Initial assessment
Port scanning with Nmap, checks with Lynis or CIS-CAT, and an inventory of services, users and outdated packages.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
Most breaches start through an open door: SSH with a weak password, RDP exposed to the internet, or a control panel nobody has updated in years. We assess your servers against CIS benchmarks, close those doors with minimal impact on running services, and document every change.
Server hardening is the process of closing the common ways into a Linux or Windows server, such as SSH with weak passwords, RDP exposed to the internet and unused services, measured against CIS benchmarks. It is needed when server logs fill with failed login attempts, a data center has handed over a server with no security configuration, or a client or auditor asks for a server security report. PikoSystem first records the current state with Nmap and Lynis without changing anything, disables root and password login over SSH and adds Fail2ban, restricts RDP to VPN with NLA, and configures CSF, nftables or Windows Defender Firewall with a default-deny policy. Configuration is backed up first and services are tested after each stage. You get a before-and-after report with Lynis or CIS scores and a change list per server.
Port scanning with Nmap, checks with Lynis or CIS-CAT, and an inventory of services, users and outdated packages.
Root login and password authentication disabled in SSH, key-based login and Fail2ban; on Windows, RDP restricted to VPN with NLA enabled.
CSF, nftables or Windows Defender Firewall with a default-deny policy and only the required ports open.
Unused services and packages removed, automatic security updates enabled, and Nginx, PHP and MySQL settings tightened.
CIS recommendations applied through Group Policy, including password policy, account lockout, SMBv1 removal and logon auditing.
auditd or Windows Event Forwarding enabled, with login logs shipped to a separate server.
The CIS Benchmark for Windows Server has two profiles. Level 1 covers settings most servers can take without breaking services, such as password policy, logon auditing and disabling legacy protocols. Level 2 is stricter and aimed at sensitive systems; some of its settings, NTLM restrictions for example, can break older applications or printer connections.
We apply Level 1 as the baseline and pick Level 2 items per server role. In a domain, settings go into a GPO linked to a test OU before wider rollout. Standalone servers are handled with LGPO and Policy Analyzer from the Microsoft Security Compliance Toolkit, and results are checked with CIS-CAT Lite.
Moving SSH to another port is often the only step taken. It quiets the logs and does little against a targeted attacker. A costlier mistake is disabling password login before key login has been tested. Run sshd -t before reloading sshd, and keep a second session open.
On AlmaLinux and Rocky, turning SELinux off instead of fixing contexts or registering a new port with semanage removes a real layer of protection. On Debian 12, which no longer installs rsyslog by default, Fail2ban without backend = systemd reads no logs and silently does nothing. And host firewalls written only for IPv4 often leave every port open over IPv6.
The most important item is a fallback way in. If an SSH or firewall change goes wrong, a KVM, iLO or iDRAC console, or the VNC console in your data center panel, is the only route back. Confirm it works before we start.
List the software on each server, the ports it uses and the addresses that connect to it, such as branch accounting software reaching SQL Server. A fresh snapshot or backup, access to control panels like cPanel or DirectAdmin, and a low-traffic window complete the list.
Server count and variety come first. Ten identical Ubuntu servers can be hardened with one checklist and one playbook, while a mix of Linux, domain-joined Windows and panel-managed hosts needs a plan per group.
Legacy software that relies on TLS 1.0, SMBv1 or a local admin account adds testing time. A report format required by an auditor or client affects the work too. Remote access is usually enough, and an on-site visit is only needed for servers without an out-of-band management console.
Using agreed access, we record the current state without changing anything.
We walk you through each change and its impact on your services, and schedule a window to apply them.
We back up configuration files, apply changes in stages and test services after each one.
We rerun the scans and deliver a comparison report together with the change log.
Some settings may not suit older software. That's why we back up configuration first, apply changes in stages and test after each one. If something causes a problem, we roll it back and propose an alternative.
Yes. We install CSF and LFD, open the right ports for the panel and mail services, and send alerts to your email. The configuration is set so it doesn't conflict with the panel's own services.
The baseline holds for a long time, but software changes and new vulnerabilities appear. We recommend periodic reviews and regular patching, which can be part of a support contract.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.