Service · Cybersecurity

System hardening

This is aimed at firms with no regulator breathing down their neck that still cannot afford a week offline after a ransomware hit. Many attacks on small and mid-sized firms use nothing sophisticated: they get in through default settings, legacy protocols and accounts everyone has forgotten about. First comes a review, then we tackle whatever buys the most protection for the smallest spend. Often that means changing settings, not buying hardware or licences.

Review
from outside and inside
Settings
often enough
Roadmap
ordered by risk
Proof
by rescanning

Included in this service

Rather than ticking off documents, we test whether your systems would survive an ordinary attack. We benchmark against CIS guidelines, Microsoft Secure Score and CERT Polska recommendations.

Talk the scope through with an engineer

Internet edge

Exposed ports, reachable admin consoles, and port forwards someone set up “temporarily” years ago.

Accounts and passwords

Passwords shared between colleagues, logins still live for staff long gone, a crowd of domain admins and service accounts with credentials untouched for years.

Default settings

Turning off SMBv1, NTLMv1 and LLMNR, basic auth in Microsoft 365, web-borne Office macros and services nobody uses.

Updates

The patch gap on each system, whether updating happens on any regular basis, and which servers run an OS past its end of support.

Backups

Whether a backup exists, where it lives, whether ransomware could encrypt it, and when anyone last restored something from it.

Action plan

A list of changes with priority, estimated effort and an indicative cost, ready to put in front of the board.

How we work together

How long the review and the urgent fixes take depends on the size of your estate. No site visits are involved at any stage.

01

Data gathering

We examine your systems both externally and from within via a secured remote connection, run tools such as PingCastle against Active Directory and talk to whoever looks after your IT.

02

Report

Findings written in plain language with their consequences for the business, not a table of acronyms and CVE numbers.

03

Quick fixes

Settings-level work comes first: credentials, rights, exposed ports, outdated protocols, safeguarding backups.

04

The rest

Anything that costs money is gathered into its own paper, with prices and the reasoning management will want to see.

A backup that nobody has ever restored from is not a backup. Typical problems are backup jobs that have been failing for months, archives holding the wrong folders, or a server restore that would take days. Regular trial recoveries are among the most neglected habits in IT.

Questions and answers

We agree the price of the review before we begin, based on how big your estate is. Remediation runs at PLN 190/hour excl. VAT, or falls within your managed support agreement. Buying anything new is a separate conversation.

All the more so, since nobody watches the configuration day to day. We handle the review and the fixes, then can keep things in shape on a Start, Business or Premium plan. You will not need to touch anything technical.

Annually, plus after any big shift: moving to the cloud, launching a new system, handing IT to someone else. In between, routine scans of your public-facing services will do.

Barely, as long as the sequence is right. Changes go to a test group first, people hear about them in advance, and anything that breaks an ageing accounting package relying on an obsolete protocol gets reversed.

No, it is a different instrument. A formal audit examines processes and documents; hardening checks whether you can easily be attacked in technical terms. Its results do prepare you well for an audit, though, because they deal with the most common technical findings.

Order a review of your environment

You receive a risk-ranked list of weaknesses, and some of them can usually be fixed straight away at no hardware cost.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.