System Hardening and Vulnerability Scanning
Hardening removes the easy ways in; vulnerability scanning finds the ones that appear later. We do both as a repeatable process, not a one-off: baseline, scan, fix, document what cannot change, and scan again. On a recent production Linux server this took the CIS Level 1 score from 76% to 92%, with every remaining item documented as a deliberate exception.
What is included
- Hardening to CIS benchmarks for Windows Server, Linux, Microsoft 365 and browsers
- Configuration compliance scans with OpenSCAP and CIS-CAT
- Vulnerability scanning with Tenable Nessus, Qualys, Rapid7, OpenVAS or Microsoft Defender Vulnerability Management
- Linux audits with Lynis; SSH, TLS and web server hardening
- Patch compliance tracking and automatic security updates
- FIPS-approved cryptography where it will not break your applications
- File-integrity monitoring, audit logging and brute-force protection
- Exceptions documented with the reason and the compensating control
What you get
- A measured baseline, and a better score after
- Vulnerabilities found and fixed before attackers find them
- Before-and-after reports your auditors and insurers can use
One engineer handles it from start to finish, so a change requested today can be in production the next day, once change-control documentation and testing are complete.
- Baseline
- Scan
- Fix
- Document exceptions
- Re-scan
- Report
Talk to us about hardening & vulnerability management
Tell us what you need. You will hear back from the person who will do the work.