This is the half of security nobody photographs, and the half that decides whether your firm is the easy option on the street. Machines that get updated. Browsing that stays filtered wherever the laptop is plugged in. Macs run by something built for Macs. Phones somebody has actually looked at.
A machine that never gets updated is the most dependable way into a small firm there is. It needs nobody clever, it needs no convincing message, and it works to a timetable that suits the other side rather than yours. Updating is dull, it is measurable, and it is the first thing an insurer will ask you about.
Alongside it comes knowing what you own. Most small firms are out by a machine or two, and it is invariably the interesting one: the elderly box driving the label printer, the laptop somebody kept after changing jobs, the spare at reception everybody signs into with the same password.
N-able N-sight takes the Windows estate and the servers: watching, updating, scripting, hands-on help, plus filtering carried by that very same agent, which spares you a cabinet. Addigy takes the Apple side on Apple terms, and that is what separates an estate of Macs somebody runs from an estate somebody merely counted.
Zimperium takes the phones. Your staff read company mail on hardware you do not own and hardly anybody looks at it. It sits on the device, judges the apps, the network it has just joined and the operating system beneath, and sends no message content anywhere to be inspected.
Billing supplies each figure below as the page draws. Add a line and it sits on the board while you read further down.
Updates applied, hardware watched, scripts run, and hands available without asking anybody to read an error message down the phone. Deeply unglamorous, and the single biggest reason a small firm stops being the easy option on the street.
| Position | Fleet console, one row for every machine |
|---|---|
| Watches for | Updates outstanding, disks going bad, services that stopped, machines gone silent |
| Log kept | Update history, warning history and every remote session, per machine |
| Escalation path | A machine gone silent raises its own callout without anybody noticing first |
| Sign-off | Closed when the machine is back on the board and its updates are current |
Category and reputation filtering carried by an agent that is already there. No appliance, no cabinet, nothing whatever to rack. It rides home inside the laptop bag, which is where a great deal of the browsing now happens.
| Position | Fleet console, one policy per group of machines |
|---|---|
| Watches for | Lookups heading somewhere known bad, and anything in the categories you closed |
| Log kept | The refused lookups, and every exception granted, with the name of who asked |
| Escalation path | Exception requests queue at the console and are answered in working hours |
| Sign-off | The exception is written into your policy so it survives the next revision |
A Mac wants managing by something built for Macs. Enrolment, profiles, custody of the disk encryption keys and Apple updates handled properly, instead of bolted onto a Windows tool with a checkbox added.
| Position | Fleet console, Apple row |
|---|---|
| Watches for | Devices wandering off profile, updates deferred indefinitely, disks left unencrypted |
| Log kept | Profile state, update state and key custody, recorded against each device |
| Escalation path | Drift raises a callout; a device reported lost rings your contact immediately |
| Sign-off | Closed once the device is back on profile and the record says so |
Your staff read company mail on phones and hardly anybody looks at those. Zimperium lives on the device and rules there on the apps, on whichever network it has just joined, and on the operating system beneath, shipping nobody's messages anywhere.
| Position | Fleet console, handset row |
|---|---|
| Watches for | Apps behaving badly, hostile networks joined, and handsets stranded on old versions |
| Log kept | A risk state per handset and the findings raised, with no message content |
| Escalation path | A handset scoring high raises a callout and reaches your nominated contact |
| Sign-off | Closed once the handset is clean, or once it is taken off company mail |
Running devices properly removes a great deal of risk and generates none of the drama. Here is what it will not do.
Heads up: card statements show FORTIFY 24X7 - SecureOps Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.