Quiet neglect.
There is a machine in most small businesses that nobody thinks about. It runs the label printer, or the scanner, or a program from a supplier who has stopped answering the phone. It has not been updated in years, and it is on the same network as everything else.
Alongside it sits the laptop that works from home three days a week, well outside whatever your office firewall was doing, and a set of phones reading the same mail as the computers.
Update, watch, and filter.
Patching is the least interesting control in security and one of the most effective. Operating system and common third party updates are applied on a schedule you approve, and the machines that fail to take them are chased rather than quietly skipped.
Filtering happens at the name lookup, so a request to a known bad destination fails before any connection is attempted. It follows the laptop, which is what makes it useful now that the office is only sometimes where people work.
Apple and mobile, done properly.
Macs managed by a tool designed for Windows are managed badly. Addigy handles Apple hardware the way Apple intends: enrolment that survives a wipe, configuration profiles for disk encryption and updates, and software deployed without visiting the desk.
Phones get their own line, because they are computers that read your mail. Zimperium runs its detection on the handset itself, so a hostile network or a malicious application is caught without the device having to phone home first, and personal content is not collected in the process.
Reboots, and a real inventory.
Patching means restarts. We schedule them outside your working hours where we can, but a machine that is never left on will eventually need one at an inconvenient time. Tell us which machines must not restart during the day and we will treat them differently.
You will also need an honest count of devices. Most businesses undercount, usually forgetting the machine in the back office and the phones. We reconcile during deployment and adjust the subscription rather than leaving you paying for a guess.
Lines on this rung
4 lines · rates per unit, per monthRemote Monitoring and Management
The unglamorous work that keeps machines from becoming the easy way in. Operating system and third party patches, disk and health monitoring, and maintenance that runs whether or not anyone remembered.
- Windows and third party application patching on a schedule you approve.
- Alerts on disk, memory, service, and hardware health before they become tickets.
- Maintenance scripts run unattended and are reported on.
- Assisted access for support work, with the user's consent.
| Platform | N-able N-sight agent |
|---|---|
| Patching | Operating system and common third party applications |
| Monitoring | Disk, memory, services, and hardware health |
| Maintenance | Scheduled scripted tasks with reporting |
| Coverage | Windows workstations and servers, macOS for monitoring |
| Priced by | Managed device, monthly |
monthly, taken in advance QTY
Web and DNS Filtering
Filtering at the name lookup, so a request to a known bad destination fails before a connection is ever made. The policy rides along with the laptop, and that counts for far more than it sounds now that people work from anywhere.
- Category policy for the whole company or for a group of machines.
- Malware and phishing destinations blocked from published intelligence.
- The policy follows the device off your network.
- Blocked requests are logged, so a pattern is visible.
| Layer | Name resolution, before the connection is attempted |
|---|---|
| Policy | By category, per company or per group |
| Portability | Enforced wherever the device is connected |
| Logging | Blocked requests recorded and reportable |
| Requires | The N-able N-sight agent on the device |
| Priced by | Managed device, monthly |
monthly, taken in advance QTY
Apple Fleet Management
Macs, iPads, and iPhones managed the way Apple intends, with configuration profiles, software deployment, and enrolment that survives a wipe. Built for Apple rather than bolted onto a Windows tool.
- Zero touch enrolment for hardware bought through Apple Business Manager.
- Configuration profiles for FileVault, firewall, updates, and restrictions.
- Software deployed and updated without visiting the machine.
- Compliance state reported per device.
| Platform | Addigy, a management tool made for Apple hardware |
|---|---|
| Enrolment | Automated Device Enrolment where hardware qualifies |
| Policy | Configuration profiles including disk encryption and updates |
| Software | Deployment and patching for Apple platform applications |
| Coverage | macOS, iPadOS, and iOS |
| Priced by | Apple device, monthly |
monthly, taken in advance QTY
Mobile Threat Defense
Phones read the mail too. Hostile applications, intercepted connections, and a compromised operating system are all caught on the handset, where the analysis runs, rather than in some distant service the phone has to reach first.
- Detection runs on the handset, so it works without a connection.
- Malicious and risky applications identified before they settle in.
- Hostile networks and interception attempts flagged as they happen.
- Jailbreak and root detection on both platforms.
| Platform | Zimperium, detection performed on the device |
|---|---|
| Coverage | iOS and Android, company owned or personal |
| Detects | Malicious applications, network interception, device compromise |
| Privacy | Personal content is not read or collected |
| Priced by | Mobile device, monthly |
monthly, taken in advance QTY
Where this rung stops
This rung manages the devices you tell us about, and manages them well. It does not extend past that boundary.
- Personal devices outside your management are not covered. If staff read company mail on their own phones, decide deliberately whether those are enrolled.
- Filtering works at the name lookup. A destination reached by numeric address, or through a service that hides the lookup, is not stopped by it.
- Patching applies vendor updates. Software the vendor no longer supports cannot be patched, and the honest answer there is replacement.
- Monitoring reports on health and raises alerts. Repair of failed physical hardware is a separate arrangement and is not included in the monthly rate.
- A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.
One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.