Service Configuration
Reviews
Hardening assessment of the platform services that carry your data and expose your business — databases, web servers and mail systems — reviewed against security best practices including CIS benchmarks, vendor guidance, and the tradecraft our operators use to attack them.
Device configuration reviews harden the hosts. Service configuration reviews harden what runs on them — and it is almost always the service layer, not the operating system, that an attacker actually exploits once inside a network. A fully patched Windows Server hardened to CIS Level 2 provides no protection whatsoever if the SQL Server instance on it has xp_cmdshell enabled and an application account with sysadmin rights.
These services share a common failure pattern. They are deployed from vendor defaults under project pressure, configured by teams optimising for functionality rather than security, and then left untouched for years because they work. Privileges accumulate, legacy protocols stay enabled to support a system that was decommissioned two years ago, and no one holds a current picture of what the configuration actually permits.
We review each service against its applicable benchmark, then go considerably further — assessing the privilege model, the trust relationships with adjacent systems, and the specific configuration states our red team operators look for when they need to move from initial access to objective. Findings are prioritised by exploitability, not compliance severity.
Scope Definition & Baseline Selection
Agreement on in-scope service instances, their role in the environment, and the applicable benchmark set. We tailor baselines to your operational constraints rather than applying them wholesale, so that recommendations remain implementable in a production estate.
Configuration Extraction
Secure capture of live service configuration — database instance and security settings, web server and virtual host definitions, mail transport and connector configuration — alongside version and patch level, loaded modules or extensions, and the service account security context.
Benchmark & Hardening Analysis
Systematic assessment against security best practices including CIS benchmarks, DISA STIGs and vendor hardening guidance, with each control marked pass, fail or not applicable and annotated for relevance to your specific deployment.
Privilege & Trust Model Review
Examination of accounts, roles, delegation and inter-service trust. This is where the highest-impact findings consistently emerge — service accounts with far more privilege than their function requires, delegation grants that survive their original purpose, and trust relationships that let a compromise in one service reach directly into another.
Exposure, Encryption & Data Handling
Assessment of network reachability, listener configuration, and transport encryption, together with how sensitive data is stored, encrypted and surfaced. We verify that services are not unnecessarily exposed, that TLS is enforced with current protocol versions and cipher suites, and that data at rest is protected appropriately.
Audit Logging & Detection Coverage
Review of what each service records, whether those records reach a monitored SIEM, and whether the events that indicate compromise would actually be visible. We identify the specific blind spots — privileged operations, bulk data access, configuration changes — through which an intrusion would currently pass unobserved.
Reporting & Remediation Guidance
A risk-rated technical report with platform-specific remediation. Executive summary and technical debrief included as standard.
Service configuration is a specialist discipline that most testing firms treat as a scanner run with a benchmark stapled to the front. Our assessors understand the internals and privilege models of each platform, and they assess configuration in the context of your wider environment — identifying how a weakness in one service combines with others to form a real attack path rather than an isolated finding.
Every recommendation is delivered as working configuration your engineers can apply, not prose describing what they should research. That difference is what turns a report into remediated infrastructure.