Skip to content
Row of business laptops being prepared for rollout in an IT workshop

// Endpoint security · for Düsseldorf & the Rhine-Ruhr region

Endpoint security and device protection

Every laptop somebody opens is a way into your data. We set devices up to one standard, hold them in that state and keep an eye on them — outside the office as well.

// Why the device matters

In the end, somebody is sitting in front of a screen

Measures in the network only bite while data is in transit. On the machine it sits unencrypted in memory, the account is signed in, and the browser still holds an open session. Whoever holds the device no longer has to clear any of the other hurdles.

The second reason is variety. Devices arrive over years, each with its own initial setup, its own software level and its own rights. Nobody sees those differences in daily work — they surface when one particular machine turns out to be the gap that everything started from.

So we treat end devices as a fleet rather than as individual items: a known base image, a maintained software level, documented rights, and an inventory that also knows about the laptop sitting in a cupboard since a colleague moved on.

// Base configuration

What should look the same on every company device

  • Encrypted disk

    Active from the start, with the recovery key stored somewhere sensible. Encrypting later is hard to schedule, which is why it quietly never happens.

  • Rights on demand

    Daily work runs without administrator rights. Anyone who needs them gets a second, separate account rather than a standing exception.

  • Maintained software level

    Operating system, browser and business applications come from a central deployment. What is not on the list does not get installed afterwards either.

  • Controlled interfaces

    Removable media and foreign devices on the USB port are governed — released where they are needed and blocked everywhere else.

  • An endpoint that reports

    The device tells you its state: patch level, encryption, protective functions. A device that has said nothing for a long time is itself a finding.

IT technician enrolling a company laptop into device management software

// Lifecycle

A device has four phases, each with its own trap

Most gaps do not appear during operation. They appear at the handovers: when a device is issued, and when it leaves.

01 · Purchase

Decided before unboxing

Which model line, which specification, which service term. A uniform fleet is cheaper to run than whatever happened to be cheapest on each individual order.

02 · Issue

Always the same state

The device is built from a fixed image and enrolled into management before anyone receives it. Hand-built machines create differences nobody can find later.

03 · Operation

Hold the state

Updates, software and settings are applied without anyone standing at the device. Drift away from the target state shows up and gets corrected.

04 · Retirement

A clean separation

Withdraw accounts, remove the device from management, erase the disk with a record of it. Only then does it go to resale, donation or disposal.

Workstation with laptop and monitor in a darkened office

// When it happens anyway

A device behaving oddly should stand out, not slip through.

No protection catches everything. So on the device what counts is not only what gets blocked, but how quickly it becomes obvious that something is wrong — and how far that machine is still allowed to travel afterwards.

Monitoring and response
Behaviour, not signatures

What gets reported is what a program does: spawning foreign processes, rewriting files in bulk, switching protection off.

Isolate the device

A suspicious endpoint can be taken off the network without anybody driving out to it.

Keep the trail

What happened stays traceable — otherwise the post-mortem begins with guesswork.

A lost device

Locked and wiped remotely, because encryption was already active beforehand.

// Questions about device protection

What really counts in day-to-day device work

Something unclear? Get in touch
01

How does endpoint security differ from anti-virus software?

Anti-virus compares files against what is already known. Endpoint security covers the whole condition of the machine: how it was set up, which rights apply, whether the disk is encrypted and the patch level current — and whether odd behavior gets reported even when no known malicious file is involved.

02

Why should staff not hold local administrator rights?

Because a program inherits the rights of the account that started it. With admin rights, malware may install itself permanently and switch protection off; without them it usually stays confined to the user profile. Anyone who genuinely needs those rights gets a separate second account for them.

03

What happens if a laptop is left on a train?

On an encrypted machine the disk stays unreadable to a stranger. If the device is managed, it can also be locked and wiped remotely. In practice this is decided far earlier — by whether encryption and management were switched on when it was first set up.

04

How do updates reach devices when everyone works from home?

Through device management, not through the office network. A managed laptop reports its state as soon as it has internet and pulls updates and software from there. Whether the person sits in the office, at home or at a customer site changes nothing.

05

Can we mix company and personal devices?

Possible, yes. Advisable, rarely. On a personal machine you cannot reliably enforce condition and rights, and if it goes missing you have no handle at all. Where it cannot be avoided, we at least separate company data into a managed area of its own.

06

What happens to devices that are retired?

They come out of management, the disks are erased with a record of it, and account access is withdrawn. After that they can safely be passed on — through our hardware buyback as well, if there is residual value left in the machine.

Do you know what state your oldest laptop is in?

In most companies a handful of machines have slipped through the net. We take stock of the fleet and show which of them are genuinely a problem.