DEVICE SECURITY CHECKLIST

Are your business devices properly protected?

Review your laptops, computers, phones and tablets across updates, endpoint protection, encryption, access, monitoring and recovery.

Computers
Mobile devices
Encryption
Monitoring
0 of 22 answered0%
1
Inventory

Does your business maintain a current register of laptops, computers, phones and tablets?

The register should identify the device, assigned user, operating system, ownership and current status.

2
Inventory

Is it clear which devices are company-owned and which are personally owned?

Company-owned and BYOD devices may require different access, support, monitoring and data-handling controls.

3
Updates

Are all business devices running supported operating systems?

Unsupported Windows, macOS, Android and iOS versions may no longer receive important security updates.

4
Updates

Are operating-system security updates installed automatically or through managed patching?

Security updates should be installed promptly to reduce exposure to known vulnerabilities.

5
Updates

Are browsers and business applications updated regularly?

Applications such as browsers, PDF readers, collaboration tools and line-of-business software also require patching.

6
Protection

Is managed endpoint protection installed on every business device?

Antivirus, EDR or equivalent protection should be active, monitored and protected from unauthorised removal.

7
Protection

Is the operating-system firewall enabled on business devices?

A device firewall helps control unauthorised inbound and outbound network connections.

8
Data Protection

Is full-disk encryption enabled on business laptops and computers?

BitLocker and FileVault help protect business information if a device is lost or stolen.

9
Access

Do devices automatically lock after a short period of inactivity?

Automatic screen locking reduces the risk of unauthorised access when a device is left unattended.

10
Access

Are users required to use secure sign-in methods?

This may include strong passwords, PINs, biometrics and multi-factor authentication for connected business services.

11
Access

Are local administrator rights restricted?

Employees should not have permanent administrator access unless it is genuinely required for their role.

12
Management

Are devices enrolled in a remote-management or mobile-device-management platform?

Managed devices can receive policies, updates, software, security configuration and remote-support actions.

13
Management

Are non-compliant or unmanaged devices restricted from sensitive business data?

Access controls can prevent insecure devices from connecting to Microsoft 365, Google Workspace and other systems.

14
Management

Can lost or stolen devices be remotely locked or wiped?

Remote action helps reduce the impact of lost equipment and protects company information.

15
Recovery

Is important device data stored in approved cloud locations or backed up?

Business files should not exist only on the local device without an approved backup or synchronisation method.

16
Recovery

Has the business tested recovery of device data and applications?

Recovery testing confirms that important files and business applications can be restored when a device fails.

17
Data Protection

Is the use of removable USB storage controlled?

Unapproved USB devices can introduce malware or allow sensitive business information to leave the organisation.

18
Network

Are employees given guidance for using public Wi-Fi securely?

Employees should avoid insecure networks or use an approved secure connection such as a managed VPN or protected network service.

19
Network

Is remote access to business devices controlled and logged?

Remote-support and remote-desktop tools should require authorisation and provide appropriate logging.

20
Monitoring

Are device security alerts and health issues monitored?

The business should be notified about malware, missing protection, failed updates, disk issues and other security events.

21
Lifecycle

Are devices securely handled when an employee leaves?

The business should recover equipment, remove access, preserve required data and reset or wipe devices before reuse.

22
Lifecycle

Are retired devices securely wiped before disposal or resale?

Storage drives should be securely erased or destroyed before devices leave business control.

Please answer all questions to calculate your device security score.