
Most of the software your team uses every day was built to do more than you actually need. Web browsers can run add-ons and plugins, Microsoft Office can launch other programs from inside a document, and PDF readers can open attachments and run scripts. These features exist for convenience, but attackers treat them as open doors. User application hardening is the practice of closing the doors you do not use, so a single dodgy email or website cannot quietly take over a computer.
It is one of the ACSC Essential Eight, the baseline set of controls the Australian Signals Directorate recommends for every organisation. The good news for small business is that a lot of hardening is free, built into Windows and Microsoft 365, and can be switched on without buying anything new. Here is what user application hardening means, why it matters, and the practical steps to get started.
What user application hardening actually means
Hardening simply means removing or turning off the parts of an application that create risk without adding much value to your business. The aim, in the ACSC’s words, is to reduce the chance that an everyday application can be used to run malicious code, steal information, or give an attacker a foothold on a device.
Think of it as trimming each program back to what your staff genuinely use. A browser that cannot run outdated plugins, an Office suite that cannot launch other programs from inside a document, and a PDF reader that cannot spawn hidden processes are all far less useful to an attacker. Importantly, hardening is different from patching. Patching fixes known holes in software, which is covered by the separate Essential Eight control on updates. Hardening reduces the attack surface even when no specific flaw is involved, by taking risky capabilities off the table entirely.
If the Essential Eight is new to you, it is worth reading our plain-English guide to the ACSC Essential Eight first, so you can see where application hardening fits alongside the other seven controls.
Why attackers go after everyday apps
The programs your staff open dozens of times a day are exactly the ones attackers want to abuse, because they are already trusted and already running. An employee who opens a document from a supplier, clicks a link in an email, or views a web page is not doing anything unusual. If that routine action can trigger a hidden instruction inside a browser or an Office file, the attacker gets to run their code using your staff member’s own access.
Older technologies are the biggest offenders. Features such as Adobe Flash, the Java browser plugin, and legacy versions of Internet Explorer were built in a different era and are riddled with weaknesses that will never be fixed because the products are no longer supported. Macros and embedded objects inside Office documents are another favourite, because a single prepared file can carry a complete attack. The pattern is consistent: attackers reach for the oldest, least maintained, most powerful feature they can find, because that is where defences are weakest.
Start with the web browser
The browser is where most of the risk lives, because it is the one application that constantly loads content from the wider internet. The ACSC guidance focuses on a handful of concrete settings that modern Windows and Microsoft Edge can enforce centrally.
- Stop the browser from processing Java and web advertisements, two common delivery routes for malicious code. Java is no longer installed by default on current versions of Windows, and ad processing can be switched off through Edge policies.
- Disable or remove Internet Explorer 11. It is no longer supported, and anything that still needs it can usually run through the IE mode built into Microsoft Edge for legacy sites.
- Apply a hardened browser configuration using the Microsoft Edge security baseline together with the ACSC’s own Edge hardening guidance.
- Lock the settings so standard users cannot simply undo them. If a setting can be changed back by anyone, it is a suggestion rather than a control.
Because the browser is such a large topic in its own right, we have a dedicated walkthrough on hardening web browsers for business use that covers the Edge settings in more detail.
Harden Microsoft Office and your PDF reader
Office documents and PDFs are the files your staff trust most, which is precisely why they are weaponised so often. A hardened setup stops a document from doing anything beyond displaying its contents.
For Microsoft Office, the key measures are blocking Office applications from creating child processes (in other words, launching other programs), blocking them from creating executable content, and preventing the activation of embedded OLE objects, which are the packaged files sometimes hidden inside a document. On modern Windows these are enforced through Attack Surface Reduction rules, which are built into Microsoft Defender and cost nothing extra to enable. This sits closely alongside macro security, and if you have not already locked those down, our guide on why Office macros are blocked and stay blocked is the companion piece.
PDF software deserves the same treatment. The main control is to stop your PDF reader from spawning child processes, so that opening an attachment cannot quietly launch something else. On current Windows installations, Microsoft Edge is the default PDF viewer, which keeps PDF handling inside an application you are already hardening rather than a separate third-party reader that needs managing on its own.
Turn off the old features you no longer need
A surprising amount of risk comes from components that are quietly sitting on your computers doing nothing useful. Removing them is some of the cheapest security you can buy, because you lose nothing you were actually using. The ACSC specifically calls out a short list of legacy items to disable or remove.
- The .NET Framework 3.5, an older component that many businesses no longer need but which remains available on Windows unless it is turned off.
- Windows PowerShell 2.0, a superseded version that attackers favour because it avoids the extra logging and safeguards in later versions.
- The Java browser plugin and Adobe Flash, both long past their useful life and best removed entirely rather than merely disabled.
- Internet Explorer 11, as covered above, which belongs in the same pile of legacy technology to retire.
Alongside removing the old, it is worth switching on better visibility. The guidance recommends centrally logging PowerShell script activity and command-line process creation, so that if something does slip through, you have a record of what happened. For a small business, the practical version of this is enabling the logging features already present in Microsoft Defender rather than building anything custom.
A simple plan to get started
You do not need to do all of this at once, and you certainly do not need to be an expert. The sensible order is to tackle the highest-risk, lowest-effort items first, then work through the rest over a few weeks.
- Standardise on Microsoft Edge as your browser and retire Internet Explorer 11 across every device.
- Turn on the Attack Surface Reduction rules in Microsoft Defender that block Office applications from launching other programs and creating executable content.
- Remove Flash, the Java plugin, the .NET Framework 3.5, and PowerShell 2.0 from your standard computer build.
- Apply the Microsoft Edge security baseline and the ACSC Edge hardening settings, and lock them so staff cannot change them back.
- Enable script and command-line logging so you have a trail if you ever need to investigate.
If you use Microsoft 365 Business Premium or manage devices through Microsoft Intune, most of these settings can be pushed out to every computer from one place, which means you set them once and they apply to new staff automatically. If you run a mix of devices without central management, your IT provider can apply the same settings through Group Policy or a device configuration tool. Either way, the point is to make the hardened state the default, not something each person has to remember.
Find out where you stand
User application hardening is one of the quietest wins in cyber security. It rarely gets in the way of normal work, it mostly uses tools you already own, and it removes some of the most popular routes attackers use to get in. The hard part is simply knowing which of these controls you already have in place and which ones are still wide open.
That is exactly what our free self-assessment is built to show you. In five to ten minutes you answer 27 plain-English questions about how your business handles security, and you get an instant, personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2. It will tell you where application hardening and the other controls sit today, and where to focus next. Take the free SecurityScore assessment and see where you stand.