Start from the configuration, not from the tools
Hardening begins with an inventory: what actually runs, who holds an account, and which services are reachable from outside. Anything nobody can account for is removed rather than watched, and every change is written down, because a setting nobody can find later is a setting nobody dares touch.
- An inventory of systems, accounts and exposed services
- Default credentials and unused services closed or removed
- Every change recorded, with what it was and why it was made









