Insights › Essential Eight

User Application Hardening: A Guide for Business

SecurityScore article cover: User Application Hardening, an ACSC Essential Eight control, on a dark navy background

Most of the software your team uses every day was built to do more than you actually need. Web browsers can run add-ons and plugins, Microsoft Office can launch other programs from inside a document, and PDF readers can open attachments and run scripts. These features exist for convenience, but attackers treat them as open doors. User application hardening is the practice of closing the doors you do not use, so a single dodgy email or website cannot quietly take over a computer.

It is one of the ACSC Essential Eight, the baseline set of controls the Australian Signals Directorate recommends for every organisation. The good news for small business is that a lot of hardening is free, built into Windows and Microsoft 365, and can be switched on without buying anything new. Here is what user application hardening means, why it matters, and the practical steps to get started.

What user application hardening actually means

Hardening simply means removing or turning off the parts of an application that create risk without adding much value to your business. The aim, in the ACSC’s words, is to reduce the chance that an everyday application can be used to run malicious code, steal information, or give an attacker a foothold on a device.

Think of it as trimming each program back to what your staff genuinely use. A browser that cannot run outdated plugins, an Office suite that cannot launch other programs from inside a document, and a PDF reader that cannot spawn hidden processes are all far less useful to an attacker. Importantly, hardening is different from patching. Patching fixes known holes in software, which is covered by the separate Essential Eight control on updates. Hardening reduces the attack surface even when no specific flaw is involved, by taking risky capabilities off the table entirely.

If the Essential Eight is new to you, it is worth reading our plain-English guide to the ACSC Essential Eight first, so you can see where application hardening fits alongside the other seven controls.

Why attackers go after everyday apps

The programs your staff open dozens of times a day are exactly the ones attackers want to abuse, because they are already trusted and already running. An employee who opens a document from a supplier, clicks a link in an email, or views a web page is not doing anything unusual. If that routine action can trigger a hidden instruction inside a browser or an Office file, the attacker gets to run their code using your staff member’s own access.

Older technologies are the biggest offenders. Features such as Adobe Flash, the Java browser plugin, and legacy versions of Internet Explorer were built in a different era and are riddled with weaknesses that will never be fixed because the products are no longer supported. Macros and embedded objects inside Office documents are another favourite, because a single prepared file can carry a complete attack. The pattern is consistent: attackers reach for the oldest, least maintained, most powerful feature they can find, because that is where defences are weakest.

Start with the web browser

The browser is where most of the risk lives, because it is the one application that constantly loads content from the wider internet. The ACSC guidance focuses on a handful of concrete settings that modern Windows and Microsoft Edge can enforce centrally.

Because the browser is such a large topic in its own right, we have a dedicated walkthrough on hardening web browsers for business use that covers the Edge settings in more detail.

Harden Microsoft Office and your PDF reader

Office documents and PDFs are the files your staff trust most, which is precisely why they are weaponised so often. A hardened setup stops a document from doing anything beyond displaying its contents.

For Microsoft Office, the key measures are blocking Office applications from creating child processes (in other words, launching other programs), blocking them from creating executable content, and preventing the activation of embedded OLE objects, which are the packaged files sometimes hidden inside a document. On modern Windows these are enforced through Attack Surface Reduction rules, which are built into Microsoft Defender and cost nothing extra to enable. This sits closely alongside macro security, and if you have not already locked those down, our guide on why Office macros are blocked and stay blocked is the companion piece.

PDF software deserves the same treatment. The main control is to stop your PDF reader from spawning child processes, so that opening an attachment cannot quietly launch something else. On current Windows installations, Microsoft Edge is the default PDF viewer, which keeps PDF handling inside an application you are already hardening rather than a separate third-party reader that needs managing on its own.

Turn off the old features you no longer need

A surprising amount of risk comes from components that are quietly sitting on your computers doing nothing useful. Removing them is some of the cheapest security you can buy, because you lose nothing you were actually using. The ACSC specifically calls out a short list of legacy items to disable or remove.

Alongside removing the old, it is worth switching on better visibility. The guidance recommends centrally logging PowerShell script activity and command-line process creation, so that if something does slip through, you have a record of what happened. For a small business, the practical version of this is enabling the logging features already present in Microsoft Defender rather than building anything custom.

A simple plan to get started

You do not need to do all of this at once, and you certainly do not need to be an expert. The sensible order is to tackle the highest-risk, lowest-effort items first, then work through the rest over a few weeks.

If you use Microsoft 365 Business Premium or manage devices through Microsoft Intune, most of these settings can be pushed out to every computer from one place, which means you set them once and they apply to new staff automatically. If you run a mix of devices without central management, your IT provider can apply the same settings through Group Policy or a device configuration tool. Either way, the point is to make the hardened state the default, not something each person has to remember.

Find out where you stand

User application hardening is one of the quietest wins in cyber security. It rarely gets in the way of normal work, it mostly uses tools you already own, and it removes some of the most popular routes attackers use to get in. The hard part is simply knowing which of these controls you already have in place and which ones are still wide open.

That is exactly what our free self-assessment is built to show you. In five to ten minutes you answer 27 plain-English questions about how your business handles security, and you get an instant, personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2. It will tell you where application hardening and the other controls sit today, and where to focus next. Take the free SecurityScore assessment and see where you stand.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading