Pillar 05

Hardening & POPIA Drift

Systems are rarely hardened once and left correct. They drift — and drift is what an auditor and an attacker both find.

A server built to a standard in January is not a server that meets it in November. Packages change, someone opens a port for a supplier, a temporary rule becomes permanent. Hardening is a measurement taken repeatedly, not a certificate earned once.

Hardening & POPIA Drift — Reed Sentinel

What we check

What we check

CIS benchmarking

Hosts measured against the published Center for Internet Security benchmarks for their actual operating system and role.

Configuration drift

The gap between the build standard and the running system, itemised rather than summarised.

Service and account review

What is running that need not be, and which accounts hold privileges nobody can now justify.

Patch position

Which systems are behind, by how far, and which of those gaps are genuinely reachable from outside.

POPIA mapping

Technical findings mapped to your obligations under the Protection of Personal Information Act, in the language a regulator uses.

Standards alignment

The same evidence expressed against ISO 27001 and NIST controls where your clients or insurers require it.

How it works

How it works

01

Scope and authorisation

Which hosts are in scope and what level of access is granted for configuration review.

02

Measure

Benchmark and drift assessment across the authorised estate, producing a per-host position rather than an average.

03

Map to obligations

Each technical finding tied to the specific obligation it affects, so the report answers a compliance question directly.

04

Remediate and re-measure

Prioritised hardening guidance, then a second measurement proving the drift is closed.

What we usually find

What we usually find

Drift findings are rarely dramatic and almost never the result of negligence. They are the accumulated residue of ordinary operational pressure — the temporary change that stayed, the exception that became the rule.

The temporary firewall rule

Opened for a supplier, a migration or an urgent diagnosis, and never closed. It is frequently the widest rule in the set and nobody currently employed remembers requesting it.

Logging enabled but never retained

Logs are being generated, then rotated away after a few days, or written to a disk nobody monitors. When something happens, the evidence covering the relevant period no longer exists.

Administrative rights granted broadly

Local administrator or domain privileges handed out to resolve a support issue and never withdrawn, so a routine compromise of one workstation becomes a serious one.

Backups nobody has ever restored

Backups running and reporting success for years, never once tested by restoring them. Under POPIA an untested backup is not a control, and ransomware is precisely when you discover which it was.

What you get

What you receive

A per-host benchmark position

Each system measured against the CIS benchmark for its actual role, itemised rather than averaged into a meaningless score.

The drift, quantified

The specific gap between your build standard and each running system.

Findings mapped to POPIA

Each technical issue tied to the obligation it affects, in language a regulator or an auditor uses.

A re-measurement

Once remediated, the benchmark is run again and the closure evidenced.

You will know the price before you commit.

A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.

Book a free callarrow_forward