// SERVICE · SECURITY HARDENING

ONGOING PROGRAM · NOT A ONE-OFF PROJECT

Your network is running. But would it withstand a targeted attack?

Whether a cyber attack cripples your company or merely scratches it — that is not decided at the moment of the attack. It is decided now.

Security hardening that turns cyber attacks from an existential crisis into a manageable incident.
Monthly
Vulnerability evaluation
Monthly
Planning session
Weekly
8h implementation
Monthly
Consolidation review

The rhythm of our M365, AD and infrastructure hardening program: transparent, plannable, continuous

// 01 — WHEN YOU NEED US

Typical starting points: IT security for companies

Security hardening is not an emergency product. But sometimes the impulse comes from a cyber attack. Or from the realization that you only just escaped one.

Managing director · Asset protection

What you have built must still be standing tomorrow.

You have survived a cyber attack. The real question is not technical — it is entrepreneurial: how do you prevent it from happening again? And how do you make sure that on the next attempt an attacker cannot paralyse your entire company?

IT lead / CISO · Preventive situation

Many findings, unclear priorities.

The last pentest delivered a long list. Resources are limited. You do not need another checklist, but a risk-based prioritisation along real attack paths that gives you internal backing.

IT lead · Technical audit evidence

Technical evidence for audits, insurers and NIS-2

Auditors, insurers and NIS-2 increasingly demand robust technical evidence: not concepts, but implemented hardening measures with documented effectiveness. That is exactly what we deliver.

IT lead · Growing infrastructure

Cloud, remote work, new systems.

The attack surface grows faster than the capacity to control it. Without structured system hardening, blind spots emerge. Reduce the attack surface: methodically, not by gut feeling, without endangering operations.

NIS-2: Technical hardening measures are among the concrete obligations of the NIS-2 directive (NIS2). What this means for your company in practice: Implementing NIS-2: which measures are mandatory? →

// 02 — OUR APPROACH

How we work

We think like an attacker — and close every path he would take through your infrastructure.

Most providers deliver a report after a hardening project. We deliver a state: verifiable, validated monthly and implemented in close coordination with your IT. Every measure follows real attack paths: the way a hacker thinks, not the way a framework dictates.

For technical security leaders: Our attack-path analysis follows the MITRE ATT&CK methodology — we prioritise by tactics, techniques and procedures (TTPs) used in real attacks against comparable infrastructures. No generic framework mapping, but concrete attack-chain logic from our own offensive experience.

Operations stay stable — always

No off-the-shelf hardening

Measures are tailored to your specific environment: risk-based, not rolled out by generic standards.

Micro-projects instead of big bang

Every operations-critical measure is prepared: risks evaluated, rollback scenario defined, implementation only after joint approval.

Announcement & sign-off

Every operational measure is communicated in advance and formally signed off with documentation afterwards. Your team always knows what is running and why.

Joint decisions

The client decides in coordination with ProSec. You stay in control of your infrastructure.

1

Attack-path analysis

We model how an attacker would reach critical assets in your real infrastructure, including Active Directory, identities and network segmentation.

2

Risk prioritisation

Measures are weighted by actual exploitability and business impact, so that limited resources work where it counts.

3

Operational IT hardening

System hardening across systems, identities, configurations and permissions — without losing usability and productivity.

4

Validation & anchoring

Monthly vulnerability evaluation tracks progress. Defense baselines and hardening standards are documented and permanently anchored.

Security becomes measurable

Monthly evaluations produce a clear progress curve. The security level becomes comparable over time and communicable to management, supervisory board or insurers.

// 03 — HARDENING AREAS

What we harden and what you receive

Security hardening and IT hardening are not off-the-shelf products. We work through every layer of your infrastructure: from identity to perimeter, from Microsoft 365 to the network. Everything prioritised by what an attacker would exploit next.

Identity & access

Active Directory hardening

Tier model, permission concept, privileged identities, service accounts. We close the paths ransomware uses to move laterally through your infrastructure and escalate to domain-admin rights.

Cloud & collaboration

Microsoft 365 security & hardening

Conditional Access, MFA enforcement, Exchange Online Protection, Teams and SharePoint permissions, Defender configuration. In almost every company, M365 is the biggest entry point. We close it systematically.

Network & segmentation

Network security & segmentation

VLAN structure, network segmentation, firewall configuration, preventing lateral movement. A hardened network keeps a compromised system from becoming a springboard into the rest of the infrastructure.

Perimeter & access

Perimeter security & remote access

VPN hardening, remote desktop protection, exposed services, DMZ configuration. The perimeter is the first point of contact for every cyber attack. We reduce the exposed attack surface to the necessary minimum.

Endpoints & servers

Endpoint & server hardening

Windows hardening along CIS benchmarks, group policies, application control, local admin rights. Every system an attacker compromises should remain an endpoint, not become a starting point.

Architecture & resilience

Security architecture & defense baselines

Architecture reviews, defense baselines, hardening standards, effectiveness checks: documented, verifiable and permanently anchored. Not just for the next audit, but for the next cyber attack.

What you actually receive

  • Monthly vulnerability evaluation by ethical hackers (ProSec Networks)
  • Prioritised attack-path analysis per hardening area
  • Documented measure packages with rollback scenarios
  • Defense baselines and Windows hardening standards for your environment
  • Team enablement: training and architecture reviews on real systems
  • Effectiveness checks of all implemented measures

Note: Not every area is equally relevant for every company. We start with an attack-path analysis and prioritise together, so budget and resources work where the risk is greatest — whether Active Directory, Microsoft 365, network security or perimeter.

// 04 — WHY PROSEC

Our perspective does not come from textbooks — it comes from intelligence services, the military, law-enforcement agencies and the hacking scene.

Origin
Hacking & offensive security
Background
Military · Intelligence services · Law enforcement
Technical validation
Ethical hackers · ProSec Networks
Field experience
DFIR in real incidents

Our team has analysed threat situations in intelligence services, accompanied cyber operations in the military, investigated cyber attacks in law-enforcement agencies and learned in the hacking scene how attackers really think. These are the fields people do not talk about loudly. And that is exactly our foundation.

The technical validation of our hardening measures is carried out by ProSec Networks, with ethical hackers who have been working at international top level for decades. Not as external service providers. As part of the same group of companies. When we validate monthly, real hackers do the testing — not automation tools.

“The knowledge of how to attack comes from the military, intelligence services and the hacking scene. The decision to use it for good — that one we made ourselves.”

ProSec Ransomware Containment Guarantee

A cyber attack does not have to be the end of your company. We make the difference between an existential crisis and a head cold — and we put our name on it.

We have been there in real attacks. We know how ransomware spreads and how to stop it. That is why we give a concrete guarantee:

No full encryption

After our hardening program, no attacker can encrypt your entire infrastructure. Ransomware stays isolated. It does not spread uncontrolled. What hits one endpoint stays at that endpoint.

Value creation continues

Your critical systems and business processes remain operational even during an attack. An incident hits parts, not everything. Your value chain does not break.

No free passage through your infrastructure

We close the propagation paths. Active Directory, lateral movement, privilege escalation. No attacker with initial access can move uncontrolled through your systems.

Scope: This guarantee applies to the jointly defined infrastructure hardened under the ongoing program, for as long as ProSec Defense actively runs the monthly validation program and agreed hardening recommendations have been implemented. Systems outside the defined scope are not included. Details on the contractual anchoring on request.

ProSec Ransomware Containment Guarantee

Maurice du Maire, Managing Director, ProSec Defense GmbH
+49 341 3542867-0 · [email protected]

// 06 — FAQ

Frequently asked questions

What makes this different from a classic hardening project?
A classic hardening project ends with a final report. Our program does not: monthly vulnerability evaluations, weekly implementation slots and a fixed planning rhythm ensure that hardening is not a one-off sprint but a measurable, continuous process.
What happens if a measure affects operations?
Every operations-critical measure is prepared as a micro-project: risks are evaluated in advance, rollback scenarios are defined, and implementation only takes place after joint approval. Nothing happens without your knowledge: every measure is announced in advance and formally signed off with documentation afterwards.
How is this different from a classic audit?
An audit documents the status quo against standards. Our attack-path analysis models how a real attacker would proceed in your specific network and prioritises hardening measures by what can actually be exploited.
Can this be combined with DFIR?
Yes. After a DFIR engagement we know exactly how the attacker proceeded. Hardening built on that knowledge is more targeted than any external analysis without this context. ProSec offers both services from a single source.
Which company sizes is this suitable for?
Our security hardening program is designed for companies from around 200 employees up to enterprise environments with more than 1,500 employees.
How is progress measured and communicated?
Monthly vulnerability evaluations produce a progress curve that makes the security status comparable over time and communicable to management, insurers or auditors.
What does the ransomware containment guarantee mean in concrete terms?
We guarantee that no attacker can carry out full encryption within the jointly defined and hardened infrastructure. This means: ransomware can hit an endpoint or a segment, but it cannot spread uncontrolled, cannot escalate to domain-admin rights and cannot paralyse the entire value chain. The guarantee applies for as long as the monthly validation program is active and agreed recommendations have been implemented. This is a guarantee — not a declaration of intent. Contact us directly about the contractual anchoring.

DEFENSE READINESS

Do you know which attack paths are open in your infrastructure today?

In a short, confidential initial consultation we assess your starting situation: whether after an incident or preventively. We show which hardening measures have the greatest protective effect in your situation.

Or directly by email: [email protected]