System hardening reduces device vulnerabilities by replacing default settings, credentials, and configurations with secure, purpose-built ones before equipment is deployed to a network. A structured approach using vendor best practices, secure baselines, and deployment templates helps ensure consistent hardening across an infrastructure.
Hardening Techniques Overview
Hardening is something that we do to devices to make them less vulnerable, to reduce how many vulnerabilities they have so they can withstand attacks or some sort of cybersecurity issues.
When ordering equipment, they usually are not going to come pre-programmed. They're not going to have a lot of configurations specific to your business, unless you pay for those types of services. Instead, what happens is they come with some sort of default settings on them, some sort of default configurations, some sort of default credentials to log on to it. This eliminates the need for them to customize everything out of the factory, which would drive up a lot of cost to this equipment. But because of that, because they have these default settings to them, they come largely insecure. That is, the default credentials are something that everybody knows about — you can go and look it up online. And these configurations often are set up so that way this piece of equipment works, not so that it is the most secure setup.
Before we actually get into hardening, we have to first of all understand that adding equipment to our network, to our infrastructure — anything that we are adding adds a level of complexity, and there is some risk involved in that. So the first thing we have to understand, the first thing we have to process, is: are we adding something that's going to increase our risk, and does the benefit that we're going to get out of that piece of equipment justify that level of risk that we increase? So the first thing we should probably do is really question, do we really need to install this piece of equipment, or install this piece of software, install this application, install whatever we're doing? Do we really need it? Is it really necessary to do business?
We also shouldn't have equipment that is end of life or end of support, especially end of support. End of life is when they stop selling or marketing a piece of equipment. End of support then is when they are going to stop supporting it. And end of life usually is going to determine when there's going to be an end of support. That is, they're not going to support something forever. So something comes end of life, where they stop selling a piece of equipment, and then they might support it for a year or two years or maybe even three years after that, and then it's going to go to the end of support, where they're no longer going to release patches and security updates for this piece of equipment. Since it's no longer releasing patches and security updates, we need to take that out of our network, we need to take it out of our infrastructure.
Provided that we actually do need this piece of equipment, and we've purchased it, we received it, now there are steps that we need to go through to harden that piece of equipment. We need to do some update and patching with it, perhaps do some sort of encryption on it, disable ports and protocols and software. We're going to uninstall certain software or uninstall certain features on it. We're going to change the default settings, the default passwords. We're going to disable any unused accounts, and we're just going to kind of strip this down to the bare basics of what we need to have it run on our network.
Now, how we should be thinking about this is some sort of comprehensive program of how do we harden equipment that we're rolling out, that we're putting on our infrastructure, that we're putting on our network. And so, how do we make sure we don't skip any steps? Well, the way we're going to do that is we're going to have some sort of process that we're going to use to go through to make sure that we harden equipment correctly.
And so where do we get that? Well, one thing that we could do is we could create our own documentation on it. So we could create our documentation on how we deploy different pieces of equipment and how we harden that piece of equipment. There's also a lot of best practices that can go into that documentation. Usually the vendor of whoever is putting that product out there will have documentation on best practices, so we need to go and research what those best practices are.
We can also create something called secure baselines. Secure baselines is going to be what is the minimum, or what is the requirement as we're deploying things — what is the requirement for the deployment of that?
We also can use techniques like imaging. One thing that we can do is if we're deploying a lot of machines, we can image that machine. We could harden that machine and then image it, and then reimage other machines as we deploy them. So we take an image from one machine that's been hardened and we deploy that on other machines.
There's also the use of templates, and this can widely vary on how we use templates, but a lot of software we can create some sort of template that we're going to use to deploy to other machines. So for instance, if I'm deploying routers and switches, I'll have a template configuration for that that starts out with the basic configurations for security, and then I'll use that template to create the actual configurations to deploy those routers and servers and switches and all of that.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →