- Database Reporting
Custom Reporting & Dashboard Development Cost in the UK in 2026
12 Apr, 2026
Password policy, multi-factor authentication and least-privilege access, properly implemented and actually followed — not a policy document nobody reads.
Password policy and multi-factor authentication are technically enforced across every account, not left to individual staff discretion.
Staff get access to what their role actually needs, with administrative rights reviewed and restricted, not handed out by default.
Access is reviewed as staff join, move roles and leave, so permissions reflect who actually needs them today, not who needed them years ago.
User access control is one of the five technical control areas Cyber Essentials assesses, and it covers more ground than most businesses initially assume — not just "do you have a password policy," but whether accounts are provisioned with least privilege, whether administrative rights are properly restricted and reviewed, whether multi-factor authentication is actually enforced rather than merely available, and whether leavers' access is removed promptly rather than sitting active for months after someone's left the business. A password policy written in a document and never technically enforced satisfies nobody — not your staff, who ignore it within a month, and not a Cyber Essentials assessor, who will ask for evidence of enforcement, not intention.
Our approach to cyber essentials access control focuses on what's technically enforced across your systems, not what's merely written in a policy nobody has actually read. Multi-factor authentication, least-privilege access, regular permission reviews and prompt leaver deprovisioning are all included as standard on our managed IT plans, from £20 per user per month, alongside 24/7 monitoring and EDR endpoint protection — so the access control evidence a Cyber Essentials assessment asks for reflects what's genuinely happening across your business, not a policy exercise completed once before an assessment and then forgotten.
The name of this page mentions password management specifically because that's usually the starting point businesses actually search for, but the underlying requirement is broader than passwords alone. A good password matters far less than it used to now that multi-factor authentication is available almost everywhere, which is why we treat MFA as the priority layer and password policy as the sensible baseline underneath it, rather than the other way round. Getting that balance right also means staff spend less time fighting overly complex password rules and more time actually protected by a second authentication factor that matters far more.
Cyber Essentials expects businesses to control who has access to what, with administrative accounts used only for administrative tasks, regular accounts restricted to what a role genuinely needs, and multi-factor authentication enforced on cloud services and remote access at minimum.
A strong password policy is only meaningful if systems technically require it — minimum length, checked against known breached password lists, and multi-factor authentication layered on top rather than relied on as a replacement for a decent password in the first place.
Staff accounts are provisioned against what their specific role requires, not a default template that grants broad access "just in case." Administrative rights are held separately from everyday accounts and reviewed regularly, so an everyday phishing compromise doesn't automatically hand over administrative control.
Access for staff who've left the business is removed promptly as part of a documented offboarding process, rather than sitting active for weeks or months because nobody owns that step of the process.
The core elements behind every access control setup we manage.



Password policy and multi-factor authentication are configured to be technically required across your systems, so protection doesn't depend on individual staff remembering or choosing to follow a document.
Access reviews happen at the moments that matter — onboarding, role changes and offboarding — rather than as an annual exercise that misses everything in between.
From assessment to enforced, monitored access control across your business.
We review current password policy, MFA coverage and access levels against Cyber Essentials requirements.
We enforce password policy and MFA technically, and restructure access to a least-privilege model by role.
Onboarding, role-change and offboarding processes are documented, so access reviews happen consistently.
Access is monitored and reviewed on an ongoing basis, alongside our wider 24/7 monitoring and EDR protection.
We configure password policy and multi-factor authentication to be technically enforced, not left as a document staff can quietly ignore once the novelty wears off.
Access is provisioned on a least-privilege basis by role, with administrative rights held separately and reviewed regularly, so a compromised everyday account doesn't automatically hand over administrative control.
Where a business already has an in-house IT team, we're often brought in specifically for the access control piece — designing the least-privilege model, configuring enforcement, and setting up the review cadence — while day-to-day support stays with the existing team. That specialist, narrower engagement suits businesses that don't need to hand over everything to get this one area properly sorted.
Leaver deprovisioning is built into a documented offboarding process, so access for former staff doesn't sit active for months after they've gone.
Access control, MFA enforcement, EDR endpoint protection and 24/7 monitoring are included as standard on our managed IT plans, from £20 per user per month, backed by a 99% SLA guarantee.
We also directly support the wider Cyber Essentials certification process, and our managed cyber security services cover the broader security picture beyond access control alone.
We're based in the City of London with remote-first delivery UK-wide, so access reviews and MFA rollouts don't wait on travel time.
We also keep clear records of your access control setup — which roles have which permissions, when reviews last happened, how leavers are deprovisioned — so answering a Cyber Essentials assessor's questions is a matter of pulling up a document, not reconstructing the picture from memory under time pressure.

Simple, transparent per-user pricing, with access control management built in. No hidden fees.
Core access control for small teams
Regular access review for growing businesses
Continuous review with dedicated support
We treat access control as something that has to be enforced and reviewed, not written once and forgotten. Here's what sets us apart.
Password policy and MFA are configured to be technically required, not left to individual staff discretion.
Accounts are provisioned against actual role requirements, not a broad default template.
Leaver deprovisioning is a defined, followed process, not something remembered only when someone notices.
A clear, measurable service standard behind your access control management, not a vague best-effort promise.
Access control sits alongside our wider Cyber Essentials certification support, covering every technical control area.
Access is reviewed at onboarding, role changes and offboarding, not just once a year in a compliance exercise.
Access control configuration and reviews delivered remotely across the UK from our City of London base.
We design policy that staff can actually work with day to day, not rules so strict they get worked around.
Clear pricing with access control management built in, not sold separately as an unpredictable add-on.
A password policy document tells staff what they should do. Cyber essentials access control, properly implemented, makes it technically required — minimum password standards enforced by the system itself, multi-factor authentication that can't simply be skipped, administrative rights genuinely separated from everyday accounts, and leaver access removed the day someone departs rather than whenever someone happens to notice. The comparison that matters isn't policy versus no policy — it's whether access control is actually enforced by your systems, or relies entirely on staff remembering and choosing to follow a document most people read once, if at all. A written policy also can't tell you, months later, whether a leaver's account is still active or whether an intern's temporary access was ever actually revoked — only an enforced, reviewed system can answer those questions with certainty rather than a shrug. Access control, MFA and regular reviews are included as standard on our managed IT plans, from £20 per user per month.
We configure and manage access control remotely for businesses across the UK, from our base in the City of London. Password policy enforcement, MFA rollout and access reviews are handled remotely, with on-site visits available in London when hardware genuinely needs physical attention.
Sector mix: our clients span professional services firms handling sensitive client data, retailers with point-of-sale and till access, and growing SMEs preparing for their first Cyber Essentials certification or a renewal.
Getting started: a free consultation is the first step, whether your current access control needs a full overhaul or simply an honest review against the standard.
Coverage
From £20 per user per month, with 24/7 monitoring, EDR protection and a 99% SLA guarantee wherever your business is based.
cyber essentials access control
Enforced password policy, multi-factor authentication and least-privilege access, reviewed regularly against Cyber Essentials requirements.
managed cyber security services uk
Access control sits alongside our wider managed cyber security services, covered in more depth on that page.
Got questions about Cyber Essentials access control? We've answered the most common ones below. If you need more detail, get in touch.
Enforced password policy, multi-factor authentication on cloud services and remote access, least-privilege account provisioning, separated administrative rights, and prompt removal of access for leavers.
No, the assessment looks for evidence that requirements are technically enforced, not simply documented and hoped for.
Cyber Essentials expects MFA on cloud services and remote access at minimum, and we typically recommend it as widely as practical across your systems.
Access control, MFA enforcement and regular reviews are included as standard across our managed IT plans, from £20 per user per month.
Leaver deprovisioning is part of a documented offboarding process, so access is typically removed the same day someone's departure is confirmed.
Yes, access control support sits alongside our wider Cyber Essentials certification support, covering all five technical control areas the assessment requires.
We design policy that's workable day to day, not so strict that staff look for workarounds, and explain the reasoning so it's understood rather than resented.
Yes, administrative rights are reviewed separately and regularly, since they carry the greatest risk if a compromised account has broad access.
Limited time offer — valid until 31/05/2026
We believe that communication is key to any successful partnership. Submit your details and one of our friendly team members will be in touch with you shortly.
Submit your details and one of our friendly team members will be in touch with you shortly
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.
12 Apr, 2026
18 Mar, 2026
27 Feb, 2026
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.
23 Aug, 2026
AI code review has moved from novelty to default in UK development teams inside about eighteen months. Pull requests now arrive pre-annotated by a model,...
22 Aug, 2026
Google Ads wasted spend is the single most recoverable line item in most UK SME marketing budgets. It is not a strategy problem and it is rarely a creative...
21 Aug, 2026
Cyber Essentials certification has quietly become a commercial requirement rather than a security badge. It is mandatory for most central government contracts...