Zero Trust · IAM · SOC 2 · Free Checklist
Security Hardening Checklist: 45 checks to close the gaps attackers actually exploit
Most breaches don't start with a zero-day. They start with a stale admin credential nobody rotated, an S3 bucket left public, or a service account with permissions nobody ever reviewed.
This self-scored checklist audits your environment across the same hardening domains our security engineers check before an audit — identity and access, network perimeter, data protection, and monitoring readiness. Enter your details and we'll send the PDF straight to your inbox.
Your Security Hardening Checklist is on its way.
Check your inbox in the next few minutes — and your spam folder just in case.
4
Hardening domains scored
45+
Diagnostic checks
20min
Typical time to complete
PDF delivered instantly to your inbox
Free
4Hardening domains — identity, network, data, monitoring
45+Diagnostic checks used by our own security engineers
20 minTo score your environment and get a hardening rating
0Sales calls required to get your results
Is This Checklist for You?
Built for Teams Who Want to Find
Gaps Before an Auditor Does. If nobody on your team can say with confidence when the last access review happened, this checklist gives you a structured, honest baseline — before a breach or an audit finding forces the conversation.
Gaps Before an Auditor Does. If nobody on your team can say with confidence when the last access review happened, this checklist gives you a structured, honest baseline — before a breach or an audit finding forces the conversation.
Security and IT leaders preparing for SOC 2, ISO 27001, or a customer security questionnaire
Teams who haven't run a formal hardening review in over a year
Teams doing a structured post-incident review and want to check for other blind spots
Anyone comparing security posture across AWS, Azure, or GCP for consistency
Teams building the case for security investment before the next budget cycle
This is probably not what you need if:
The checklist is free either way — it's a working document, not a sales funnel in disguise.
You're responding to an active breach right now — this is a proactive review tool, not incident response.
You already run continuous penetration testing and a mature red team program.
You need hands-on remediation, not a self-serve score — talk to our security team instead.
What's Inside
Four Domains.One Hardening Score. Each domain scores a different way real breaches actually start — with a plain-language question, not a jargon-heavy audit.
Identity & Access Management
12 checks
Where most real-world breaches actually start.
MFA enforcement coverage
Least-privilege role design
Privileged access review cadence
Service account & key rotation
Network & Perimeter Security
11 checks
Whether your attack surface is bigger than anyone realises.
Network segmentation & zero-trust boundaries
Public exposure & open port audit
Firewall & security group rule hygiene
VPN & remote access controls
Data Protection & Encryption
11 checks
Whether a breach becomes a data-loss headline or a non-event.
Encryption at rest & in transit coverage
Secrets management maturity
Backup encryption & access control
Data classification & handling
Monitoring & Compliance Readiness
11 checks
Whether you'd know about a breach in minutes, or months later.
Centralised logging & SIEM coverage
Vulnerability scanning cadence
Patch management SLA adherence
Audit trail & compliance evidence readiness
Platform-Agnostic
Works Whichever CloudYou're Actually Securing. The hardening checks are the same regardless of platform — but the follow-up guidance in the PDF is tailored, since AWS, Azure, and GCP each carry different native security tooling.
AWS
Amazon Web ServicesIAM · Security Hub · GuardDuty
Guidance calibrated against AWS IAM best practices, Security Hub findings, and GuardDuty threat detection.
IAM policy & least-privilege signals
Public S3 & resource exposure checks
AZ
Microsoft AzureEntra ID · Defender · Sentinel
Guidance calibrated for Entra ID Zero-Trust identity, Microsoft Defender, and Sentinel SIEM coverage.
Conditional access & MFA coverage fit
Defender & Sentinel alerting signals
GCP
Google CloudIAM · Security Command Center
Guidance calibrated for GCP IAM design and Security Command Center posture findings.
IAM role & service account fit
Security Command Center coverage signals
How to Use It
Twenty Minutes.Four Steps. No workshop, no consultant on the call. Answer honestly and score your environment as it actually is today.
01
Score Each Domain
~12 Minutes
Work through the 45+ checks across all four hardening domains.
02
Get Your Hardening Rating
~2 Minutes
Get a rating per domain — Hardened, At Risk, or Critical Gap.
03
Flag the Critical Gaps
~3 Minutes
Identify the lowest-scoring domain — that's where breach risk concentrates.
04
Build a Remediation Plan
~3 Minutes
Turn the gaps into a prioritised remediation plan for the next quarter.
What Checklists Typically Reveal
The Breach Started With a Gap Everyone Assumed Was Covered.
Across the hardening reviews our security engineers run before scoping engagements, the same gaps recur: a stale admin credential nobody rotated, MFA that wasn't enforced on service accounts, and a logging gap that meant nobody noticed for weeks. Each one is fixable — if it's found in the checklist, not the incident report.
This self-scored checklist is the same starting point we use before scoping any security engagement — free, self-serve, and yours to keep either way.
Talk to a Security Architect
Why Trust This Checklist
Written From Real Security Engagements.Not a Generic Checklist. This isn't a repackaged blog post. It's the same diagnostic our engineers run before scoping any Zero-Trust or compliance engagement.
Built from real breach patterns
Every check exists because it was the actual root cause of a real incident somewhere — not because it sounded thorough in a template.
Platform-agnostic by design
One checklist whether you're running AWS, Azure, GCP, or a hybrid environment.
No obligation, no upsell
It's a free working document. Keep it, use it, share it with your team — no strings attached.
Get the Checklist
Ready to Find OutHow Hardened You Actually Are? Enter your name and work email — the PDF lands in your inbox in minutes. Prefer an expert-led review instead? Talk to our team →
