Patching (specific CVEs and patch identifiers) - Configuration hardening (firewall rules, service configurations) - Architecture changes (network segmentation, access control)