Does Cyber Essentials protect against ransomware?
Cyber Essentials addresses ransomware risks through five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. MFA is an important requirement within the applicable controls; recovery needs additional measures.

Section 01
Does Cyber Essentials protect against ransomware?
Cyber Essentials materially reduces ransomware risk but does not eliminate it. The five controls block the most common initial-access routes for ransomware - phishing-delivered malware, credential theft, exposed remote-access services, and exploitation of unpatched vulnerabilities - but post-intrusion containment and recovery require additional controls beyond CE.
Section 02
How the five controls reduce ransomware risk
Patching (14-day rule)
A large share of ransomware initial access in UK incidents exploits known vulnerabilities with patches available but unapplied. The 14-day rule closes that window.
MFA on user and admin accounts
Credential stuffing and phishing-harvested credentials are two of the top three ransomware initial-access routes. MFA - phishing-resistant for admin accounts under v3.3 - materially reduces both.
No direct internet exposure of management services
RDP, SMB, and management interfaces exposed to the internet are a frequent ransomware entry point. The firewalls control requires these to be gated behind MFA and strong authentication.
Malware protection
Real-time endpoint protection catches the majority of commodity ransomware samples at the initial-payload stage.
Admin-account separation
Limits the blast radius if a standard user account is compromised.
Section 03
What Cyber Essentials does not directly require
Ransomware resilience also depends on controls Cyber Essentials does not directly assess:
- Offline or immutable backups with tested restore procedures
- Network segmentation to limit lateral movement
- Privileged Access Management (PAM) beyond basic admin / user separation
- EDR / XDR with behavioural detection and response capabilities
- Incident response retainer or documented IR plan
- Security information and event management (SIEM)
- Tabletop exercises and ransomware-specific simulations
These sit above the CE baseline, in IASME Cyber Assurance Level 2, ISO 27001, or specialist ransomware-resilience programmes.
Section 04
What the data says
The NCSC's own assessments suggest that organisations meeting the full Cyber Essentials controls are materially less likely to suffer successful commodity ransomware attacks than organisations without the baseline. That is a risk-reduction claim, not a guarantee - and it applies specifically to commodity ransomware rather than targeted, sophisticated campaigns.
Section 05
What about cyber insurance?
UK cyber insurance policies typically treat Cyber Essentials (and especially Cyber Essentials Plus) as a positive underwriting signal. Ransomware sub-limits and extortion-cover terms are better for insured organisations holding CE than those that do not. See Cyber Essentials and cyber insurance.
Section 06
Bottom line
Cyber Essentials is the strongest single step a UK SME can take to reduce ransomware initial-access risk at proportionate cost - but it is the baseline, not a complete ransomware defence. Combine CE with offline backups, an IR plan, and (for higher-risk organisations) EDR and segmentation.
Certify with Fig Group from £299.99 + VAT in 6 working hours.
Start Cyber Essentials from £299.99 + VAT | Cyber Essentials and cyber insurance | Free readiness check
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
What are the five Cyber Essentials controls?
The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.
Read articleTechnical Guides
User Access Control for Cyber Essentials v3.3: the complete pillar guide
User Access Control is the pillar of Cyber Essentials that catches the most UK organisations out at assessment. This guide walks through every v3.3 requirement - individual accounts, MFA, admin separation, joiner-mover-leaver, third-party access - and the exact evidence assessors now expect.
Read articleTechnical Guides
Secure Configuration for Cyber Essentials: The Controls Assessors Expect to See
Secure configuration is the control area with the broadest scope and the most room for getting details wrong. This guide covers default passwords, auto-run, unnecessary software, cloud service configuration, and the specific settings assessors check against v3.3 (effective 27 April 2026).
Read article

