Skip to content
Cybersecurity

CIS Security Audit

85% of attacks exploit configuration errors that CIS Controls block. We'll audit Windows, Linux, AWS, Azure against CIS Benchmarks. You get a report with deviations and a prioritized hardening plan.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

What is a CIS security audit?

A CIS security audit measures how well your systems comply with CIS Benchmarks — the globally recognized hardening guidelines published by the Center for Internet Security for operating systems, cloud platforms, databases, and network devices. nFlo uses CIS-CAT Pro and OpenSCAP alongside manual checks to identify deviations, map them to MITRE ATT&CK techniques, and deliver a prioritized hardening guide that blocks 85% of common attacks.

CIS Controls v8
Current standard
CIS Benchmarks
Globally recognized
85% protection
vs typical attacks

Default configuration = open doors for attackers

85% of attacks exploit configuration errors that CIS Controls block

Automated scanning + hardening guide

Automated Scanning

Scan systems against CIS Benchmarks

Gap Analysis

Identify deviations and risks

Hardening Plan

Prioritized remediation actions

Ransomware Attack Through RDP with Default Password

Manufacturing company lost €200,000 to a ransomware attack. Attackers got in through RDP with default local administrator password. System wasn’t hardened according to CIS Benchmark - RDP publicly accessible, no MFA, local accounts with simple passwords.

Without CIS hardening:

  • Default configurations = open doors (RDP, SMB, SSH exposed)
  • Excessive privileges for local accounts
  • No monitoring of critical events
  • 85% of attacks exploit configuration errors that CIS would block

CIS Benchmarks - Proven Hardening Recipes

CIS (Center for Internet Security) publishes benchmarks - detailed hardening guidelines for every system. Used by governments, military, Fortune 500. We’ll check if your systems are compliant.

What you get:

  • System scanning against CIS Benchmarks (automated + manual checks)
  • Compliance report: % compliance for each system and control
  • Deviation list with severity (Critical, High, Medium, Low)
  • MITRE ATT&CK mapping: which attack techniques you block
  • Hardening guide: specific commands/settings to fix
  • Automation scripts for hardening where possible

Who Is It For?

This service is for you if:

  • You must meet compliance requirements (PCI DSS, NIST, ISO 27001)
  • Cyber insurer requires CIS Controls
  • You want to harden systems but don’t know where to start
  • You’ve experienced an incident due to configuration error
  • You’re deploying new systems and want to configure them properly from the start

CIS Controls v8 - 18 Controls

CIS Controls are prioritized defensive security actions:

Implementation Group 1 (IG1) - Small businesses

  1. Inventory of Assets
  2. Inventory of Software
  3. Data Protection
  4. Secure Configuration
  5. Account Management
  6. Access Control Management

Implementation Group 2 (IG2) - Medium businesses

  1. Continuous Vulnerability Management
  2. Audit Log Management
  3. Email and Web Browser Protections
  4. Malware Defenses
  5. Data Recovery
  6. Network Infrastructure Management
  7. Network Monitoring and Defense
  8. Security Awareness Training

Implementation Group 3 (IG3) - Large enterprises

  1. Service Provider Management
  2. Application Software Security
  3. Incident Response Management
  4. Penetration Testing

CIS Benchmarks - Systems

We audit according to official CIS Benchmarks for:

Operating Systems

  • Windows - Server 2016/2019/2022, Windows 10/11
  • Linux - RHEL, Ubuntu, Debian, CentOS, Amazon Linux
  • Unix - Solaris, AIX

Cloud Platforms

  • AWS - Foundations Benchmark
  • Azure - Foundations Benchmark
  • Google Cloud - Foundations Benchmark

Applications

  • Databases - MS SQL, Oracle, PostgreSQL, MySQL, MongoDB
  • Web servers - Apache, Nginx, IIS
  • Containers - Docker, Kubernetes

Network Devices

  • Cisco - IOS, ASA

Tools We Use

  • CIS-CAT Pro - official CIS tool
  • OpenSCAP - open-source compliance scanner
  • AWS Security Hub - CIS Benchmark for AWS
  • Azure Security Center - CIS Benchmark for Azure
  • InSpec - infrastructure testing (Chef)
  • Nessus - configuration audit

Learn more about key concepts related to this service:

Contact your account manager

Discuss CIS Security Audit with your dedicated account manager.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

Response within 24 hours
Free consultation
Custom quote

Providing your phone number will speed up contact.

How we work

Our proven service delivery process.

01

Scope Definition

Define systems and benchmarks for audit

02

Automated Scan

CIS-CAT, OpenSCAP, cloud-native tools scanning

03

Analysis

Deviation analysis, MITRE ATT&CK mapping

04

Hardening Guide

Report with prioritized actions

Benefits for your business

What you gain by choosing this service.

85% Protection

CIS Controls block most common attacks

Compliance

CIS required by PCI DSS, NIST, cyber insurance

Lower Premiums

Insurers offer discounts for CIS compliance

Quick Wins

Hardening can be done in weeks, not months

Frequently Asked Questions

Common questions about CIS Security Audit.

How long does a CIS Benchmarks audit take and what systems does it cover?

The audit takes 5-10 business days. It covers operating systems (Windows Server, Linux RHEL/Ubuntu), cloud platforms (AWS, Azure, GCP), databases (MS SQL, PostgreSQL, Oracle), containers (Docker, Kubernetes) and network devices (Cisco).

Will I get specific fix instructions after the audit, not just a list of problems?

Yes. The hardening guide contains specific commands and settings to fix for each system, MITRE ATT&CK mapping (which attack techniques you block) and ready-made scripts automating hardening where possible.

Are CIS Benchmarks required by regulations?

CIS Controls and Benchmarks are required or recommended by PCI DSS, NIST, ISO 27001 and many cyber insurers. CIS compliance also provides discounts on cyber insurance premiums.

What tools do you use for scanning?

We use CIS-CAT Pro (official CIS tool), OpenSCAP, AWS Security Hub, Azure Security Center, InSpec and Nessus. Automated scanning is supplemented with manual checks for areas that tools miss.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist