What is a Build Review?

A build review – also known as a secure configuration review or configuration audit – is a structured assessment of how an operating system, server, workstation, network device or cloud service has been configured, comparing current settings against industry-standard hardening benchmarks to identify security weaknesses.

Most organisations deploy systems using default or vendor-recommended settings, which are rarely optimised for security. A build review identifies where those defaults introduce unnecessary risk – open ports, excessive permissions, weak authentication settings, unnecessary services, outdated protocols – and provides a prioritised remediation plan to harden the configuration before attackers can exploit it.

CyberLab assesses builds against CIS Benchmarks Level 1 and 2, DISA STIG and Microsoft Security Baselines across Windows 11, Windows Server 2022, Ubuntu 22.04, RHEL 9 and macOS, delivered by CREST and CHECK-accredited consultants.

Why Choose CyberLab for a Build Review?

Unmatched Expertise

Build reviews delivered by our 14-strong UK team, including 7 CHECK Team Leaders, 6 CTMs, and SC/NPPV3-cleared consultants.

Proven Track Record

Over a decade of assessing devices, servers, and cloud services for public sector and regulated industries, building on our ex-Armadillo Sec heritage.

Trusted by 1,200+ Organisations

Including NHS, local authorities, housing, manufacturing, education, and financial services.

Rapid Response

Fast turnaround when configurations need checking against NCSC guidance and CIS benchmarks ahead of audits or deadlines.

No Jargon. No Orphaned Reports.

Just clear, prioritised recommendations to fix misconfigurations and keep your systems secure.

CyberLab is trusted by over 1,200 organisations across the UK to secure their operations, systems and data.

Ipswich Borough Council The Cambridge Building Society BCH Police East Lothian Council NHS Moat Homes Buckinghamshire Council

Build Reviews: The CyberLab Approach

Our Build Review process follows a structured, step-by-step approach to thoroughly assess and strengthen your IT systems. By identifying misconfigurations and vulnerabilities, we ensure your systems align with industry benchmarks, providing actionable recommendations to enhance security and reduce risk.

1 Planning and Scoping

The first step involves understanding the scope of the review, including identifying the systems, devices, and services that will be assessed. Information about the organisation's IT environment is gathered to tailor the review accordingly.

2 Configuration Review Against Benchmarks

Security experts manually log into systems or administrative consoles to review configurations. This step involves comparing current settings against trusted industry benchmarks such as NCSC guidance and CIS benchmarks.

3 Identifying Vulnerabilities and Misconfigurations

During the review, any misconfigurations, unnecessary services, weak access controls, or other vulnerabilities are identified. These could include insecure passwords, incorrect permissions, or outdated software versions.

4 Risk Assessment and Prioritisation

Identified vulnerabilities are evaluated based on their potential impact. Risks are prioritised, categorising them by severity (low, medium, high) to ensure critical issues are addressed first.

5 Remediation Recommendations

After identifying vulnerabilities, actionable recommendations for remediation are provided. These may involve updating configurations, disabling unnecessary services, enhancing security settings, or applying patches.

6 Reporting

A detailed report is generated, summarising the findings and providing a clear set of recommendations for improving security configurations. This report also includes steps to maintain secure configurations moving forward.

7 Follow-up and Re-Assessment

Once remediation actions have been implemented, a follow-up review may be conducted to verify that the security measures are correctly applied and functioning as intended.

What Does a Build Review Cover?

CyberLab’s build reviews assess the security configuration of a wide range of systems and devices, including:

  • Operating systems – Windows 11, Windows Server 2022, Ubuntu 22.04, RHEL 9 and macOS, assessed against CIS Benchmarks Level 1 and 2 and DISA STIG.
  • Microsoft environments – Microsoft 365, Azure AD and Active Directory configurations assessed against Microsoft Security Baselines and CIS Microsoft 365 Foundations Benchmark.
  • Network devices – firewalls, routers, switches and wireless access points assessed against vendor hardening guides and CIS network benchmarks.
  • Cloud platforms – AWS, Azure and Google Cloud configurations reviewed against cloud security benchmarks and NCSC cloud security principles.
  • Mobile devices – iOS and Android device configurations reviewed against MDM policy benchmarks for organisations with BYOD or managed device programmes.

Our Accreditations

As a CREST and CHECK-accredited build review provider, trusted by 1,200+ organisations including NHS Trusts, local authorities and enterprise businesses, we assess configurations against CIS Benchmarks, DISA STIG and Microsoft Security Baselines – delivered by a 14-strong UK team with findings mapped to severity and clear remediation guidance.

Build Review Success Stories

Trusted by NHS Trusts, local authorities and enterprise organisations across the UK. View all success stories →

SUCCESS STORY

NHS

A leading NHS Trust engaged CyberLab to assess and harden the configuration of their Microsoft 365 environment, ensuring security settings, policies and access controls met both NCSC guidance and NHS DSPT requirements.

CyberLab’s configuration review identified weaknesses across tenant settings, identity controls and data protection policies – delivering prioritised remediation guidance that allowed the Trust to strengthen their security posture without disrupting clinical operations.

Read Success Story
NHS Success Story

Build Reviews for Regulatory Compliance

Secure configuration sits at the heart of most major compliance and regulatory frameworks – yet it’s one of the most commonly overlooked controls. Whether you’re working toward Cyber Essentials, ISO 27001 or PCI DSS, a build review provides the documented evidence that your systems meet the configuration requirements each framework demands.

Cyber Essentials

Requires secure configuration of in-scope devices.

Get Cyber Essentials

Cyber Essentials Plus

Requires secure configuration of in-scope devices, verified through hands-on technical assessment.

Get Cyber Essentials Plus

NCSC 10 Steps to Cyber Security

Secure configuration sits within the Architecture and Configuration step.

Get NCSC 10 Steps to Cyber Security

PCI DSS

Requires hardening of all in-scope systems.

Get PCI DSS

ISO 27001

Mandates configuration management controls across your information systems.

DORA Digital Operational Resilience Act

Mandates configuration management for financial sector organisations.

Build Review FAQs

A Build Review involves evaluating the security configurations of your IT systems, ensuring they align with industry best practices and security benchmarks. This helps identify vulnerabilities and misconfigurations that could be exploited by attackers.

Build Reviews proactively identify and address security weaknesses in your system configurations, reducing the risk of breaches and ensuring your IT environment is securely configured against evolving threats.

A cyber security build review involves a systematic assessment of the security configuration applied to devices and systems within your organization’s IT environment. This includes servers, laptops, mobile devices, and network equipment such as firewalls, routers, and switches. The review evaluates the effectiveness of current security settings, identifies misconfigurations or deviations from best practices, and uncovers any weaknesses that could expose your organization to potential threats.

Build Reviews should be conducted regularly, especially after significant changes to your IT environment or systems. It’s also recommended to perform reviews annually to ensure your configurations remain secure and compliant with the latest security standards.

A Build Review should be conducted by certified security professionals with expertise in configuration management and security benchmarking. CyberLab’s team is CREST and CHECK certified, ensuring compliance with industry standards and best practices.

While Penetration Testing simulates attacks to identify exploitable vulnerabilities, Build Reviews focus on manually inspecting system configurations against security benchmarks to identify misconfigurations and hardening weaknesses before they can be exploited.

Yes, you will receive a comprehensive report that outlines the findings, categorising vulnerabilities by severity, and providing actionable recommendations to enhance your systems’ security.

CyberLab assesses configurations against CIS Benchmarks Level 1 and 2, DISA STIG (Defense Information Systems Agency Security Technical Implementation Guides) and Microsoft Security Baselines. CIS Benchmarks are globally recognised consensus-based configuration guidelines developed by the Center for Internet Security and are widely accepted as the industry standard for system hardening. Level 1 benchmarks cover essential configuration changes with minimal operational impact, while Level 2 covers more comprehensive hardening measures suited to high-security environments.

A penetration test actively attempts to exploit vulnerabilities in your systems, simulating a real attacker. A build review is a manual inspection of how your systems have been configured, comparing current settings against security benchmarks without attempting active exploitation. The two services are complementary – a build review identifies hardening weaknesses before a pen test, and a pen test validates whether remaining weaknesses after remediation can actually be exploited. Many organisations run both as part of a structured security programme.

HackRisk Logo White

What is your HackRisk score?

We scan your external attack surface and deliver a board-ready report with your risks and remediation advice, free of charge, within 24 hours.

Dark Web Scanning
Vulnerability Scanning
Recon Scanning
Supply Chain Security
Take the Platform Tour







    Speak With an Expert

    Get a scoped build review quote within one working day.

    Whether you need a one-off configuration audit ahead of an audit or compliance deadline, or want to establish a regular cadence of build reviews across your estate, our CREST and CHECK-accredited team can scope and deliver an engagement tailored to your environment. Speak with our team to discuss your requirements.

    This page was reviewed by Steve Clarke, Head of Penetration Testing at CyberLab, on 25.09.26.