Windows and Linux servers
Unused roles and services removed, legacy protocols disabled, administration accounts separated, and remote connections restricted to the addresses that genuinely need them.
A system shipped with default settings is tuned to work anywhere, not to hold out at your premises. Demonstration accounts still live, legacy protocols accepted just in case, shares open to every user, services listening on the network that nobody has used in years: correcting those costs nothing and closes a large share of the routes an attacker takes once inside. Hardening is the security work that needs the least money and the most method.
We apply published guidance, ANSSI documents and recognised configuration baselines, while leaving out anything that would break a line-of-business tool. Hardening applied wholesale without thought stops more users than attackers.
Unused roles and services removed, legacy protocols disabled, administration accounts separated, and remote connections restricted to the addresses that genuinely need them.
Macros from the internet blocked, the local firewall configured, unnecessary scripting engines disabled and the execution paths favoured by booby-trapped attachments closed off.
The pivot of nearly every attack. We revisit delegations, service accounts whose password has not moved since installation, administration groups that grew too wide, and settings inherited from an environment long gone.
Sender authentication through SPF, DKIM and DMARC, executable attachments blocked, and detection of automatic forwarding rules quietly added to a mailbox.
For a medical practice or a team handling health information we go further: encryption everywhere, short screen lock, tracked access to records and a reception workstation kept apart from the rest.
What we did not harden, why, and what it would take to lift the constraint. It is usually a line-of-business tool demanding an old setting, and the question then belongs with its vendor.
Each batch of settings is applied to a reference group before the rest, and the previous configuration is kept so a rollback is immediate.
Your current configuration compared with the chosen baselines. The report shows the gap, workstation by workstation and server by server.
Together we set aside the settings incompatible with your business software and rank the remainder by real security gain.
Reference group, a few days of observation, then extension. Settings touching printing, card readers or scanners call for the most caution.
A periodic check for drift, because a rebuilt machine, a major update or an installation done in a hurry tends to bring the defaults back.
Hardening is the one security measure that appears on no invoice. It cannot be bought, only done. That is also why it gets postponed so often: nothing reminds you, no subscription comes up for renewal, and it only becomes visible on the day a compromised machine leads nowhere because the usual routes were shut.
That is the main risk, which is why nothing goes in all at once. Each batch passes first over a reference group chosen with you, and older software, often in a back office or a laboratory, is tested first. The rollback is prepared before the change, not improvised afterwards.
Yes, because configuration drifts on its own. A rebuilt machine, a major update, a setting reset to help somebody out on a Friday evening: within a year the gap has reopened. A check once or twice a year is enough to close it before it becomes a project again.
Yes, in two ways. Hosting itself has to sit with a provider certified for health data, which is a contractual matter rather than a configuration one. On the workstations and servers we tighten access tracking, lock timings and separation, and we document each measure for your compliance file.
No. We work through a named account, activated for the length of the work and logged in your own systems. If you prefer, one of your administrators shares their screen and applies the changes while we guide them; the outcome is the same and the audit trail stays entirely yours.
Tell us which systems you run, their versions and any delicate business software. We will propose a first batch of settings and a timetable.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.