Configuration Review
A detailed review of how your firewalls, servers, network devices, directories and cloud tenants are configured against security benchmarks.
- NIST CSF 2.0 functions
- Protect
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Many breaches start with a setting, not a sophisticated exploit: a firewall rule left open, a default account enabled, legacy authentication still allowed. A configuration review checks the settings of your most important systems against recognized security benchmarks and shows exactly what to change.
What you get
- Misconfigurations found before attackers use them
- Settings compared with CIS Benchmarks, Microsoft security baselines and vendor hardening guides
- Clear pass/fail results with evidence and exact remediation settings
- Hardened baselines you can apply to new systems
What we cover
- Firewall rule bases and next-generation firewall policies
- Windows and Linux servers and workstations
- Active Directory and Group Policy
- Network switches, routers and wireless controllers
- Microsoft 365, Entra ID and Azure tenants
- Databases and web servers
How we work
-
Scope and sampling
We agree which systems and device types to review and select representative samples where estates are large.
-
Configuration collection
We collect configurations using read-only access or exports provided by your team.
-
Benchmark comparison
We compare each setting with the relevant benchmark and your own security policies.
-
Risk analysis
We rate each deviation by risk and note where a deviation is justified by business need.
-
Reporting and baselines
We deliver findings with exact remediation settings and recommended hardened baselines.
Deliverables
- Configuration review report with pass/fail results and evidence
- Remediation guidance with exact settings
- Firewall rule-base cleanup recommendations (unused, shadowed and overly permissive rules)
- Hardened configuration baselines
Questions buyers ask
Do you need administrative access?
No. Read-only access or configuration exports are usually enough, and we can work from files your team provides.
Can you help apply the fixes?
Yes. Remediation can be delivered as a follow-on solution integration engagement, with changes made through your change-management process.
Related offerings
-
Vulnerability Assessment
A broad, systematic scan and analysis of your systems to find known weaknesses and prioritize what to patch first.
NIST CSF function: Identify -
Penetration Testing
Controlled, authorized attacks on your networks, applications and people to find what a real attacker could exploit — and how to fix it.
NIST CSF function: Identify NIST CSF function: Protect -
Solution Architecture
Security and IT architectures designed around your requirements — from Zero Trust and network segmentation to SOC platforms and data center designs.
NIST CSF function: Govern NIST CSF function: Protect