Hardening and Configuration Review
Most breaches start with a setting someone left on the default. We compare your live configurations against trusted benchmarks, then hand you a clear, prioritised path to a hardened estate.
How We Work
Attackers rarely need a fancy exploit when a storage bucket is public, a firewall rule allows any-any, or a domain controller still trusts weak protocols. Hardening and configuration review measures your real settings against CIS Benchmarks, DISA STIGs and vendor baselines, then separates the changes that matter from the noise. You get evidence of where you stand, a scorecard you can track over time, and runbooks your team can actually apply. We cover cloud, operating systems, firewalls, Active Directory, and your database and web server tiers.
Jump to the 5 ServicesServices in Hardening and Configuration Review
Benchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers
5 services in this practice area
- 01Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- 02Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- 03Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- 04Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- 05Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks
Measured Against
NIST SP 800-53MSMicrosoftSecurity BaselinesMITRE ATT&CKVENDORHardening GuidesCISAWS FoundationsCISMicrosoft Azure FoundationsCISGoogle Cloud Platform FoundationsCISKubernetesWhat We Run
CIS-CAT ProProwlerTrivygcloud and Cloud Asset InventoryOpenSCAPAnsibleNessus (compliance audit)NmapEvery one of these is scoped, run and reported by the same team. See All Practice Areas
How is a configuration review different from a penetration test?
A penetration test proves what an attacker can do by exploiting weaknesses in a defined scope. A hardening and configuration review works from the other direction: it reads your actual settings, compares them line by line with a trusted benchmark, and tells you every place they fall short, whether or not an exploit exists today. The review finds the quiet misconfigurations a timeboxed test may never reach, such as an unused firewall rule, a weak domain controller policy or an unencrypted database connection, and it gives you a scorecard you can track release after release. The two work best together. A test shows which gaps are exploitable now; a review makes sure the estate is built right so the next test finds less. Many clients run a review of cloud, Active Directory or the perimeter first, then test the systems it flags as most exposed.
Which benchmarks do you review against?
CIS Benchmarks by default, because they are specific, widely recognised by auditors and customers, and published for almost every platform we review: the CIS Foundations Benchmarks for AWS, Azure and Google Cloud, the Kubernetes benchmark, Windows and Linux benchmarks, and benchmarks for SQL Server, Oracle, MySQL, PostgreSQL, Apache, Nginx and major network devices. Where contracts or regulators call for them, we align to DISA STIGs instead or as well. We add each vendor's own hardening guidance and map findings to NIST SP 800-53 and MITRE ATT&CK so they carry weight in a compliance programme and in a threat discussion. A benchmark is a starting point, not a verdict: we mark settings that do not fit how your systems are meant to work as accepted deviations with a reason, rather than forcing every recommendation through regardless of the operational cost.
Will a review disrupt production or change our systems?
No. Every review in this practice works from read-only access and exported configuration. Cloud accounts are assessed through read-only roles, firewall rule bases from exported configurations, Active Directory through read-only collection with any heavier queries scheduled with you, and databases and web servers from configuration and evidence rather than intrusive testing. We do not change a setting, a rule or a policy. Where a finding needs confirming from outside, such as whether a port is really exposed to the internet, that check is limited, agreed in advance and non-destructive. Your team applies every fix through its own change process, using the ordered runbook we provide, so nothing reaches production without your approval. That approach is also why a review can run during normal business hours on live environments without a change freeze, which a full penetration test sometimes cannot.
Where should we start if we cannot review everything?
Start where one misconfiguration exposes the most. For cloud-first companies that is usually the cloud accounts, because a public storage bucket or an over-privileged role can expose customer data directly from the internet. For organisations running Windows networks it is Active Directory, since the attack path from an ordinary account to domain admin decides how far any intrusion can spread. Where the internet edge is the main concern, a firewall and perimeter review comes first. Operating system builds are best reviewed through the golden images they come from, because fixing an image fixes every host built from it, and database and web server tiers follow once the paths to them are closed. We usually recommend one surface first, then a second after remediation, and we confirm the order on the scoping call against what your customers, auditors and incident history say matters most.
What do we receive, and how long does a review take?
Each review delivers a findings report that ranks issues by real exposure rather than benchmark order, a scorecard against the benchmark for every account, host type, device or instance in scope, a hardening runbook your team can apply, with sample automation such as Ansible or Group Policy where it helps, and a re-check report once you have remediated, so you can prove the gaps are closed. Most single-surface reviews take two to four weeks from scoping to the findings report: a few days to scope and collect configuration, a week or two of analysis and validation, and a few days to report and walk your engineers through the results. Active Directory and large multi-account cloud estates sit at the longer end. The re-check follows whenever your fixes land. We confirm the timeline and a fixed price in writing after the scoping call.
Not Sure Which of These You Need?
Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.
Related Reading
Articles on Hardening and Configuration Review
Elsewhere
Other Practice Areas
- ComplianceCertifications and Privacy Programmes Across 13 Frameworks
- VAPTManual, Exploit-Driven Penetration Testing Across 7 Surfaces
- Secure Code Review (SCR)Manual, line-by-line review of your most sensitive code paths, backed by SAST triage.
- Software Composition Analysis (SCA)Know every third-party and open-source dependency you ship, and every risk it carries.
- Managed ServicesOngoing Offensive, Defensive and Advisory Security Run by Our Team