyber Essentials reduce cyber risk by at least 92%. More can be read in the DIST <a href="https://www.gov.uk/government/publications/cyber-essentials-scheme-impact-evaluation?utm_source=brevo&amp;utm_campaign=10th%20Anniversary%20Comms%20CB%20Email&amp;utm_medium=email" title="https://www.gov.uk/government/publications/cyber-essentials-scheme-impact-evaluation">Cyber Essentials Impact Evaluation</a></p>

<p>We’re so grateful for our amazing customers and their unwavering support. Back in 2014, we were among the first Cyber Essentials Assessors, and since then, we’ve seen fantastic progress with our customer base. The majority of our customers are actively embracing Cyber Essentials by implementing controls throughout the year, not just during assessment time. Your support over the last decade has been incredible, here’s to the next 10 years of stronger cyber resilience!</p>

<p>If your business requires Cyber Essentials or you would like to know more, please <a href="../../contact-us/">📧 contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Cyber Essentials is 10 Years Old 🎉]]></summary></entry><entry><title type="html">Cyber Essentials Price Increase From April 2024</title><link href="https://baigents.net/Cyber-Essentials-Price-Increase-From-April-2024/" rel="alternate" type="text/html" title="Cyber Essentials Price Increase From April 2024" /><published>2024-02-19T10:08:44+00:00</published><updated>2024-02-19T10:08:44+00:00</updated><id>https://baigents.net/Cyber-Essentials-Price-Increase%202024</id><content type="html" xml:base="https://baigents.net/Cyber-Essentials-Price-Increase-From-April-2024/"><![CDATA[<h3 id="cyber-essentials-price-increase-from-april-2024">Cyber Essentials Price Increase From April 2024</h3>

<p><a href="https://iasme.co.uk/cyber-essentials/faq-cyber-essentials#howmuch">IASME have published here</a> that they are increasing the costs for Cyber Essentials from 2nd April 2024. As you will remember, the last time they raised the price was 2022, and that was for everyone except Micro companies.</p>

<p>This time, all prices will be raised as follows.</p>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Size</th>
      <th style="text-align: left">Cost</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">Micro organisations (0-9 employees)</td>
      <td style="text-align: left">£320 (from £300) +VAT</td>
    </tr>
    <tr>
      <td style="text-align: left">Small organisations (10-49 employees)</td>
      <td style="text-align: left">£440 (from £400) +VAT</td>
    </tr>
    <tr>
      <td style="text-align: left">Medium organisations (50-249 employees)</td>
      <td style="text-align: left">£500 (from £450) +VAT</td>
    </tr>
    <tr>
      <td style="text-align: left">Large organisations (250+ employees)</td>
      <td style="text-align: left">£600 (from £500) +VAT</td>
    </tr>
  </tbody>
</table>

<p>IASME has also increased the costs associated with being a certification body and performing plus assessments. This action, along with that of other providers, made it difficult for us to continue with the same pricing. As a result, we will be reviewing prices and making some adjustments to future plus assessment costs.</p>

<p>This will mean an increase in costs for Cyber Essentials/Plus for all customers.</p>

<p>Orders placed and paid for in March will be at the old pricing. Any outstanding quotes will also be reviewed from March.</p>

<p>📧 <a href="../../contact-us/">Contact us for more information</a></p>]]></content><author><name>BISS</name></author><summary type="html"><![CDATA[Cyber Essentials Price Increase From April 2024]]></summary></entry></feed>