What is a Configuration Review?
A configuration review provides detailed insight into the security configurations of your off-the-shelf appliances and software products. Configuration reviews ensure that all the security features in your operating systems and software are enabled and correctly configured.
While black-box penetration testing assesses systems from an attacker’s external viewpoint, a configuration review provides a “white-box” audit of underlying operating systems, server templates, databases, network devices, and workstation builds. This assessment benchmarks system settings against globally recognised hardening frameworks—such as the Centre for Internet Security (CIS) Benchmarks and NIST.
Key Areas & Vulnerabilities Identified
Assessments meticulously evaluate system settings across physical, virtual, and cloud-hosted environments. Core focus areas include.
Operating System Hardening
Reviewing Windows Server, Linux, and macOS builds to ensure default administrator accounts are disabled, unnecessary local services are deactivated, and robust auditing policies are enforced.
Default Credentials Weak Account Policies
Identifying unchanged factory passwords, permissive password complexity rules, missing account lockout thresholds, and insecure session inactivity timeout limits.
Insecure Protocols and Legacy Services
Spotting vulnerable services running by default (such as Telnet, SMBv1, or unencrypted SNMPv1/v2c) that allow credential harvesting or man-in-the-middle attacks.
Database and Web Server Configurations
Auditing configuration files and access control mechanisms for platforms such as Microsoft SQL Server, PostgreSQL, Apache, Nginx, and IIS to prevent data leakage and remote exploitation.
Network Device and Appliance Baselines
Evaluating routers, switches, and load balancers to verify encrypted management access (SSH/HTTPS), secure syslog logging, and restricted administrative network interfaces.
Privilege and Access Control Misconfigurations
Inspecting user rights assignments, sudoer configurations, file permission structures, and access control lists (ACLs) to block privilege escalation vectors.
A CREST-Accredited Methodology
Because enterprise environments feature diverse technology stacks, configuration reviews are tailored to each organisation’s unique infrastructure. Assessments combine automated compliance scanning tools with extensive manual inspection of registry entries, configuration files, and Group Policy Objects (GPOs).
As a CREST-accredited service provider, Cyber Security Specialists ensures reviews are conducted by certified security professionals with recognised technical certifications, such as OSCP and CREST. All assessments follow industry-recognised standards, ensuring compliance with PCI DSS, Cyber Essentials Plus, and ISO 27001 requirements.
Comprehensive Reporting and Remediation
After the assessment, we deliver a detailed, actionable report to internal IT and engineering teams. This documentation classifies risks to the overall cybersecurity posture, prioritises vulnerabilities for remediation, and provides clear technical recommendations. Systems administrators receive step-by-step configuration guidance and baseline hardening templates to remediate identified weaknesses efficiently.
Harden Enterprise Systems Today
Penetration testing and configuration reviews help organisations identify and fix vulnerabilities before an attacker can exploit them, reducing risk and protecting core operational infrastructure.
To discuss your exact Configuration Review requirements, please get in touch with a member of the team by emailing info@cybersecurityspecialists.co.uk or calling 0161 706 0244.