System hardening is the process of configuring servers, computers, network devices, applications and cloud services to reduce their attack surface. You remove the services, ports, accounts and permissions nobody needs and swap factory defaults for secure settings, then document the result as a baseline that gets reviewed on a regular schedule. The goal is for each system to do only what the business needs.
This guide covers what an IT leader needs to apply it in their company: the problem it solves, what gets secured in each layer of the infrastructure, how to do it in five steps with recognized guides such as the CIS Benchmarks, and how it works alongside patching and monitoring.
What system hardening is and what problem it solves
Think of a house fresh from the builder. It works from day one, but every window is unlocked, the front door has the lock it shipped with, there is a spare key under the doormat and a back door to the yard that nobody will ever use. Before you move in, you lock the windows, change the lock, pick up that key and seal the extra door. That is hardening applied to your systems.
Devices and software leave the factory configured to get up and running fast, with security as an afterthought: services turned on by default, generic vendor passwords, open ports and shared administrator accounts. The attack surface is the sum of all those doors someone could try to get through. Every one you close is one you no longer have to watch.
At 8 a.m. on a Monday, your IT team connects the new server for the billing system. It comes with remote desktop open to the internet and the administrator account still using the password the vendor left. It works from the very first minute, and that is the problem: anyone on the internet who tries that password can get in too. Hardening means closing that gap before the server goes into production.
The benefit goes beyond security. A system with fewer active services breaks less often and updates faster. It is also easier to audit, because its configuration is documented and can be compared against what it should be.
What gets secured: servers, computers, network, applications and cloud
Hardening is applied layer by layer. Each one comes from the factory with its own open doors:
| Layer | What gets closed or adjusted | Example |
|---|---|---|
| Servers | Unused services and roles, restricted remote access, personal administrator accounts instead of shared ones. | A file server that also had a web server enabled that nobody used. |
| Employee computers | Local administrator rights, software installation, USB use according to policy, disk encryption. | A sales team that can no longer install programs on its own. |
| Network | Open ports, "allow all" firewall rules, factory passwords on devices, a separate guest network. | Visitor Wi-Fi kept apart from the accounting network. |
| Applications and databases | Default accounts, error messages that reveal technical details, unencrypted connections. | A database that stops accepting the generic account it was installed with. |
| Cloud | Storage made public by mistake, access without two-step verification, activity logs turned off. | A Microsoft 365 activity log that had been disabled since the subscription started. |
On the network, the firewall is the first piece worth hardening, because it defines what comes into and goes out of the entire company. We explain this in detail in our guide on what a firewall is.
Across every layer, much of the work comes down to adjusting who can do what. That part relies on access controls: role-based permissions, personal accounts and two-step verification.
At 4 p.m. on a Wednesday, someone in administration shares a spreadsheet with a vendor using the "anyone with the link" option. In a hardened cloud environment, that option is disabled by policy for every employee, so the file can only be shared with identified accounts and nobody has to remember the rule.
How to apply system hardening in your company in 5 steps
- Take inventory. List the servers, computers, network devices, applications and cloud services you have, and who is responsible for each one. What isn't on the list can't be hardened. A cybersecurity assessment helps build that inventory when none exists.
- Define a baseline using a recognized guide. The baseline is the written version of "how each system should be set up." You don't need to invent it: the CIS Benchmarks are free guides from the Center for Internet Security (CIS), a nonprofit organization, with recommended configurations for more than 100 technologies, from Windows and Linux to Microsoft 365 and AWS. Vendors also publish their own, such as Microsoft's security baselines.
- Start with what reduces risk the most. Begin with administrator access, remote access exposed to the internet, factory passwords and services nobody uses. Test each change on one device or in a test environment before rolling it out, because it could break an application that depended on that setting.
- Verify with an independent review. A configuration scan or a penetration test confirms that what the policy says is what is actually configured. If you plan to hire one, read how to choose a pentesting provider.
- Maintain the baseline. Every new device is delivered already hardened, and the configuration is reviewed at least once a quarter or after any major change. Updates and day-to-day tweaks gradually pull settings away from the baseline; this is called configuration drift.
Here is what it looks like in practice. At 9 a.m. on a Monday, the IT team at a logistics company with 60 computers and 4 servers starts on the inventory. That week it defines its baseline using the CIS Benchmarks for Windows and Microsoft 365. It applies the baseline to the IT team's own devices first and rolls it out to everyone else two weeks later. In the quarterly review it finds two servers that reopened remote desktop after an update, and fixes them in an afternoon.
Hardening, patching and monitoring: how they work together
Back to the house: hardening locks the windows and changes the lock; patches replace the lock when the manufacturer warns that it has a flaw; and monitoring is the camera that alerts you if someone tries to get in anyway. None of them replaces the other two.
| Control | What it solves | How often |
|---|---|---|
| Hardening | Doors left open by configuration. | When each system is installed and at every quarterly review. |
| Patching | Known software flaws. | Every month, and right away when the flaw is critical. |
| Monitoring | Whatever gets past the other two controls. | 24/7. |
A well-configured system that isn't kept up to date is still exposed to publicly known flaws. That is why hardening goes hand in hand with an update process. We go deeper into that topic in our guide on what a security patch is.
And since no configuration is perfect, someone has to review the activity on your systems to catch whatever did get through. That is the job of a SOC (security operations center).
At 11 p.m. on a Friday, an automated program starts trying passwords against the payroll server. Remote access only accepts connections through the company's VPN (virtual private network, an encrypted private connection), which is hardening at work, and the system is up to date thanks to patching, so the attempt fails. Monitoring logs it, and on Monday your IT team sees it in the report with the source address already blocked.
Frequently asked questions about system hardening
In cybersecurity, hardening means configuring a system so it offers fewer points of entry, making it harder to break into. When it covers servers, computers and network devices, it is usually called system hardening. You can find the short definition in our cybersecurity glossary.
It gets recorded as an exception: which setting is not applied, why, who approved it and until when. While the exception lasts, it is offset by another measure, for example limiting which devices can reach that application. A documented exception is part of hardening, while a forgotten configuration is simply a gap.
ISO 27001 calls for managing and documenting the secure configuration of systems. PCI DSS (the Payment Card Industry Data Security Standard) prohibits using vendor-supplied default passwords and settings. The CIS Controls dedicate one of their 18 controls to the secure configuration of assets. In every case, the baseline and its periodic review are the evidence the auditor checks.
No. Hardening reduces the ways in; antivirus detects and blocks malicious software that arrives through the ones that remain, such as an email attachment. They complement each other, and today it pays to choose protection that also detects suspicious behavior. To compare options, see our guide to business antivirus.
Yes, and it is worth doing. On Windows you apply it with Group Policy or with device management tools such as Intune; in the cloud, with the platform's own templates and policies. There are also tools that compare each system against the baseline and alert you when something drifts.
Your IT team defines and applies the baseline, with sign-off from whoever is accountable for security. When the team doesn't have time to keep it current, a managed cybersecurity service can run the configurations and report their status to you.
Alexander Chapellin
I'm passionate about SEO and copywriting at TecnetOne, where I combine my technical knowledge with optimization skills and persuasive writing. I use advanced tools and techniques to boost companies' online visibility, making sure they stay at the forefront of technology and achieve outstanding results in a competitive digital landscape. My goal is to build effective strategies that drive our clients' technological and commercial success.