System hardening: reduce your attack surface

Servers, laptops, network devices and cloud systems usually arrive with settings chosen for convenience. Unused services run, extra network ports stay open and default passwords stay in place. Each of these is a possible way in for an attacker. System hardening is the work of switching off what you do not need and locking down the rest.

Why this deserves management attention

Many successful attacks need no clever technique. They simply use a default setting that nobody changed. Hardening is one of the cheapest ways to reduce that risk, and auditors and regulators routinely ask for evidence that it has been done.

What good hardening looks like

Start by removing what is not needed: unused services, ports, user accounts and software. Less running software means fewer things to attack and fewer things to patch.

Next, apply a secure configuration baseline, which is a written standard for how each type of system should be set up. The CIS Benchmarks (free configuration guides from the Center for Internet Security) and vendor security guides are good starting points. Record any deliberate exceptions and the reason for each.

Keep operating systems, firmware and applications patched on a regular schedule. Give administrator rights only to people who need them, require strong authentication and change credentials regularly.

Finally, switch on audit logging and send the logs to your SIEM (the system that collects and analyzes security events) or your security operations center. That way, unusual activity gets noticed.

Making sure it stays that way

Settings drift over time as systems are updated and staff apply quick fixes. Regular configuration reviews and penetration testing confirm that the baseline is still in place and still doing its job.