Monitor

Getting started

Using Monitor

Network and troubleshooting

Your account

Project

Read the checks

Every hour each probe reports what it finds. The portal decides what each reading means, so a change in the rules applies to every machine at once, without touching them.

The headline: how old are the missing updates

Updates, in days is the age of the oldest critical or important Windows update the machine has not installed. Cyber Essentials allows 14 days. The overview shows every machine on that 14-day scale.

A machine that takes its updates from WSUS is measured against what your WSUS has approved for it, not against everything Microsoft has released.

What each result means

The page of the machine QLM-SURGERY-02: every check with its result, detail and time, and Patch age days failing at 19 days
One machine. Its missing update is 19 days old, past the 14 allowed.
ResultMeaning
okThe reading meets the rule.
warnClose to a limit, or worth a look. Nothing has failed yet.
failThe reading does not meet the rule. It appears under Needs action.
unknownThe machine could not read this, so nothing was decided. Unknown is never counted as a pass.
readingInformation with no verdict - hardware, installed software.

An unknown says why on the machine's page, when the probe said:

One slow or stuck part of Windows never stops a machine reporting everything else.

Some checks read several settings. Where the probe could read some of them and not others, the check shows what it read and adds a line, Could not be read on the machine:, naming the rest. It is then at least a warn, never a pass: a pass on half a reading would claim more than anyone knows. A setting that is simply not configured is different - it says not set (Windows default), because the default is a real answer.

Controls are the settings Cyber Essentials looks at: updates, antivirus, firewall, supported Windows, encryption, accounts, screen lock and similar. They can fail. Health readings - disk space, disk health, certificates, failing scheduled tasks - can warn but never fail, because a full disk is not a missed control.

The overview

The overview for Wrenfield IT: machines grouped under Needs action, Warning, Health, Alerts silenced, Waiting and Healthy, beside the 14-day update window
The overview, grouped by what needs doing.

Machines are grouped by what needs doing: Needs action, Warning, Health, Alerts silenced, Paused, Waiting, Healthy. A machine that has reported but has not yet had any check graded sits under Warning, not Healthy - reporting in is not the same as passing.

In Needs action, Warning, Alerts silenced and Paused, each machine is one short block:

A machine that has gone quiet shows one line, "Gone quiet, last report" and the time. What it said at that report is behind At its last report - what it said then, not what is true now.

The most failures come first, then machines that have gone quiet, then those with warnings only; machines with the same are in name order. Expand all opens every block's hidden lines and Collapse all closes them; the portal remembers your choice. The menu on each block pauses the machine for you, and lets an owner silence it.

Days are whole days everywhere: an update 751 days old, not 751.2. When antivirus fails, the line says what the machine reported - real-time protection off, or definitions a number of days old, or out of date. If the reading does not say which, it says "Antivirus reported a problem it didn't name"; the portal never guesses.

On Linux

A Linux machine is judged on the same controls, read the Linux way. Its page describes each reading in Linux terms.

Updates: the Linux number is the age, in days, of the oldest security update waiting on the machine - judged by the same 14 days as Windows. Ubuntu and Debian do not record on the machine when an update was released, so the portal dates each one itself, from Ubuntu's security notices and Debian's security announcements, which it collects daily. The machine's page names the oldest: which package, which notice, released when. An update that no notice dates is named as not dated by any notice, and makes the reading unknown unless something already fails - never a pass. A probe from before this counts the waiting security updates instead, and any at all is a warn.

CheckWhat the Linux probe readsWhat fails it
AntivirusClamAV, Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Sophos: running, real-time protection, definitions agenone found; not running; real-time protection off; definitions too old
Firewallufw; the nftables and iptables rules on incoming trafficnothing filtering incoming traffic. Rules that still let everything else in are a warn
Updates allowedthe apt timers that fetch and install updates; unattended upgradesboth apt timers switched off. Unattended upgrades off is shown, not judged: your own tools may do the patching
Encryptionwhether / and each data disk sit on an encrypted (LUKS) device/ not encrypted. A data disk not encrypted is a warn
Secure configurationssh's own settings, accounts with an empty password (counted, never named), system folders anyone can write toan empty password, or ssh accepting one. Root allowed to log in over ssh, or an open system folder, is a warn
Accountshow many are in the sudo, admin and wheel groups; sudo rules that need no password; accounts with UID 0 besides root (counted, never named)another account with UID 0. Many admins, or a passwordless sudo rule, is a warn
Password policythe minimum length PAM enforces (pam_pwquality or pam_unix, with their own defaults) and pam_faillock's lockoutshorter than 8. No lockout is a warn
Screen lockwhether there is a desktop at all; on a desktop, the system-wide lock settingslock switched off. Longer than 15 minutes is a warn
Failing taskssystemd units that have failed, by namehealth: a warn, never a fail

A Linux machine with no antivirus at all fails, and its page says so: No antivirus found. Cyber Essentials also accepts application allow-listing; if this machine is protected that way, silence this check with the reason. The probe cannot see allow-listing, so it never assumes it; the silence records that it was a decision, and the failure still shows in the portal and in evidence packs. Many Linux servers run no antivirus: where your Windows estate's EDR (Defender for Endpoint, CrowdStrike, SentinelOne, Sophos) has a Linux agent, installing it is often the simplest answer, and the probe will see it.

Some checks do not apply to every machine, and say so as not applicable with the reason, never as a pass:

On a desktop whose lock is set by each user rather than system-wide, screen lock is unknown: the lock is set per user, which the probe does not read.

What a result is, and is not

The machine belongs to someone else, so what it reports is an attestation, not proof. Someone with administrator rights on it could make it report something untrue. Every product of this kind shares that limit. What the portal gives you is continuous monitoring and a record of it, which is useful evidence; it cannot verify that a machine is set up as it says.

Next: See hardware and software