Secure configuration best practices: Strengthening your first line of defence

If there’s one thing attackers love, it’s a system that’s been left with the digital equivalent of doors and windows wide open. That’s why secure configuration is such a simple but powerful way to reduce your cyber risk, it is also a key control of Cyber Essentials. Setting things up properly – and checking back in regularly – shuts down easy paths for attackers and gives your IT setup a solid foundation. So today we’re talking about secure configuration best practices.

Why secure configuration matters

Out of the box, most software and devices are designed to be easy to use. That means wide – open defaults, like standard passwords, extra features you’ll never need, and ports that are always listening. Handy for getting started, sure – but they can also make life far too easy for an attacker.

A secure configuration means setting up devices to do only what your business needs. No more, no less. The fewer moving parts you have, the less there is to go wrong.

Cut the bloat: remove unnecessary software and features

Every piece of software has its own set of risks – even if you’re not using it. Old tools, bundled apps, or outdated plugins can introduce vulnerabilities that attackers know how to spot.

If you don’t use it, uninstall it. Removing unused software reduces the number of things you need to keep patched, simplifies support, and can even speed things up. It’s a win – win.

Eliminate unused accounts

Dormant user accounts are low – hanging fruit for attackers. They’re easy to overlook and often still connected to systems or services behind the scenes.

If an account doesn’t serve a purpose, get rid of it. This should be part of your joiners – and – leavers process, with regular reviews to make sure old accounts don’t stick around longer than they should.

Lock down your devices

Lost laptop? Stolen phone? A lock screen might be the only thing stopping someone from getting at your company data. Make sure all devices require a PIN, passphrase, or biometric login. It’s a simple step, but an important one.

Control what runs on your systems

Autorun and autoplay features might be convenient, but they’re also a way in for malware. USB stick plugged in and something installs itself? Not good. Turning off autorun means nothing gets launched without the user saying so.

Understand and manage your open ports

Open ports let your systems talk to the outside world – but they also open doors. Every open port should be:

  • Necessary: there for a good reason.
  • Understood: you know what it’s doing.
  • Documented: tracked and reviewed.

Some ports are particularly risky – like 3389 for Remote Desktop Protocol. If you’re not using it, secure configuration best practices dictate you close it. If you are, make sure it’s tightly secured and monitored.

Keep everything up to date

Old, unpatched software is an open invitation for attackers. Known vulnerabilities are often exploited within days of being made public. Keeping software updated means closing those gaps quickly.

Stick with supported versions of apps and operating systems, and apply updates promptly. Where you can, use automatic updates. For systems that can’t be patched right away, limit access and keep a close eye on them.

Final thoughts

Secure configuration best practice isn’t about adding new tools. It’s about taking control of what you already have – trimming the fat, closing unused paths, and locking things down. It’s one of the most practical steps you can take to make your organisation more secure. It is both effective, and cost effective, and can typically be completed to a good standard without the need for expert help.

Although that help is available if you need it 👽 – To find out how I can help your organisation protect itself against a constantly evolving threat landscape, contact me via YDC, and find out whether your organisation is ready for Cyber Essentials for FREE TODAY!