How Combilift Hardened Its Global Server and Workstation Environment and Simplified NIS2 Compliance

Reading time: 4 Minutes Read
How Combilift Hardened Its Global Server and Workstation Environment and Simplified NIS2 Compliance

“If a mistake is made or a machine’s offline for a while, whenever it comes back online, CalCom acts automatically and re-hardens the device according to any policies we’ve set.”

IT Team Lead, Combilift Group

The Challenge:

Manual Server Hardening Across a Global Endpoint Fleet

Combilift Group’s IT team manages a complex environment of servers and endpoints across its headquarters in Monaghan, a distribution facility in Greensboro, NC, and remote sales staff located in multiple countries. Their existing hardening solution covered endpoints, while servers were managed through a completely separate system.

Server hardening was performed manually, one setting at a time. The team proceeded cautiously because the environment contained a mix of legacy applications, and an incorrect change could potentially disrupt a production system. While this approach minimized risk, it also slowed progress and resulted in inconsistent coverage across the server environment.

The team also lacked a reliable way to detect configuration drift. If a device went offline or a Group Policy change reversed a setting, there was no automatic mechanism to identify or correct the issue. With NIS2 compliance requirements approaching in Ireland, Combilift needed a solution that could demonstrate to auditors that hardening controls remained effective over time, as configuration drift posed just as much risk as initial security gaps.

As the team explained, these gaps were difficult to identify without a dedicated hardening solution in place:

“There is always in the back of your mind you are like, ‘I am missing something here.’ There are vulnerabilities lying open; I can’t cover everything.”

Key Challenges

  • Harden servers running a mix of legacy applications without disrupting production
  • Replace manual, one-at-a-time hardening with a consistent and repeatable process
  • Detect and remediate configuration drift on devices that go offline or are modified outside policy
  • Produce audit-ready evidence to support NIS2 compliance requirements
  • Manage security hardening across a global environment with a small IT team

The Solution:

CalCom Hardening Suite (CHS)

Combilift was introduced to CalCom by its managed service provider, Integrity360. Their recommendation and support throughout the evaluation process helped ensure the solution was a strong fit for the organisation. Following a successful proof of concept, CHS proved straightforward to deploy within a live production environment, giving the team confidence that a full-scale rollout could be completed smoothly.

Two capabilities stood out during the proof of concept. Learning Mode allowed the team to see exactly what CHS would recommend before any controls were enforced, enabling them to assess the potential impact of each change and resolve issues in advance. Automatic re-hardening ensured that if a device went offline for an extended period or a policy setting was reverted, CHS would automatically restore the correct configuration as soon as the device reconnected, without requiring manual intervention from the IT team.

Combilift also evaluated other hardening platforms before selecting CHS and found competing solutions to be cluttered and difficult to navigate.

“It was literally in front of you. Other solutions were heavily focused on the UI, and it was just too complicated. It’s better to have it clear in front of you where you go.”

Implementation was managed by CalCom’s team and was described as straightforward and stress-free, with prompt responses to any questions raised throughout the process.

With CHS, Combilift Gained

  • Automatic re-hardening of devices that drift out of compliance or go offline
  • Faster onboarding of new PCs through deployment of the CHS agent
  • Audit-ready reporting to support NIS2 compliance efforts
  • A significant reduction in manual hardening work for the IT team
  • A single, intuitive dashboard that replaced a fragmented manual process
  • Confidence to enforce hardening policies across legacy systems without disrupting operations

The Results:

From Manual Hardening to Just Minutes Per Week

Since the full deployment of CHS, Combilift’s IT team has moved from manually managing hardening across hundreds of endpoints to a streamlined, predictable process. One team member now reviews the CHS dashboard once or twice per week to address any exceptions requiring attention. New PCs are provisioned simply by installing the CHS agent, eliminating the need for manual configuration checklists. Login security has also been enhanced, with users now required to authenticate using their full email address and password rather than a stored username.

The team describes the post-deployment experience as consistently positive, highlighting a continued reduction in manual effort and the uncertainty associated with the previous approach.

“I have no hesitation in recommending CalCom. It’s definitely worth speaking with the team to see how they can add value to your organisation.”

Results

  • All endpoints managed under policy
  • Manual server hardening replaced with automated, policy-driven enforcement
  • Devices automatically re-hardened following downtime or configuration drift
  • Audit-ready reporting in place to support NIS2 compliance
  • Day-to-day management reduced to one or two dashboard reviews per week
  • Partnership established through MSP provider Integrity360

Beyond the Rollout

Making Hardening a Background Process

For Combilift, the only challenge was the pace of the initial rollout, which was deliberately approached with caution due to the number of legacy systems involved. Once fully deployed, CHS became a background process rather than an everyday operational task.

Rather than relying on manual checks or waiting for vulnerability notifications through security bulletins, the IT team now has a solution that proactively identifies gaps. This shift has enabled the team to focus on higher-value priorities instead of manually monitoring configuration drift across a globally distributed device estate.

“It’s all been positive. So far, so good.”

Contact us to learn how we can help your organization

    More to Explore

    About Us

    Established in 2001, CalCom is the leading provider of server hardening solutions that help organizations address the rapidly changing security landscape, threats, and regulations. CalCom Hardening Suite (CHS) is a security baseline hardening solution that eliminates outages, reduces operational costs, and ensures a resilient, constantly hardened, and monitored server environment.

    More about us
    Background Shape
    About Us

    Ready to simplify compliance?

    See automated compliance in action—book your demo today!