Zero Trust · IAM · SOC 2 · Free Checklist
Security Hardening Checklist: 45 checks to close the gaps attackers actually exploit Most breaches don't start with a zero-day. They start with a stale admin credential nobody rotated, an S3 bucket left public, or a service account with permissions nobody ever reviewed. This self-scored checklist audits your environment across the same hardening domains our security engineers check before an audit — identity and access, network perimeter, data protection, and monitoring readiness. Enter your details and we'll send the PDF straight to your inbox.
Instant PDF delivery. No sales call required. Unsubscribe anytime.
Your Security Hardening Checklist is on its way. Check your inbox in the next few minutes — and your spam folder just in case.
4 Hardening domains scored
45+ Diagnostic checks
20min Typical time to complete
PDF delivered instantly to your inbox Free
4Hardening domains — identity, network, data, monitoring
45+Diagnostic checks used by our own security engineers
20 minTo score your environment and get a hardening rating
0Sales calls required to get your results
Is This Checklist for You? Built for Teams Who Want to Find
Gaps Before an Auditor Does.
If nobody on your team can say with confidence when the last access review happened, this checklist gives you a structured, honest baseline — before a breach or an audit finding forces the conversation.
Security and IT leaders preparing for SOC 2, ISO 27001, or a customer security questionnaire
Teams who haven't run a formal hardening review in over a year
Teams doing a structured post-incident review and want to check for other blind spots
Anyone comparing security posture across AWS, Azure, or GCP for consistency
Teams building the case for security investment before the next budget cycle
This is probably not what you need if:
You're responding to an active breach right now — this is a proactive review tool, not incident response.
You already run continuous penetration testing and a mature red team program.
You need hands-on remediation, not a self-serve score — talk to our security team instead.
The checklist is free either way — it's a working document, not a sales funnel in disguise.
What's Inside
Four Domains.
One Hardening Score.
Each domain scores a different way real breaches actually start — with a plain-language question, not a jargon-heavy audit.
Identity & Access Management 12 checks
Where most real-world breaches actually start.
MFA enforcement coverage
Least-privilege role design
Privileged access review cadence
Service account & key rotation
Network & Perimeter Security 11 checks
Whether your attack surface is bigger than anyone realises.
Network segmentation & zero-trust boundaries
Public exposure & open port audit
Firewall & security group rule hygiene
VPN & remote access controls
Data Protection & Encryption 11 checks
Whether a breach becomes a data-loss headline or a non-event.
Encryption at rest & in transit coverage
Secrets management maturity
Backup encryption & access control
Data classification & handling
Monitoring & Compliance Readiness 11 checks
Whether you'd know about a breach in minutes, or months later.
Centralised logging & SIEM coverage
Vulnerability scanning cadence
Patch management SLA adherence
Audit trail & compliance evidence readiness
Platform-Agnostic
Works Whichever Cloud
You're Actually Securing.
The hardening checks are the same regardless of platform — but the follow-up guidance in the PDF is tailored, since AWS, Azure, and GCP each carry different native security tooling.
AWS
Amazon Web ServicesIAM · Security Hub · GuardDuty

Guidance calibrated against AWS IAM best practices, Security Hub findings, and GuardDuty threat detection.

IAM policy & least-privilege signals Public S3 & resource exposure checks
AZ
Microsoft AzureEntra ID · Defender · Sentinel

Guidance calibrated for Entra ID Zero-Trust identity, Microsoft Defender, and Sentinel SIEM coverage.

Conditional access & MFA coverage fit Defender & Sentinel alerting signals
GCP
Google CloudIAM · Security Command Center

Guidance calibrated for GCP IAM design and Security Command Center posture findings.

IAM role & service account fit Security Command Center coverage signals
How to Use It
Twenty Minutes.
Four Steps.
No workshop, no consultant on the call. Answer honestly and score your environment as it actually is today.
01
Score Each Domain ~12 Minutes Work through the 45+ checks across all four hardening domains.
02
Get Your Hardening Rating ~2 Minutes Get a rating per domain — Hardened, At Risk, or Critical Gap.
03
Flag the Critical Gaps ~3 Minutes Identify the lowest-scoring domain — that's where breach risk concentrates.
04
Build a Remediation Plan ~3 Minutes Turn the gaps into a prioritised remediation plan for the next quarter.
What Checklists Typically Reveal The Breach Started With a Gap Everyone Assumed Was Covered. Across the hardening reviews our security engineers run before scoping engagements, the same gaps recur: a stale admin credential nobody rotated, MFA that wasn't enforced on service accounts, and a logging gap that meant nobody noticed for weeks. Each one is fixable — if it's found in the checklist, not the incident report. This self-scored checklist is the same starting point we use before scoping any security engagement — free, self-serve, and yours to keep either way. Talk to a Security Architect
Security team reviewing access controls and audit logs
Why Trust This Checklist
Written From Real Security Engagements.
Not a Generic Checklist.
This isn't a repackaged blog post. It's the same diagnostic our engineers run before scoping any Zero-Trust or compliance engagement.
Built from real breach patterns Every check exists because it was the actual root cause of a real incident somewhere — not because it sounded thorough in a template.
Platform-agnostic by design One checklist whether you're running AWS, Azure, GCP, or a hybrid environment.
No obligation, no upsell It's a free working document. Keep it, use it, share it with your team — no strings attached.
Get the Checklist
Ready to Find Out
How Hardened You Actually Are?
Enter your name and work email — the PDF lands in your inbox in minutes.
Prefer an expert-led review instead? Talk to our team →