Configuration and
Hardening Review
A fully patched server behind a permissive firewall rule, running a service account with domain privilege, reports zero vulnerabilities. Configuration is where the estate is actually won or lost — and it is what automated tools most often miss.
Scope
What the review covers
Security configurations are evaluated against CERT-In benchmarks and industry best practice, identifying misconfigurations that automated tools often miss.
01
Server hardening review
Operating system baseline, service exposure, patch state, local privilege, logging and audit policy — across Windows and Linux estates.
02
Firewall configuration audit
Rule base review for shadowed, redundant and overly permissive rules, any-any exposure, unused objects, and the drift between what the diagram claims and what the device enforces.
03
Network architecture assessment
Segmentation design, trust boundaries, management-plane separation, and whether the zones on the diagram are actually enforced by a control.
04
Access control validation
Privileged access paths, service accounts, Active Directory group nesting, and the difference between the access policy grants and the access people hold.
What it finds
The four things a configuration review reliably surfaces
A rule base that grew and never shrank
Firewall rules accumulate. Nothing removes them. The review names the rules that are shadowed, the ones that are unused, and the ones whose original owner has left.
Segmentation that exists on the diagram
A zone is only a zone if something enforces it. Where a boundary is documented but not enforced, the review says so and shows the path across it.
Baselines applied once, at build time
A hardening baseline applied to a golden image and never re-checked drifts with every change, every emergency fix, and every new host built from a different template.
Privilege that outlived its reason
Service accounts with interactive logon, nested groups that grant more than anyone intended, and administrative access granted for a project that finished.
Where it fits
Standalone, or a component of the audit
Configuration and hardening review maps to the CERT-In IMP marker and can be delivered inside a CERT-In security audit, alongside the web application, network and mobile components that carry the CSM, PRO and DET markers. It is equally often bought on its own — after a migration, after a merger, or when an estate has been running long enough that nobody is certain what the firewall actually permits.
Findings are tracked to closure in Lemon, with remediation guidance written for the team that has to apply it rather than for the report.
Questions
Frequently asked
How is this different from a vulnerability assessment?
A vulnerability assessment asks what is unpatched or known-vulnerable. A configuration and hardening review asks whether what you have built is configured to resist attack — a fully patched server with a permissive firewall rule and a service account holding domain privilege has no vulnerabilities to report and a straightforward path to compromise.
Does this replace penetration testing?
No, and it is not intended to. Penetration testing establishes what an attacker can reach and do. This review establishes whether the configuration itself is sound. They answer different questions, and the findings from each tend to explain the other — a segmentation weakness found here is usually the reason a penetration test moved as far as it did.
Which benchmarks do you assess against?
CERT-In benchmarks and industry best practice, including CIS baselines where they apply to the platform. Where your organisation maintains its own hardening standard, the review is run against that as well — a finding that you have diverged from your own published standard is more actionable than one against a generic baseline.
Does it map to CERT-In requirements?
Yes. Configuration and hardening review maps to the CERT-In IMP marker within a CERT-In security audit. It can be delivered as a component of that audit or as a standalone engagement.
Do you need production access?
Configuration review is largely evidence-based: exported configurations, rule bases, directory exports and baseline reports. Where live validation of a segmentation boundary is needed, that is agreed in scoping and performed where it is safe and authorised.
Find out what your configuration actually permits
Scoping starts with your rule base, your baselines and your directory — not with a questionnaire.
Request a Scoping Call