Field Services
Endpoint & Access Hardening
Practical security work at the endpoint layer: disk encryption, patch posture, credential hygiene, MFA rollout, and removal of the standing local-admin rights nobody remembers granting. Scoped to what measurably reduces exposure, not to a compliance theatre checklist.
- Scopes it runs at
- 3
- Steps in a job
- 3
- Deliverables
- 5
- Estimate
- $0
Scope
What this looks like at your size
Most small and mid-sized estates are not breached through anything sophisticated. They are breached through a laptop with no disk encryption, a shared local administrator password, a user who has been a local admin since 2019, or a mailbox with no second factor. These are unglamorous and entirely fixable, and they are the same items an insurer or an auditor will ask about first.
- 01
A handful of machines
Encryption on, patching current, admin rights reduced, recovery keys escrowed somewhere they can actually be retrieved from.
- 02
A whole estate
The same baseline applied across every device, with an inventory of what was found and what was changed.
- 03
Audit or insurance preparation
Working from the questionnaire you have been given, so the answers are true when you sign them rather than aspirational.
How it runs
In the order the work happens
The sequence matters more than the list. Most of what goes wrong on these jobs traces back to a step skipped early rather than to the work itself.
- 01
Establish the actual state
Which machines are encrypted, which are patched, who holds local administrator rights, where recovery keys are, and which accounts have no second factor. Almost every estate contains at least one surprise here.
- 02
Fix the items that carry real risk first
Disk encryption with escrowed recovery, second factor on mail and remote access, local administrator rights removed from daily accounts. These are the ones that turn a lost laptop into a non-event.
- 03
Leave a record of what changed
What the baseline is, what was applied, and what was deliberately not — because an exception you decided on is different from one nobody noticed.
What you get
What is actually delivered
- Full-disk encryption enrolment and key escrow
- Patch posture audit with remediation plan
- MFA rollout and credential hygiene pass
- Local admin rights review and removal
- Offboarding runbook for departing staff
Not this
What we do not do here
Stating this is what makes the rest of the page worth believing, and it saves you a call that was never going to end in work.
- Penetration testing and red teaming.
- Formal compliance certification — we will get the estate into a defensible state; the attestation is an assessor's.
- Incident response and forensics on an active compromise, which needs a specialist firm.
Questions
Before you call
- Will this get in our users' way?
- Some of it is felt and most of it is not. Removing standing administrator rights is the change people notice; encryption and patching are invisible. We will tell you which is which before doing it rather than after the complaints.
- Can you help with an insurance questionnaire?
- Yes, and it is a common reason people call. We work from the actual questions so that what you attest to is true, which is the part that matters if you ever claim.
Related
Usually bought alongside
- Field Services
Workstation Deployment & Refresh
Seats imaged, staged, and cut over at floor scale without touching business hours.
- Infrastructure
Disaster Recovery & Business Continuity
Get trading again first, then get everything back — and know which is which beforehand.
- Infrastructure
Network Optimisation & Troubleshooting
Find the actual fault rather than the one everybody has been guessing at.
Next step
Need Endpoint & Access Hardening?
Free diagnostics and a written estimate before anyone is dispatched. Tell us the site and the deadline and we will tell you what it takes.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge