Meeting Cyber Essentials Access Control Requirements With Password Management That Sticks

Password policy, multi-factor authentication and least-privilege access, properly implemented and actually followed — not a policy document nobody reads.

Enforced, Not Just Written

Password policy and multi-factor authentication are technically enforced across every account, not left to individual staff discretion.

Least Privilege by Default

Staff get access to what their role actually needs, with administrative rights reviewed and restricted, not handed out by default.

Reviewed Regularly

Access is reviewed as staff join, move roles and leave, so permissions reflect who actually needs them today, not who needed them years ago.

Cyber Essentials access control that survives contact with real staff

User access control is one of the five technical control areas Cyber Essentials assesses, and it covers more ground than most businesses initially assume — not just "do you have a password policy," but whether accounts are provisioned with least privilege, whether administrative rights are properly restricted and reviewed, whether multi-factor authentication is actually enforced rather than merely available, and whether leavers' access is removed promptly rather than sitting active for months after someone's left the business. A password policy written in a document and never technically enforced satisfies nobody — not your staff, who ignore it within a month, and not a Cyber Essentials assessor, who will ask for evidence of enforcement, not intention.

Our approach to cyber essentials access control focuses on what's technically enforced across your systems, not what's merely written in a policy nobody has actually read. Multi-factor authentication, least-privilege access, regular permission reviews and prompt leaver deprovisioning are all included as standard on our managed IT plans, from £20 per user per month, alongside 24/7 monitoring and EDR endpoint protection — so the access control evidence a Cyber Essentials assessment asks for reflects what's genuinely happening across your business, not a policy exercise completed once before an assessment and then forgotten.

The name of this page mentions password management specifically because that's usually the starting point businesses actually search for, but the underlying requirement is broader than passwords alone. A good password matters far less than it used to now that multi-factor authentication is available almost everywhere, which is why we treat MFA as the priority layer and password policy as the sensible baseline underneath it, rather than the other way round. Getting that balance right also means staff spend less time fighting overly complex password rules and more time actually protected by a second authentication factor that matters far more.

What proper access control actually covers

Cyber Essentials expects businesses to control who has access to what, with administrative accounts used only for administrative tasks, regular accounts restricted to what a role genuinely needs, and multi-factor authentication enforced on cloud services and remote access at minimum.

Password Policy, Technically Enforced

A strong password policy is only meaningful if systems technically require it — minimum length, checked against known breached password lists, and multi-factor authentication layered on top rather than relied on as a replacement for a decent password in the first place.

Least-Privilege Access by Role

Staff accounts are provisioned against what their specific role requires, not a default template that grants broad access "just in case." Administrative rights are held separately from everyday accounts and reviewed regularly, so an everyday phishing compromise doesn't automatically hand over administrative control.

Prompt Leaver Deprovisioning

Access for staff who've left the business is removed promptly as part of a documented offboarding process, rather than sitting active for weeks or months because nobody owns that step of the process.

What our access control service covers

The core elements behind every access control setup we manage.

Multi-factor authentication rollout

Multi-Factor Authentication

MFA enforced across cloud services, remote access and administrative accounts, not left optional for staff to enable or ignore.

Authentication
Least privilege access review

Least-Privilege Access

Access provisioned and reviewed against actual role requirements, with administrative rights held separately from everyday accounts.

Access Control
Leaver deprovisioning process

Leaver Deprovisioning

Access removed promptly when staff leave, as part of a documented, followed offboarding process.

Offboarding

Our approach to access control

Enforced Technically, Not Just Written

Password policy and multi-factor authentication are configured to be technically required across your systems, so protection doesn't depend on individual staff remembering or choosing to follow a document.

Reviewed as People Join, Move and Leave

Access reviews happen at the moments that matter — onboarding, role changes and offboarding — rather than as an annual exercise that misses everything in between.

Ready for access control that's actually enforced?

How it works

From assessment to enforced, monitored access control across your business.

1

Assess

We review current password policy, MFA coverage and access levels against Cyber Essentials requirements.

2

Configure

We enforce password policy and MFA technically, and restructure access to a least-privilege model by role.

3

Document

Onboarding, role-change and offboarding processes are documented, so access reviews happen consistently.

4

Monitor & Support

Access is monitored and reviewed on an ongoing basis, alongside our wider 24/7 monitoring and EDR protection.

Businesses need Cyber Essentials access control support when

They're preparing for Cyber Essentials and aren't sure their current access control practice would pass assessment
A password policy exists in a document but isn't technically enforced across any systems
Most staff accounts have administrative rights they don't actually need for their role
Nobody has a clear, followed process for removing access when staff leave the business
Multi-factor authentication is available on cloud services but not actually enforced for staff
A client or supplier contract now requires Cyber Essentials certification as a condition of doing business
A phishing incident succeeded partly because the compromised account had broader access than its role warranted
Cyber insurance requires evidence of proper access control and MFA enforcement as a condition of cover
Growth means more staff and more systems, and access has never been reviewed since the business was much smaller

Why choose Cloudswitched for Cyber Essentials access control?

We configure password policy and multi-factor authentication to be technically enforced, not left as a document staff can quietly ignore once the novelty wears off.

Access is provisioned on a least-privilege basis by role, with administrative rights held separately and reviewed regularly, so a compromised everyday account doesn't automatically hand over administrative control.

Where a business already has an in-house IT team, we're often brought in specifically for the access control piece — designing the least-privilege model, configuring enforcement, and setting up the review cadence — while day-to-day support stays with the existing team. That specialist, narrower engagement suits businesses that don't need to hand over everything to get this one area properly sorted.

Leaver deprovisioning is built into a documented offboarding process, so access for former staff doesn't sit active for months after they've gone.

Access control, MFA enforcement, EDR endpoint protection and 24/7 monitoring are included as standard on our managed IT plans, from £20 per user per month, backed by a 99% SLA guarantee.

We also directly support the wider Cyber Essentials certification process, and our managed cyber security services cover the broader security picture beyond access control alone.

We're based in the City of London with remote-first delivery UK-wide, so access reviews and MFA rollouts don't wait on travel time.

We also keep clear records of your access control setup — which roles have which permissions, when reviews last happened, how leavers are deprovisioned — so answering a Cyber Essentials assessor's questions is a matter of pulling up a document, not reconstructing the picture from memory under time pressure.

Cyber Essentials access control for UK business

What our access control service delivers

01

Enforced Password Policy

Minimum length and complexity requirements technically enforced across systems, checked against known breached password lists where supported.

02

Multi-Factor Authentication

MFA enforced on cloud services, remote access and administrative accounts, not left as an optional setting for staff to enable.

03

Least-Privilege Access

Accounts provisioned against actual role requirements, with administrative rights separated and reviewed regularly.

04

Prompt Leaver Deprovisioning

Access removed promptly when staff leave, as part of a documented, consistently followed offboarding process.

05

Ongoing Access Reviews

Regular review of who has access to what, so permissions reflect current roles rather than historical ones nobody's revisited.

Choose Your Plan

Simple, transparent per-user pricing, with access control management built in. No hidden fees.

Essentials

Core access control for small teams

£20/user/month
  • Enforced password policy
  • Multi-factor authentication
  • 24/7 monitoring
  • 99% SLA guarantee
  • Quarterly access review
  • Dedicated account manager
Get Essentials
Most Popular

Assurance

Regular access review for growing businesses

£40/user/month
  • Everything in Essentials
  • Quarterly access review
  • Documented offboarding
  • Cyber Essentials support
Get Assurance

Ultimate

Continuous review with dedicated support

£60/user/month
  • Everything in Assurance
  • Continuous access review
  • Dedicated account manager
  • Virtual CIO input
Get Ultimate

Why Cloudswitched for access control?

We treat access control as something that has to be enforced and reviewed, not written once and forgotten. Here's what sets us apart.

Enforced, not just written

Password policy and MFA are configured to be technically required, not left to individual staff discretion.

Least privilege by default

Accounts are provisioned against actual role requirements, not a broad default template.

Documented offboarding

Leaver deprovisioning is a defined, followed process, not something remembered only when someone notices.

99% SLA guarantee

A clear, measurable service standard behind your access control management, not a vague best-effort promise.

Full certification support

Access control sits alongside our wider Cyber Essentials certification support, covering every technical control area.

Regular reviews

Access is reviewed at onboarding, role changes and offboarding, not just once a year in a compliance exercise.

UK-wide, remote-first

Access control configuration and reviews delivered remotely across the UK from our City of London base.

Practical, not just theoretical

We design policy that staff can actually work with day to day, not rules so strict they get worked around.

Transparent, per-user pricing

Clear pricing with access control management built in, not sold separately as an unpredictable add-on.

Access Control vs. a Password Policy Document

A password policy document tells staff what they should do. Cyber essentials access control, properly implemented, makes it technically required — minimum password standards enforced by the system itself, multi-factor authentication that can't simply be skipped, administrative rights genuinely separated from everyday accounts, and leaver access removed the day someone departs rather than whenever someone happens to notice. The comparison that matters isn't policy versus no policy — it's whether access control is actually enforced by your systems, or relies entirely on staff remembering and choosing to follow a document most people read once, if at all. A written policy also can't tell you, months later, whether a leaver's account is still active or whether an intern's temporary access was ever actually revoked — only an enforced, reviewed system can answer those questions with certainty rather than a shrug. Access control, MFA and regular reviews are included as standard on our managed IT plans, from £20 per user per month.

Access Control Coverage Across the UK

We configure and manage access control remotely for businesses across the UK, from our base in the City of London. Password policy enforcement, MFA rollout and access reviews are handled remotely, with on-site visits available in London when hardware genuinely needs physical attention.

Sector mix: our clients span professional services firms handling sensitive client data, retailers with point-of-sale and till access, and growing SMEs preparing for their first Cyber Essentials certification or a renewal.

Getting started: a free consultation is the first step, whether your current access control needs a full overhaul or simply an honest review against the standard.

Coverage

UK-Wide, Remote-First

From £20 per user per month, with 24/7 monitoring, EDR protection and a 99% SLA guarantee wherever your business is based.

Compliance We Support
GDPRCyber EssentialsCyber Essentials PlusUK Electronic Commerce Regulations
Service

Cyber Essentials Access Control

cyber essentials access control

Enforced password policy, multi-factor authentication and least-privilege access, reviewed regularly against Cyber Essentials requirements.

Related

Managed Cyber Security Services

managed cyber security services uk

Access control sits alongside our wider managed cyber security services, covered in more depth on that page.

Frequently Asked Questions

Got questions about Cyber Essentials access control? We've answered the most common ones below. If you need more detail, get in touch.

What does Cyber Essentials actually require for access control?

Enforced password policy, multi-factor authentication on cloud services and remote access, least-privilege account provisioning, separated administrative rights, and prompt removal of access for leavers.

Is a written password policy enough to pass Cyber Essentials?

No, the assessment looks for evidence that requirements are technically enforced, not simply documented and hoped for.

Do all staff need multi-factor authentication?

Cyber Essentials expects MFA on cloud services and remote access at minimum, and we typically recommend it as widely as practical across your systems.

How much does access control management cost?

Access control, MFA enforcement and regular reviews are included as standard across our managed IT plans, from £20 per user per month.

How quickly is access removed when someone leaves?

Leaver deprovisioning is part of a documented offboarding process, so access is typically removed the same day someone's departure is confirmed.

Can you help with a wider Cyber Essentials certification, not just access control?

Yes, access control support sits alongside our wider Cyber Essentials certification support, covering all five technical control areas the assessment requires.

What if some of our staff resist a stricter access policy?

We design policy that's workable day to day, not so strict that staff look for workarounds, and explain the reasoning so it's understood rather than resented.

Do you review administrative access specifically?

Yes, administrative rights are reviewed separately and regularly, since they carry the greatest risk if a compromised account has broad access.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

12
  • Database Reporting

Custom Reporting & Dashboard Development Cost in the UK in 2026

12 Apr, 2026

Read more
18
  • Internet & Connectivity

How to Set Up Quality of Service for Business Applications

18 Mar, 2026

Read more
27
  • Cloud Backup

Multi-Cloud Backup: Spreading Risk Across Providers

27 Feb, 2026

Read more

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

23
  • AI

AI Code Review: A UK Development Team's Guide to Using AI Without Introducing Technical Debt in 2026

23 Aug, 2026

AI code review has moved from novelty to default in UK development teams inside about eighteen months. Pull requests now arrive pre-annotated by a model,...

Read more
22
  • Google Ads & PPC

Google Ads Budget Waste: A UK Business Guide to Cutting Wasted PPC Spend in 2026

22 Aug, 2026

Google Ads wasted spend is the single most recoverable line item in most UK SME marketing budgets. It is not a strategy problem and it is rarely a creative...

Read more
21
  • Cyber Security

Cyber Essentials Certification: A UK Business Step-by-Step Guide to Passing First Time in 2026

21 Aug, 2026

Cyber Essentials certification has quietly become a commercial requirement rather than a security badge. It is mandatory for most central government contracts...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.