Service · IT security

System hardening

Operating systems and cloud services are shipped to work as smoothly as possible, not to be as secure as possible. Windows Server still speaks legacy protocols so that a twenty-year-old scanner keeps working. Microsoft 365 lets any user grant third-party apps access to their mailbox. A fresh Linux server accepts password logins, and routers and printers arrive with factory credentials. None of this is a bug as such, but together it adds up to an attack surface that can be shrunk considerably with built-in tools. Hardening means going through these settings methodically and switching off everything that is not needed. It costs no new licences, only care: you have to know which printer needs which protocol before you turn it off. Our yardsticks are recognised guidance such as the CIS Benchmarks, Microsoft security baselines and the Austrian Information Security Handbook, adapted to what actually runs in your business.

Nothing to buy
settings only, no new licences
CIS Benchmarks
and Microsoft baselines as the yardstick
Deviations
justified and documented
Regular checks
so nothing slides back

Everything this covers

We harden layer by layer, from the cloud tenant down to a single printer. Each layer is assessed, changed and then tested.

Settle the details with an engineer

Microsoft 365 and Entra ID

User consent to third-party apps only after approval, no automatic forwarding to outside addresses, audit logging on, tighter defaults for sharing and Teams guest access.

Windows workstations

Security baselines through Intune or Group Policy, internet macros blocked, a unique local admin password per device, unneeded services disabled, credential protection enabled.

Windows Server and Active Directory

Legacy protocols such as SMBv1 and NTLMv1 switched off, a tiered model for admin accounts, domain controllers locked down, stale accounts and groups removed.

Linux servers

Key-based login only, no direct root login, a host firewall, automatic security updates and a minimal package set.

Network gear and printers

Factory passwords replaced, insecure management access such as Telnet or plain HTTP closed, firmware updated, unused features like scan-to-FTP turned off.

Drift detection

Automated checks at intervals confirm the hardened settings still apply, for instance after updates or after someone changed something while troubleshooting.

Our working method

Hardening can break things if done without preparation, so we move in small, verifiable steps.

01

Gap analysis

An automated comparison of your systems against the chosen guidance. You get a list of deviations with risk and likely side effects.

02

Agreement

Together we decide what changes and where justified exceptions apply, for example an older machine controller that relies on an old protocol.

03

Changes in waves

Test systems and a pilot group first, then everyone else. Changes are made remotely in maintenance windows, with a documented rollback.

04

Verification

A re-check and handover of the exception list with reasons. Ongoing monitoring within a service plan if you wish.

The cheapest security measure is one you have already paid for. Many successful attacks on SMEs exploit settings that could have been closed with built-in tools: a legacy protocol, open app consent, a factory password on a printer. Hardening costs working time, not new software.

Frequently asked questions

If done carelessly, yes. That is why we test with a pilot group first, confirm with the software partner which protocols and rights the application needs, and document justified exceptions instead of abandoning the hardening.

The assessment takes a few days; implementation takes two to six weeks depending on findings, because we work in waves and wait after each one to see whether problems appear.

Freely available configuration recommendations for operating systems, cloud services and applications, maintained by a non-profit organisation. They are not law, but they are a widely accepted yardstick that auditors also refer to.

Mostly yes, if it is applied through Intune or Group Policy. Major feature updates can introduce new settings, though, which is why we recommend regular automated checks.

Shut what ships open by default

Give us a rough outline of your systems. We will tell you which hardening steps pay off most in comparable environments.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.