Server hardening.
Servers configured to a recognised security benchmark, audited against it, and kept there as your estate changes.
Scope
What the service coversCIS and NCSC-aligned baselines
Benchmarks applied per distribution, with justified exceptions recorded rather than silently skipped.
Access control
Key-only SSH, MFA where supported, PAM policy and sudo rights scoped to role.
Host firewalls
nftables and firewalld on every host, default-deny, with rules held in configuration management.
Audit and logging
auditd rules and central log collection, so logins and changes are traceable.
Vulnerability management
Scheduled scanning, prioritised findings and tracked remediation.
Compromised host assessment
Triage, evidence preservation and clean rebuild for systems suspected of compromise.
Method
4 stagesAssess
Current configuration scanned and reviewed against the target benchmark.
Plan
Changes, exceptions and maintenance windows agreed in writing.
Apply
Changes rolled out through Ansible, tested and reversible.
Verify
Hosts re-scanned and compliance reported per server.
You receive
- +Baseline assessment report
- +Per-host compliance scores
- +Exceptions register
- +Ansible roles for your baseline
- +Scheduled re-audit
Tooling
- Managed
- Project
- On call