Congratulations, you have just upgraded your infrastructure to VMware Cloud Foundation (VCF) 9.1, taking advantage of its latest capabilities and source code hardening. But your security journey does not stop there; this is just the beginning.
With VCF 9.1, Broadcom leverages frontier AI models to uncover vulnerabilities and conduct rigorous source code review, delivering its most secure platform to date. But a successful deployment is just the starting point. Ongoing work to harden your environment and take advantage of the platform’s security capabilities remains essential to reducing your overall risk and safeguarding sensitive data and workloads against evolving threats.
If you just finished your migration, or you’re planning it now, here are five steps you need to take to secure your VCF 9.1 environment.
1. Harden the Platform
Hardening is the deliberate process of minimizing your attack surface by disabling unnecessary services, locking down management planes, and enforcing strict access controls. This is the most important step in this list and if you don’t know where to start, we have you covered:
- VMware Security Configuration Guides (SCG): For commercial enterprises, the SCG is your baseline. The SCG outlines 260 controls, providing guidance on how to assess and implement these controls in your environment. The controls are aligned to NIST 800-53 R5, PCI DSS 4.0.1 and the Secure Controls Framework to help you with mapping applicable controls to your cybersecurity framework practices.
- Click here to learn more.
- STIG Readiness Guides: For federal agencies, defense contractors, and highly regulated industries, baseline security is not enough. You must align with the Defense Information Systems Agency (DISA) standards. The STIG Readiness Guides provide the validated configurations needed to ensure your VCF 9.1 environment meets these rigorous, audit-ready mandates.
- Click here to learn more.
We always recommend that you test the implementation of hardened configurations in a lab or test environment prior to moving to production. Security is never a one-size-fits-all-approach. What works in one environment may cause disruptions in another, so it is important that you perform proper due diligence and testing of security related controls.
2. Secure Identities
Compromised administrator credentials remain one of the main attack vectors used by bad actors to gain access to private cloud environments. Having strong role-based access controls following the concept of least privilege is the best way to protect your administrative credentials.
- VCF Identity Broker (VIDB): VIDB acts as a centralized bridge for SSO integrations with external providers, mandating OAuth-based token validation for all programmatic interfaces. By separating the authentication logic from the VMware vCenter layer, it provides a more resilient and unified framework for identity governance across the platform.
3. Reduce the Attack Surface
If an attacker compromises a virtual machine, what happens next? They perform reconnaissance, escalate privileges, and move laterally, potentially compromising your business critical data.
VCF 9.1 is designed for Zero Trust, but it is not on by default; you have to configure and implement the appropriate processes behind it. By leveraging VMware vDefend, you can fortify your network boundaries and reduce the attack surface.
- Microsegmentation: Distributed (east/west) and Gateway (north/south) firewalls are the mechanisms for implementing a Zero Trust network architecture in the environment and isolate business critical workloads.
- Threat Inspection: Turn on distributed IDS/IPS to actively monitor lateral traffic, allowing the system to block traffic that exhibits malicious behavior.
4. Streamline Patch Management
Historically, security teams and IT operations were constantly at odds Security demanded immediate patching for critical Common Vulnerabilities and Exposures (CVEs) and operations delayed them because patching required host evacuations, massive vMotion events, and disruptive downtime.
VCF 9.1 fundamentally breaks this tension, but your operational teams need to adopt the new workflows to benefit from it.
- Centralized Lifecycle Management: Use VCF Operations to handle the lifecycle of the entire stack. This helps ensure that compute, network, and storage patches are applied in the correct, validated order, preventing compatibility breaks.
- Zero-Downtime Live Patching: VCF 9.1 introduces TPM-enabled VMware ESX Live Patching. You can apply critical security updates to the hypervisor without migrating workloads, evacuating hosts, or entering maintenance mode.
5. Manage Configuration Drift
You followed the SCG, segmented your network, and patched your hosts. You are secure on Day 1. But what about Day 201? How do you ensure your current state meets the target secure state? Configuration drift must be managed and addressed in a timely manner to maintain a robust security posture. In VCF 9.1 we have native capabilities to manage your configuration drift:
- Native Security Posture Visibility: VMware Cloud Foundation Operations features a dedicated Security Operations (SecOps) dashboard, giving you single-pane-of-glass insight into the security configuration of your entire VCF environment.
- VMware Advanced Cyber Compliance (ACC): Leverages VMware Salt to continuously monitor your VCF 9.1 stack against your chosen security baseline (SCG or PCI-DSS). If an ESX host drifts out of compliance, ACC detects it and can automatically remediate the configuration back to the desired state.
The Path Forward
Upgrading to VCF 9.1 delivers an incredibly robust, deeply hardened foundation right out of the gate—but optimal security is a journey, not a single milestone. Building a true Zero Trust private cloud requires moving past the default settings to actively enforce hardening baselines, strong access controls, improving patch operations, microsegmentation, and elimination of configuration drift.
If you want to fast-track your security transformation, our VCF Professional Services team is ready to jump in as an extension of your own.
Whether you need a comprehensive security posture assessment, tailored architectural design, or hands-on help deploying automated compliance workflows, we bring the deep technical expertise to make it happen. Let’s bridge the gap between your current deployment and a highly secure, audit-ready future state.
Reach out to your VCF Technical Adoption Manager (TAM) for more information, or talk to your Account Director about how you can engage the VCF Professional Services team to ensure that your VCF environment is resilient and secure.
Discover more from VMware Cloud Foundation (VCF) Blog
Subscribe to get the latest posts sent to your email.