
Most breaches don’t start with a clever exploit, they start with a misconfiguration. We review the security configuration of your network devices, servers, cloud accounts and DevOps platforms against recognised benchmarks, and hand you a prioritised path to hardening every one of them.
A configuration review is a systematic check of how your systems are set up, not whether they can be exploited from the outside, but whether they are configured the way a secure, well-run environment should be. We compare your actual settings against established hardening benchmarks and vendor best practice, and flag every gap that weakens your posture.
It covers far more than firewalls. Operating systems, databases, network gear, cloud accounts, container platforms, identity providers and the DevOps tools your engineers live in, GitHub, GitLab, Bitbucket and their pipelines, all carry security-relevant settings that drift, get loosened for convenience, or ship insecure by default. We find those, explain the risk, and tell you exactly what to change.
The work is read-only and non-disruptive: we assess configuration and evidence, we don’t attack or change your systems. It pairs naturally with a penetration test, the review tells you where you’re not hardened, the test tells you what an attacker could do with it.
Three broad domains, each a common source of avoidable exposure.
Firewalls, routers, switches, load balancers and VPN gateways; Windows and Linux servers; virtualisation and hypervisors; databases; and endpoints. We check hardening, access control, patch and service posture, logging and rule hygiene.
AWS, Azure and GCP, identity and access (IAM), storage exposure, network and security groups, encryption, key management, logging and monitoring, and account-level guardrails. Plus Kubernetes/containers and Microsoft 365 / Google Workspace tenants.
GitHub, GitLab and Bitbucket, organisation and repository settings, branch protection, access and role hygiene, secret scanning, token and webhook exposure, along with CI/CD pipelines, artifact registries and identity providers (Entra ID, Okta).
We agree the systems in scope and the benchmarks to assess against, CIS, vendor or your own standard.
We gather settings and evidence read-only, via exports, config files, read-only accounts or a guided walkthrough. Nothing is changed.
We compare against the benchmark, remove false positives, and confirm findings with your team so the results reflect reality.
You get a risk-rated report with specific remediation per finding, and an optional re-check once fixes are in place.
Tell us what’s in scope, devices, cloud accounts or DevOps platforms, and we’ll scope a configuration review.