Skip to content

OVH Cloud configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On OVH Cloud, Black Cat runs 7 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OVH Cloud connector needs.

Checks (7)

severity: medium Developer Mode Enabled fix difficulty: easy #

Disable developer mode on the OVHcloud account when not actively needed

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Click your account name in the top-right corner and select "My account"
  3. Navigate to Security settings
  4. Locate the "Developer mode" toggle and switch it off
  5. Confirm the change when prompted
  6. Verify that developer mode is shown as disabled

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low IAM Policy No Identities fix difficulty: easy #

Assign identities to unused IAM policies or delete them to reduce configuration clutter

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Account > IAM > Policies
  3. Identify policies that have no identities (users, groups, or service accounts) assigned
  4. Determine whether the policy is still needed by reviewing its purpose
  5. If not needed, click "Delete policy" and confirm the deletion
  6. If still needed, assign the appropriate identities to the policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low OAuth2 Client No Description fix difficulty: easy #

Add a meaningful description to OAuth2 service accounts to aid security reviews

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Account > API > OAuth2 Clients
  3. Click the OAuth2 client that lacks a description
  4. Select "Edit" and add a clear description indicating the client's purpose and owning team
  5. Save the updated client configuration
  6. Verify the description appears in the OAuth2 client list view

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: critical Cloud Project Suspended fix difficulty: medium #

Investigate and resolve the suspended Public Cloud project to restore normal operations

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud and select the suspended project
  3. Review any notifications or banners explaining the reason for suspension (billing, quota, policy)
  4. Resolve the underlying issue — update payment method, settle outstanding invoices, or contact support
  5. If the project is no longer needed, delete it to remove it from scope
  6. Verify the project status returns to active after resolving the issue

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Instance Using Default Image fix difficulty: medium #

Replace stock OS images with hardened or custom images for new instances

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud > Compute > Instances
  3. Create a hardened or organisation-standard image using the snapshot or custom image feature
  4. For new instances, select the custom image during creation instead of the default stock image
  5. For existing instances, snapshot the current instance, apply hardening, and create a new instance from the hardened snapshot
  6. Validate that the instance boots correctly and meets security baseline requirements

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Instance In Shelved State fix difficulty: easy #

Unshelve active instances or delete shelved instances that are no longer needed

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud > Compute > Instances
  3. Identify instances in the shelved state
  4. If the instance is still needed, click "Unshelve" to restore it to active status
  5. If the instance is no longer required, click "Delete instance" to remove it and free resources
  6. Confirm the action and verify the instance list reflects the updated state

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Instance Rescue Mode fix difficulty: medium #

Reboot the instance out of rescue mode to restore normal boot security controls

  1. Log in to the OVHcloud Control Panel at ovh.com/manager/
  2. Navigate to Public Cloud > Compute > Instances and select the instance in rescue mode
  3. Review any open support tickets or maintenance tasks that initiated rescue mode
  4. Once the remediation task is complete, click "Exit rescue mode" or reboot normally
  5. Wait for the instance to boot from its standard disk image
  6. Verify the instance is running normally and all services are responding

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More OVH Cloud checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial