Monitor

Blog › Article

30 September 2026 · Article

Secure configuration in practice

Secure configuration is the least dramatic of the five controls and one of the easiest to get quietly wrong. It's about removing what isn't needed and changing what shipped insecure — and keeping it that way as machines change.

What the control asks for

Where Windows estates fall short

Old protocols left on

Legacy features that nothing uses any more but that were never switched off. SMBv1, the original Windows file-sharing protocol, is the usual example: long superseded, widely exploited, and still present on machines that were upgraded rather than rebuilt. If nothing needs it, it shouldn't be there.

Remote access that's more open than it needs to be

Remote desktop is often enabled for support and left on. Where it's needed, it should require authentication before a session is set up, and it should never be reachable directly from the internet.

User Account Control turned down

UAC, the prompt before a change needs administrator rights, is sometimes switched off to stop the prompts. That removes a barrier between a user's session and the whole machine.

Autorun still active

Autorun lets inserted media run a program automatically. It's rarely needed and easy to disable.

Screen lock that depends on the user

A screen saver without a password on resume, or a lock timeout set per user and never set at all. A machine that doesn't lock when someone walks away is open to anyone who walks past.

Local password policy never set

Windows doesn't lock out local accounts unless a lockout policy is configured. A machine can be domain-joined, fully patched and still allow unlimited guesses at a local account.

Configuration drifts. Each of these settings can be right on the day a machine is built and wrong six months later, changed by a user, an installer or a technician fixing something else. Checking once a year finds the problem long after it appeared.

A practical baseline for Windows

Setting these centrally, through group policy or device management, keeps them consistent. Checking them on each machine shows whether they actually took effect.

Quick answers

What is secure configuration in Cyber Essentials?

Removing what isn't needed, changing insecure defaults, disabling autorun, making devices lock, and protecting logins against guessing.

Is SMBv1 allowed?

If nothing in the organisation needs it, it counts as an unnecessary service and should be removed. Very few estates genuinely still need it.

Does the guest account need to be disabled?

Unused and default accounts should be removed or disabled, and the Windows guest account is one of them.