Pillar 05
Systems are rarely hardened once and left correct. They drift — and drift is what an auditor and an attacker both find.
A server built to a standard in January is not a server that meets it in November. Packages change, someone opens a port for a supplier, a temporary rule becomes permanent. Hardening is a measurement taken repeatedly, not a certificate earned once.
What we check
Hosts measured against the published Center for Internet Security benchmarks for their actual operating system and role.
The gap between the build standard and the running system, itemised rather than summarised.
What is running that need not be, and which accounts hold privileges nobody can now justify.
Which systems are behind, by how far, and which of those gaps are genuinely reachable from outside.
Technical findings mapped to your obligations under the Protection of Personal Information Act, in the language a regulator uses.
The same evidence expressed against ISO 27001 and NIST controls where your clients or insurers require it.
How it works
Which hosts are in scope and what level of access is granted for configuration review.
Benchmark and drift assessment across the authorised estate, producing a per-host position rather than an average.
Each technical finding tied to the specific obligation it affects, so the report answers a compliance question directly.
Prioritised hardening guidance, then a second measurement proving the drift is closed.
What we usually find
Drift findings are rarely dramatic and almost never the result of negligence. They are the accumulated residue of ordinary operational pressure — the temporary change that stayed, the exception that became the rule.
Opened for a supplier, a migration or an urgent diagnosis, and never closed. It is frequently the widest rule in the set and nobody currently employed remembers requesting it.
Logs are being generated, then rotated away after a few days, or written to a disk nobody monitors. When something happens, the evidence covering the relevant period no longer exists.
Local administrator or domain privileges handed out to resolve a support issue and never withdrawn, so a routine compromise of one workstation becomes a serious one.
Backups running and reporting success for years, never once tested by restoring them. Under POPIA an untested backup is not a control, and ransomware is precisely when you discover which it was.
What you get
Each system measured against the CIS benchmark for its actual role, itemised rather than averaged into a meaningless score.
The specific gap between your build standard and each running system.
Each technical issue tied to the obligation it affects, in language a regulator or an auditor uses.
Once remediated, the benchmark is run again and the closure evidenced.
A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.
Book a free callarrow_forward