Does your business maintain a current register of laptops, computers, phones and tablets?
The register should identify the device, assigned user, operating system, ownership and current status.
Review your laptops, computers, phones and tablets across updates, endpoint protection, encryption, access, monitoring and recovery.
The register should identify the device, assigned user, operating system, ownership and current status.
Company-owned and BYOD devices may require different access, support, monitoring and data-handling controls.
Unsupported Windows, macOS, Android and iOS versions may no longer receive important security updates.
Security updates should be installed promptly to reduce exposure to known vulnerabilities.
Applications such as browsers, PDF readers, collaboration tools and line-of-business software also require patching.
Antivirus, EDR or equivalent protection should be active, monitored and protected from unauthorised removal.
A device firewall helps control unauthorised inbound and outbound network connections.
BitLocker and FileVault help protect business information if a device is lost or stolen.
Automatic screen locking reduces the risk of unauthorised access when a device is left unattended.
This may include strong passwords, PINs, biometrics and multi-factor authentication for connected business services.
Employees should not have permanent administrator access unless it is genuinely required for their role.
Managed devices can receive policies, updates, software, security configuration and remote-support actions.
Access controls can prevent insecure devices from connecting to Microsoft 365, Google Workspace and other systems.
Remote action helps reduce the impact of lost equipment and protects company information.
Business files should not exist only on the local device without an approved backup or synchronisation method.
Recovery testing confirms that important files and business applications can be restored when a device fails.
Unapproved USB devices can introduce malware or allow sensitive business information to leave the organisation.
Employees should avoid insecure networks or use an approved secure connection such as a managed VPN or protected network service.
Remote-support and remote-desktop tools should require authorisation and provide appropriate logging.
The business should be notified about malware, missing protection, failed updates, disk issues and other security events.
The business should recover equipment, remove access, preserve required data and reset or wipe devices before reuse.
Storage drives should be securely erased or destroyed before devices leave business control.
Please answer all questions to calculate your device security score.