Skip to content

What we protect

Devices.

Laptops nobody manages.

The personal laptops nobody manages are one of the ways in that gets skipped, and a shared Wi-Fi password that cannot be changed is the reason nobody can prove a leaver’s access is gone. This is the work on the devices themselves, and on what they are allowed to reach.

Where this gets in

the laptops nobody manages, and the password everybody knows.

Two questions decide most of this: what is actually connecting, and whose account is it connecting as?

  • Personal laptops nobody manages

    Most testing points at the network and the applications. The personal laptops that hold company access are the ones nobody manages and nobody tests.

  • A shared password cannot be revoked

    One Wi-Fi password known by every current employee, every former employee, every contractor who ever visited, and the personal phones of all of them. Changing it disrupts the whole company, so it never gets changed.

  • A laptop gone with access to production

    One of the three situations companies call us about. Answering it starts with knowing which device it was, whose account it used and what that account could reach.

The services

two services, and what each one covers.

Bringing the devices under management, and tying what they reach to a named account.

/ 01

endpoint hardening & management

Manage the laptops, including the ones nobody manages now.

Most testing points at the network and the applications; the personal laptops with company access are the ones that get skipped. We establish what is actually connecting, bring it under management, and close the gap where updates happen whenever somebody remembers rather than on a schedule. Devices also stop sitting on one flat network where the printer, the cameras and the systems holding company data can all reach each other.

  • the unmanaged personal laptops included, not excluded
  • updates on a schedule rather than when somebody remembers
  • devices that cannot reach everything else on one flat network
  • a record of what connected, and when

/ 02

device access & identity

Every connection attributable to a named account, not a shared secret.

Wi-Fi and remote access move onto the identity system you already have, so joining the network uses the same account as email, with a second factor available on remote access. Your own IT and security leads get read-only administrative accounts, so they can inspect any configuration, policy or log at any time without depending on us to see their own environment.

  • offboarding becomes a single action
  • every connection tied to a named account, not a shared password
  • a second factor on remote access
  • read-only accounts for your own leads, to inspect anything at any time

Where to start

where this work usually starts.

Where to start, and two engagements where the same problem had already been solved.

engagement

security posture assessment

Find out where you actually stand: which gaps matter, which don’t, and a short list in the order things should be fixed.

view details
case study

Wi-Fi that knows who you are

One shared password known by everyone who had ever visited, replaced by the identity system the company already had. Offboarding became a single action, and every connection is attributable to a named account.

read the case study
case study

A whole company on a shop-bought router

One flat network where the printer, the cameras, the laptops, personal phones and the systems holding company data could all reach each other — replaced in stages, so the business kept working throughout.

read the case study

the other five things we protect.

People

The inbox, and the person reading it.

4 services

Offices

The front door, and the room behind it.

2 services
See all 18 services in one list

Next step

make offboarding one action.

If someone left last month, can you prove their access is gone? If the answer involves changing a password everybody uses, that is the gap — and it is the same gap that decides how fast a lost laptop can be dealt with.