Linux Hardening & Compliance; CIS, NIS2, DORA

Linux Hardening & Compliance

A system that hasn't been hardened is an open invitation. Default configurations, unnecessary services, weak file permissions & missing kernel parameters are among the most common entry points attackers exploit and most of them are preventable.

Kangasec closes that gap with structured, automated Linux hardening aligned to internationally recognised benchmarks and verified compliance reporting for NIS2, DORA, ISO 27001 and the Cyber Resilience Act.

What we do

  • CIS & STIG benchmark hardening

    We enforce CIS (Center for Internet Security) and STIG benchmarks across your Linux systems; servers, containers & Kubernetes nodes. New machines are delivered hardened & compliant within the hour. Configuration is fully automated via Ansible, making it repeatable, auditable and scalable.

  • OpenSCAP compliance verification

    We verify your hardening posture using OpenSCAP, the open source standard for security compliance scanning. Every scan produces a structured report you can hand directly to auditors, management or your compliance team.

  • fapolicyd application whitelisting

    For environments that require an additional layer of control, we implement fapolicyd; a kernel-level application whitelisting solution. Every binary executed on the system is checked against an allowlist. Malware that manages to reach a system cannot execute, regardless of the path it uses.

  • Compliance support

    We help you demonstrate compliance with:

    • NIS2, security measures for operators of essential services
    • DORA, operational resilience for financial entities
    • ISO 27001, information security management
    • CRA, Cyber Resilience Act product security requirements

What you get

  • Hardened Linux systems, automated & repeatable via Ansible
  • OpenSCAP compliance reports ready for audit
  • fapolicyd application whitelisting for high-sensitivity environments
  • Continuous compliance monitoring, not a one-off scan
  • Clear remediation guidance when gaps are found

Why open source?

Commercial hardening tools are often opaque, expensive & slow to update. Our approach is built entirely on open source: CIS benchmarks, OpenSCAP, Ansible & fapolicyd are all community-maintained, transparent and auditable. 

You can inspect every rule, every configuration, every scan result, no black boxes.

Frequently Asked Questions

  • What is CIS hardening for Linux?

    CIS hardening applies a structured set of security configuration guidelines published by the Center for Internet Security. For Linux systems, this covers kernel parameters, filesystem permissions, network settings, auditing rules and more. Kangasec enforces these automatically via Ansible & verifies them using OpenSCAP.

  • Does hardening help with NIS2 compliance?

    Yes. NIS2 requires organisations to implement appropriate technical measures to manage security risks. CIS-hardened systems, combined with OpenSCAP audit reports, provide documented evidence of those measures; which auditors & regulators increasingly expect.

  • What is fapolicyd and do I need it?

    fapolicyd is a Linux security daemon that enforces application whitelisting at the kernel level. It prevents any binary not on the allowlist from executing; even if an attacker manages to drop malware onto the system. It's particularly relevant for high-sensitivity environments such as financial services, public sector & critical infrastructure.

  • Can you harden systems we already have running in production?

    Yes. We assess your current posture first, then apply hardening incrementally to avoid disruption. Every change is tested & documented before being applied to production systems.

Keep me posted with latest news

Yes, I would like to receive occasional marketing communications regarding Kangaroot services & events.