Hardening guides

How to make a thing harder to attack, written for somebody who has to do it on Monday to an estate that is already running and cannot be taken down for it.

two sections most guides leave out

How to verify. Nearly every hardening guide tells you to change a setting and stops there. Whether the setting applied is a different question from whether you set it: policy loses to a local override, a management profile fails silently on a subset of devices, and a tick in a console is not evidence. Every step here says how to confirm it took.

What it does not cover. A control trusted beyond its reach is worse than no control, because the gap it leaves is one nobody is looking at.

01

Securing the operating systems you already run

Whoever owns the build, in an estate that is already deployed

Three published baselines exist and they disagree with each other on purpose. Picking one and applying a subset beats reading all of them and applying none, which is what usually happens.

5 steps · 1 take minutes · 3 stated limits

02

Making phishing harder for one department

Anyone asked to reduce phishing risk without a budget

Business email compromise remains the most commonly reported incident type, and in essentially every case where MFA was deployed it was defeated rather than absent. The technical layer is worth doing and it is not the layer that decides the outcome.

5 steps · 2 take minutes · 3 stated limits

03

Redacting a document so it stays redacted

Anyone publishing a report, responding to a request, or handling disclosure

Redaction failures are among the most reliably embarrassing incidents there are, because the document is usually already public by the time anybody notices and it cannot be recalled.

5 steps · 4 take minutes · 3 stated limits

04

Securing switch ports on a campus network

Network and security staff sharing responsibility for the edge

Physical ports in meeting rooms, receptions and lecture theatres are an access route that nothing else on this site covers, and the controls are old, well understood and frequently unconfigured.

5 steps · 0 take minutes · 3 stated limits