A CERT-In Empanelled Auditing Organization
Configuration Review
Home/Audits & Assessments/Configuration Review
Configuration Review

Secure configuration review for devices & cloud.

Most breaches don’t start with a clever exploit, they start with a misconfiguration. We review the security configuration of your network devices, servers, cloud accounts and DevOps platforms against recognised benchmarks, and hand you a prioritised path to hardening every one of them.

Overview

Hardening, measured against a known-good baseline.

A configuration review is a systematic check of how your systems are set up, not whether they can be exploited from the outside, but whether they are configured the way a secure, well-run environment should be. We compare your actual settings against established hardening benchmarks and vendor best practice, and flag every gap that weakens your posture.

It covers far more than firewalls. Operating systems, databases, network gear, cloud accounts, container platforms, identity providers and the DevOps tools your engineers live in, GitHub, GitLab, Bitbucket and their pipelines, all carry security-relevant settings that drift, get loosened for convenience, or ship insecure by default. We find those, explain the risk, and tell you exactly what to change.

The work is read-only and non-disruptive: we assess configuration and evidence, we don’t attack or change your systems. It pairs naturally with a penetration test, the review tells you where you’re not hardened, the test tells you what an attacker could do with it.

What we review

Every layer that carries a setting.

Three broad domains, each a common source of avoidable exposure.

Devices & infrastructure

Firewalls, routers, switches, load balancers and VPN gateways; Windows and Linux servers; virtualisation and hypervisors; databases; and endpoints. We check hardening, access control, patch and service posture, logging and rule hygiene.

Cloud platforms

AWS, Azure and GCP, identity and access (IAM), storage exposure, network and security groups, encryption, key management, logging and monitoring, and account-level guardrails. Plus Kubernetes/containers and Microsoft 365 / Google Workspace tenants.

Application & DevOps platforms

GitHub, GitLab and Bitbucket, organisation and repository settings, branch protection, access and role hygiene, secret scanning, token and webhook exposure, along with CI/CD pipelines, artifact registries and identity providers (Entra ID, Okta).

Platforms we commonly assess

Named systems, real benchmarks.

AWS · Azure · GCPCloud accounts against CIS Benchmarks and vendor baselines.
GitHub · GitLab · BitbucketOrg, repo, branch-protection and access configuration.
Windows & LinuxServer and endpoint OS hardening.
Firewalls & network gearRule hygiene, management-plane and device hardening.
Kubernetes & containersCluster, workload and registry configuration.
DatabasesAccess, encryption, auditing and configuration.
M365 & Google WorkspaceTenant, identity and sharing controls.
Entra ID & OktaIdentity provider and SSO configuration.
Benchmarks

What we measure you against.

CIS BenchmarksThe de-facto hardening standard across OS, cloud and platforms.
Vendor security baselinesAWS, Azure and GCP well-architected and security guidance.
Platform hardening guidesProvider best practice for GitHub, Kubernetes and more.
Your policy & regulationMapped to your internal standards, RBI, ISO 27001 or PCI DSS needs.
How we work

A clear, low-friction process.

1

Scope & baseline

We agree the systems in scope and the benchmarks to assess against, CIS, vendor or your own standard.

2

Collect configuration

We gather settings and evidence read-only, via exports, config files, read-only accounts or a guided walkthrough. Nothing is changed.

3

Assess & validate

We compare against the benchmark, remove false positives, and confirm findings with your team so the results reflect reality.

4

Report & harden

You get a risk-rated report with specific remediation per finding, and an optional re-check once fixes are in place.

Why it matters

Misconfiguration is the quiet risk.

Close the common gapsPublic buckets, weak IAM and open ports before someone finds them.
Stop configuration driftCatch settings that loosened over time or shipped insecure by default.
Evidence for auditorsDemonstrable hardening for ISO 27001, SOC 2, PCI DSS and RBI.
Protect your code supply chainLock down repos, branches and pipelines against tampering.
FAQ

Common questions

How is this different from a penetration test?
A penetration test attacks your systems to see what an attacker could achieve. A configuration review inspects how your systems are set up and compares that to a hardening benchmark, it’s read-only and finds weaknesses before they’re exploited. The two are complementary, and many clients run both.
Is it safe to run on production?
Yes. The review is read-only and non-disruptive, we assess configuration and evidence, we don’t change settings or run intrusive tests. Access is typically via read-only roles, exports or a guided session.
Which benchmarks do you use?
Primarily the CIS Benchmarks, complemented by vendor security baselines (AWS, Azure, GCP) and platform hardening guides. We can also assess against your own internal standard or a specific regulatory requirement.
Can you review GitHub, Bitbucket and our CI/CD?
Yes. We review organisation and repository settings, branch protection, access and role hygiene, secret scanning, tokens and webhooks across GitHub, GitLab and Bitbucket, plus your CI/CD pipelines and artifact registries, the security of your software supply chain, not just your servers.
What do we receive?
A risk-rated report with each misconfiguration, its impact and specific remediation, an executive summary, and a prioritised hardening plan, plus an optional re-check to confirm fixes.

Find the misconfigurations before someone else does.

Tell us what’s in scope, devices, cloud accounts or DevOps platforms, and we’ll scope a configuration review.