PikoSystem IT engineering services
Security & Recovery

Linux and Windows server hardening

Most breaches start through an open door: SSH with a weak password, RDP exposed to the internet, or a control panel nobody has updated in years. We assess your servers against CIS benchmarks, close those doors with minimal impact on running services, and document every change.

Tools & technology server-hardening
  • Lynis
  • CIS Benchmarks
  • Nmap
  • Fail2ban
  • CSF
  • nftables
  • OpenSSH
  • Group Policy
  • auditd
6work areas
4deliverables
4steps

What is Server Hardening?

Server hardening is the process of closing the common ways into a Linux or Windows server, such as SSH with weak passwords, RDP exposed to the internet and unused services, measured against CIS benchmarks. It is needed when server logs fill with failed login attempts, a data center has handed over a server with no security configuration, or a client or auditor asks for a server security report. PikoSystem first records the current state with Nmap and Lynis without changing anything, disables root and password login over SSH and adds Fail2ban, restricts RDP to VPN with NLA, and configures CSF, nftables or Windows Defender Firewall with a default-deny policy. Configuration is backed up first and services are tested after each stage. You get a before-and-after report with Lynis or CIS scores and a change list per server.

When you need Server Hardening

  • Our server logs are full of failed SSH login attempts.
  • Our Windows server has RDP open directly to the internet.
  • The data center handed us a server with no security configuration at all.
  • A client or auditor has asked for a server security report.

What Server Hardening includes

01

Initial assessment

Port scanning with Nmap, checks with Lynis or CIS-CAT, and an inventory of services, users and outdated packages.

02

Access lockdown

Root login and password authentication disabled in SSH, key-based login and Fail2ban; on Windows, RDP restricted to VPN with NLA enabled.

03

Host firewall

CSF, nftables or Windows Defender Firewall with a default-deny policy and only the required ports open.

04

Updates and services

Unused services and packages removed, automatic security updates enabled, and Nginx, PHP and MySQL settings tightened.

05

Windows policies

CIS recommendations applied through Group Policy, including password policy, account lockout, SMBv1 removal and logon auditing.

06

Logging and audit

auditd or Windows Event Forwarding enabled, with login logs shipped to a separate server.

What you get from Server Hardening

  • A before-and-after report with Lynis or CIS scores
  • A list of changes applied to each server
  • A server security checklist for future builds
  • Open items that need a decision from you

Server Hardening: a practical guide

Windows Server hardening with CIS: Level 1 or Level 2?

The CIS Benchmark for Windows Server has two profiles. Level 1 covers settings most servers can take without breaking services, such as password policy, logon auditing and disabling legacy protocols. Level 2 is stricter and aimed at sensitive systems; some of its settings, NTLM restrictions for example, can break older applications or printer connections.

We apply Level 1 as the baseline and pick Level 2 items per server role. In a domain, settings go into a GPO linked to a test OU before wider rollout. Standalone servers are handled with LGPO and Policy Analyzer from the Microsoft Security Compliance Toolkit, and results are checked with CIS-CAT Lite.

Linux server hardening mistakes we keep finding

Moving SSH to another port is often the only step taken. It quiets the logs and does little against a targeted attacker. A costlier mistake is disabling password login before key login has been tested. Run sshd -t before reloading sshd, and keep a second session open.

On AlmaLinux and Rocky, turning SELinux off instead of fixing contexts or registering a new port with semanage removes a real layer of protection. On Debian 12, which no longer installs rsyslog by default, Fail2ban without backend = systemd reads no logs and silently does nothing. And host firewalls written only for IPv4 often leave every port open over IPv6.

How to prepare for server hardening

The most important item is a fallback way in. If an SSH or firewall change goes wrong, a KVM, iLO or iDRAC console, or the VNC console in your data center panel, is the only route back. Confirm it works before we start.

List the software on each server, the ports it uses and the addresses that connect to it, such as branch accounting software reaching SQL Server. A fresh snapshot or backup, access to control panels like cPanel or DirectAdmin, and a low-traffic window complete the list.

What affects the scope of a server security project?

Server count and variety come first. Ten identical Ubuntu servers can be hardened with one checklist and one playbook, while a mix of Linux, domain-joined Windows and panel-managed hosts needs a plan per group.

Legacy software that relies on TLS 1.0, SMBv1 or a local admin account adds testing time. A report format required by an auditor or client affects the work too. Remote access is usually enough, and an on-site visit is only needed for servers without an out-of-band management console.

How Server Hardening works

  1. 01

    Review and scan

    Using agreed access, we record the current state without changing anything.

  2. 02

    Change plan

    We walk you through each change and its impact on your services, and schedule a window to apply them.

  3. 03

    Apply and test

    We back up configuration files, apply changes in stages and test services after each one.

  4. 04

    Report and handover

    We rerun the scans and deliver a comparison report together with the change log.

Server Hardening: frequently asked questions

Could hardening break our website or software?

Some settings may not suit older software. That's why we back up configuration first, apply changes in stages and test after each one. If something causes a problem, we roll it back and propose an alternative.

Do you install the CSF firewall on cPanel or DirectAdmin servers?

Yes. We install CSF and LFD, open the right ports for the panel and mail services, and send alerts to your email. The configuration is set so it doesn't conflict with the panel's own services.

Is hardening a one-time job?

The baseline holds for a long time, but software changes and new vulnerabilities appear. We recommend periodic reviews and regular patching, which can be part of a support contract.

Related searches

  • server hardening
  • VPS security
  • Linux server hardening
  • Windows Server CIS hardening
  • CSF firewall setup
  • server security checklist

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.