MDR Services

Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...

Incident Response

Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...

Gartner Recognised

Integrity360 has been recognised as a Gartner Representative Vendor.

Download our CyberFire MDR ebook

Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.

The hidden human costs of a cyber attack

Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories. 

The reality of ransomware in 2025: What you need to know

In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.

Your guide to 2026: Trends and Predictions

Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.

Cybersecurity testing services

Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.

What is PCI? Your most common questions answered

If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.

Weekly Threat roundups

Stay informed with the latest cybersecurity news with our weekly threat roundups.

The A-Z Glossary of cybersecurity terms

Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.

Read our latest blog

For many small and mid-sized businesses, cybersecurity can feel overwhelming.

Integrity360 completes SOC 2 certification to strengthen global cyber defence ecosystem

SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries. 

Integrity360 expands into North America with Advantus360 Acquisition

Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America

Security First 2026

See the full list of our conferences across the UK, Europe, Africa & the Caribbean
Integrity360 Emergency Incident Response button Under Attack?

Configuration build review

Configuration build reviews check your servers, endpoints, network devices and cloud workloads against recognized hardening standards, and rank the settings worth changing first.

0 +

security specialists in our SOCs

0

SOCs in Ireland, Sweden, Bulgaria, Spain, Italy, South Africa & Canada (coming 2026)

0 +

dedicated cybersecurity experts

What is a Configuration Build Review?

A configuration build review is an independent assessment of how a system, platform or device has been configured, measured against recognized security benchmarks and vendor hardening guidance.

A fully patched system can still be exposed when services are running that nobody uses, permissions are broader than the role requires, default settings were never changed, or a security control was implemented only partially.

Reviews cover servers, desktops, laptops, mobile devices, network devices and cloud environments. Each finding is weighed in the context of your environment and how you operate. You get a practical view of where your configuration creates risk, and which changes to make first.

Benefits of Configuration Build Review

  • Secure before go-live: New builds checked against security benchmarks and vendor guidance before they reach production.

  • Fixes ranked by exposure: Misconfigurations prioritized by what each one allows in your environment.

  • Changes that won't break operations: Recommendations are weighed against how your systems are used day-to-day, so nothing needed gets switched off.

  • Consistency across your estate: Systems that should be configured alike, checked against each other, so drift between builds shows up.

  • A baseline you can reuse: A reviewed configuration your team can apply to future builds and new deployments.

  • Evidence for compliance: Your configuration state is documented against the standards you report against.

  • Reviews on a cycle: Repeat reviews as your estate changes, after major upgrades, platform migrations or new rollouts.

CREST accreditation is independently assessed rather than self-declared, covering technical capability, ethical conduct and quality of delivery. Your engagement follows the methodology and standards it certifies.

CREST-CSIR

In-depth scope with Integrity360

Penetration Testing

Penetration Testing

Red Teaming

Red Teaming

Cloud Security Testing

Cloud Security Testing

Application Security Testing

Application Security Testing

Social Engineering

Social Engineering

Our Certifications

  CREST-CSIR OSCP

 

 

 

Schedule a configuration build review

Connect with an Integrity360 advisor to explore how a Configuration Build Review can strengthen the foundations and resilience of your security environment.

Access key insights

How Should Organisations Respond to a Data Breach?

How Organisations are Getting Data Security Wrong

What is Penetration Testing in Cyber Security and why do you need it?

Overcome the complexities of Multi-Vendor Cyber security management with Integrity360

Configuration build FAQs

What is a configuration build review?

A configuration build review assesses the security of your system or application configurations to ensure they align with industry best practices, compliance standards, and your organization’s risk profile. This helps prevent misconfigurations that attackers could, and will, exploit.

Why are secure configurations important?

Misconfigurations are a common cause of cyber breaches. Unsecured services, default credentials, or overly permissive access controls can create serious vulnerabilities. A configuration review helps you identify and fix these issues before they’re exploited.

How often should a Configuration Build Review be performed?

Most organizations should conduct reviews annually or following significant infrastructure changes, cloud migrations, major software deployments, or regulatory audits.

What systems can be reviewed?

Integrity360 reviews configurations across a wide range of environments, including:

  • Servers (Windows, Linux)

  • Databases (SQL, Oracle, MongoDB)

  • Firewalls and routers

  • Cloud platforms (AWS, Azure, GCP)

  • Virtualization and container platforms

  • Workstations and mobile devices

  • Applications and web servers

What standards are used during the review?

Reviews are based on globally recognized benchmarks and guidelines such as:

  • CIS Benchmarks

  • NIST security frameworks

  • ISO/IEC 27001

  • Vendor-specific hardening guides

  • Best practices developed by Integrity360

What does the review process involve?

The process includes collecting and analyzing configuration data, identifying deviations from best practices, evaluating associated risks, and providing detailed, prioritized remediation guidance for improving system hardening.

How does this support compliance requirements?

Configuration reviews support compliance with frameworks including ISO 27001, PCI DSS, NIST CSF, SOC 2, and OSFI guidelines. These standards require evidence of secure system configuration and regular control validation.

Is this service suitable for cloud and hybrid environments?

Yes. Integrity360 provides in-depth reviews for cloud-native, on-premise, and hybrid environments. We also assess cloud service configurations, IAM policies, and platform-specific risks in AWS, Azure, and Google Cloud.

What makes Integrity360’s configuration review service different?

Integrity360 combines automated analysis with expert interpretation. Our reports are clear, actionable, and mapped to real-world risk for meaningful improvements to your organization’s security posture.