Back to blog
Cybersecurity

Endpoint Hardening for Small Businesses: A Practical Workstation Checklist

Use this endpoint hardening checklist to reduce workstation attack surface across updates, admin rights, encryption, browsers, security tools, remote access, and recovery.

SMART Solutions September 11, 2026 11 min read
Business cybersecurity environment representing secure workstation configuration, endpoint protection, and access controls.

Installing security software is not the same as securing a workstation.

A business laptop or desktop can have antivirus installed and still carry unnecessary risk from local administrator rights, unsupported software, weak recovery settings, unused services, insecure remote access, missing encryption, browser extensions, or inconsistent configuration.

Endpoint hardening is the process of reducing that avoidable attack surface while preserving the applications and workflows employees actually need.

SMART Solutions provides Cybersecurity Protection focused on devices, access, network exposure, and practical risk reduction, along with Computer, Server & Device Support for configuration, maintenance, troubleshooting, and data-protection planning.

Business cybersecurity and workstation protection planning

SMART takeaway

Hardening is a controlled baseline, not a pile of restrictions.

Define the secure configuration a workstation should have, test it against real business applications, deploy it consistently, and verify that changes or exceptions remain visible over time.

Quick answer: what is endpoint hardening?

Endpoint hardening means configuring computers and other endpoints to reduce unnecessary exposure, strengthen access controls, and make important security settings more consistent.

NIST describes a security configuration checklist — also called a hardening guide, lockdown guide, or benchmark — as instructions or procedures used to configure an IT product for an operational environment, verify that it was configured properly, and identify unauthorized changes.

In May 2026, NIST published Revision 5 of SP 800-70, its National Checklist Program guidance. NIST states that security configuration checklists can help minimize attack surface, reduce vulnerabilities, lessen the impact of successful attacks, and identify changes that might otherwise go unnoticed.

Source: NIST SP 800-70 Rev. 5 — National Checklist Program for IT Products

For a small business, endpoint hardening should be tailored to the device’s purpose. A front-desk workstation, accounting laptop, conference-room PC, server-management workstation, and field laptop may need different settings even when they use the same operating system.

Hardening should start with an inventory

You cannot create a reliable baseline when you do not know what devices, applications, users, and dependencies exist.

Before changing settings, identify:

  • Which endpoint models and operating systems are in service
  • Which applications each role needs
  • Which users have local administrator rights
  • Which devices store or access sensitive information
  • Which endpoints connect remotely
  • Which security and management tools are installed
  • Which systems have special vendor requirements
  • Which devices are unsupported or approaching replacement

Our IT asset inventory guide provides a practical structure for connecting devices and services with owners, sensitive data, lifecycle status, and recovery priorities.

1. Start from a documented secure configuration

Do not harden workstations one setting at a time from memory.

Create a baseline that answers what a properly configured device should look like for a defined role.

The baseline can cover areas such as:

  • Operating-system security settings
  • Account and privilege rules
  • Disk encryption
  • Host firewall configuration
  • Update settings
  • Security software
  • Remote access
  • Browser configuration
  • Screen locking
  • Logging
  • Approved software

NIST’s National Checklist Repository exists to make security configuration guidance from authoritative sources easier to find and apply. A published benchmark is still a starting point rather than permission to enable every setting blindly.

Source: NIST — Security Configuration Checklists for Commercial IT Products

Business applications, device roles, accessibility needs, and vendor support requirements still need to be tested.

2. Remove software and services that are not needed

Every unnecessary application or service creates another item to patch, monitor, configure, and potentially troubleshoot.

Review endpoints for:

  • Old remote-support tools
  • Unused browser extensions
  • Trial software
  • Legacy utilities
  • Duplicate security products
  • Unapproved file-sharing applications
  • Old vendor agents
  • Software from former business processes

Do not remove an unfamiliar application simply because nobody recognizes its name. Confirm what it supports first.

A specialized line-of-business system may depend on a background service that looks unnecessary until it disappears.

The right process is inventory, validate, remove, and test.

3. Reduce local administrator use

Employees usually do not need permanent administrator rights for everyday email, web browsing, document work, or line-of-business applications.

Excessive privilege can increase the impact of a compromised account or malicious application.

Review:

  • Who is a local administrator
  • Why that access is needed
  • Whether ordinary work can use a standard account
  • How approved software is installed
  • How emergency elevation is handled
  • Whether admin credentials are shared

NIST CSF 2.0 includes least privilege in its access-control outcomes and recommends restricting access and privileges to the minimum necessary.

A later user access review should confirm that privileged access still matches current responsibilities rather than becoming permanent because someone once needed it.

4. Keep the operating system and applications maintained

A hardening baseline will not remain secure if software stops receiving updates.

The FTC’s small-business cybersecurity guidance recommends setting a regular schedule for updating applications, browsers, and operating systems and enabling automatic updates when appropriate.

Source: FTC — Cybersecurity for Small Business

For business endpoints, patching should still account for application compatibility and operational timing.

Our patch management guide explains how to prioritize updates, test them on representative devices, document exceptions, verify successful installation, and plan around unsupported legacy systems.

Hardening and patch management reinforce one another:

Hardening Defines how the endpoint should be configured.
Patch management Keeps supported software and firmware current as vulnerabilities and fixes evolve.

5. Protect data stored on portable devices

Laptops are designed to leave the office.

That makes loss and theft part of the endpoint-security plan.

The FTC recommends considering full-disk encryption for laptops and other mobile devices that connect remotely, particularly when they store sensitive information.

Source: FTC — Secure Remote Access

For encryption to be operationally useful, also plan:

  • Recovery-key storage
  • Who is authorized to recover a device
  • What happens after motherboard or hardware changes
  • How encryption status is verified
  • How retired drives are handled

Enabling encryption without a recovery process can convert a security control into a support emergency.

6. Harden browsers and web access

The browser is one of the most exposed applications on a business workstation.

Review:

  • Supported browser versions
  • Automatic updates
  • Unapproved extensions
  • Saved credentials
  • Download behavior
  • Notification permissions
  • Pop-up and site permissions
  • Whether business profiles are separated from personal profiles where appropriate

Browser hardening should not create an endless list of blocked websites with no business rationale.

Prioritize settings that reduce credential theft, malicious extensions, untrusted downloads, and uncontrolled data sharing while preserving legitimate work.

Our Business Email Compromise prevention guide covers the human and account side of fraudulent email, payment requests, compromised mailboxes, and identity protection.

7. Strengthen authentication and workstation locking

Hardening includes what happens when a user sits down at the device.

Review:

  • Unique user accounts
  • Multi-factor authentication for supported business services
  • Automatic screen locking
  • Password or passkey policies
  • Shared workstation workflows
  • Account recovery
  • Local administrator credentials

A workstation can be technically hardened and still expose business systems if everyone shares the same application account or leaves sessions unlocked.

For higher-risk services, our phishing-resistant MFA guide explains how WebAuthn, passkeys, and FIDO security keys differ from authentication methods that can be relayed through phishing pages.

8. Review host firewall, remote access, and network exposure

Endpoints should not accept network connections simply because an application once requested them.

Review the host firewall and remote-access configuration for:

  • Approved management tools
  • Remote desktop or remote-control software
  • Inbound firewall exceptions
  • Services listening on the network
  • Public vs. private network profiles
  • Vendor remote-access agents
  • VPN configuration

If remote access is required, document who can use it, what systems they can reach, how MFA works, and how access is removed.

Our business VPN and remote-access checklist covers those controls in more depth.

9. Make security tools observable

Antivirus, antimalware, endpoint detection, firewalls, and other protective tools are useful only when the business can tell whether they are installed, active, current, and generating meaningful alerts.

Check:

  • Is the security agent installed?
  • Is protection enabled?
  • Are definitions, signatures, or components current?
  • Is the device checking in to its management console?
  • Who receives alerts?
  • What happens when a device falls out of compliance?
  • Can security settings be changed by ordinary users?

A dashboard showing 50 devices is not enough if the business actually has 63 endpoints.

That is another reason hardening should be connected to a current asset inventory.

10. Test, document exceptions, and verify drift

Hardening is not complete when settings are deployed.

It is complete when the business knows the configuration works and can detect when important settings change.

Use a staged process:

  1. Define the baseline. Choose settings appropriate to the operating system, role, and risk.
  2. Test representative devices. Include real business applications and peripherals.
  3. Record exceptions. Document why a setting cannot be applied and what compensating control exists.
  4. Deploy in stages. Avoid changing every endpoint at once when the impact is uncertain.
  5. Verify. Confirm devices received the intended configuration.
  6. Monitor drift. Identify unauthorized or accidental configuration changes.
  7. Review periodically. Update the baseline as products, threats, and business requirements change.

NIST SP 800-70 Rev. 5 specifically treats verification and identification of unauthorized configuration changes as purposes of security configuration checklists.

That makes hardening an ongoing configuration-management process rather than a one-day cleanup project.

Hardening reality

The strongest baseline is one the business can operate.

A configuration that breaks critical software will be bypassed. Test hardening against real workflows, document justified exceptions, and keep the secure baseline maintainable.

Questions to ask during an endpoint-hardening review

  • Do we know every workstation that should be managed?
  • Which operating systems and applications are unsupported?
  • Who has local administrator rights?
  • Are laptops encrypted and are recovery keys controlled?
  • Are automatic locking and unique user identities configured?
  • Are browsers and extensions managed appropriately?
  • Are unnecessary remote-access tools installed?
  • Is the endpoint security agent active on every expected device?
  • Who receives security alerts?
  • Which hardening exceptions exist and who approved them?

A Network & Security Assessment can help identify device, access, network, lifecycle, and configuration gaps before a hardening plan is prioritized. SMART Solutions can also support the underlying endpoint environment through Computer, Server & Device Support.

If your workstations have been configured one at a time over several years and nobody is sure what the secure baseline should be, contact SMART Solutions to review the environment and build a practical improvement plan.

Sources and further reading