Concrete approach to reduce attack surface using standardized configurations, patching processes and access controls.
Security hardening is a systematic method to reduce the attack surface by applying configuration, architectural, and operational controls across systems and services. It comprises baseline configurations, patching, access control, network restrictions, and automated verification of configuration drift to prevent common vulnerabilities. Applied to infrastructure, applications and cloud to improve compliance and resilience.
Share of systems that have successfully implemented baseline hardening.
Frequency and extent of deviations from the baseline per period.
Average time from discovery to full remediation.
Bank implemented baselines, automated patching and compliance checks before production.
Dev team reduced runtime privileges, minimized layers and integrated scans into CI/CD.
Organization uses CIS benchmarks as foundation for automated policies via configuration management tool.
Inventory and prioritize critical systems.
Define baselines and hardening policies.
Integrate automated enforcement and continuous checks.