Service · Cybersecurity

System hardening

Software and devices leave the factory configured to be easy to set up, not to be safe. Old protocols stay enabled for compatibility, any employee can let an outside app into company mailboxes, and the printer's web interface sits on the network with its default password. None of these is a disaster on its own, but they are exactly what attackers look for. Consider a law firm where the file server still speaks a file-sharing protocol from a decade ago, staff in Microsoft 365 can let any app read their email, and Office macros run even in documents downloaded from the internet. Fixing all of that needs no new product, only settings. System hardening is the methodical review of those settings against published references like CIS Benchmarks and Microsoft security baselines. Changing a setting is simple; changing it without breaking something that works is the real skill. So we measure first, test on a small group, then apply, and record every exception along with its reason.

No new licences
settings only
CIS Benchmarks
plus Microsoft's own baselines as reference
Exceptions
justified and documented
Drift checks
so settings do not slip back

What the work covers in practice

Work proceeds tier by tier, starting with the cloud tenant and ending at individual printers, and every tier is assessed, adjusted and retested.

Agree the scope with the engineer who will do the work

Microsoft 365 and Entra ID

Third-party app consent only with approval, legacy authentication disabled, automatic external forwarding blocked, and guest and external access settings in Teams reviewed.

Windows workstations

Microsoft baselines deployed via Intune or GPO, macros blocked in documents from the internet, PowerShell restrictions and a tidy-up of local admin accounts.

Windows servers and Active Directory

Retiring SMBv1 and NTLMv1, unneeded services like the print spooler switched off on servers that do not print, admin accounts tiered and password policies modernised.

Linux servers

SSH restricted to keys, root unable to log in directly, a local firewall on each host, unattended security patching and a trimmed package list.

Network devices and printers

Default passwords changed, unencrypted management protocols turned off and firmware updated. Printers, NAS units and camera recorders are frequently the weakest link.

Drift detection

Regular automated checks that hardened settings are still in place, so that an update or a rushed change undoing them gets noticed.

How we approach the job, from first call to handover

Hardening without preparation can break things, which is why progress comes in small steps that can each be checked.

01

Gap analysis

Systems are scanned automatically against the selected benchmark. The output lists each setting's current value, the recommended value and the likely impact of changing it.

02

Agreement

We jointly settle which settings change and where a justified exception stays, for example a protocol an old business application still depends on.

03

Waves

Changes land on test machines and a few pilot users before the wider estate. They are applied through policies so they can be rolled back if needed.

04

Verification and handover

A repeat scan and the exception register with reasons. If you like, drift monitoring carries on as a recurring service.

The cheapest security improvement is switching on something you already own. Hardening needs no new product, console or licence, only attention and discipline. Many attack chains run through a single default setting that should have been changed years ago.

Frequently asked questions

Consensus-built hardening guides from the Center for Internet Security, a not-for-profit body, covering operating systems, cloud platforms and network equipment in setting-by-setting detail. They are free to access and are widely used as a concrete, setting-level reference in frameworks such as ISO 27001.

No. Some do not suit every environment and a few can break older applications. We pick those that make sense for you and write a short justification for the rest. A documented exception looks far better in an audit than a silent gap.

We keep the protocol enabled only on the server and clients that run that application and disable it everywhere else. The exception goes into the risk register with a reminder to upgrade or replace the application.

Because changes are made through policies, rolling back takes minutes, and the pilot catches most problems early. If something slips through, email helpme@apply.tr; we reverse the setting, find the cause and apply a targeted fix.

Replace risky defaults with safe settings

Tell us which systems you run and roughly how many. We will say which layer to harden first for the biggest benefit.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.