Cyber security warning
21 Feb 2024

Cyber Essentials: A practical way to improve cyber security


Cyber security remains a critical and ever-evolving challenge. With the escalation of threats such as ransomware and sophisticated phishing attacks, fraudulent emails aimed at deceiving individuals into disclosing sensitive information, the stakes have never been higher.

This issue is particularly pertinent for unions, who hold the personal details of thousands of members on their systems. Trade union membership itself is deemed as special category sensitive data under Data Protection legislation, and so even more care is needed around this.

A government backed review into the most common causes of cyber security breaches over five years found that relatively simple security measures would have prevented most attacks. Consequently, the government and the National Cyber Security Centre endorsed a new security standard known as Cyber Essentials. This standard has gained traction in the private sector and is a prerequisite for all government contracts.

Although well-established in the private sector, Cyber Essentials is less recognized within the union movement. However, it’s something that unions would benefit from greatly, as it provides a practical and transparent way for organisations to tighten up and ensure a base level of Cyber Security. It also helps non-technical staff have more confidence that the necessary security measures are in place.

In my role as Virtual Chief Information Officer at the TUC, I have been actively pursuing this accreditation—a goal we have recently attained. The accreditation process proved invaluable, compelling us to conduct numerous checks that were previously overlooked, particularly with our third-party technology providers. This led to the strengthening of various areas and processes.

Cyber Essentials focuses on the implementation of five key controls that, when properly configured, can prevent many common cyber-attacks. These controls include boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management.

The accreditation is available at two levels: the basic level and Cyber Essentials Plus. The basic level requires a rigorous, human-reviewed self-assessment to verify compliance with core standards. Cyber Essentials Plus, the more advanced option, entails external vulnerability testing within your systems. Considering that unions manage extensive personal membership data, there is a compelling case for aiming for the advanced level.

I’m going to be doing some work with the TUC’s Digital labs in the coming months to explain why Cyber Essentials can be of great benefit to unions.