Skip to main content

Cyber Tech Insights

Server Hardening Checklist for Linux and Windows

October 4, 2026
Server Hardening Checklist: 6 Best Proven Steps for 2026

Sponsored resource. When you request this resource, the details you submit are shared with its sponsor, who may contact you. See our Privacy Policy.

A server hardening checklist for Linux and Windows: accounts, services, patching, logging and data protection, aligned with the CIS Benchmarks.

Default server installations favour convenience over security. Hardening reduces the attack surface so that a single weakness is less likely to become a breach. Recognised baselines such as the CIS Benchmarks provide detailed settings; this checklist covers the essentials.

Accounts and access

  • Disable or rename default accounts and remove unused ones.
  • Enforce strong authentication and multi-factor authentication for administrative access.
  • Use least privilege; avoid shared administrator accounts.
  • Restrict remote administration (SSH, RDP) to management networks or bastion hosts.

Services and software

  • Remove unneeded roles, packages and services.
  • Close unused ports with host-based firewalls.
  • Disable legacy protocols and weak ciphers.

Patching and lifecycle

  • Patch operating systems and applications on a defined schedule.
  • Prioritise vulnerabilities known to be exploited.
  • Replace operating systems before vendor end of support.

Logging and monitoring

  • Forward security logs to a central platform.
  • Alert on new administrator accounts, failed logins and service changes.
  • Use file integrity monitoring for critical system files.

Data protection

  • Encrypt disks where appropriate, especially on portable or edge hardware.
  • Back up configuration as well as data.
Automate it: apply hardening through configuration management or golden images so every new server starts secure.

Turning the checklist into a repeatable process

Hardening once is not enough. Servers drift as administrators make changes, applications are installed and new vulnerabilities are discovered. These six proven steps make server hardening sustainable.

  1. Adopt a baseline. Start from a recognised benchmark and document justified exceptions for your environment.
  2. Build hardened images. Bake settings into golden images or templates so every new server starts compliant.
  3. Enforce with automation. Use configuration management or policy tools to apply and continuously enforce settings.
  4. Scan for compliance. Regularly assess servers against the baseline and report deviations to owners.
  5. Restrict administrative access. Use privileged access management, just-in-time elevation and multi-factor authentication for administrators.
  6. Review annually. Update the baseline as operating systems, threats and business requirements change.

Common mistakes to avoid

  • Applying a benchmark blindly and breaking applications without testing.
  • Leaving default accounts, sample files or unused roles installed.
  • Disabling logging to save disk space.
  • Hardening production while leaving development servers exposed.

Frequently asked questions

Which servers should be hardened first?

Prioritise internet-facing systems, domain controllers and servers that hold sensitive data.

Does hardening affect performance?

Most settings have negligible impact. Test changes such as auditing and encryption on representative workloads.

How do we handle exceptions?

Record each exception with a business reason, owner, compensating control and review date.

A 90-day action plan

Days 1 to 30: choose a baseline for each operating system you run, scan a sample of servers against it and record the most common deviations.

Days 31 to 60: test baseline settings on non-production systems, agree documented exceptions with application owners and update golden images.

Days 61 to 90: roll out settings through configuration management, schedule compliance scans and publish a dashboard showing compliance by owner.

Questions to ask application owners

  • Which services and ports does the application genuinely require?
  • Which accounts need administrative rights, and when?
  • Are there vendor requirements that conflict with baseline settings?
  • What logs are needed for troubleshooting and security investigations?
  • How can the application be tested after changes?

Key terms explained

  • Baseline: an agreed set of secure configuration settings.
  • Golden image: a pre-configured template used to build new servers.
  • Least privilege: giving accounts only the access they need.
  • Attack surface reduction: removing unused services, ports and software.
  • Configuration drift: gradual divergence from the approved settings.

The bottom line

Secure configuration is one of the most effective and least expensive defences available. Adopting a recognised baseline, building it into images, enforcing it automatically, scanning for deviations and documenting exceptions turns a one-off exercise into a sustainable process. Prioritise internet-facing systems and those holding sensitive information, test changes before rollout and review the baseline regularly. Consistently applied, these practices reduce the attack surface across the entire fleet.

Further reading on server hardening

For authoritative, vendor-neutral guidance on server hardening, see the CIS Benchmarks. You can also browse our free whitepapers.