Service · Cybersecurity

System hardening

A system shipped with default settings is tuned to work anywhere, not to hold out at your premises. Demonstration accounts still live, legacy protocols accepted just in case, shares open to every user, services listening on the network that nobody has used in years: correcting those costs nothing and closes a large share of the routes an attacker takes once inside. Hardening is the security work that needs the least money and the most method.

Zero
additional licence cost
ANSSI
configuration guidance as reference
In batches
a handful of settings at a time
Rollback
prepared for every change

Where this service reaches

We apply published guidance, ANSSI documents and recognised configuration baselines, while leaving out anything that would break a line-of-business tool. Hardening applied wholesale without thought stops more users than attackers.

Put your scope to an engineer

Windows and Linux servers

Unused roles and services removed, legacy protocols disabled, administration accounts separated, and remote connections restricted to the addresses that genuinely need them.

Workstations

Macros from the internet blocked, the local firewall configured, unnecessary scripting engines disabled and the execution paths favoured by booby-trapped attachments closed off.

Directory

The pivot of nearly every attack. We revisit delegations, service accounts whose password has not moved since installation, administration groups that grew too wide, and settings inherited from an environment long gone.

Mail

Sender authentication through SPF, DKIM and DMARC, executable attachments blocked, and detection of automatic forwarding rules quietly added to a mailbox.

Sensitive environments

For a medical practice or a team handling health information we go further: encryption everywhere, short screen lock, tracked access to records and a reception workstation kept apart from the rest.

Documenting the gaps

What we did not harden, why, and what it would take to lift the constraint. It is usually a line-of-business tool demanding an old setting, and the question then belongs with its vendor.

The way an engagement runs

Each batch of settings is applied to a reference group before the rest, and the previous configuration is kept so a rollback is immediate.

01

Measurement

Your current configuration compared with the chosen baselines. The report shows the gap, workstation by workstation and server by server.

02

Selection

Together we set aside the settings incompatible with your business software and rank the remainder by real security gain.

03

Batch application

Reference group, a few days of observation, then extension. Settings touching printing, card readers or scanners call for the most caution.

04

Keeping it

A periodic check for drift, because a rebuilt machine, a major update or an installation done in a hurry tends to bring the defaults back.

Hardening is the one security measure that appears on no invoice. It cannot be bought, only done. That is also why it gets postponed so often: nothing reminds you, no subscription comes up for renewal, and it only becomes visible on the day a compromised machine leads nowhere because the usual routes were shut.

Questions and answers

That is the main risk, which is why nothing goes in all at once. Each batch passes first over a reference group chosen with you, and older software, often in a back office or a laboratory, is tested first. The rollback is prepared before the change, not improvised afterwards.

Yes, because configuration drifts on its own. A rebuilt machine, a major update, a setting reset to help somebody out on a Friday evening: within a year the gap has reopened. A check once or twice a year is enough to close it before it becomes a project again.

Yes, in two ways. Hosting itself has to sit with a provider certified for health data, which is a contractual matter rather than a configuration one. On the workstations and servers we tighten access tracking, lock timings and separation, and we document each measure for your compliance file.

No. We work through a named account, activated for the length of the work and logged in your own systems. If you prefer, one of your administrators shares their screen and applies the changes while we guide them; the outcome is the same and the audit trail stays entirely yours.

Close the doors you already have

Tell us which systems you run, their versions and any delicate business software. We will propose a first batch of settings and a timetable.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.