In 2013, SteelCloud’s business was shifting so we set out to find something in the cybersecurity field that others had determined was too difficult to automate. We wanted to rethink the challenge, take a greenfield view and come up with something magic—a game-changer that had never been done before.
Nine patents later, SteelCloud had created the only customizable off-the-shelf (COTS) product that automates STIG and CIS hardening for government and commercial organizations. Recently named a Top 10 Cloud Security Solutions Provider by Enterprise Security Magazine, SteelCloud’s ConfigOS is proven over a decade of successful implementations. It removes 90% of the effort and 70% of the costs of hardening. And it can accomplish weeks of system hardening work in about an hour, making systems more secure, up-to-date and available than ever before.
Yes, we know it sounds like marketing talk.
We get it. We set out to create something magical. We succeeded. And now when we talk about it, it sounds a bit exaggerated. But it’s not.
SteelCloud’s ConfigOS has been proven on cloud infrastructures, OT/SCADA infrastructures, and enterprise IT networks throughout government and industry. ConfigOS has been implemented by internal IT staff as well as specialized security consultants.
And it’s not like being a big part of some of the world’s most secure networks is easy or unscrutinized. Every nefarious hacker in the world wants inside these networks and they have tried, daily. For more than a decade. ConfigOS is part of the strategy that keeps them out. It’s battle tested in the world’s most extreme environments under increasing threats in recent years. And all our claims have been proven out.
ConfigOS creates a secure baseline in about an hour.
Energy and utilities. Education. Banking. Business and ecommerce. Healthcare. Those are the commercial industries most at threat from cyberattack. From ransomware attacks to hacktivism and cyberterrorism, the annual damage to our country is $100 billion. More than half of the global cyberattacks are aimed at US companies and, every year, we lose 500,000 jobs to cyberattacks.
-
SteelCloud’s ConfigOS has been proven on cloud infrastructures, OT/SCADA infrastructures, and enterprise IT networks throughout government and industry
To help combat this problem, the Center for Internet Security (CIS) has created a checklist for commercial organizations to use to lock down their systems in the same ways our government and military do to prevent spies, hacktivists and cybercriminals form accessing national secrets. Based on the same series of controls the Department of Defense uses to harden their systems, CIS spells out the steps you need to take to secure areas of vulnerability. While you may never face the threats the DoD faces on a daily basis, locking down as tightly as them gives you a steel-clad baseline of security.
Traditionally, the hardening work is done by hand. Technical experts scan the system for vulnerabilities around these controls, then they remediate the vulnerabilities. This can take weeks, even months. Meanwhile, you’re working on a system with vulnerabilities until the hardening is done. And if you are just installing a new application or upgrade, it won’t be secure to operate until the hardening is done.
ConfigOS automates the processes of auditing and scanning CIS controls, enterprise-wide remediation and compliance reporting, and interfaces to other technologies around these rules-based controls. What once took weeks is now completed in an hour. It’s done exactingly and consistently, as only bots can do. And your upgrades are available this afternoon, instead of next month.
Cyber workforce shortages, recruiting and upskilling. Oh my!
The job of hardening is tough on your highly paid cybersecurity experts. Manual hardening is tedious work so relieving your people of this burden frees them to address backlogs and other risk management work.
Beyond that, automation is becoming the smartest way to staff a cybersecurity team. There is a massive shortage of cybersecurity professionals. In the time ConfigOS has existed, the number of unfilled cybersecurity jobs has increased by 350%. Globally, today’s shortage is estimated to be 2.72 million. Automation is key to closing that gap.
Another benefit of automation is that it takes less skill to run a robot than it does to manually harden. So you can recruit lower-level workers to run ConfigOS. And an added benefit is that, by running the software, they learn the hardening trade. ConfigOS becomes the perfect team member for combatting not only cybercriminals, but the cyber workforce shortage itself.
Benefits that extend beyond simple system hardening.
ConfigOS is a complete cybersecurity compliance solution. In addition to the hardening and workforce benefits already discussed, ConfigOS provides:
● Simple policy authoring to customize and streamline baseline policy creation
● A flexible interface to track all your hardening efforts
● High productivity, remediating 3000-5000 endpoints per hour
● Splunk-ready data, visible in ConfigOS DashView
● A complete solution for commercial clients, proven over years of implementations
● Two minutes to install, two hours to train and you’re set
People are often left speechless when they see ConfigOS in action and realize all the time and money they could have saved with a simple install. See why SteelCloud’s ConfigOS routinely amazes. Schedule your free demo today.




