Sentinel Information Technologies

Security · Hardening

Default settings are not secure

Hardening of servers, Active Directory, network devices and firewalls against CIS baselines; admin accounts, password policy, protocols and rule sets are reviewed and corrected.

  • Reference

    CIS Benchmarks

  • Scope

    Servers · AD · Network

  • Output

    Compliance report

Ransomware usually walks in through a door left open, not a zero-day

Legacy protocols, shared admin passwords, shares open to everyone and firewall rules untouched for years: hardening closes these doors. Sentinel adapts CIS baselines to your environment, applies the changes after testing and documents them with a compliance report.

  • Identity and access

    Reducing privileged accounts, LAPS, tiered administration, mandatory MFA.

  • System hardening

    Disabling legacy protocols such as SMBv1 and NTLMv1, service and port cleanup, logging.

  • Network and firewall

    Rule set cleanup, segmentation, restricting management interfaces.

Hardening areas

Areas chosen in the scope document

  • Active Directory

    Admin tiers, LAPS, GPO baseline, Kerberos

  • Windows Server

    CIS baseline, protocols, services, auditing

  • Linux servers

    SSH, sudo, package and service hardening

  • Virtualization

    vSphere / Hyper-V management access and network separation

  • Firewall

    Rule cleanup, geo-IP, IPS profiles

  • Network devices

    Management VLAN, SNMPv3, passwords and firmware

  • Endpoints

    Local admin, USB, script restrictions

  • Compliance report

    Before/after score and remaining exceptions

Process

From assessment to compliance report

Hardening flow

Assessment

CIS score and gaps

Priority

Risk and impact

Implementation

Test group, waves, exceptions

Validation

Application testing

Compliance report

Before / after

Settings that may affect applications are tried in a test group first; exceptions are documented with their rationale.

CIS Benchmarks · Microsoft Security Baselines

Packages

Three packages by scope

  • Focused

    Active Directory

    Hardening the identity infrastructure

    Fixed price

    Project based

    • Privileged account analysis
    • LAPS and tiered administration
    • GPO baseline
    • Compliance report
    Request a quote
  • Most popular

    Comprehensive

    Infrastructure

    AD, servers, virtualization and firewall

    By scope

    Project based

    • CIS compliance across all layers
    • Rule set cleanup
    • Implementation in waves
    • Before/after report
    Request a quote
  • Ongoing

    Compliance Tracking

    Quarterly reassessment

    Annual

    12 months

    • Quarterly CIS scan
    • Drift detection and correction
    • Baseline for new systems
    • Annual compliance report
    Request a quote

Frequently asked questions

The most common questions about hardening

  • Risky settings are applied in a test group first; exceptions are defined and documented for applications that need legacy protocols. A rollback plan is ready at every step.

  • The compliance percentage calculated against the CIS Benchmark checklist; the before and after comparison is in the report.

  • Yes. The findings in the report are turned into a remediation plan and implemented; verified by retest.

  • Changes such as password policy and MFA affect users; announcements and a transition period are planned.

  • The Active Directory package 2 weeks; the infrastructure package 4 to 8 weeks depending on scope.

Free IT Health Check

See your infrastructure through a sentinel’s eyes.

Current state assessment, risk inventory and a prioritized roadmap. No commitment.

Cookie preferences

We use cookies that are necessary for the site to work. Measurement and analytics cookies are enabled only with your consent. See our cookie policy for details. Cookie policy