Security · Hardening
Default settings are not secure
Hardening of servers, Active Directory, network devices and firewalls against CIS baselines; admin accounts, password policy, protocols and rule sets are reviewed and corrected.
Reference
CIS Benchmarks
Scope
Servers · AD · Network
Output
Compliance report
Ransomware usually walks in through a door left open, not a zero-day
Legacy protocols, shared admin passwords, shares open to everyone and firewall rules untouched for years: hardening closes these doors. Sentinel adapts CIS baselines to your environment, applies the changes after testing and documents them with a compliance report.
Identity and access
Reducing privileged accounts, LAPS, tiered administration, mandatory MFA.
System hardening
Disabling legacy protocols such as SMBv1 and NTLMv1, service and port cleanup, logging.
Network and firewall
Rule set cleanup, segmentation, restricting management interfaces.
Hardening areas
Areas chosen in the scope document
Active Directory
Admin tiers, LAPS, GPO baseline, Kerberos
Windows Server
CIS baseline, protocols, services, auditing
Linux servers
SSH, sudo, package and service hardening
Virtualization
vSphere / Hyper-V management access and network separation
Firewall
Rule cleanup, geo-IP, IPS profiles
Network devices
Management VLAN, SNMPv3, passwords and firmware
Endpoints
Local admin, USB, script restrictions
Compliance report
Before/after score and remaining exceptions
Process
From assessment to compliance report
Hardening flow
Assessment
CIS score and gaps
Priority
Risk and impact
Implementation
Test group, waves, exceptions
Validation
Application testing
Compliance report
Before / after
Settings that may affect applications are tried in a test group first; exceptions are documented with their rationale.
CIS Benchmarks · Microsoft Security Baselines
Packages
Three packages by scope
Focused
Active Directory
Hardening the identity infrastructure
Fixed price
Project based
- Privileged account analysis
- LAPS and tiered administration
- GPO baseline
- Compliance report
- Most popular
Comprehensive
Infrastructure
AD, servers, virtualization and firewall
By scope
Project based
- CIS compliance across all layers
- Rule set cleanup
- Implementation in waves
- Before/after report
Ongoing
Compliance Tracking
Quarterly reassessment
Annual
12 months
- Quarterly CIS scan
- Drift detection and correction
- Baseline for new systems
- Annual compliance report
Frequently asked questions
The most common questions about hardening
Risky settings are applied in a test group first; exceptions are defined and documented for applications that need legacy protocols. A rollback plan is ready at every step.
The compliance percentage calculated against the CIS Benchmark checklist; the before and after comparison is in the report.
Yes. The findings in the report are turned into a remediation plan and implemented; verified by retest.
Changes such as password policy and MFA affect users; announcements and a transition period are planned.
The Active Directory package 2 weeks; the infrastructure package 4 to 8 weeks depending on scope.
Free IT Health Check
See your infrastructure through a sentinel’s eyes.
Current state assessment, risk inventory and a prioritized roadmap. No commitment.