VMware ESXi Virtualization Security: Best Practices After the Broadcom Acquisition
The Broadcom acquisition of VMware changed the licensing landscape significantly. If you are still running ESXi, here is how to secure your virtualization infrastructure and evaluate your options.
By Tom Brennan
The Broadcom acquisition of VMware in late 2023 fundamentally changed the commercial landscape. Significant licensing changes and price increases have prompted many organizations to evaluate alternatives including Hyper-V, Proxmox, and Nutanix. Regardless of your roadmap, ESXi has been a high-value ransomware target with multiple threat actor groups developing ESXi-specific ransomware variants.
ESXi Security Hardening Essentials
Enable Lockdown Mode
ESXi lockdown mode restricts direct host access, requiring all management to go through vCenter. Enable normal lockdown mode for most environments.
Patch and Update Immediately
Apply security patches within 72 hours of release for critical severity. The ESXiArgs ransomware campaigns exploited unpatched ESXi hosts at scale.
Restrict Management Network Access
ESXi management interfaces should never be exposed to the internet. Place them on a dedicated management VLAN accessible only from jump hosts with MFA.
Disable Unnecessary Services
Disable services not actively in use: CIM Server, Direct Console UI remote access, and legacy shell access.
Free Virtualization Security Resources
Strengthen your ESXi and virtualization security posture with Proactive Risk's free resources, available in the Downloads library:
- Security Incident Response Plan (SIRP) Template — a ready-to-use incident response plan template aligned to NIST SP 800-61, covering detection, containment, eradication, and recovery — essential for ESXi ransomware scenarios
- Proactive Risk GitHub Repositories — open-source security automation scripts and infrastructure hardening tools published by the Proactive Risk team
Explore Related Resources