We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Windows Hardening: ANSSI and CIS Guidelines and Tools

Hardening Windows workstations without disrupting production: ANSSI, CIS, and Microsoft guidelines; 15 priority settings; HardeningKitty, Intune, and GPO.

Windows Hardening: ANSSI and CIS Guidelines and Tools

Key Takeaways

  • Windows hardening involves applying security settings from public standards (Microsoft Security Baselines, CIS Benchmarks, ANSSI recommendations) to reduce the attack surface of workstations.
  • On Windows 11, most of these settings are deployed centrally, via GPO or Microsoft Intune, without having to configure each computer individually.
  • Three critical priority areas: password policy + admin privilege management, automated OS/application updates, and disabling obsolete protocols (SMBv1, NTLMv1, TLS 1.0).
  • Be mindful of the balance: overly strict security measures can block business applications. Standards provide different levels (such as CIS Level 1 and Level 2) that can be selected based on the risk profile.
  • Estimated cost for an SME with 50 workstations: 3 to 8 k€ for initial deployment + 300 to 800 €/month for ongoing support with an MSP. ROI measured by the reduction in incident resolution time (−60% on average).

Hardening workstations involves reducing an operating system's attack surface: disabling unnecessary services, strengthening default configurations, and enforcing strict security policies. On Windows 10 and 11, a hardened workstation makes it harder for an attacker to succeed and gives endpoint detection and response (EDR) more time to react.

‍
The usual line: “Apply the CIS Level 2 Benchmarks to all your workstations.” The reality on the ground: hundreds of settings, business applications that crash, printers that stop working, and an IT department that’s daunted by the scale of the task. Between the default Windows workstation and the CIS Level 2 “fortress” (which is unusable without modifications), there is a balance.
‍

This article compares security frameworks (CIS, ANSSI, Microsoft Security Baselines), details 15 priority settings, presents tools that automate these settings without disrupting production (Intune, GPO, HardeningKitty), and lists common mistakes to avoid.

Why Harden Your Windows Workstations in 2026

The attack surface explodes

A standard Windows 11 workstation comes with :

  • Many Windows services are enabled by default, some of which are unnecessary in a corporate environment
  • SMBv1 enabled by default (critical vulnerability exploited by WannaCry)
  • Print Spooler listening (PrintNightmare, Evil Printer, dozens of CVEs)
  • Unrestricted PowerShell, widely used by attackers once they are inside the network (technique listed as T1059.001 in MITRE ATT&CK)
  • Local administrator accounts with identical passwords for the entire fleet
  • Administrative shares (C$, ADMIN$, IPC$) accessible without strong authentication

Every service, outdated protocol, or permissive configuration is a potential entry point. Attackers automate the search for vulnerable systems.

‍

Today's threats target endpoints

Ransomware: It encrypts computers by exploiting weak local administrator accounts, then spreads from a compromised computer to the rest of the domain.

Living-off-the-land: attacks without malicious files that use legitimate Windows tools (PowerShell, WMI, PsExec) and evade signature-based antivirus software. Execution restrictions (AppLocker, WDAC) mitigate this risk.

Credential theft: Mimikatz, Rubeus extract NTLM hashes from LSASS memory. An unhardened workstation with Credential Guard disabled = admin credentials exposed.

Supply chain attacks: malware hidden in signed MSI/EXEs. Automatic execution if installation strategies are not hardened.

‍

Mandatory regulatory compliance

NIS2 (Directive (EU) 2022/2555): requires affected entities to implement cybersecurity risk management measures, including system security. Fines of up to €10 million or 2% of global revenue for critical entities, and €7 million or 1.4% for important entities.

RGPD: an unsecured workstation that leaks personal data = demonstrable technical non-compliance = CNIL sanction.

ISO 27001, HDS, PCI-DSS: audits require proof of secure configurations. CIS Benchmarks or equivalent = expected standard.

Cyber insurance: Application forms focus on the security measures in place. Documented security hardening (CIS-CAT report or HardeningKitty) helps in answering these questions.

‍

The cost of non-hardening

Average cost of a data breach: $4.99 million worldwide, up 12% year-over-year, according to the IBM Cost of a Data Breach 2026 report. This is a global average across all types of breaches: an order of magnitude, not an estimate for your company.

Compromise of an administrator account: lateral movement, data exfiltration, persistent backdoor.

‍

Strengthen Your Positions Without Disrupting Production

A tailored risk mitigation plan
based on your risk profile

Audits, GPO or Intune deployment, testing, and monitoring—all without disrupting your users.

ANSSI Recommendations GPO / Intune Risk Profile Incident Tracking
Audit My Windows Environment Free · 30 min · no obligation

Hardening Guidelines: CIS, ANSSI, Microsoft—Which One Should You Choose?

‍

CIS Benchmarks: the international standard

Principle: worldwide expert consensus recommendations, 2 levels of hardening.

Level 1: Settings designed to minimize the impact on usage, applicable to most corporate environments.

Level 2: Enhanced security for sensitive environments (finance, defense, healthcare). May block certain business applications without modifications.

Available versions (as of September 2026 on cisecurity.org):

  • CIS Microsoft Windows 11 Enterprise Benchmark v5.1.0
  • CIS Microsoft Windows 10 Enterprise Benchmark v4.0.0 (Microsoft has discontinued support for Windows 10 as of October 14, 2025)
  • CIS Microsoft Windows Server 2025 Benchmark v2.1.0
  • CIS Microsoft Windows Server 2022 Benchmark v5.1.0

Advantages:

  • Universal recognition (audits, insurance, certification)
  • Extensive documentation (1200+ pages) with justifications
  • Free (CIS-CAT Lite) and paid (CIS-CAT Pro) auditing tools
  • Build Kits GPO for automation (fee-based, SecureSuite membership)

Disadvantages:

  • Verbose, intimidating for beginners
  • Level 2 breaks all common functionalities (Remote Desktop without adaptations, simplified file sharing)
  • Quarterly updates = ongoing maintenance
  • Free as a PDF; advanced tools require a fee (CIS-CAT Pro, included in the CIS SecureSuite subscription)

ANSSI: Targeted Recommendations, No Comprehensive Windows Benchmark

ANSSI does not publish the equivalent of the CIS Benchmarks for Windows 10 and 11. Its configuration guide, BP-028, focuses on GNU/Linux. For Windows, it publishes targeted recommendations, such as those on the secure deployment of a Windows server or on Active Directory security.

In practice: We use a Microsoft or CIS framework as a foundation and supplement it with the ANSSI recommendations that apply to the specific context (industry, requirements of a public-sector client, OIV).

Microsoft Security Baselines: the manufacturer's approach

Principle: Microsoft-recommended configurations for Windows, Office, Edge, servers. Delivered via Security Compliance Toolkit.

Format: pre-configured GPOs (.pol), PowerShell scripts, Intune profiles.

Versions:

  • Windows 11 Version 25H2 Security Baseline (September 2025)
  • Windows Server 2025 Security Baseline, Version 2602 (February 2026)
  • Windows 10 22H2 Security Baseline (Windows 10 is no longer supported as of October 14, 2025)
  • Microsoft 365 Apps for Enterprise Baseline

Advantages:

  • Compatibility: Microsoft tests its baselines on its own system; these are the safest settings for getting started
  • Direct import into GPO or Intune (no manual conversion)
  • Updates synchronized with Windows feature updates
  • Free, officially supported

Disadvantages:

  • Less stringent than CIS Level 2 (productivity/safety compromise)
  • No third-party certification (audits prefer CIS)
  • Covers Microsoft products only (no Linux or macOS guidance)

Comparative table: which reference system for which need?

‍

__wf_reserved_inherit

Pragmatic recommendation:

  • SMEs: Microsoft Security Baseline + 10–15 priority manual hardening measures
  • Company 200-2000 workstations, regulated sector: CIS Level 1 as baseline, Level 2 on critical workstations
  • French environment, OIV, public-sector clients: CIS or Microsoft framework, supplemented by applicable ANSSI recommendations
  • Multinational, ISO/SOC2 audits: CIS Level 1 (international recognition)

In practice, choosing a standard is only worthwhile if it can be applied without disrupting day-to-day operations. A preliminary audit allows you to determine the appropriate level of hardening, anticipate the impact on applications, and define a realistic roadmap.→Book a workstation hardening audit

‍

The 15 critical configurations that change everything

Instead of applying an entire CIS benchmark all at once, start with these 15 settings, which close off commonly exploited attack vectors.

‍

1. Disable SMBv1 (critical)

Why: exploited by WannaCry, NotPetya, EternalBlue. 30-year-old protocol, riddled with vulnerabilities.

How to : PowerShell Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol or GPO.

Impact: 0% if no legacy devices (NAS 2010, legacy printers). Test before mass deployment.

‍

2. Local Administrator Password Solution (LAPS)

Why: When the local administrator password is the same on all computers, a single compromised computer grants access to the others (lateral movement).

How to use: Microsoft LAPS (free) or Intune LAPS (native Windows LAPS on Windows 11). Automatic 30-day rotation, secure AD/Azure AD storage.

Impact: Each workstation has a unique, automatically renewed local administrator password, which helps prevent the spread.

‍

3. Credential Guard (Windows 10 Enterprise/11 Pro)

Why: protects credentials in LSASS memory against Mimikatz, NTLM hash theft.

How to activation via GPO Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security.

Prerequisites: TPM 2.0, UEFI, CPU with virtualization (VT-x/AMD-V). Not compatible with older VMs.

Impact: Makes it much more difficult to steal credentials from memory; the attacker must bypass virtualization-based security.

‍

4. Attack Surface Reduction (ASR) Rules

Why: Block common malicious behaviors (Office macros, obfuscated PowerShell scripts, code injection).

How to: Microsoft Defender / Intune, activate rules :

  • Block Office child processes (prevents malicious macros from launching CMD/PowerShell)
  • Block credential theft from LSASS
  • Block execution of potentially obfuscated scripts

Deployment mode: 30-day audit → log analysis → Enforce on rules without false positives.

Impact: Blocks behaviors typical of ransomware and malicious macros (rules documented by Microsoft).

‍

5. Application Control (AppLocker or WDAC)

Why: Whitelist of authorized executables. An unauthorized program will not run, regardless of whether it is recognized by antivirus software.

AppLocker (old, simple): rules based on editor/path/hash. Can be bypassed by DLL hijacking.

WDAC (Windows Defender Application Control, modern): Kernel-level control, including drivers. More robust than AppLocker when properly configured.

How to start with AppLocker in Audit mode on C:\Program Files, C:\Windows. Whitelist signed editors (Microsoft, Adobe, etc.). Block %TEMP%, %APPDATA%, files that malware often uses to run itself.

Complexity: high. Requires complete app inventory, exception handling.

Impact: Very strong protection if implemented properly, but high operational costs.

‍

6. BitLocker with TPM + PIN

Why: Full disk encryption. Physical theft of laptop = unreadable data.

Standard configuration: BitLocker with TPM only = auto-decryption at boot (weak protection against physical attacks).

Reinforced configuration: TPM + user PIN. Attacker must know PIN (4-8 digits) in addition to stealing machine.

Key storage: mandatory in Azure AD or AD (recovery key backup).

Impact: immediate RGPD compliance on theft/loss of equipment.

‍

7. Disable PowerShell v2

Why: PowerShell 2.0 does not support recent security features (script block logging, AMSI). An attacker could call it to bypass these protections.

How to : Disable-WindowsOptionalFeature -Online -FeatureName MicrosoftWindowsPowerShellV2Root

Impact: eliminates a major attack vector without breaking compatibility (PS 5.1+ is sufficient for all legitimate uses).

‍

8. Enhanced audit logging

Why: post-incident detection impossible without logs. By default, Windows logs too little.

Critical configurations:

  • Process Creation (4688) with command line
  • PowerShell ScriptBlock Logging (4104)
  • Logon events (4624/4625) with NTLMv2
  • Object Access on sensitive files

Storage: forward to SIEM or Azure Sentinel (min. 90-day retention).

Volume: Depends on the events being collected; should be measured on a pilot group before sizing the storage.

‍

9. User Account Control (UAC) forcé

Why: prevents silent elevation of privileges. Pop-up UAC = friction required.

Configuration : AlwaysNotify (max level), no auto-rise for admins.

User resistance: high ("it's boring"). Risk education.

Impact: drastically reduces drive-by infections.

‍

10. Print Spooler disabled (except print servers)

Why: Print Spooler = CVE factory. PrintNightmare (CVE-2021-34527), dozens of others.

User workstations: rarely necessary when printing is routed through a print server.

How to : GPO, stop and disable service Spooler.

Exception: print servers, workstations with local USB printers (rare).

Impact: removes an entire class of critical vulnerabilities.

‍

11. Network-Level Authentication (NLA) for RDP

Why: RDP without NLA = attacker can attempt login before encryption. Bruteforce easy.

Configuration : force NLA via GPO Require user authentication for remote connections by using Network Level Authentication.

Impact: The user authenticates before the remote session begins, which reduces exposure to brute-force attacks.

‍

12. Disable Remote Registry

Why: Remote Registry service enables remote access to the Windows registry. Used for recognition and lateral movement.

Legitimate use: rare today (replaced by centralized management).

How to stop and deactivate service RemoteRegistry.

Impact: reduced info disclosure, slower network recognition.

‍

13. Windows Firewall enabled on all profiles

Why: common default = firewall disabled on "Domain" profile because "we're in a secure network". Not true.

Configuration: activate on Domain, Private, Public. Block all inbound by default, with business exceptions (SMB to file servers, RDP to jump hosts).

Outbound filtering: advanced level, block outbound except whitelist. Prevents data exfiltration, C2 malware.

Outbound complexity: very high. For high-security environments only.

‍

14. Disable LLMNR and NetBIOS

Why: legacy name resolution protocols. Exploited for MITM and credential theft (Responder, LLMNR poisoning).

How: GPO disable LLMNR, disable NetBIOS over TCP/IP on all interfaces.

Compatibility: No impact if DNS resolution is configured correctly; to be tested on a pilot group.

Impact: removes the attack vector used in the initial reconnaissance phase.

‍

15. Endpoint Privilege Management (EPM)

Why: contextual elevation of privileges (approve specific app, not all user). Replaces "make everyone a local admin".

Solutions: Intune Endpoint Privilege Management, BeyondTrust, CyberArk.

Principle standard user can launch app-metier.exe with admin rights via policy, without knowing admin password.

Impact: drastically reduces the need for permanent local admins.

‍

Turnkey Curing: IT Systems

Audit, hardening plan,
, GPO or Intune deployment, monthly monitoring

For SME and mid-market portfolios.

Audit Included GPO / Intune Monthly monitoring SMEs and mid-sized companies
Request a hardening quote Quote within 48 hours · no obligation

‍

Automation tools: Intune, GPO, HardeningKitty

‍

Microsoft Intune: the cloud-native approach

For whom: cloud-first enterprises, Azure AD, mobile workstations, Zero Trust.

Advantages:

  • Configuration deployment via profiles (Configuration Profiles, Settings Catalog)
  • Integrated Microsoft Security Baselines (1-click import)
  • Compliance policies conditioning access to resources
  • Remediation automatic scripts (PowerShell execute if non-compliant)
  • Unified management Windows/macOS/iOS/Android

Workflow hardening Intune:

  1. Import Microsoft Security Baseline (Windows 11, Edge, Defender)
  2. Create additional profiles (disable SMBv1, LAPS, ASR rules)
  3. Deploy in Audit mode on a pilot group (50 workstations)
  4. Analyze compliance reports 30 days
  5. Adjust rules (business app exceptions)
  6. Progressive rollout (10% users/week)

Limitations:

  • Requires Intune licenses (included with Microsoft 365 Business Premium, E3, and E5, or available as a standalone license)
  • Workstations must be online to retrieve policies (OK for nomads, problem if network is isolated)
  • No conventional GPOs (migration learning curve)

‍

Group Policy Objects (GPO): the on-premise approach

For whom: Existing Active Directory, domain workstations, internal network, total control.

Advantages:

  • Free (included in Windows Server)
  • Granular control (thousands of settings)
  • Forced application at boot/login (offline-first)
  • Reverse engineering possible (GPO backups)

Workflow hardening GPO:

  1. Download CIS Build Kit GPO or Microsoft Security Baseline GPO
  2. Import into AD test environment (lab)
  3. Apply to OU test, reboot 10 machines
  4. Test critical apps (ERP, CRM, Office suite)
  5. Document incompatibilities (e.g. CIS blocks Office macros by default)
  6. Create exceptions (GPO override or WMI filtering)
  7. Deploy in production by OU (IT, Finance, Sales...) progressively

GPO traps:

  • Complex application order (Local > Site > Domain > OU, Last Writer Wins)
  • Troubleshooting difficult (gpresult /h report.html required)
  • No native compliance reporting (requires SCCM or custom scripts)

‍

HardeningKitty: the open-source Swiss Army knife

Principle: PowerShell script that audits and applies CIS/Microsoft Baseline/ANSSI configurations.

GitHub: github.com/0x6d69636b/windows_hardening

Features:

  • Audit: scan workstation, generate CSV report with compliance score
  • Hardening: applies recommendations automatically (HailMary mode)
  • Backup: config backup before modifications (rollback possible)
  • Support multiple finding lists (CIS, Microsoft, BSI, DoD STIG)

How to use:

powershell

# Audit
Invoke-HardeningKitty -Mode Audit -Log -Report -FileFindingList .\finding_list_cis_win11.csv

# Automatic hardening
Invoke-HardeningKitty -Mode HailMary -Log -Report -FileFindingList .\finding_list_msft_baseline_win11.csv -BackupFile backup.csv

# Rollback
Invoke-HardeningKitty -Mode HailMary -FileFindingList .\backup.csv -SkipRestorePoint

Advantages:

  • Free, open-source
  • Local execution (no AD/Intune dependency)
  • Ideal for master image (golden image hardening)
  • Export reports for audits

Limitations:

  • Machine-by-machine execution (no native centralized deployment)
  • No continuous monitoring (one-shot)
  • Requires PowerShell expertise for customization

Best practice: Hardcode the reference image (VDI/MDT) before cloning; all workstations deployed from this image will inherit the same settings.

‍

Fatal errors and hardening myths

‍

Error 1: Applying CIS Level 2 without testing

The result: business applications stop working, users are left stranded, and a rollback must be performed urgently.

Real-life example: CIS Level 2 blocks remote assistance (Quick Assist, TeamViewer). IT support paralyzed.

Best practice: start Level 1, test for 60 days, upgrade Level 2 only on critical positions (finance, HR).

‍

Error 2: Hardening without application inventory

Consequence: app legacy business uses SMBv1 → case hardening → business process blocked.

Best practice: complete inventory beforehand (SCCM, Intune, scripts), identify dependencies (protocols, services, ports).

‍

Error 3: No rollback plan

Consequence: configuration applied = unexpected performance regression. No backup = impossible to roll back cleanly.

Best practice: systematically backup beforehand (HardeningKitty backup, GPO export, Intune policy versioning).

‍

Error 4: Big-bang deployment

The result: the entire system went live overnight, the support team was flooded with tickets, and the IT department was overwhelmed.

Good practice: progressive rollout. 5% → 10% → 25% → 50% → 100%. 2 weeks between each wave. Stabilize before next phase.

‍

Error 5: Hardening = set and forget

Consequence: workstations compliant Month 1. Month 12: configuration drift (new software installed, local admin users added, services reactivated).

Best practice: continuous monitoring. Intune compliance reports, monthly CIS-CAT scripts, deviation alerts.

‍

Myth 1: "Hardening breaks productivity".

Fact: A well-tested baseline hardening (CIS Level 1, Microsoft baseline) has little impact on day-to-day work. Level 2 requires some adjustments, but doesn't cause any issues if tested on a pilot system.

‍

Myth 2: "Antivirus is enough".

Reality: antivirus detects known malware. Does not protect against exploitation of bad configurations (weak admin accounts, vulnerable services). Hardening = additional defense in depth.

‍

Myth 3: "It's too complex for us".

Fact: Microsoft baselines can be imported directly into Intune or GPOs. This is a solid starting point that can be fine-tuned later.

‍

How much time and effort should I expect to spend?

The effort depends on three factors: the size of the device fleet, the number of business applications to be tested, and the tools already in place (Intune or GPO).

The typical approach: an assessment (using CIS-CAT Lite or HardeningKitty on a few workstations), a pilot with a small group, followed by a phased rollout with a fallback plan.

The benefits are measured in the field: compliance gaps before and after, workstation-related incidents, and responses to audit and assurance questionnaires.

→ Get a cost estimate for upgrading your fleet

‍

Intelligent hardening, not dogmatic

Hardening workstations is not a checklist to be applied blindly; it is a risk reduction strategy tailored to your business context. Between the vulnerable default Windows workstation and the unworkable CIS Level 2 fortress, there is an optimal balance that no one can give you ready-made.

‍

The real priorities:

  1. Disable dangerous legacy services (SMBv1, PowerShell v2, Print Spooler not required)
  2. Implement LAPS (stop lateral movement)
  3. Activate Credential Guard
  4. Deploy Attack Surface Reduction rules in targeted mode
  5. Auditing and logging (detecting abnormalities)

These five measures close some of the most commonly exploited attack vectors and are deployed in phases using Intune or GPO. The remaining measures (CIS Level 2) are then added based on your risk profile.

‍

‍

Don't make mistakes:

  • Deploy without testing (broken business apps = humiliating rollback)
  • Hardening big-bang (guaranteed operational chaos)
  • Forget the rollback plan (no backup = no net)
  • Set and forget (config drift in 6 months)

‍

The Winning Strategy for 2026:

  • Baseline: Microsoft Security Baseline (free, supported, the safest option to start with)
  • Enrichment: 15-20 additional critical configurations (list above)
  • Sensitive positions: full CIS Level 1 (finance, HR, management)
  • Regulated environments: CIS Level 2 and applicable ANSSI recommendations (banking, healthcare, OIV)
  • Automation: Intune (cloud) or GPO (on-prem), never manual
  • Monitoring: monthly compliance, deviation alerts, automatic re-hardening

The real benefit: workstations that can withstand the most common opportunistic attacks, and a configuration you can demonstrate during an audit or assurance questionnaire.

Hardening isn't an option in 2026—it's basic security. Just as washing your hands reduces infections, hardening your systems reduces security breaches. Simple, measurable, essential.

‍

Next steps:

  1. Current Status: Scan a few workstations using CIS-CAT Lite (free) or HardeningKitty to assess the gap
  2. Choose baseline: Microsoft (simplicity) or CIS Level 1 (recognition)
  3. Deploy 50 workstations on a pilot basis (1 week)
  4. Measure before/after incidents (3 months)
  5. Scale up production once the pilot project has stabilized

Don't leave your devices set to factory defaults.

‍

‍Is your Windows environment truly secure?
We conduct a practical audit of your workstations and provide you with a prioritized action plan without complicating your operations.
Need an IT security provider to harden your IT infrastructure?

‍

Frequently asked questions about workstation hardening

‍

What is IT hardening?

Hardening involves reducing a system's attack surface: disabling unused features, strengthening default settings, and restricting permissions. It applies to workstations, servers, directories such as Active Directory, and network equipment.

‍

Does hardening block business applications?

No, not if the right methodology is used. A pilot test involving 10 to 20 workstations identifies any issues before the system is rolled out to the entire fleet.

‍

How long does it take to secure a network of 200 workstations?

‍ It depends on the IT infrastructure and business applications: expect an initial assessment, a pilot, and then a phased rollout. The timeline will be determined after the audit.

‍

What is the difference between CIS Level 1 and Level 2?

Level 1 includes settings designed to minimize the impact on usage. Level 2 adds stricter settings for sensitive environments that require further adjustments.

‍

Is hardening recommended during an IT security audit ?

Yes. Configuration flaws on workstations are among the most common findings in a security audit; hardening corrects them. To take it a step further, an in-house penetration test then verifies that these fixes hold up against a real attack.

‍

What is the connection between workstation hardening and securing Active Directory ?

Active Directory deploys security hardening Group Policy Objects (GPOs) and manages identities across the entire network. A hardened workstation without secure AD remains vulnerable, and vice versa. Both must be addressed together.

‍

‍

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026