Directly exposed RDP is the top ransomware entry vector — find every instance, close it now, and move remote access behind VPN/ZTNA, a gateway, or Bastion.
Firewall & Network Security
Strengthen firewalls, VPNs, switches, DNS, and network security using practical hardening checklists and best practices.
Get notified when new items are published
Combine subnet-level NSGs with a centralized Azure Firewall in a hub-spoke topology for defense-in-depth network filtering.
Separate servers, clients, management interfaces, and IoT/OT devices into VLANs with inter-VLAN firewall rules to contain lateral movement.
Audit your firewall for overly permissive rules and replace them with explicit source, destination, and port definitions.
Remove the legacy SMBv1 protocol and require SMB signing to stop relay attacks and exploits like EternalBlue.