Configuration audit

Security configuration audit: fix weak settings before attackers do

Comprehensive IT configuration audits and system hardening aligned with CIS Benchmarks. We identify configuration errors in servers, Active Directory, cloud and containers and deliver recommendations to strengthen your infrastructure protection.

  • 1,000+Penetration tests completed
  • CIS v8Latest security benchmarks
  • 30 daysRetest included
vipentest · CIS configuration audit (sample)LIVE
  • SSHGap
  • AuditdPartial
  • SudoPartial
  • FirewallOK
  • PasswordsPartial
  • PartitionsOK
  • ServicesOK
  • KernelOK
  • LoggingPartial
  • UpdatesGap
  • NTPOK
  • CronOK
71%CIS Level 1
compliantneeds workcritical
  • 6hosts
  • 439controls
  • 38deviations
Certifications

Our certifications

Configuration audits are carried out by certified security engineers — including OSCP, OSEP, OSCE³, CISSP and ISO 27001 Lead Auditor.

OSCP certificate – OffSec Certified ProfessionalOSCE³ certificate – OffSec Certified Expert 3KLCP certificate – Kali Linux Certified ProfessionalOSWE certificate – OffSec Web ExpertRed Team Ops I certificate – Zero-Point Security (Red Team Operator)OSEP certificate – OffSec Experienced Penetration TesterOSWP certificate – OffSec Wireless ProfessionalOSED certificate – OffSec Exploit DeveloperPECB ISO/IEC 27001 Lead Auditor certificateeWPTX v2 certificate – Web Application Penetration Tester eXtremeeCPPT v2 certificate – Certified Professional Penetration TesterCISSP certificate – Certified Information Systems Security Professional
Definition

What is a security configuration audit and hardening?

A configuration audit is a systematic analysis of system, application, and network device settings for compliance with recognized security benchmarks such as CIS. Our experienced cybersecurity engineers not only identify potential security gaps but also provide recommendations for effective hardening to strengthen protection against threats.

System hardening is the practical application of those recommendations: disabling unnecessary services, restricting permissions, correct password and logging policies, encryption and segmentation. A configuration audit and a penetration test are two different tools — the audit checks settings without exploitation, while penetration testing of the same infrastructure verifies whether the weaknesses can actually be exploited. Combining both gives the best result.

  • CIS Benchmark compliance verification
  • System hardening recommendations
  • Detailed report with remediation priorities
  • Cloud audits — AWS, Azure, GCP
  • Retest within 30 days and access to the vulnerability management platform
Scale of the problem
95%

of breaches stem from configuration errors

Standard
CIS v8

latest security benchmarks

Audit result
List

of settings to fix, with risk rating and implementation steps

Audit scope

Scope: Windows and Linux servers, Active Directory, AWS, Azure and GCP, Kubernetes and Docker, databases, network devices

We offer configuration audits tailored to CIS Benchmark standards and industry best practices. Each area is audited against its dedicated benchmark and checklist.

Cloud audits (AWS / Azure / GCP)

Comprehensive analysis of cloud environment configurations for compliance with CIS Benchmarks for AWS, Azure, and GCP. We verify IAM policies, network configuration, data encryption, logging and monitoring, and compliance with security best practices.

  • IAM policy and permission audit
  • VPC, Security Groups, and NSG configuration review
  • Data encryption analysis (at rest and in transit)
  • Security logging and alert review
  • Storage and backup configuration verification
AWSAzureGCPCIS BenchmarkIAM

Operating systems (Windows / Linux)

Windows Server / Desktop / Active Directory

Comprehensive verification of Windows system security in accordance with CIS Benchmark — password policies, GPO, firewall configuration, event auditing, user and service permissions, and privileged groups in the domain.

Linux (Ubuntu, RHEL, CentOS, Debian)

Linux distribution security assessment for compliance with best practices — SSH configuration, PAM, file permissions, kernel hardening, partitioning, and logging.

Windows ServerActive DirectoryUbuntuRHELCIS BenchmarkHardening

Databases

In-depth analysis of Oracle, MS SQL, PostgreSQL, and MySQL database security settings to protect against attacks and data leaks. We verify authentication mechanisms, encryption, query auditing, and network configuration.

  • User permission and role verification
  • Encryption mechanism analysis (TDE, SSL/TLS)
  • Query logging and monitoring audit
  • Database network and firewall configuration
OracleMS SQLPostgreSQLMySQLCIS Benchmark

Network devices and firewalls

Review of router, switch, and firewall configurations to ensure maximum network protection. Detailed verification of firewall rules and policies, tailored to your organization’s specific requirements and threats.

  • Traffic filtering rule analysis (ACL, firewall rules)
  • Network segmentation verification (VLAN, DMZ)
  • VPN and remote access configuration
  • Management protocol audit (SNMP, SSH, HTTPS)
  • Network logging and alert review
CiscoPalo AltoFortinetJuniperCIS Benchmark

Container environments (Docker / Kubernetes)

Analysis of Docker and Kubernetes container environment configurations for potential security vulnerabilities. We verify container isolation, permissions, base images, networking, and secrets management.

  • Dockerfile and base image analysis
  • Container permission and isolation verification
  • Kubernetes configuration audit (RBAC, NetworkPolicy, PodSecurity)
  • Secrets and environment variable management
DockerKubernetesCIS BenchmarkContainer Security

Applications and source code

Application security configuration audit

Review and optimization of installed application security settings — web servers (Apache, Nginx, IIS), application servers, middleware, and other application infrastructure components.

Source code audit (code review)

Application source code security assessment — identifying potential weaknesses, injection vulnerabilities, business logic flaws, and recommendations for remediation.

ApacheNginxIISSASTCode Review
Methodology

CIS benchmark audits

CIS Benchmarks are globally recognized security guidelines developed by the Center for Internet Security. They contain detailed configuration recommendations for operating systems, databases, applications, network devices, and cloud environments. Following CIS Benchmarks is recommended by many industry regulations (PCI DSS, HIPAA, ISO 27001).

During an infrastructure security configuration audit we compare every setting with the relevant benchmark — automatically (compliance scanners) and manually (result verification, business context, documented exceptions). The outcome is a list of deviations with a risk rating and concrete hardening steps, not a raw scanner printout.

If you need to demonstrate compliance rather than fix settings, the right service is a compliance audit for NIS2, DORA and ISO 27001; a CIS benchmark audit is often one of its technical building blocks. We also tailor benchmarks to sector specifics — from security for industry and high-tech environments to hardening for healthcare and HIPAA-regulated systems.

Benchmark per system

Windows, Linux, AWS, Azure, GCP, Kubernetes, Docker, databases, network devices — each audited against its dedicated CIS document.

Automated and manual

A compliance scan detects deviations; an engineer decides which of them really matter in your environment.

Risk rating

Every deviation gets a priority: fix immediately, fix in the next change window, or accept with a documented reason.

Hardening scripts

Optionally we deliver ready-made scripts and configurations (GPO, Ansible, cloud policies) that automate the rollout.

Process

How we work: methodology and audit process

Our configuration audit follows a proven, repeatable process — from scoping to verification of the applied fixes.

  1. 01
    Start

    Scope & discovery

    We define the audit scope — systems, benchmarks, priorities. We gather information about the infrastructure and environment, agree read-only access, NDA and the schedule.

    ScopeCIS BenchmarkNDA
  2. 02
    Analysis

    Configuration analysis

    Automated and manual verification of system settings in accordance with CIS Benchmark and industry best practices. Findings are published to the vulnerability management platform as we go, so you can follow the audit in real time.

    Compliance scanManual verificationVM platform
  3. 03
    Report

    Reporting

    Detailed report with findings, risk assessment, prioritization, and specific hardening recommendations — an executive summary for management and a technical section for administrators.

    Executive summaryDeviation listPriorities
  4. 04
    Remediation

    Remediation support

    We help implement recommendations — providing hardening scripts, consultations, and post-implementation verification. A retest performed within 30 days of report delivery is included in the price.

    Hardening scriptsConsultations30-day retest
Pricing

Configuration audit pricing

The price depends on the number of systems, benchmarks and environments (on-premise, cloud, containers). We prepare a quote after a short scoping call.

from PLN 9,999 net

Security configuration audit and hardening — quote after a scoping call. Large environments (hundreds of hosts, multiple cloud accounts, several Kubernetes clusters) are quoted individually, always as an open “from” price with no upper limit. Every quote lists the systems, benchmarks and deliverables so you can compare it line by line.

Always included in every audit

  • Report: executive summary + technical section with the deviation list, risk rating and evidence
  • Specific hardening recommendations with implementation steps and priorities
  • Retest within 30 days of report delivery
  • Access to the VIPentest vulnerability management platform during and after the audit
  • Consultation with the engineer after the audit and remediation support
Report

What you get in the audit report

The report is meant to be a working tool for administrators and an argument for the board — not a scanner printout.

Executive summary

A summary for management: benchmark compliance status, the most important risks and the decisions we recommend.

Complete list of deviations

Every deviation from the CIS Benchmark with a risk rating, a description of the impact and evidence (configuration fragment, control result).

Hardening recommendations

Concrete implementation steps for each setting — commands, policy values, sample configurations.

Remediation priorities

The order of fixes by risk and implementation cost, so that the gaps most often used in attacks are closed first.

Automation scripts

Optionally: ready-made scripts and templates (GPO, Ansible, cloud policies) that speed up hardening at scale.

Retest and VM platform

Post-implementation verification within 30 days included, plus access to the vulnerability management platform with the status of every deviation.

Who it’s for

Who a configuration audit is for

Configuration errors are one of the most common sources of incidents — an audit makes sense wherever infrastructure changes faster than procedures.

Regulated organizations

Finance, healthcare, energy and entities subject to DORA, NIS2 or PCI DSS that must demonstrate configuration compliance with a recognized standard and repeat the audit periodically.

Cloud and DevOps teams

Teams running AWS, Azure, GCP and Kubernetes, where a single wrong IAM policy or a public bucket can mean a data leak caused by a configuration error.

Before production go-live

New servers, clusters and environments before they go live, and after every significant infrastructure change or migration.

After a pentest or an incident

Organizations that, after a penetration test or an incident, want to put the foundations in order: operating systems, Active Directory, databases and network devices.

FAQ

Frequently asked questions about configuration audits

Find answers to the most common questions about configuration audits and hardening.

What is a configuration audit and why should you perform one?

A configuration audit is a systematic analysis of IT system settings for compliance with recognized security standards such as CIS Benchmark. It helps identify configuration errors, which are one of the most common sources of security breaches, before they are exploited by attackers. The result is a concrete list of settings to fix and a prioritised hardening plan, not a raw scanner printout.

How does a configuration audit differ from a penetration test?

A penetration test simulates an attack and actively attempts to exploit vulnerabilities. A configuration audit, on the other hand, reviews system settings without exploitation attempts — it compares the current configuration against recognized security standards (e.g., CIS Benchmark) and identifies deviations. Both approaches complement each other, and we recommend using them together, for example a server configuration audit alongside penetration testing of the same infrastructure.

How often should a configuration audit be performed?

We recommend performing configuration audits at least once a year, after every significant infrastructure change, and before deploying new systems to production. Organizations subject to regulations (DORA, NIS2, PCI DSS) should conduct audits more frequently. Once you have applied the recommendations we run a retest — a retest within 30 days of report delivery is included in the price.

What is CIS Benchmark?

CIS Benchmarks are globally recognized security guidelines developed by the Center for Internet Security. They contain detailed configuration recommendations for operating systems, databases, applications, network devices, and cloud environments. Following CIS Benchmarks is recommended by many industry regulations (PCI DSS, HIPAA, ISO 27001).

What will I receive after the audit is completed?

You will receive a detailed report containing: an Executive Summary for management, a complete list of benchmark non-conformities with risk assessment, specific hardening recommendations with implementation steps, remediation action prioritization, and optionally ready-made hardening automation scripts. We also offer support throughout the remediation process, a retest within 30 days and access to our vulnerability management platform.

What does hardening of Windows and Linux servers involve?

Hardening means applying the audit recommendations so that a system runs only the services, permissions and settings it really needs. On Windows Server this covers password policies, GPO, firewall configuration, event auditing, and user and service permissions, including privileged groups in Active Directory. On Linux (Ubuntu, RHEL, CentOS, Debian) it covers SSH and PAM configuration, file permissions, kernel hardening, partitioning and logging. We deliver hardening scripts and verify the result after implementation.

Does the audit cover AWS, Azure, GCP and Kubernetes clusters?

Yes. We verify cloud environments against the CIS Benchmarks for AWS, Azure and GCP: IAM policies, VPC, Security Groups and NSG configuration, data encryption, logging and monitoring, and storage and backup settings. In container environments we review Dockerfiles and base images, container isolation and permissions, Kubernetes configuration (RBAC, NetworkPolicy, PodSecurity) and secrets management. One audit can combine on-premise servers, several cloud accounts and multiple clusters.

Does a configuration audit require admin access or cause downtime?

To compare settings against a benchmark we need read access to the configuration — for example an audit account, a configuration export or a read-only role in the cloud. We do not attempt exploitation or make changes to your systems, so the audit generates no load and no downtime and can run during business hours. Most audits are performed remotely over VPN or dedicated read-only access; on-site work is done when your security policy or an isolated network requires it.

Ready to strengthen your infrastructure?

Contact us to discuss a configuration audit scope tailored to your infrastructure. Our certified engineers will help identify and eliminate configuration errors.

  1. Enquiry confirmedWe reply within 24 h on business days and ask about the scope.
  2. Scoping call under NDAWe agree on goals, environment, dates and access.
  3. Quote and test planUsually the same day after the call. No commitment.
  • Retest within 30 days included
We reply within 24 h

Write to us: free quote and scoping consultation

Describe your environment in a few sentences (number of servers, cloud accounts, clusters) and we will propose a scope and a quote for the configuration audit. We reply within 24 business hours and sign an NDA before discussing details.

    I consent to the processing of my personal data by VIPentest sp. z o.o. in order to respond to my enquiry. Details in the Privacy Policy.

    No commitment. NDA before any scoping call.

    Configuration audit · from PLN 9,999 netGet a quote