Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Practice Area5 services in this area
Hardening and Configuration Review

Hardening and Configuration Review

Most breaches start with a setting someone left on the default. We compare your live configurations against trusted benchmarks, then hand you a clear, prioritised path to a hardened estate.

How We Work

Attackers rarely need a fancy exploit when a storage bucket is public, a firewall rule allows any-any, or a domain controller still trusts weak protocols. Hardening and configuration review measures your real settings against CIS Benchmarks, DISA STIGs and vendor baselines, then separates the changes that matter from the noise. You get evidence of where you stand, a scorecard you can track over time, and runbooks your team can actually apply. We cover cloud, operating systems, firewalls, Active Directory, and your database and web server tiers.

Jump to the 5 Services

Services in Hardening and Configuration Review

Benchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers

5 services in this practice area

Measured Against

NIST SP 800-53MSMicrosoftSecurity BaselinesMITRE ATT&CKVENDORHardening GuidesCISAWS FoundationsCISMicrosoft Azure FoundationsCISGoogle Cloud Platform FoundationsCISKubernetes

What We Run

CIS-CAT ProProwlerTrivygcloud and Cloud Asset InventoryOpenSCAPAnsibleNessus (compliance audit)Nmap

Every one of these is scoped, run and reported by the same team. See All Practice Areas

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How is a configuration review different from a penetration test?

A penetration test proves what an attacker can do by exploiting weaknesses in a defined scope. A hardening and configuration review works from the other direction: it reads your actual settings, compares them line by line with a trusted benchmark, and tells you every place they fall short, whether or not an exploit exists today. The review finds the quiet misconfigurations a timeboxed test may never reach, such as an unused firewall rule, a weak domain controller policy or an unencrypted database connection, and it gives you a scorecard you can track release after release. The two work best together. A test shows which gaps are exploitable now; a review makes sure the estate is built right so the next test finds less. Many clients run a review of cloud, Active Directory or the perimeter first, then test the systems it flags as most exposed.

Which benchmarks do you review against?

CIS Benchmarks by default, because they are specific, widely recognised by auditors and customers, and published for almost every platform we review: the CIS Foundations Benchmarks for AWS, Azure and Google Cloud, the Kubernetes benchmark, Windows and Linux benchmarks, and benchmarks for SQL Server, Oracle, MySQL, PostgreSQL, Apache, Nginx and major network devices. Where contracts or regulators call for them, we align to DISA STIGs instead or as well. We add each vendor's own hardening guidance and map findings to NIST SP 800-53 and MITRE ATT&CK so they carry weight in a compliance programme and in a threat discussion. A benchmark is a starting point, not a verdict: we mark settings that do not fit how your systems are meant to work as accepted deviations with a reason, rather than forcing every recommendation through regardless of the operational cost.

Will a review disrupt production or change our systems?

No. Every review in this practice works from read-only access and exported configuration. Cloud accounts are assessed through read-only roles, firewall rule bases from exported configurations, Active Directory through read-only collection with any heavier queries scheduled with you, and databases and web servers from configuration and evidence rather than intrusive testing. We do not change a setting, a rule or a policy. Where a finding needs confirming from outside, such as whether a port is really exposed to the internet, that check is limited, agreed in advance and non-destructive. Your team applies every fix through its own change process, using the ordered runbook we provide, so nothing reaches production without your approval. That approach is also why a review can run during normal business hours on live environments without a change freeze, which a full penetration test sometimes cannot.

Where should we start if we cannot review everything?

Start where one misconfiguration exposes the most. For cloud-first companies that is usually the cloud accounts, because a public storage bucket or an over-privileged role can expose customer data directly from the internet. For organisations running Windows networks it is Active Directory, since the attack path from an ordinary account to domain admin decides how far any intrusion can spread. Where the internet edge is the main concern, a firewall and perimeter review comes first. Operating system builds are best reviewed through the golden images they come from, because fixing an image fixes every host built from it, and database and web server tiers follow once the paths to them are closed. We usually recommend one surface first, then a second after remediation, and we confirm the order on the scoping call against what your customers, auditors and incident history say matters most.

What do we receive, and how long does a review take?

Each review delivers a findings report that ranks issues by real exposure rather than benchmark order, a scorecard against the benchmark for every account, host type, device or instance in scope, a hardening runbook your team can apply, with sample automation such as Ansible or Group Policy where it helps, and a re-check report once you have remediated, so you can prove the gaps are closed. Most single-surface reviews take two to four weeks from scoping to the findings report: a few days to scope and collect configuration, a week or two of analysis and validation, and a few days to report and walk your engineers through the results. Active Directory and large multi-account cloud estates sit at the longer end. The re-check follows whenever your fixes land. We confirm the timeline and a fixed price in writing after the scoping call.

Not Sure Which of These You Need?

Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.