Using your normal login for admin tasks? That is a Cyber Essentials fail waiting to happen
Cyber Essentials requires administrator accounts to be separate from standard user accounts, and most small businesses skip this without realising why it matters.
Here's a scenario that plays out often enough to be a pattern, not a one-off: one laptop gets infected with malware after someone clicks a convincing-looking invoice attachment. Because the person who clicked it is logged in with an account that also has full administrator rights across the company's systems, the malware inherits those same rights instantly. What should have been one infected laptop becomes a foothold across the network, because there was no separation between "browsing email" and "having the keys to everything."
Cyber Essentials asks a direct question under CE3 User Access Control: are administrator accounts separate from standard user accounts? Most small businesses, when they actually check, find the answer is no, because nobody set it up any other way from the start.
Why the same login for everything is a problem
When someone uses one account for both day-to-day work and administrative tasks, like installing software, changing settings, or managing other users, every piece of malware, every phishing click, every compromised session inherits whatever privileges that account holds. If the account has admin rights, the malware does too, automatically, without needing to do anything clever to escalate its access.
Separating the two means day-to-day work happens on an account with standard user permissions, and administrative tasks require switching to a dedicated admin account, used only for that purpose and nothing else. If the standard account gets compromised, which is statistically far more likely since it's the one used for email and web browsing, the damage stays contained to what a standard user can do, not what an administrator can do.
How this typically gets overlooked
In a small business with one or two people handling IT informally, it's common for that person to simply use their normal everyday login for admin work too, because setting up a second account feels like unnecessary friction when you're the only one who needs admin access anyway. The risk doesn't feel real until the everyday account, the one used for email and browsing the web, is the one that gets compromised.
It also gets overlooked because most cloud platforms default new accounts to whatever permission level was convenient at setup time, often full admin, rather than nudging businesses toward a least-privilege structure from day one. Setting accounts up correctly the second time, after the fact, takes more deliberate effort than setting them up correctly from the start would have.
Setting this up properly
Create a dedicated administrator account for each person who genuinely needs admin rights, separate from the account they use for daily work. The admin account should never be used to check email, browse the web, or do anything other than the specific administrative task at hand. Log in to it, do the task, log out.
For most cloud platforms, Microsoft 365, Google Workspace, AWS, this is a matter of creating a second user account and assigning it administrator permissions while demoting the everyday account to standard user. It takes longer to describe than to actually do.
This works alongside restricting standard accounts to only what people need for their job, since separating admin from standard accounts is only half the picture if the standard accounts themselves still have more access than necessary.
Frequently asked questions
Does this apply to a business with only one or two people? Yes, Cyber Essentials' requirement doesn't have a business size exemption, and the risk of a compromised everyday account inheriting admin rights is the same regardless of company size.
Is it inconvenient to keep switching between two accounts? There's a small amount of friction, logging out and back in for admin tasks, but it's minor compared to the friction of dealing with a compromised system that had unrestricted access.
What counts as an "administrative task" that requires the separate account? Installing software, changing system or security settings, managing other user accounts, and accessing infrastructure-level controls all count; routine work like email, documents, and normal application use doesn't need admin rights at all.
Can the same person have both an admin account and a standard account? Yes, that's exactly the intended setup; one person can hold both, used for different purposes, rather than one account doing both jobs.
Will an assessor ask to see proof this separation exists? Assessors typically ask about your account structure and may request evidence such as a list of accounts and their assigned permission levels.
Run a free scan of your domain and your CE Readiness checklist will cover this alongside the rest of CE3 User Access Control, ready before your assessor asks: olimpio.io/free-scan