Service · Cybersecurity

System hardening

Windows, Microsoft 365, a NAS or a Linux server leave the factory set up to work first time, not to withstand an attack. Protocols from twenty years ago left on for compatibility, Office macros that run straight from an email, administrator accounts with the same name and password on every machine, print services listening on servers that never print. None of it appears on an invoice, but it is exactly what attackers' automated tools exploit once they are inside. Hardening means removing what is not needed and tightening what remains, following recognised public guidance: the CCN-STIC guides from Spain's National Cryptologic Centre, the reference for the ENS, and the CIS benchmarks. It is one of the best returns on effort in security, because it almost never requires buying anything.

CCN-STIC and CIS
public guides as the reference
€0
in new licences in most cases
In stages
with rollback for every change
Baseline
documented and verifiable

What falls within the scope of this service

We do not apply a whole guide blindly. Each recommendation is weighed against your applications, because some break older software you still rely on.

Pin down the details with one of our engineers

Windows workstations

SMBv1, LLMNR and NetBIOS switched off, macros from internet downloads blocked, attack surface reduction rules, restricted PowerShell and unique local admin passwords through LAPS.

Servers

Only the roles and services required, print spooler disabled where nothing is printed, remote desktop restricted and using network level authentication, and extended audit logging.

Active Directory

A review of privileged accounts, groups with more members than they should have, old delegations and service accounts with passwords that never expire. Admin accounts separated from everyday accounts.

Microsoft 365

Legacy authentication disabled, user consent to third-party apps restricted, limits on external mail forwarding and secure settings for SharePoint and Teams.

Linux and NAS

Key-only SSH, no direct root login, a local firewall, automatic security updates and NAS web panels kept off the internet.

Baseline

Every setting applied is recorded in a document and in policies or templates, so a new machine starts life already hardened and any unauthorised change is spotted.

How the engagement unfolds, one stage at a time

First we measure how far each system is from the guide. Then we apply changes in small groups to see whether anything complains.

01

Measurement

An automated assessment of workstations, servers and Microsoft 365 against the chosen guide, giving a starting score.

02

Selection

Together we decide which recommendations to apply, which to postpone and which do not fit, and why.

03

Application

Group Policy, Intune or scripts, group by group, starting with the lowest-impact changes.

04

Verification

A fresh measurement, a documented baseline and periodic checks to catch drift.

Much of what an attacker uses is already installed on your machines. PowerShell, remote desktop, WMI and Windows' own admin tools let someone move through the network without downloading anything suspicious. Hardening does not take those tools away from administrators, but it does take them away from everyone else.

Common questions

The CCN-STIC guides published by CCN-CERT are public, written in Spanish, kept up to date and serve as the reference for ENS compliance. For a public body or a supplier to the administration, aligning hardening with them makes the audit simpler. They are just as useful for other companies, and we combine them with the CIS benchmarks where that helps.

It could, which is why we work in groups with rollback ready. Typical culprits are old programs that depend on SMBv1, Excel macros the accounts team cannot live without, or elderly printers. They show up in the pilot and are handled with a specific, documented exception rather than by switching the measure off for everyone.

If the baseline lives in policies, it maintains itself. We recommend a quarterly measurement to catch drift, a yearly review against the latest version of the guide and another after any major change, such as a server migration.

There the approach changes: if the machine controlling a production line cannot be altered, we protect it from outside through network segmentation, access control and monitoring. We harden what we can and isolate what we cannot.

Close what comes open out of the box

Tell us how many servers and workstations you have, which operating systems they run and whether you use Microsoft 365. We will propose an initial measurement against a reference guide.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.