New network equipment arrives with outdated software, default passwords, and unnecessary features enabled — all of which must be addressed before deployment. Equipment hardening covers the techniques used to reduce those vulnerabilities across every device added to a network.
Equipment Hardening
Every time I got a new piece of equipment, I felt a little like it was a present for me. Despite the fact that I knew it wasn't mine, and I knew it was part of my work to get it up and running and set up on the network — I realized all that, but it still was fun to unwrap the piece of equipment. But all equipment comes with its own set of vulnerabilities, and so we need to make sure that we harden the equipment when we're putting it on the network.
When you get a new piece of equipment, there are a few things that you need to watch out for. For instance, when it rolls off the assembly line, it's going to take days, weeks, possibly months to get to you. Maybe it sits in some sort of warehouse. It could be a long time before you actually get to it. By that point in time, the operating system, the firmware, whatever software is installed on it is already outdated and has vulnerabilities — known vulnerabilities that people can leverage out there. So there are things that we're going to want to do to remove some of those vulnerabilities, like update the software.
Another thing to watch out for is that it's going to come fully functioning with lots of features turned on, because they want you to be able to successfully put it on the rack, plug things into it, put power to it, and have it working with a minimal number of steps to actually get that thing up and running and programmed. They want you to be successful and to be less likely that you return it. So equipment essentially comes to you very insecure, and we're going to need to take steps to secure that piece of equipment, to harden that piece of equipment.
Then the question is, what are you going to harden? The answer to that is everything. It could be networking equipment such as firewalls, routers, wireless access points, wireless controllers, VoIP phones. It could be servers, end user machines, copiers, printers, the internet of things, cameras, appliances. Anything that comes to you that you're putting onto your network, you should think about how you're going to harden that piece of equipment and what steps you're going to go through.
There are a lot of different steps you can take depending on what it is that you're hardening. If it's some sort of internet of things device, or some sort of server, or some sort of switch, there's going to be a different process to harden that, so you need to look that up. But there are some generalities.
As we're hardening our equipment, we're going to want to go through checklists. We're going to want to find online documentation of what needs to be done, and each piece of equipment is going to be different. We're going to want to raise each piece of equipment up to a certain standard. That standard is called a baseline. That's the minimum that we have to do in order to implement something in a secure way. So for each piece of equipment that we have — for instance, switches or firewalls or routers or laptops or desktops — we're going to want to have that standard baseline configuration to make sure that we implement it in a secure way.
We pretty much want to harden everything. There are some general approaches that we can take when it comes to hardening the equipment, but really it's going to take a little bit of research to find out what is the process that you should go through to harden the equipment that you're rolling out on your network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →