Blog › Article
Secure configuration in practice
Secure configuration is the least dramatic of the five controls and one of the easiest to get quietly wrong. It's about removing what isn't needed and changing what shipped insecure — and keeping it that way as machines change.
What the control asks for
- Remove or disable software, services and user accounts that aren't needed.
- Change default passwords on everything, including network equipment and appliances.
- Disable features that run code automatically, such as autorun for inserted media.
- Make devices lock when unattended, needing a PIN, password or biometric to unlock.
- Protect password logins against guessing.
Where Windows estates fall short
Old protocols left on
Legacy features that nothing uses any more but that were never switched off. SMBv1, the original Windows file-sharing protocol, is the usual example: long superseded, widely exploited, and still present on machines that were upgraded rather than rebuilt. If nothing needs it, it shouldn't be there.
Remote access that's more open than it needs to be
Remote desktop is often enabled for support and left on. Where it's needed, it should require authentication before a session is set up, and it should never be reachable directly from the internet.
User Account Control turned down
UAC, the prompt before a change needs administrator rights, is sometimes switched off to stop the prompts. That removes a barrier between a user's session and the whole machine.
Autorun still active
Autorun lets inserted media run a program automatically. It's rarely needed and easy to disable.
Screen lock that depends on the user
A screen saver without a password on resume, or a lock timeout set per user and never set at all. A machine that doesn't lock when someone walks away is open to anyone who walks past.
Local password policy never set
Windows doesn't lock out local accounts unless a lockout policy is configured. A machine can be domain-joined, fully patched and still allow unlimited guesses at a local account.
Configuration drifts. Each of these settings can be right on the day a machine is built and wrong six months later, changed by a user, an installer or a technician fixing something else. Checking once a year finds the problem long after it appeared.
A practical baseline for Windows
- SMBv1 removed.
- Remote desktop off unless needed; where on, requiring authentication first and not exposed to the internet.
- User Account Control on.
- Autorun disabled.
- Screen lock enforced with a timeout, needing credentials to resume.
- Account lockout or throttling configured for local accounts.
- Default and unused accounts, including the guest account, disabled.
Setting these centrally, through group policy or device management, keeps them consistent. Checking them on each machine shows whether they actually took effect.
Quick answers
What is secure configuration in Cyber Essentials?
Removing what isn't needed, changing insecure defaults, disabling autorun, making devices lock, and protecting logins against guessing.
Is SMBv1 allowed?
If nothing in the organisation needs it, it counts as an unnecessary service and should be removed. Very few estates genuinely still need it.
Does the guest account need to be disabled?
Unused and default accounts should be removed or disabled, and the Windows guest account is one of them.