Security configuration audit: fix weak settings before attackers do
Comprehensive IT configuration audits and system hardening aligned with CIS Benchmarks. We identify configuration errors in servers, Active Directory, cloud and containers and deliver recommendations to strengthen your infrastructure protection.
- 1,000+Penetration tests completed
- CIS v8Latest security benchmarks
- 30 daysRetest included
- SSHGap
- AuditdPartial
- SudoPartial
- FirewallOK
- PasswordsPartial
- PartitionsOK
- ServicesOK
- KernelOK
- LoggingPartial
- UpdatesGap
- NTPOK
- CronOK
- 6hosts
- 439controls
- 38deviations
Our certifications
Configuration audits are carried out by certified security engineers — including OSCP, OSEP, OSCE³, CISSP and ISO 27001 Lead Auditor.






What is a security configuration audit and hardening?
A configuration audit is a systematic analysis of system, application, and network device settings for compliance with recognized security benchmarks such as CIS. Our experienced cybersecurity engineers not only identify potential security gaps but also provide recommendations for effective hardening to strengthen protection against threats.
System hardening is the practical application of those recommendations: disabling unnecessary services, restricting permissions, correct password and logging policies, encryption and segmentation. A configuration audit and a penetration test are two different tools — the audit checks settings without exploitation, while penetration testing of the same infrastructure verifies whether the weaknesses can actually be exploited. Combining both gives the best result.
- CIS Benchmark compliance verification
- System hardening recommendations
- Detailed report with remediation priorities
- Cloud audits — AWS, Azure, GCP
- Retest within 30 days and access to the vulnerability management platform
of breaches stem from configuration errors
latest security benchmarks
of settings to fix, with risk rating and implementation steps
Scope: Windows and Linux servers, Active Directory, AWS, Azure and GCP, Kubernetes and Docker, databases, network devices
We offer configuration audits tailored to CIS Benchmark standards and industry best practices. Each area is audited against its dedicated benchmark and checklist.
Cloud audits (AWS / Azure / GCP)
Comprehensive analysis of cloud environment configurations for compliance with CIS Benchmarks for AWS, Azure, and GCP. We verify IAM policies, network configuration, data encryption, logging and monitoring, and compliance with security best practices.
- IAM policy and permission audit
- VPC, Security Groups, and NSG configuration review
- Data encryption analysis (at rest and in transit)
- Security logging and alert review
- Storage and backup configuration verification
Operating systems (Windows / Linux)
Windows Server / Desktop / Active Directory
Comprehensive verification of Windows system security in accordance with CIS Benchmark — password policies, GPO, firewall configuration, event auditing, user and service permissions, and privileged groups in the domain.
Linux (Ubuntu, RHEL, CentOS, Debian)
Linux distribution security assessment for compliance with best practices — SSH configuration, PAM, file permissions, kernel hardening, partitioning, and logging.
Databases
In-depth analysis of Oracle, MS SQL, PostgreSQL, and MySQL database security settings to protect against attacks and data leaks. We verify authentication mechanisms, encryption, query auditing, and network configuration.
- User permission and role verification
- Encryption mechanism analysis (TDE, SSL/TLS)
- Query logging and monitoring audit
- Database network and firewall configuration
Network devices and firewalls
Review of router, switch, and firewall configurations to ensure maximum network protection. Detailed verification of firewall rules and policies, tailored to your organization’s specific requirements and threats.
- Traffic filtering rule analysis (ACL, firewall rules)
- Network segmentation verification (VLAN, DMZ)
- VPN and remote access configuration
- Management protocol audit (SNMP, SSH, HTTPS)
- Network logging and alert review
Container environments (Docker / Kubernetes)
Analysis of Docker and Kubernetes container environment configurations for potential security vulnerabilities. We verify container isolation, permissions, base images, networking, and secrets management.
- Dockerfile and base image analysis
- Container permission and isolation verification
- Kubernetes configuration audit (RBAC, NetworkPolicy, PodSecurity)
- Secrets and environment variable management
Applications and source code
Application security configuration audit
Review and optimization of installed application security settings — web servers (Apache, Nginx, IIS), application servers, middleware, and other application infrastructure components.
Source code audit (code review)
Application source code security assessment — identifying potential weaknesses, injection vulnerabilities, business logic flaws, and recommendations for remediation.
CIS benchmark audits
CIS Benchmarks are globally recognized security guidelines developed by the Center for Internet Security. They contain detailed configuration recommendations for operating systems, databases, applications, network devices, and cloud environments. Following CIS Benchmarks is recommended by many industry regulations (PCI DSS, HIPAA, ISO 27001).
During an infrastructure security configuration audit we compare every setting with the relevant benchmark — automatically (compliance scanners) and manually (result verification, business context, documented exceptions). The outcome is a list of deviations with a risk rating and concrete hardening steps, not a raw scanner printout.
If you need to demonstrate compliance rather than fix settings, the right service is a compliance audit for NIS2, DORA and ISO 27001; a CIS benchmark audit is often one of its technical building blocks. We also tailor benchmarks to sector specifics — from security for industry and high-tech environments to hardening for healthcare and HIPAA-regulated systems.
Benchmark per system
Windows, Linux, AWS, Azure, GCP, Kubernetes, Docker, databases, network devices — each audited against its dedicated CIS document.
Automated and manual
A compliance scan detects deviations; an engineer decides which of them really matter in your environment.
Risk rating
Every deviation gets a priority: fix immediately, fix in the next change window, or accept with a documented reason.
Hardening scripts
Optionally we deliver ready-made scripts and configurations (GPO, Ansible, cloud policies) that automate the rollout.
How we work: methodology and audit process
Our configuration audit follows a proven, repeatable process — from scoping to verification of the applied fixes.
- 01
Scope & discovery
We define the audit scope — systems, benchmarks, priorities. We gather information about the infrastructure and environment, agree read-only access, NDA and the schedule.
- 02
Configuration analysis
Automated and manual verification of system settings in accordance with CIS Benchmark and industry best practices. Findings are published to the vulnerability management platform as we go, so you can follow the audit in real time.
- 03
Reporting
Detailed report with findings, risk assessment, prioritization, and specific hardening recommendations — an executive summary for management and a technical section for administrators.
- 04
Remediation support
We help implement recommendations — providing hardening scripts, consultations, and post-implementation verification. A retest performed within 30 days of report delivery is included in the price.
Configuration audit pricing
The price depends on the number of systems, benchmarks and environments (on-premise, cloud, containers). We prepare a quote after a short scoping call.
Security configuration audit and hardening — quote after a scoping call. Large environments (hundreds of hosts, multiple cloud accounts, several Kubernetes clusters) are quoted individually, always as an open “from” price with no upper limit. Every quote lists the systems, benchmarks and deliverables so you can compare it line by line.
Always included in every audit
- Report: executive summary + technical section with the deviation list, risk rating and evidence
- Specific hardening recommendations with implementation steps and priorities
- Retest within 30 days of report delivery
- Access to the VIPentest vulnerability management platform during and after the audit
- Consultation with the engineer after the audit and remediation support
What you get in the audit report
The report is meant to be a working tool for administrators and an argument for the board — not a scanner printout.
Executive summary
A summary for management: benchmark compliance status, the most important risks and the decisions we recommend.
Complete list of deviations
Every deviation from the CIS Benchmark with a risk rating, a description of the impact and evidence (configuration fragment, control result).
Hardening recommendations
Concrete implementation steps for each setting — commands, policy values, sample configurations.
Remediation priorities
The order of fixes by risk and implementation cost, so that the gaps most often used in attacks are closed first.
Automation scripts
Optionally: ready-made scripts and templates (GPO, Ansible, cloud policies) that speed up hardening at scale.
Retest and VM platform
Post-implementation verification within 30 days included, plus access to the vulnerability management platform with the status of every deviation.
Who a configuration audit is for
Configuration errors are one of the most common sources of incidents — an audit makes sense wherever infrastructure changes faster than procedures.
Regulated organizations
Finance, healthcare, energy and entities subject to DORA, NIS2 or PCI DSS that must demonstrate configuration compliance with a recognized standard and repeat the audit periodically.
Cloud and DevOps teams
Teams running AWS, Azure, GCP and Kubernetes, where a single wrong IAM policy or a public bucket can mean a data leak caused by a configuration error.
Before production go-live
New servers, clusters and environments before they go live, and after every significant infrastructure change or migration.
After a pentest or an incident
Organizations that, after a penetration test or an incident, want to put the foundations in order: operating systems, Active Directory, databases and network devices.
Frequently asked questions about configuration audits
Find answers to the most common questions about configuration audits and hardening.
What is a configuration audit and why should you perform one?
A configuration audit is a systematic analysis of IT system settings for compliance with recognized security standards such as CIS Benchmark. It helps identify configuration errors, which are one of the most common sources of security breaches, before they are exploited by attackers. The result is a concrete list of settings to fix and a prioritised hardening plan, not a raw scanner printout.
How does a configuration audit differ from a penetration test?
A penetration test simulates an attack and actively attempts to exploit vulnerabilities. A configuration audit, on the other hand, reviews system settings without exploitation attempts — it compares the current configuration against recognized security standards (e.g., CIS Benchmark) and identifies deviations. Both approaches complement each other, and we recommend using them together, for example a server configuration audit alongside penetration testing of the same infrastructure.
How often should a configuration audit be performed?
We recommend performing configuration audits at least once a year, after every significant infrastructure change, and before deploying new systems to production. Organizations subject to regulations (DORA, NIS2, PCI DSS) should conduct audits more frequently. Once you have applied the recommendations we run a retest — a retest within 30 days of report delivery is included in the price.
What is CIS Benchmark?
CIS Benchmarks are globally recognized security guidelines developed by the Center for Internet Security. They contain detailed configuration recommendations for operating systems, databases, applications, network devices, and cloud environments. Following CIS Benchmarks is recommended by many industry regulations (PCI DSS, HIPAA, ISO 27001).
What will I receive after the audit is completed?
You will receive a detailed report containing: an Executive Summary for management, a complete list of benchmark non-conformities with risk assessment, specific hardening recommendations with implementation steps, remediation action prioritization, and optionally ready-made hardening automation scripts. We also offer support throughout the remediation process, a retest within 30 days and access to our vulnerability management platform.
What does hardening of Windows and Linux servers involve?
Hardening means applying the audit recommendations so that a system runs only the services, permissions and settings it really needs. On Windows Server this covers password policies, GPO, firewall configuration, event auditing, and user and service permissions, including privileged groups in Active Directory. On Linux (Ubuntu, RHEL, CentOS, Debian) it covers SSH and PAM configuration, file permissions, kernel hardening, partitioning and logging. We deliver hardening scripts and verify the result after implementation.
Does the audit cover AWS, Azure, GCP and Kubernetes clusters?
Yes. We verify cloud environments against the CIS Benchmarks for AWS, Azure and GCP: IAM policies, VPC, Security Groups and NSG configuration, data encryption, logging and monitoring, and storage and backup settings. In container environments we review Dockerfiles and base images, container isolation and permissions, Kubernetes configuration (RBAC, NetworkPolicy, PodSecurity) and secrets management. One audit can combine on-premise servers, several cloud accounts and multiple clusters.
Does a configuration audit require admin access or cause downtime?
To compare settings against a benchmark we need read access to the configuration — for example an audit account, a configuration export or a read-only role in the cloud. We do not attempt exploitation or make changes to your systems, so the audit generates no load and no downtime and can run during business hours. Most audits are performed remotely over VPN or dedicated read-only access; on-site work is done when your security policy or an isolated network requires it.
Ready to strengthen your infrastructure?
Contact us to discuss a configuration audit scope tailored to your infrastructure. Our certified engineers will help identify and eliminate configuration errors.
- Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
- Scoping call under NDAWe agree on goals, environment, dates and access.
- Quote and test planUsually the same day after the call. No commitment.
- Retest within 30 days included
Write to us: free quote and scoping consultation
Describe your environment in a few sentences (number of servers, cloud accounts, clusters) and we will propose a scope and a quote for the configuration audit. We reply within 24 business hours and sign an NDA before discussing details.
