OVH Cloud configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On OVH Cloud, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OVH Cloud connector needs.
Checks (7)
severity: medium Developer Mode Enabled fix difficulty: easy #
Disable developer mode on the OVHcloud account when not actively needed
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Click your account name in the top-right corner and select "My account"
- Navigate to Security settings
- Locate the "Developer mode" toggle and switch it off
- Confirm the change when prompted
- Verify that developer mode is shown as disabled
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low IAM Policy No Identities fix difficulty: easy #
Assign identities to unused IAM policies or delete them to reduce configuration clutter
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > IAM > Policies
- Identify policies that have no identities (users, groups, or service accounts) assigned
- Determine whether the policy is still needed by reviewing its purpose
- If not needed, click "Delete policy" and confirm the deletion
- If still needed, assign the appropriate identities to the policy
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low OAuth2 Client No Description fix difficulty: easy #
Add a meaningful description to OAuth2 service accounts to aid security reviews
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Account > API > OAuth2 Clients
- Click the OAuth2 client that lacks a description
- Select "Edit" and add a clear description indicating the client's purpose and owning team
- Save the updated client configuration
- Verify the description appears in the OAuth2 client list view
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: critical Cloud Project Suspended fix difficulty: medium #
Investigate and resolve the suspended Public Cloud project to restore normal operations
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Public Cloud and select the suspended project
- Review any notifications or banners explaining the reason for suspension (billing, quota, policy)
- Resolve the underlying issue — update payment method, settle outstanding invoices, or contact support
- If the project is no longer needed, delete it to remove it from scope
- Verify the project status returns to active after resolving the issue
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Instance Using Default Image fix difficulty: medium #
Replace stock OS images with hardened or custom images for new instances
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Public Cloud > Compute > Instances
- Create a hardened or organisation-standard image using the snapshot or custom image feature
- For new instances, select the custom image during creation instead of the default stock image
- For existing instances, snapshot the current instance, apply hardening, and create a new instance from the hardened snapshot
- Validate that the instance boots correctly and meets security baseline requirements
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low Instance In Shelved State fix difficulty: easy #
Unshelve active instances or delete shelved instances that are no longer needed
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Public Cloud > Compute > Instances
- Identify instances in the shelved state
- If the instance is still needed, click "Unshelve" to restore it to active status
- If the instance is no longer required, click "Delete instance" to remove it and free resources
- Confirm the action and verify the instance list reflects the updated state
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Instance Rescue Mode fix difficulty: medium #
Reboot the instance out of rescue mode to restore normal boot security controls
- Log in to the OVHcloud Control Panel at ovh.com/manager/
- Navigate to Public Cloud > Compute > Instances and select the instance in rescue mode
- Review any open support tickets or maintenance tasks that initiated rescue mode
- Once the remediation task is complete, click "Exit rescue mode" or reboot normally
- Wait for the instance to boot from its standard disk image
- Verify the instance is running normally and all services are responding
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10