Englishالعربية Soon
Under attack?
Configuration management & hardening

Most systems are not breached. They are found already open.

Secure baselines defined for every platform you run, current configuration measured against them, deviations closed through your change process, and drift monitored continuously so the position holds after we leave.

Benchmarked against
CIS Benchmarks
Vendor hardening guidance
ISO 27001 Annex A
PCI DSS configuration requirements
Your own build standards

Nothing is applied blind. Every baseline is tuned against what your applications require, tested outside production, and rolled out in waves with a defined roll-back.

Why it matters

Four reasons this outranks most of what gets funded first

Attackers exploit configuration more often than code

A default credential, an exposed management interface or an over-permissive share requires no exploit development at all.

Patching does not fix configuration

A fully patched server with default settings and unnecessary services running is still an easy target.

Auditors ask for it by name

ISO 27001, PCI DSS and central bank requirements all expect documented baselines and evidence of compliance with them.

Drift is invisible without measurement

Nobody announces that they disabled a control to resolve a ticket. It only surfaces when something is measured against a standard.

The cycle

Six stages, and the last one is what makes it worth doing

A hardening project that ends at remediation buys you a good month. Enforcement and drift monitoring are what buy you a year.

01
Discover
Every asset in scope enumerated, including the ones missing from the inventory. Platform, version, role and owner recorded, because a baseline cannot be applied to a host nobody knows about.
02
Define the baseline
A hardening standard per platform, derived from CIS benchmarks and vendor guidance, then adjusted for what your applications actually need. A benchmark applied unmodified breaks production.
03
Assess
Current configuration measured against the baseline, per host and per setting, producing a compliance percentage and a specific list of deviations rather than a pass or fail.
04
Remediate
Deviations closed in waves, tested in a non-production environment first, applied through your change process, with roll-back defined before anything is changed.
05
Enforce
Baselines pushed and held through group policy, configuration management or image builds, so a rebuilt host comes back hardened rather than default.
06
Monitor drift
Continuous comparison against the baseline. Configuration decays, through troubleshooting, exceptions and rebuilds, and drift is the reason last year’s hardening does not hold.
Coverage

Six platform families, each with its own baseline

One standard per platform and role. A domain controller and a web server share an operating system and almost nothing else.

Servers & operating systems
Windows Server, Linux distributions, hypervisors
Services and roles, account policy, audit settings, filesystem permissions, unnecessary features removed
Workstations & endpoints
Windows, macOS, managed laptops
Local admin rights, script execution policy, USB and peripheral control, disk encryption, screen lock
Databases
Relational and NoSQL platforms
Default accounts, listener configuration, encryption at rest and in transit, privilege grants, audit logging
Network devices
Switches, routers, firewalls, wireless
Management plane access, protocol hygiene, unused ports, logging destinations, firmware currency
Cloud & containers
IaaS, PaaS, Kubernetes, images
Identity and role scope, storage exposure, network policy, image provenance, runtime restrictions
Applications & middleware
Web servers, application servers, runtimes
Default installs and sample content, error verbosity, TLS configuration, session and header settings
Reporting

A percentage, and the list behind it

Compliance against baseline is one of the few security metrics that is genuinely measurable, comparable over time and understandable by a board.

Per-host compliance
Every asset scored against its baseline, so the outliers are visible instead of averaged away.
Per-setting deviation
Which control failed, on which hosts, with the required value and the current one.
Exception register
Deviations accepted for a documented reason, with an owner and an expiry date rather than silence.
Drift over time
Whether the estate is improving or decaying, tracked per platform and per team.
Audit evidence
Baselines, assessment results and exception approvals in the form ISO 27001 and PCI DSS assessors ask for.
Engagement model

One-off hardening

A defined engagement: baselines authored per platform, the estate assessed, remediation planned in waves and delivered with your team, and the standards handed over documented.

Talk to an engineer →

Engagement model

Continuous programme

Baselines maintained as vendors change them, the estate reassessed on a cycle, drift alerted on, exceptions governed, and a compliance figure reported every month.

Managed services →

Related

Work that sits next to it

Vulnerability management

Patching and hardening are the two halves of exposure. Doing one without the other leaves the estate open.

Vulnerability assessment

Configuration audits against benchmarks are part of the same scanning cycle.

Penetration testing

Testing establishes which of the remaining deviations an attacker could actually use.

Measure one platform first.

We assess your server estate against a benchmark and give you a compliance figure and the deviation list behind it. It is usually lower than expected.