Services / Infrastructure security audit

A configuration-level review of your servers, network and operations: hardening, access, patching, logging and backups.

Most breaches do not need a zero-day. They use an SSH key nobody rotated, a database port left open to the internet, or a server years behind on patches.

We review how your infrastructure is actually configured and run, host by host, against recognised benchmarks, and give you a prioritised list of what to fix first.

sshd_config.diff — prod-db-01
# /etc/ssh/sshd_config- PermitRootLogin yes- PasswordAuthentication yes+ PermitRootLogin no+ PasswordAuthentication no+ AllowGroups ops-admins ✕ 5432/tcp open to 0.0.0.0/0 · restrict to app subnet
When you need this
  • You run your own servers, VMs or data-centre equipment
  • A client security questionnaire asks about hardening, patching or access control
  • Your infrastructure grew quickly and nobody has reviewed it end to end
  • Before an ISO 27001 or similar audit
Coverage

What we test

The exact scope is agreed in writing before we start. This is what a typical engagement covers.

01

Server hardening

  • OS configuration against CIS Benchmarks
  • Running services and listening ports
  • SSH, kernel and file-permission settings
02

Access & identity

  • Who can log in where, and with what rights
  • SSH key and password practices, shared accounts
  • Admin and sudo access, MFA on privileged paths
  • Access still held by people who have left
03

Network & perimeter

  • Firewall rules and exposed management ports
  • Segmentation between production, staging and office networks
  • VPN and bastion design
  • TLS configuration of public endpoints
04

Patching & vulnerabilities

  • OS and package versions against known CVEs
  • End-of-life operating systems and software
  • Container image vulnerabilities
05

Containers & deployment

  • Docker and Kubernetes configuration
  • Secrets in images, env files and repositories
  • CI/CD pipeline permissions and deploy credentials
06

Logging, backup & recovery

  • What is logged, where, and for how long
  • Alerting on suspicious activity
  • Backup coverage, encryption and restore testing
Deliverables

What you receive.

  • Inventory of the hosts and services reviewed
  • Findings with risk rating and exact remediation steps
  • Hardening checklist for each server role
  • Prioritised remediation plan: what to fix this week, this month, this quarter
  • Optional mapping of findings to ISO/IEC 27001 Annex A controls
Standards we work to
  • CIS Benchmarks
  • NIST SP 800-123
  • ISO/IEC 27001:2022 Annex A
  • CVSS
Before we start

What we need from you

  • A list of hosts and environments in scope
  • Read-only access, or a supervised screen-share session if access cannot be granted
  • Network diagrams, if you have them
  • A technical contact who knows how the systems are run

Never send passwords or keys by email. We set up a secure channel once the scope is agreed.

Often combined with

Related services.

Let's strengthen your security — get in touch.

Araval · Technologies
Email us
  1. 01Tell us what you need and by when
  2. 02We reply with questions or a written scope
  3. 03You get a fixed quote before any work starts
Discuss your scope