Case Study – How a Regional Bank Hardened 700+ Production Servers and Achieved 99% Compliance

Reading time: 5 Minutes Read
Case Study – How a Regional Bank Hardened 700+ Production Servers and Achieved 99% Compliance
“CalCom allows you to comply with CIS Benchmarks and greatly reduce the attack surface, even in an active production environment, with very little interruption to production services. ”
VP of Information Security, VanHopwell Bank

The Challenge – Closing an Audit Finding Without Disrupting Production

(Company name in this case study has been changed to protect confidentiality. All details, metrics, and quotes reflect an actual customer engagement.)

VanHopwell Bank (is a regional U.S. bank operating a complex server environment supporting critical financial services. Like many banks that have grown through acquisition, the organization had inherited a diverse infrastructure that had evolved over time, with servers built from different images, configurations, and operational requirements.

When a mandatory audit identified significant gaps in server hardening, the security team faced an urgent challenge.

Prior to the project, server hardening across the bank’s environment was inconsistent. Many systems were operating at less than 50% compliance with hardening standards, and some were closer to 30%. The lack of a standardized baseline created a large attack surface and made it difficult to assess true risk or demonstrate compliance.

At the same time, the team faced a significant operational challenge. Hardening production servers is fundamentally different from hardening new systems before deployment. Every production server supports unique applications, services, and business processes, creating the risk that security changes could disrupt critical operations.

As the bank’s VP of Information Security explains:

“It’s much easier to harden a server before it gets into production. But when it’s in production, it’s much harder because all servers have their own quirks, special requirements, and unique business processes running on them.”

VP of Information Security, VanHopwell Bank

VanHopwell Bank needed a solution that would allow it to harden hundreds of production servers, close the audit finding, and reduce risk without creating outages or impacting customer-facing services.

Key Challenges

  • Address audit findings related to server hardening
  • Reduce attack surface across a large production environment
  • Harden more than 700 production servers
  • Avoid outages and disruption to business-critical applications
  • Improve compliance with CIS-based hardening standards
  • Navigate formal banking change-control processes
  • Maintain operational stability throughout deployment

The Solution – CalCom Hardening Suite (CHS)

Unlike traditional hardening tools that focus solely on gap analysis, CHS places servers into Learning Mode and develops a detailed understanding of how each system operates. By observing services, applications, usage patterns, and dependencies over time, CHS can identify not only what should be hardened, but also what could be negatively affected by those changes.

This visibility proved critical in VanHopwell Bank’s production environment.

For example, if a service such as Print Spooler is enabled, CHS does more than identify it as a policy violation. It also determines whether the service is actively being used and whether disabling it could disrupt business operations.

By understanding how each server functions before making changes, the security team could harden systems confidently while minimizing operational risk.

“I don’t think there is any significant competitor that can do what CalCom does.”

VP of Information Security, VanHopwell Bank

The deployment began with a small test environment before expanding into production batches of approximately 70 servers at a time. Each server was placed into Learning Mode for roughly three weeks before reports were generated and reviewed by security and operations teams.

Because VanHopwell Bank operates in a highly regulated environment, each deployment batch was reviewed through formal Change Control Board processes before implementation.

Following deployment, VanHopwell Bank:

  • Installed CHS agents across production systems
  • Ran servers in Learning Mode to profile activity and dependencies
  • Generated server-specific impact analysis reports
  • Reviewed exceptions with security and operations stakeholders
  • Approved changes through formal governance processes
  • Hardened servers in controlled deployment waves

With CHS, VanHopwell Bank Gained

  • Visibility into the operational impact of policy changes
  • Server-specific hardening recommendations
  • Reduced risk of application outages
  • Automated hardening aligned with CIS-based standards
  • Consistent policy enforcement across hundreds of systems
  • Centralized reporting and compliance visibility
  • Confidence to harden production systems safely

The Result: Audit Finding Closed, 700+ Servers Hardened

Using CHS, VanHopwell Bank successfully hardened more than 700 production servers while maintaining operational continuity across the organization.

The audit finding that originally triggered the initiative was successfully remediated and closed.

At the same time, the bank dramatically improved its security posture. Today, the organization estimates that its production server environment achieves approximately 99% compliance with approved hardening policies.

The improvement was significant. Prior to the project, hardening compliance was inconsistent and difficult to measure. Today, most servers operate with zero exceptions, while those that do require exceptions typically have only one or two deviations across more than 300 evaluated policy parameters.

Most importantly, these improvements were achieved with minimal disruption to business operations.

“We were able to harden all of our production environment with very little interruption whatsoever.”

VP of Information Security, VanHopwell Bank

The project enabled VanHopwell Bank to significantly reduce its attack surface while maintaining the stability required in a highly regulated banking environment.

Results at a Glance

  • 700+ production servers hardened
  • Audit finding successfully closed
  • Approximately 99% policy compliance achieved
  • More than 300 security parameters evaluated per server
  • Significant reduction in attack surface
  • Minimal disruption to production services
  • Consistent policy enforcement across the environment
  • Increased confidence for security and compliance teams

Beyond the Rollout – Maintaining Secure Baselines

For VanHopwell Bank, server hardening did not end with deployment.

Maintaining hardened configurations across hundreds of production systems can be just as challenging as the initial rollout. Without continuous enforcement, configuration drift, operational changes, and manual modifications can gradually weaken security controls over time.

CHS now serves as an ongoing hardening and compliance platform, helping VanHopwell Bank maintain approved baselines and continuously enforce security policies across its server environment.

Rather than relying solely on periodic audits or manual reviews, the security team can continuously monitor compliance, identify deviations, and ensure systems remain aligned with approved standards.

This approach provides ongoing assurance that hardening controls remain effective while reducing the operational burden associated with maintaining compliance at scale.

As a result, VanHopwell Bank not only closed an audit finding and improved compliance—it established a sustainable framework for reducing attack surface and maintaining security across its production infrastructure.

“It definitely gives me and the CISO peace of mind. We closed the findings, but we also have the peace of mind of having a much reduced attack surface.”

VP of Information Security, VanHopwell Bank

If your organization is facing similar audit findings, compliance gaps, or the operational risk of hardening systems already in production, CalCom Hardening Suite can help.

See how CHS can give your team the visibility and confidence to harden servers safely, without disrupting the business. Talk to our team.

Contact us to learn how we can help your organization

    More to Explore

    About Us

    Established in 2001, CalCom is the leading provider of server hardening solutions that help organizations address the rapidly changing security landscape, threats, and regulations. CalCom Hardening Suite (CHS) is a security baseline hardening solution that eliminates outages, reduces operational costs, and ensures a resilient, constantly hardened, and monitored server environment.

    More about us
    Background Shape
    About Us

    Ready to simplify compliance?

    See automated compliance in action—book your demo today!