Skip to content

Security Hardening

Turn findings into fixes. MFA, backups you can actually restore, endpoint protection, and Essential Eight uplift that measurably lowers your risk.

Practical, right-sized remediation: multi-factor authentication, backups you can actually restore from, staff awareness, and a plan for when something goes wrong.

Findings are not fixes

Most businesses that come to us for hardening already know roughly what is wrong. They have a report, or a list from an insurer, or a nagging awareness of three things that have needed doing for a year. What they do not have is somebody to actually work through it.

That is what this is. It is delivery rather than advice, and it ends with evidence that each item is closed rather than with a document recommending that it should be.

What the first wave usually contains

The specifics vary, but the pattern rarely does.

Multi-factor authentication, properly. Not “we have MFA”, but MFA enforced on every account with the exemptions removed, the shared mailboxes dealt with, and the legacy authentication protocols that bypass it entirely switched off. That last step is the one most often missed, and skipping it makes the rest decorative.

Backups that have been restored. A backup job reporting success proves the job ran. It does not prove the data is usable, complete, or reachable if the thing you are restoring from has also been encrypted. We restore, verify, and check that the backups are isolated from the systems they protect.

Administrator sprawl. Almost every environment has more administrators than anybody expects, usually including at least one person who has left. Reducing that list costs nothing and removes a great deal of potential damage.

What is exposed. We check from the outside what of yours is reachable from the internet, and close what does not need to be. Remote access left open from a 2020 arrangement is a recurring find.

Patching that happens. Not a policy about patching, but a mechanism, with visibility into what is out of date and what cannot be updated and therefore needs a different control around it.

Measured, so it means something

Every engagement starts with a baseline and ends with the same measurements repeated. MFA coverage as a percentage of accounts. Number of privileged accounts. Systems more than 30 days behind on patches. Externally reachable services. Restores actually performed.

The point is partly to prove the work happened, and partly that these are the numbers an insurer, a client questionnaire, or a board will eventually ask you for. Having them already measured turns a week of scrambling into an email.

Typical timeframe
First wave typically 2 to 6 weeks
Best for
Businesses with a list of known problems and nobody to work through it

The engagement

How it runs

Every engagement follows the same shape, so you always know which part you are in and what is coming next.

  1. 1

    Agree the list

    We start from your audit findings, or run a short assessment if you do not have any, and agree what is in this wave and what is not.

  2. 2

    Fix the cheap and critical first

    MFA gaps, exposed services, stale administrator accounts, and unpatched systems. This is usually the majority of the real risk and a minority of the cost.

  3. 3

    Prove it worked

    Each change is verified rather than assumed. Backups are tested by restoring, MFA is checked account by account rather than by policy, and exposure is rechecked from outside.

  4. 4

    Document and hand over

    Every change is written down, so the next person to touch it knows why it is that way and does not undo it.

Common questions

We already have antivirus and a firewall. Is that not enough?

Those cover two specific paths, and most incidents we see arrive by a third: someone's credentials. An attacker who logs in with a valid username and password is not doing anything a firewall is designed to stop, and endpoint protection often never sees a file at all. That is why multi-factor authentication is consistently the highest-value single control, and why it is the first thing we look at.

Will hardening break things or annoy staff?

Some of it changes how people log in, and that needs communicating rather than springing on people. We stage changes, start with a pilot group, and time anything disruptive around your business. Where a control would cost more in friction than it removes in risk, we will say so rather than implementing it because it is on a list.

How do we know it worked?

Because we measure it. Coverage figures before and after, restores actually performed, external exposure rechecked. A hardening engagement that ends with a report saying the work was done, without evidence, is not distinguishable from one where it was not.

Can you work alongside our existing IT provider?

Yes, and it is often the best arrangement. We do the uplift work and document it, they maintain it. We write handover notes for them rather than for ourselves.

What is the single most valuable thing we could do?

For almost every business that has not done it: enforce multi-factor authentication on every account, with no exemptions, starting with administrators and email. It is usually an afternoon of work and it removes the most common path into an Australian small business by a wide margin.

Need help with Security Hardening?

Tell us where you are and what is worrying you. We will tell you honestly what we would do first.

Get in touch