[ Servers & DevOps  /  Server Security Hardening ]

Get hardened before you get compromised.

Servers are scanned within minutes of coming online and probed continuously afterwards. Hardening is not paranoia, it is basic maintenance. I audit what you have, fix it, and give you a written record of what changed.

Read-only audit first · Report in 5 days · No agent installed

5 daysto a written audit
Read-onlyto start
No agentinstalled on your box
Reportyou keep either way

[ Attack surface ]

How servers actually get taken.

Almost never a sophisticated exploit. Nearly always one of these, left in place because it was never anyone's job.

Weak or reused SSH access

Password authentication enabled, root login permitted, and keys shared between people who have since left.

Unpatched packages

Known vulnerabilities with public exploit code, sitting unpatched for months because updates are manual.

Services exposed by accident

A database, cache or admin panel bound to a public interface because that was the quickest way to test it.

No intrusion detection

Nothing watching for repeated failures, new listening ports or changed system binaries.

Over-privileged applications

Web processes running as root, so a single application flaw becomes full machine access.

Secrets in plain text

Database passwords and API keys in world-readable config files and shell history.

[ How it works ]

Audit, harden, verify.

01  —  Day 1-5

Audit

A read-only review of access, exposed services, patch level, permissions, logging and secret handling. You get a findings report rated by severity.

02  —  Day 6-10

Harden

Findings fixed in severity order, each change tested so nothing breaks. Anything risky is scheduled inside a maintenance window you choose.

03  —  Handover

Verify & document

Re-scan to confirm each finding is closed, then a written record of every change and an ongoing maintenance schedule for your team.

[ What actually changes ]

The hardening checklist.

Applied proportionately — a marketing site and a system holding payment data do not need the same controls, and I will not sell you the same job twice.

Access & exposure

  • SSH hardening — key-only authentication, no root login, per-person keys, brute-force protection.
  • Firewall rules — default deny, minimal open ports, internal services bound to private interfaces.
  • Least-privilege accounts — per-service users, no application running as root, sudo scoped and logged.
  • Secret management — credentials out of config files and history, permissions locked down.
  • Admin surface — control panels and dashboards behind authentication or a private network.

Detection & upkeep

  • Automatic security updates — unattended patching for security packages, with reboot policy agreed.
  • Intrusion detection — file integrity monitoring and alerting on suspicious authentication patterns.
  • Centralized logging — logs shipped off the machine so an attacker cannot simply erase them.
  • Malware and rootkit scanning — scheduled, with results actually delivered to a human.
  • Incident runbook — what to do, in order, if the machine is suspected compromised.

[ Example engagement ]

Sixteen findings, eleven of them critical.

A production server with password SSH, a publicly bound database, and eight months of missing security patches. All critical findings closed inside a week with no service interruption.

Illustrative example of a typical engagement. Figures vary with the state of your systems and are not a guarantee of a specific outcome.

16findings identified
11rated critical or high
6 daysto all closed
0downtime during work

[ Free · read-only · 5 days ]

Find out where you actually stand.

A written audit of your servers with every finding rated by severity and effort. Yours to keep and fix in-house if you prefer.

Request the audit

[ Pricing ]

Pricing that fits your budget.

Tell me the number you have to work with. I'll tell you honestly what's achievable within it — and if it isn't enough, I'll say so before we start rather than halfway through.

Fixed project price

Scope agreed in writing, price agreed in writing, before any work starts. No hourly creep and no invoice you haven't already approved.

Monthly retainer

For ongoing work — maintenance, monitoring, updates and small changes. Month to month, cancel whenever, no minimum term.

Hourly for small jobs

For a single bug or a short task where writing a full scope would cost more than simply doing the work.

Budget too tight for the whole thing? I'll often suggest doing the highest-value part first and the rest later, rather than doing all of it badly.

[ Questions ]

Common questions.

Will hardening break our application?

Not if it is done in the right order and tested, which is why the audit comes first. Anything with a risk of breaking something is scheduled inside a window you choose, with a rollback ready.

Do you install security software on our servers?

The audit is read-only and installs nothing. During hardening I may add standard open-source tooling for patching, file integrity and log shipping — all of it visible, documented, and removable.

We already passed a compliance audit. Do we need this?

Compliance and security overlap but are not the same thing. A checklist audit confirms you have controls documented; this confirms they actually hold up on the machine.

Can you help if we have already been hacked?

Yes, and that is a different and more urgent job — containment first, then forensics, then a clean rebuild. Get in touch and say clearly that you are actively compromised.

How often should this be repeated?

An annual review is reasonable for most businesses, with automated patching running continuously in between. If you handle payment or health data, more often.

[ Let's talk ]

Tell me what's broken.

Describe the problem in a few lines and you'll get a real reply from the person who'd do the work — same working day, no discovery call required.