Glossary · OT cybersecurity
Hardening
Also known as: Security hardening
German: Härtung
In cybersecurity, hardening is the reduction of the attack surface of a device, operating system, application or network by removing or disabling everything not needed and by configuring the remaining functions securely. It applies to single components as well as to whole systems.
- OT security
In one sentence
Hardening reduces the attack surface of devices, software and networks by removing unneeded functions and configuring the rest securely.
Example
Before handover, the integrator disables the PLC's web server and FTP service, changes all default passwords and locks unused switch ports.
How it applies
- Engineering: Typical measures are closing unused ports and services, removing sample accounts and software, changing default credentials, enabling secure protocol variants, setting the controller to a protected run mode and restricting USB interfaces.
- Product development: Suppliers should ship products in a secure default state where possible ("secure by default"), which the Cyber Resilience Act (CRA) requires for products with digital elements, and document what else can be hardened.
- Maintenance: Hardening settings are part of the Configuration baseline. Updates and service work can reset them, so they need to be checked afterward.
- Documentation: A hardening guide in the product documentation lists every configurable security setting, its default, the recommended value and any effect on functions. Integrators need to know which services they can disable without breaking diagnostics.
Hardening vs. system hardening
"Hardening" is the general practice for any element. System hardening applies it to a complete system, such as an industrial PC with its operating system and applications or a whole control system.