Cyber Hygiene

Foundations of Security

Cyber Hygiene

The most effective security starts with the basics. We help organisations build and sustain the cyber hygiene practices that prevent the majority of real-world attacks.

"Most breaches are preventable."

Why Cyber Hygiene Matters

Research consistently shows that over 80% of successful cyberattacks exploit basic security failures — unpatched systems, weak credentials, misconfigured services, and untrained staff. Cyber hygiene is not a checkbox exercise; it is the operational discipline that determines whether your organisation is an easy target or a hardened one.

Tools of Tech works with organisations of all sizes — from SMEs to government ministries — to assess current hygiene maturity, identify critical gaps, and implement sustainable improvement programmes aligned to CIS Controls v8.1, ENISA guidelines, NIS2, and sector-specific requirements.

Our approach is practical and risk-based: we prioritise the controls that deliver the greatest reduction in attack surface for your specific context, and we build the internal capability to sustain them over time.

Cybersecurity controls and checklist

12 Essential Controls Every Organisation Should Implement

Based on CIS Controls v8.1

Core Cyber Hygiene Controls

Control 01

Inventory & Control of Enterprise Assets

Actively manage all enterprise assets — end-user devices, network devices, servers, and cloud assets — so that only authorised devices are given access and unauthorised devices are found and prevented from gaining access.

Control 02

Inventory & Control of Software Assets

Actively manage all software on the network so that only authorised software is installed and can execute, and that unauthorised and unmanaged software is found and prevented from installation or execution.

Control 03

Data Protection

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data — ensuring sensitive information is protected throughout its lifecycle.

Control 04

Secure Configuration of Enterprise Assets & Software

Establish and maintain the secure configuration of enterprise assets and software to prevent attackers from exploiting vulnerable services and settings.

Control 05

Account Management

Use processes and tools to assign and manage authorisation to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.

Control 06

Access Control Management

Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.

Control 07

Continuous Vulnerability Management

Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise's infrastructure, in order to remediate and minimise the window of opportunity for attackers.

Control 08

Audit Log Management

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.

Control 09

Email & Web Browser Protections

Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behaviour through direct engagement.

Control 10

Malware Defences

Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.

Control 11

Data Recovery

Establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state.

Control 12

Network Infrastructure Management

Establish, implement, and actively manage network devices in order to prevent attackers from exploiting vulnerable network services and access points.

Frameworks We Work With

CIS Controls v8.1

Prioritised, actionable security controls mapped to attack patterns and maturity levels.

ENISA Guidelines

European Union Agency for Cybersecurity baseline recommendations for organisations of all sizes.

NIS2 Directive

EU-wide cybersecurity requirements for essential and important entities across critical sectors.

ISO/IEC 27001

International standard for information security management systems (ISMS).

NIST CSF 2.0

Framework for improving critical infrastructure cybersecurity, widely adopted globally.

Cyber Resilience Act

EU regulation establishing cybersecurity requirements for products with digital elements.

Start with the fundamentals.

Let us assess your current cyber hygiene posture and build a practical roadmap for improvement.

Get in Touch