Securing and Hardening Your On-premises IT Environment — Servers, Endpoints & Network Security
IT Partner helps organizations improve the security of their existing on-premises IT environment by analyzing infrastructure and applying security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. The service is billed at $90 per hour, typically runs 1 week, and is managed by Mike Mackey.
What this engagement is
This service focuses on making your on-premises IT infrastructure safer and more secure using the systems, devices, and technologies you already use. IT Partner analyzes the environment, helps apply security best practices, verifies the changes, and provides a project closeout report. Security requirements can vary for different types of workloads.
Success criteria
What you receive
How the work unfolds
Start the project: confirm scope, in-scope systems, contacts, access, and maintenance windows.
Assess the in-scope servers, endpoints, and network services and review key findings with the client.
Apply the agreed hardening changes to in-scope systems following the approved plan and change windows.
Verify that the applied changes operate as expected and did not disrupt in-scope workloads.
Finalize the configuration and document what was changed.
Complete agreed post-assessment tasks and hand over the closeout report.
Prerequisites
Who does what
IT Partner
- Analyze IT infrastructure
- Use Privileged Access Workstations
- Use Multi-Factor Authentication
- Limit and constrain administrative access
- Control and limit endpoint access
- Encrypt virtual disks and disk storage
- Manage operating systems
- Firewall and network settings
- Update policy and software review
Your team
- Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules
- Configure all networking equipment, such as load balancers, routers, firewalls, and switches
- Provide access to physical and virtual servers and/or systems and services, as needed. Provide remote and/or physical access to facility and systems required to complete work.
What's not included
Limitations & technical notes
Frequently asked questions
What is included in IT Partner’s Securing and Hardening Your On-premises IT Environment service?
The service includes analysis of your on-premises IT infrastructure and application of security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. The engagement also includes verification of changes and a project closeout report documenting final status, evidence of meeting acceptance criteria, outstanding issues, and final budget.
What is the main outcome of this on-premises security hardening service?
The main outcome is a more secure on-premises environment in accordance with best practices. IT Partner achieves this by reviewing the existing infrastructure, applying agreed security improvements, verifying the changes, and documenting the final project status.
How long does the Securing and Hardening Your On-premises IT Environment engagement take?
The engagement typically runs 1 week. The actual plan can vary by workload and environment, because security requirements differ for different types of workloads; scheduling details are confirmed during scoping and kickoff.
How is this service priced?
The service is billed at $90 per hour, and no out-of-scope work is performed without your written approval. Total effort depends on the number of in-scope systems and the hardening changes you approve.
What happens during the engagement?
The engagement starts with a kickoff meeting, followed by an on-premises health check, the securing process, verification of changes, finalization of changes, and any post-assessment tasks. This sequence lets IT Partner understand the current environment, apply hardening measures, and confirm the work before closeout.
What security areas does IT Partner review or harden?
IT Partner reviews and hardens administrative access, endpoint access, virtual disks and disk storage, operating systems, firewall and network settings, and update policies. The service also applies practices such as Privileged Access Workstations, multi-factor authentication, and limiting or constraining administrative access where appropriate.
Does this service include migration or deployment work?
No, migration and deployment are not included in this service. The engagement is focused on securing and hardening the existing on-premises IT environment rather than moving workloads or deploying new infrastructure.
What are the customer prerequisites for this service?
The customer provides a dedicated point of contact, a list of in-scope systems and administrative accounts, approved administrative access to those systems and their management tools, current documentation such as network diagrams and patching process details, confirmed maintenance windows and change approvals, and recent backups or other recovery options for systems where configuration changes will be applied.
What is IT Partner responsible for during the hardening engagement?
IT Partner analyzes the IT infrastructure and applies security best practices across privileged access, MFA, administrative access constraints, endpoint access, storage encryption, operating system management, firewall and network settings, and update policy and software review. IT Partner also verifies changes and provides the project closeout report.
Does IT Partner configure firewalls, routers, switches, and other network equipment?
The client is responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches. IT Partner’s scope includes reviewing and hardening firewall and network settings; the exact division of hands-on configuration work is confirmed before the engagement begins.
Will this service cause downtime or business disruption?
Changes to firewalls, operating systems, endpoint access, storage, or update policies can affect operations. Maintenance windows, change approvals, and rollback contacts are confirmed before changes are made, and recent backups are a prerequisite for systems where changes carry operational risk.
Is detailed documentation included with the service?
The included documentation is the project closeout report showing final project status, evidence of meeting acceptance criteria, outstanding issues, and final budget. More extensive documentation can be provided for an additional fee.